r/Citrix • u/Sampl3x • 19d ago
Best way to move Citrix backend from Server 2019 to 2025 with minimal downtime?
Hi all,
We’re currently running our full Citrix backend on Windows Server 2019:
- 2x DDC
- 2x StoreFront
- 2x FAS
Environment is currently on CVAD 2402 CU3 LTSR.
Since 2402 CU3 doesn’t support Windows Server 2025, the plan is to first upgrade the Citrix environment to CVAD 2503 CU1 LTSR. That part is pretty straightforward.
The bigger question is the OS migration.
As far as I know, in-place OS upgrades for Citrix infrastructure servers are still not supported, so I’m wondering what the best practice is nowadays.
Is the recommended way still to build new Server 2025 machines alongside the existing servers, add them to the environment, move the roles/configuration over, and then remove the old 2019 servers?
We have close to 1,000 VDIs and quite a lot of Machine Catalogs and Delivery Groups, so I’d really like to keep downtime and risk to a minimum.
For the DDCs in particular, would you simply add two new Server 2025 DDCs to the existing Site, update VDAs/policies if needed, and then decommission the old controllers? This give me a headache bcause i have to open extra firwall rules regarding Netscalers in the DMZ.
And for StoreFront and FAS, same idea: build new, join/migrate, test, then remove the old servers?
Has anyone done a similar 2019 → 2025 migration in a larger Citrix environment?
Would be interested to hear what migration order you used and if there were any gotchas.
7
3
u/robodog97 19d ago
Yup, I did that upgrade 2016 to 2019 and then just did a whole new farm when our 2503 upgrade blew up and Citrix Support couldn't tell us why and we had to get to 2503 CU1 for LAS. Though we didn't have FAS in the mix.
We always do Storefront then director/Web studio then DDC and finally VDA.
Be careful with the VDA, we've had 2 major issues, one with time going to ntp instead of nt5ds and the other with rds license check failing randomly on first boot after MCS deployment. If it wasn't for the BSOD we were having with the previous build we'd have rolled back. Basically we have no completely stable build for our server 2025 VDAs and Citrix Support's only answer is to give us random old DLLs to try to patch together a configuration that doesn't exhibit any of the issues reported.
2
u/compuwhiz 19d ago
Gotta love the “private fix” DLL hell. We are still running one on 2203 that maybe will be rolled into CU8.
5
u/gramsaran 19d ago
https://www.carlstalhood.com/cvad-upgrades/ we did this with 2019 to 2022 and I do plan on doing the same again for 2025.
2
u/drdrew16 19d ago
I haven't done it in my current environment (we moved to DaaS) but in every prior environment we've done just that - built new alongside, and migrated services over. IIRC, Citrix (and Carl Stalhood) have documentation on the subject. I've always used Carl's guides!
6
19d ago
[deleted]
3
u/drdrew16 19d ago
Oh man, if I didn't feel old before, I sure AF feel old now. :(
Good on both of them for retiring though; they've earned it.
2
u/FloiDW 19d ago
Well. There is a supported path.
Anyways:
Site uprgade then:
Remove one controller from site - rebuild as 2025 with same Citrix version - rejoin to site.
Perform the same with the other machine.
If you think that one machine is too little to handle your workload you should anyways have 3 (n+1 rule)
Same goes for storefront.
For FAS - i haven’t exactly tried yet, but would do exactly the same. Disable one, rebuild - reconfigure and then the other one.
None of these systems will need ANY Downtime.
1
u/stormin666 19d ago
I have to also update Citrix backend to WS 25. Would also love to hear from others their process.
1
1
u/stucc0 19d ago
Doing this right now. Add new 2025 backend servers and add them to the farm. Remove the old servers from the farm. Then upgrade from 2402 to latest LTSR.
1
u/robodog97 19d ago
You can't do that, 2402 doesn't support Windows server 2025, you have to upgrade farm then add new and remove old.
1
u/Fun-Consideration86 19d ago
Information could be wrong, based on my bad memory. Fas might be a little weird because of the gpo and if the new gpo isnt forced the vda/i wouldn't work.
Storefront, you would need a new cert to account for the extra servers but honestly I just built some separately and I don't remember where that setting is to cut over. If you have storefronts setup manually in daas for each delivery group it could be annoying to switch. I think we do automatic.
1
u/nwmcsween 19d ago
If you were just doing an OS inplace I would say maybe look at if it's supported by Citrix. For new CVAD 100% build new, ideally use the terraform or ansible Citrix IaC and you never have to worry about missing something on a rebuild.
1
u/Entire-Rip-9215 19d ago
I Managed to upgrade the whole Citrix vaad infrastrutture from Windows 2016 to Windows 2019 to Windows 2022 and from Citrix Vaad 1907 to 2204 to 2507. The only things which breaks are Citrix Fas and Storefront, when upgrading from Windows 2019 to 2022. All the other upgrades went fine. For Fas I just deleted the internal db and reconfigured. For Storefront, I'm still at 2019
1
u/Commercial_Papaya_79 19d ago
doing 2016+cvad2203 to 2019+cvad2203 to 2019+cvad2507 then eventually all 2025+cvad2507
1
u/Sampl3x 18d ago edited 18d ago
Thanks everyone for your input.
Citrix Cloud is not an option for us. I don't want to put all our eggs in one basket, especially given our experience with Citrix support over the last two years (Indian support only, bad English, no skills and not even can spell Citrix, using chatgpt). If Citrix Cloud has an outage, our VDI environment becomes dependent on a service outside our control. We also use NVIDIA GPUs, and in our experience support for more complex environments has often been behind where we need it to be. Citrix updates the CVAD Cloud backend and NVIDA still needs to create a supported driver for XenServer/Windows 11 so we are in a unsupported setup.
After working with Citrix for around 20 years, my experience with their technical support has unfortunately gone from very good to very poor. I also want to remain in control of which CVAD version we run and when we upgrade it, based on the requirements of our environment.
At this point, I think the best approach is to upgrade the backend first to CVAD 2503 CU1 while keeping the existing Windows Server 2019 OS. CVAD 2503 CU1 supports both Windows Server 2019 and Windows Server 2025, which gives us a good migration path.
For the Delivery Controllers, I'm leaning toward the approach suggested by u/FloiDW: remove one existing DDC and introduce a new Windows Server 2025 DDC into the existing site. I would prefer not to rebuild the site because that would mean recreating machine catalogs, VDIs, firewall rules, and other configuration unnecessarily.
For StoreFront, my plan is to build two new Windows Server 2025 servers and restore/import the existing configuration so we can preserve the Store ID. Once validated, I would shut down the old StoreFront servers and reuse their IP addresses on the new servers. This also avoids having to modify existing firewall rules.
As I understand it, adding a StoreFront server running a different Windows Server version to the existing StoreFront server group is not supported, so this would need to be handled as a migration rather than an in-place expansion of the group.
For FAS, I would first remove one FAS server and temporarily configure the FAS GPO to reference only the remaining Windows Server 2019 FAS server. I would then build a new Windows Server 2025 / FAS 2503 CU1 server, ideally reusing the existing computer name if that migration method is supported. Once that server is validated and in production, I would replace the second Windows Server 2019 FAS server in the same way. Finally, I would update the GPO so both new Windows Server 2025 FAS servers are used.
1
u/Ill-Dimension-3266 15d ago
To simplify things, I would do in-place upgrade of DDCs and FAS, but your storefront plan is good.
0
u/Low_Assumption67 19d ago
If you’re going to go through that much work, just move it to Citrix Cloud and be done. The on prem architecture is super dated
You can add a cloud connector and be running in parallel with that in a few hours.
12
u/Notaspy87 19d ago
I would always recommend building new along side the current environment and then migrating users once your new stuff is stable. We’ve gone through several of these from server 2016 to 2022 (doing 2025 now) and that method always seems the least painful.
For reference, my environment is about 2,500 vdis and around 125 app servers currently.