Link to home
Start Free TrialLog in
Avatar of mpssasan
mpssasanFlag for Canada

asked on

Folder access to external users with Citrix

We have Citrix Presentation server farm. It is working internally for all users. We need to publish a file share (Folder shared on a file server) to allow access to external users connected via internet.
The present set up I have is
Published share as an application with command line c:\windows\explorer.exe "\\servername\sharename" and working directory as %homedrive%%homepath%

It is opening up the share as far as user logged in from within the network but not externally.
However, another conern, even if user is logged in from the withing the network, he can accessed the share and at the same time he can navigate the network which we don't want. Example, after share is opened in a new window, click on "up" icon and it goes to higher level. User may not be open any doucment but it still give visibility to other resources on the network.
From outside of the network, it error out with "path not found" error because itis looking for the resource on the local disk.

Our objectives are:
Provide access to a share for users from outside of the company netwrok, accessing citrix server via URL (Cannot give external IP to file server, and not prefer to use log on scripts)
Make sure user cannot browse through  the network.

Any help is highly appreciated
Avatar of AcceleraSolutions
AcceleraSolutions
Flag of United States of America image

The easiest way I know how to do this is to use the NetScalers file share utility.  When a user logs in through the netscaler you can present them with file shares, and they are unable to click up to up an additional level.

I do not know if this is possible in Windows because you are limited by Windows itself.  Any share you open in windows will give you this option.
Avatar of mouseware
mouseware

The only way I could see this happening is by using GPOs, login scripts, and NTFS/Share permissions. GPO to hide all local drives (except the mapping) and prevent users from browsing the network, and a logon script to map a drive.
Avatar of mpssasan

ASKER

Hello mouseware
Please elaborate on GPO and login scripts, if you can give example or steps that will be great and appreciated.
ASKER CERTIFIED SOLUTION
Avatar of mouseware
mouseware

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial