Secure Gateway 3 and Web Interface 4.2 Multiple Site
Posted on 2006-06-28
I am having some issues configuring a second Web Interface site. We currently have one Citrix Farm supporting one company. We have a second small company of a couple dozen users who will also be accessing some apps in the farm. The partners want this second company to have their own branded WI site. I get as far as creating a second site in IIS 6 and changing the port to 444 and then the second site stops running in IIS. It says the port is already in use. 444? I'm specifyng IP addresses in IIS for the WI site 1 and this second one.
My current config is a single IIS 6 box (W2k3 SP1) in my DMZ with WI 4.2 and CSG 3.0 installed on it. PS4 servers are behing the firewall. I have a cert for secure gateway. I have a cert for my primary WI site. I have a cert for my 2nd WI site. CSG, WI site 1, and WI site 2 each have separate public IP's so no NAT or translation going on. This should be a very direct config but IIS is killing me off the bat.
I also forsee a problem with my current setup once this hurdle is cleared. Since everything is on the same box I am using the Indirect Access option in my CSG configuration. I have unchecked the "Installed on this computer" option so I can specify the FQDN for my WI site 1 in the field. This is the only way I could get it to work when I specified the specific IP address in IIS for my WI site 1. If I leave "Installed on this computer" checked off the only way to get access to the WI site 1 through CSG was to not specify an IP address in IIS and leave "All Unassigned".
My concern here, since CSG is specifying WI Site 1 in the config is how will it interact with Site 2 once I get it running in IIS? My guess is I have something fundamentally misconfigured here but I've tried every iteration I can think of to get just the one site working with specified IP addresses in IIS and this is the only way I could get the pages to come up correctly.
So, I have two tasks here:
1. Get the second site running on 444 in IIS6.
2. Get my CSG setup correctly to work with multiple WI sites.