Configure the network ranges from which you want users' application or desktop launch traffic (ICA traffic) to be routed directly to the XenApp server. This configuration is typically used to provide internal access to the Citrix-published resources integrated with Workspace ONE Access.

When a user launches an application or desktop from the Workspace ONE Intelligent Hub app or portal, if the user's IP address falls in the internal network range, the ICA traffic is routed directly to the XenApp server.

Note: To configure resource launch for external networks, see Configuring Citrix Resource Launch for External Networks with Citrix Gateway.


A Super Admin role, or a custom role that can perform the Manage Settings action in the Identity and Access Management service, is required to create and edit network ranges.


  1. In the Workspace ONE Access console, select Resources > Virtual Apps Collections.
  2. Click the Citrix collection for which you want to set network ranges.
  3. Select the Network Ranges tab.
  4. In the Network Ranges tab, click the network range to configure for internal Citrix resource launch so that end users accessing Citrix resources from an internal network can connect to the correct server.
    1. Click the network range to edit or create a new network range, if necessary.
    2. If you are creating a new network range, enter a name, optional description, and the IP address range.
    3. Scroll to the Server Farm section.
      This section lists all the XenApp servers that you configured in the Citrix virtual apps collection.
    4. For each XenApp server, enter the appropriate values for this network range.
      Option Description
      Client Access FQDN

      Enter the complete StoreFront URL. This entry must match the URL that you entered in the StoreFront Server URL text box in the virtual apps collection.

      Use the following format:


      For example:

      If a load balancer is configured, use the following format:


      Port The StoreFront server port. For example, 443.

      If you entered a load balancer URL in the Client Access FQDN text box, use port 443.

      NetScaler Set this option to No.

      edit network range dialog box

    5. Click Save.
    6. Repeat these steps to edit the other network ranges, if necessary.
    Important: Verify that each network range in your environment has a Client Access FQDN set. If a network range is missing the Client Access FQDN, users accessing resources through that network range cannot launch their Citrix desktops and applications.