This message was deleted.
# citrix-vad
s
This message was deleted.
b
In the properties of the Delivery Group you have the option under Access Policy to select "Connections through NetScaler Gateway" and deselect "All connections not through NetScaler Gateway".
đź’Ż 1
r
I need to look at my notes, but I recall doing this before. But look here “Connection Type” “Again when editing a Delivery Group under the Access Policy section you can allow connections that do not come through NetScaler Gateway, do come through NetScaler Gateway or both.” https://jgspiers.com/controlling-application-and-desktop-access/
s
@Bruce Payne - DG has both apps and desktop, if I do that then apps will not be accessible internally
I believe it’s for entire DG, correct. We can’t do granular.
b
We were discussing options for this just this week. Single Store and want to hide apps from external users. The topic has not been fully developed, but we were tossing around "Key Words" on the Store and then hiding those items in Studio from external access that have the Key Word. Like I said...haven't completed the thoughts on that one.
s
Our setup - Single Gateway pointed to single store. If I use keywords and filter resources, then those resources will be hidden in both StoreFront and Gateway since Gateway is talking to single store.
m
Got it, you are right. Maybe you can use the SDK to set an Excluded Client IP Filter and specify your internal subnet? Check Example 2: https://developer-docs.citrix.com/en-us/citrix-daas-sdk/Broker/Set-BrokerAccessPolicyRule/