I have a Cisco firewall in place. Do i just NAT 443 to my Citrix Web Interface?
Main Topics
Browse All TopicsHi,
I want to be able to provide Citrix Apps from the real world. I currently have Citrix PS 4.5 running internally.
What is the best and most secure way to do this?
Do i just buy a certificate and select 443 in IIS and just NAT it through my firewall or use CSG??
Got no experience with CSG but is this recommended?
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I disagree with not using Secure Gateway.
There are 2 remote options, you can install Secure Gateway, purchase your Cert and push 443 from your firewall to your SG and things are secure.
If you would prefer an appliance, you can get the Citrix Access Gateway, which works just like secure gateway but is an appliance. It has other features such as Endpoint analysis, and you can have seperate application policies for remote users. For instance, if you wanted to just give them outlook, but internally they get 10 other applications you can do that.
I wouldn't use VPN either, makes life more difficult.
Get your Cert, install SG on your Web interface box, configure it, point 443 to that same box, and wham you are good to go in less then 20 minutes.
Monarchit
If your WI is in the DMZ do all users hit it via the external FQDN? If they don't then you are going to have put an altaddr record on the WI to make sure to change the ICA files to an external IP, not a problem to do just a little more complication that Secure Gateway does for you.
I personally wouldn't recommend just natting 443 through unless you are using Secure Gatway.
Secure Gateway comes with PS 4.5 might as well use it, it makes your life easier on the config side, and SSL management side. I believe it's on the Components CD, but it is on one of them, i just can't remember which off the top of my head. You can also download it from your My Citrix account.
The FREE Citrix Secure Gateway is a piece of cake to install, setup and use.
I use a GoDaddy wildcard SLL cert on my personal lab setups.
http://www.msterminalservi
http://www.msterminalservi
Citrix doesn't recommend installing CSG and WI on the same server but they support it and I have NEVER had an issue with it.
Business Accounts
Answer for Membership
by: mrwalker15Posted on 2008-10-27 at 07:17:17ID: 22812882
I dont recommend CSG/AGEE from personal experience.
My suggestion is to use a SSL VPN appliance such a Juniper, F5 or Cisco.