Hi Daniel, try this one described here
https://www.julianjakob.com/citrix-adc-always-on-machine-user-tunnel-vpn/#Configuration_Hints
⢠The Client-Registry REG_SZ
suffixList is the DNS-Suffix which you configured in your ADC Setup. This is used by the AOVPN Service to check if the Secure Access Client is able to resolve the FQDN with a private or public IP, to choose if a VPN connection has to initiate (external) or not (when connected directly internal). Set your ADS FQDN with
add dns suffix contoso.local.
Try to modify the suffixList Regkey at the client and set another internal entry which resolves to an internal IP.
But yes, it's frustrating that the global DNS Suffix configured on NetScaler is used to determine the AlwaysOn on the Clientside š I requested a config change for that to Citrix, but this will take a while...