Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Secure Gateway & Presentation Server 4.5

Posted on 2007-11-28
4
Medium Priority
?
1,473 Views
Last Modified: 2010-04-21
Everything is working great internally and externally for Citrix users using Http instead of Https.
Current setup is:
External: citrix.domain.com
Internal: citrix.domain.local (192.168.1.0 IP Range)

I am using ISA Server 2004 and have a standard Publishing Rule for traffic 1494, 2598, & 80 to go citrix.domain.local.  I setup access routs as follows:
Default - Translated
192.168.1.0 - Direct.
Firewall translations:
citrix.domain.local 80 to citrix.domain.com 80
citrix.domain.local 1494 to citrix.domain.com 1494
citrix.domain.local 2598 to citrix.domain.com 2598

Users can go to http://citrix.domain.com/citrix/accessplatform from home and everything works great.
So, I setup Secure gateway.  Went through the wizard ok with no problem.

Setup the gateway settings as:
FQDN:  citrix.domain.local
STA FQDN:  http://citrix.domain.com/Scripts/ctxsta.dll
Port: 443
Session Reliablity Checked.
Installed the Root Certificate from my server
Open up a port on the ISA to allow traffice on 443.
I also tried to setup a address translation for port 443 with no luck.

I can go to https://citrix.domain.com/citrix/accessplatform and login, but the server cannot be found when I click on an application.  Running a sniffer shows it is trying to connect to citrix.domain.local and not citrix.domain.com which should be a translation issue, but I have tried every combination.

Basic setup is:
Public IP - ISAServer 2004 - Private IP (192.168.1.0) NAT
Citrix computer is a member server on the private subnet

Thanks!!
0
Comment
Question by:tyty4u2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 11

Expert Comment

by:AdamBNYC
ID: 20400951
Redirection to https in 4.5. On the server that is holding the secure gateway go to
C:\Inetpub\wwwroot\webinterface.htm

Edit this file, and make these changes and you should be set. All your changing is the address. This will redirect to https

<!--
  WebInterface.htm
  Copyright (c) 2000 - 2006 Citrix Systems, Inc. All Rights Reserved.
  Web Interface 4.5.1.8215
-->
<script type="text/javascript">
  <!--
  window.location="https://YOURPORTAL.ADDRESSGOESHERE.com/Citrix/AccessPlatform";
  // -->
</script>
0
 
LVL 11

Accepted Solution

by:
AdamBNYC earned 2000 total points
ID: 20400977
Also did you look at the DMZ settings for the web interface on the secure gateway. When you go into the access management console, you expand out web interface, click on your website, then click manage secure client access, go into the DMZ settings. I believe the setting you may be looking for is gateway direct. Since this is WAN side, you probably dont need to put anything else in here, unless you have your local network users pointed to the secure gateway for access, then you will have to put some other DMZ settings in there. Let me know how it goes.
0
 

Author Comment

by:tyty4u2
ID: 20401013
I appreciate the help.  I have had this question posted for awhile with no response and wouldn't ya know it, I fix it and I get a response.  

I ended up changing the 192.168.1.0 translation to Gateway Direct and the default to Gateway Translation and that seemed to fix the problem.  Its VERY odd that the 192.168.1.0 translation was taking presidence no matter what, even externally, but only when using HTTPS.  HTTP translated ok.  I ended up getting it resolved by setting up a new Web Interface Site and trying every possible combination.

Ran a packet sniffer and all traffice was going over HTTS and TLS.  Also opened the launch.ica and saw the address as being encrypted.

Thanks for the help though.
0
 

Author Closing Comment

by:tyty4u2
ID: 31411595
I ended up fixing it before I received a response, but this answer was correct.  THANKS!
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #POC #XenDesktop #vCenter #VMware #ESX
Several part series to implement Internet Explorer 11 Enterprise Mode
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question