I wanted to test this out for myself, so I span up a NetScaler in my lab and started the configuration. I wanted to enable AAA so that I could pre-authenticate requests into my web applications (Outlook Web Access in my lab). The below picture shows an overview (check out the Citrix article it is linked from!)
Firstly I completed the NetScaler Gateway Wizard and ensured that I could authenticate and launch desktops from my XD7.11 lab.
Next I followed Dave Bretty's blog to Content Switch the NetScaler Gateway VS and a newly created VS for OWA.
Then I created an Authentication VS, then created a policy which say any requests to the AAA address would go to the authentication VS. Lastly I went to bind the policy to my Content Switch VS. I received the titled error message.
This left me scratching my head for a while. The VPN server that is mentioned is the NetScaler Gateway VS. Then it struck me, the NetScaler Gateway is completing pre-authentication, I should just be able to use this VS.
I went into the LB VS for OWA and under authentication I chose Form Based Authentication, Authentication FQDN needs to be the NS gateway address. Lastly ensure that the NetScaler Gateway VS is the one that is being used for NS gateway.
After saving this, when trying to go to email URL (email.domain.com) the NetScaler should redirect this to the NS Gateway URL (xendesktop.domain.com). After successfully authenticating, the NetScaler should redirect to the email URL (email.domain.com) and if you have IWA enabled on your exchange server, you should be presented with your inbox!