Your users reach DaaS, web apps and servers from outside. That front door has to be one you can patch tonight — NetScaler Gateway is the Citrix appliance in front of DaaS — SSL VPN, ICA proxy, clientless and RDP access with AAA sign-in, on MPX or VPX you run. Patch status: only 14.1-73.37 and 13.1-64.23 or later fix the September 2026 zero-days.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers NetScaler Gateway — the remote-access role of NetScaler, in Advanced and Premium editions. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
One internet-facing appliance that signs users in and then gives them a VPN tunnel, a virtual-app session or a browser path inward.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN, a jump host and a VDI portal | NetScaler Gateway |
|---|---|---|
| Front doors to maintain | A VPN, an RDP jump host and a VDI portal | One Gateway vserver for VPN, ICA proxy and RDP |
| Reaching virtual apps | Full tunnel first, then the desktop | ICA proxy straight to the DaaS session |
| Unmanaged devices | Install a client or refuse access | Clientless browser access to web apps |
| Device checks | Trust whatever connects | EPA scan, then SmartAccess rules (extra licence) |
| Where sessions end | Scattered across boxes and clouds | On the MPX or VPX you place, in India if you choose |
| What it is NOT | — | Per-app zero trust, or a box you can leave unpatched |
The cheapest first step is a build check: list every Gateway and AAA vserver with its running version and compare it with 14.1-73.37 and 13.1-64.23.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
One virtual server on the appliance carries the user-facing modes: a full SSL VPN tunnel, ICA proxy for virtual apps, clientless web access and RDP proxy.
An authentication, authorisation and auditing server checks every sign-in first; it is also a configuration named in the CitrixBleed advisories, so patch it with the gateway.
The Citrix Secure Access client builds the full tunnel on Windows and macOS, and the Endpoint Analysis client scans the device first; both took fixes in July 2026.
Gateway ships on MPX physical boxes or VPX virtual ones that you host; hardware is bought apart from the software subscription and keeps RMA cover for the device’s life.
One appliance at the edge — AAA sign-in first, then SSL VPN, ICA proxy, clientless or RDP proxy on MPX or VPX you run.
NetScaler Gateway signs remote users in once, then hands them a tunnel, a virtual-app session or a browser path.
The Secure Access client opens an SSL VPN tunnel from Windows or macOS, so thick-client and legacy apps work as if users sat in the office.
ICA proxy relays Citrix DaaS sessions through the appliance, so users open published apps and desktops without any network tunnel.
Clientless VPN serves internal web apps in a browser with nothing installed, and RDP proxy carries remote-desktop sessions without a full tunnel.
nFactor strings together SAML, OAuth, LDAP, RADIUS, TACACS, client certificates and native or push OTP before any session starts.
Endpoint Analysis checks the device before access is granted; for virtual-app policies it needs extra universal licences on top of the edition.
SmartAccess and SmartControl turn scan outcomes into rules for what a virtual-app session may do; both sit behind the same extra licence.
NetScaler’s WAF and API security tools can sit in front of Gateway and authentication vservers, as Citrix’s own NetScaler demo shows.
NetScaler Console, formerly ADM, can set up ACME and zero-touch certificate management, so Gateway certificates renew without a manual swap.
Since 15 April 2026 Citrix products activate through the License Activation Service; appliances left on licence files stop working.
WAF protection for Gateway and sign-in vservers, ACME certificate renewals from NetScaler Console, and a 2017 Unified Gateway overview for background.
Putting NetScaler’s WAF and API security tools in front of Gateway and authentication virtual servers.
Setting up ACME and zero-touch certificate handling for NetScaler appliances from NetScaler Console.
A 2017 overview of Unified Gateway; names, builds and licensing have all changed since, so treat it as background.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
The same appliance relays Citrix DaaS sessions through ICA proxy and runs a full SSL VPN for everything else, with clientless web access and RDP proxy beside them. For a Citrix estate that means one internet-facing edge, one sign-in through the AAA server and one set of certificates, not three separate front ends.
Gateway is an MPX appliance or a VPX virtual appliance in your own data centre or cloud account, so every remote session ends on infrastructure you control. That suits Indian teams that want the termination point in India, since Citrix Cloud itself offers only US, EU and Asia Pacific South regions.
Endpoint Analysis scans a device before it connects, and SmartAccess and SmartControl let the result decide what a virtual-app session may do. For virtual apps and desktops those features need extra universal licences, so put them in the first quote rather than finding them mid-rollout.
This is the most attacked part of a Citrix estate: CitrixBleed in 2023, CitrixBleed 2 and two more KEV-listed flaws in 2025, then the exploited CVE-2026-88771 and 88772 in September 2026. Builds before 14.1-73.37 or 13.1-64.23 are exposed. And as a VPN it grants network reach, not per-app zero trust.
Read the running version on each Gateway; anything below 14.1-73.37 or 13.1-64.23 is exposed to the exploited September 2026 flaws.
Upgrade each appliance, then review sessions and logs for earlier compromise; a patch does not remove an intruder already inside.
13.1 left maintenance on 15 September 2026, so schedule the move to 14.1, which Citrix maintains until 8 August 2029.
Sort users into ICA proxy only, clientless web, RDP admins and true full-tunnel needs; DaaS-only users can stay on ICA proxy.
Pilot SecurAccess ZTNA beside the VPN for private web and TCP apps; Citrix supports running both together for a gradual move.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“After the September advisory we went from 13.1-58.32 to 13.1-64.23 overnight. The CitrixBleed 2 build alone was not enough.”
“ICA proxy is why we keep it. Branch staff open their DaaS desktops from one URL and never get a full network tunnel.”
“The EPA scan stops unpatched laptops before login, but the extra universal licences surprised our finance team at renewal.”
“We run a VPX pair in our own Mumbai data centre, so every remote session ends on infrastructure we control.”
“Moving activation to the License Activation Service before April mattered; a lab box still on a licence file went dark.”
“Contractors use clientless access for two web apps with nothing to install, and RDP proxy covers our server admins.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the remote access gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted; Fixed Capacity or inside a Citrix platform subscription.
The grid nobody publishes — how many access paths the product offers vs how much of the internet-facing edge the vendor runs and patches for you.
VPN, ICA proxy, clientless and RDP proxy; every box is yours to patch.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Palo Alto GlobalProtect, Fortinet FortiGate VPN, Cisco Secure Client, Zscaler ZPA and F5 BIG-IP Zero Trust Access — on access modes, VDI, posture, price, exploited flaws, patching and India.
| Dimension | NetScaler Gateway | Palo Alto GlobalProtect | Fortinet FortiGate VPN | Cisco Secure Client | Zscaler Private Access (ZPA) | F5 BIG-IP Zero Trust Access |
|---|---|---|---|---|---|---|
| What it is | Citrix VPN + ICA proxy | NGFW or Prisma VPN | VPN on the firewall | Client for Cisco kit | Cloud ZTNA, no VPN | BIG-IP access module |
| Where it runs | MPX or VPX, yours | Firewall or Prisma cloud | Your FortiGate | Your Cisco headend | Cloud plus connectors | BIG-IP you host |
| Access modes | Tunnel, clientless, RDP | Agent + clientless | IPsec dial-up client | Device or per-app VPN | Connector app + browser | Proxy, Per-App, IPsec |
| Virtual desktop access | Native ICA proxy | Inside the tunnel | Through the IPsec tunnel | Tunnel to the desktop | Desktop as a private app | Citrix VDI listed |
| Device posture | EPA, extra licence | HIP needs a licence | Posture is a paid tier | Posture in Premier | Agent + browser signals | MDM verdicts gate access |
| Identity and MFA | nFactor, SAML, OTP | LDAP, SAML, RADIUS… | FortiAuthenticator adds | SAML at the headend | SAML, OIDC, SCIM | SAML, OAuth, OIDC |
| Pricing model | Edition on an appliance | Free base, paid extras | Firewall-bundled | Per unique user | Per-user editions | BIG-IP licence models |
| Published entry price | Not published | Basic VPN at no charge | No public price | 25-user minimum | Reported $4–11/user | Unpriced on f5.com |
| Included vs add-on | Universal licences extra | Gateway licence per box | Enterprise for support | Premier for posture | Network Connector extra | Module plus platform |
| Exploited flaws | 5 KEV entries since 2025 | CVE-2024-3400 | CVE-2024-21762 | CVE-2023-20269 | No VPN listener | Two exploited in 2026 |
| Who patches the edge | You, every appliance | You, or Palo Alto | You, on each FortiGate | You, on each headend | Zscaler, mostly | You; old trains lapsed |
| India termination | Your Indian site | Your site or Mumbai | Your Indian FortiGate | Your Indian headend | Indian PoPs unnamed | Your own Indian BIG-IP |
| Lock-in and exit | Tied to Citrix DaaS | Palo Alto firewalls | FortiGate required | Cisco headends | Zscaler’s cloud | BIG-IP policy flows |
| Best fit | Citrix DaaS estates | Palo Alto firewall shops | FortiGate estates | Cisco network estates | Retiring the VPN | BIG-IP owners |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no remote access gateway guide yet, so NetScaler Gateway sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (remote users; admin-hour cost). Estimates model IT time spent per remote user on client installs, access tickets and separate VPN, RDP and VDI front ends at an assumed 1.5 hours per user a year, with 70% of it removed by one gateway and one sign-in. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Citrix publishes no price for NetScaler Gateway or any current offering. Gateway runs on NetScaler, bought standalone as NetScaler Fixed Capacity (throughput and instances bought individually) or bundled into Universal Hybrid Multi-Cloud and Citrix Platform subscriptions; MPX hardware is bought separately and carries RMA for the device’s life. For virtual-app use, EPA, SmartAccess and SmartControl need extra universal licences. Citrix shows no rupee price. TechBag checks your builds and users first, then quotes in INR with GST.
Best for a Gateway bought on its own
Best for a broader rollout
Best for estates already licensing Citrix DaaS
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is every Gateway and AAA vserver on 14.1-73.37, 13.1-64.23 or later, or on 14.1-73.37 FIPS or 13.1-37.279 FIPS?
Is any appliance still on 13.1, out of maintenance since 15 Sep 2026, or on 12.1 or 13.0, already end-of-life?
Has every appliance moved to the License Activation Service, which replaced licence files on 15 April 2026?
Advanced or Premium, and does the quote include universal licences for EPA, SmartAccess and SmartControl?
Are Windows Secure Access and EPA clients updated for July 2026’s CVE-2026-53565 and CVE-2026-53566?
Which users truly need a full tunnel, and which can use ICA proxy, clientless access or RDP proxy instead?
Does nFactor enforce MFA, through SAML, RADIUS or native OTP, on every Gateway mode you expose?
Will the appliances sit in an Indian data centre or cloud region, and is a hardware RMA path agreed?
Check your builds against the September 2026 fixes first, or let a TechBag advisor map which users need a tunnel and which only need ICA proxy.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.