Link to home
Start Free TrialLog in
Avatar of Ekuskowski
Ekuskowski

asked on

Citrix Web interface down

We currently have 4 Citrix presentation 4.5 servers in the farm each configured identical ( for application installation ). each of them have the web interface installed and when you connect to citrix from home you get one of the servers. The users have no idea we have four servers , it is seamless to them.

The problem is that if i shutdown our server called "Citrix01" no one can get to the web interface from home.

I know basically nothing about the citrix servers as i did not initially set them up,  but i think citrix has a database or something to manage itself. My guess is this piece is running on "Citrix01"

does this make sense ?

any one know a way to avoid this issue ?

Periodically we disable certain servers for maintencnce , but obviously "CITRIX01" cannot be shutdown for maintence

Thanks
Avatar of Carl Webster
Carl Webster
Flag of United States of America image

You should have the Web Interface installed on only one server.  Ideally that server would be in the DMZ and be behind a Citrix Secure Gateway (CSG) server or Citrix Access Gateway appliance.  CSG is FREE and helps secure your Citrix traffic with SSL.

My recommendation would be to have 1 server, can be low end or virtual, that has CSG and WI installed.  The WI server points to the XML Broker/Data Collector for your farm (command prompt qfarm /zone will tell you that server) plus another for backup.  User hits the URL for the CSG box, CSG routes to WI, WI routes to XML Broker for authentication, XML Broker provides lists of apps and servers to WI, WI builds list of apps for the user and icons, users clicks an icon, XML Broker determines the least busiest server and directs the user to that server, the server launches the app and the user gets to work.
I assume the NAT in your firewall points to Citrix01, which explains why your users can't connect when it is down. There really isn't anyway around this with your current setup.

Carl suggestions are great for securing your farm. The only thing that I would add is that if you would would want to add some redundancy, create two web interface server and use microsoft NLB.
Avatar of Ekuskowski
Ekuskowski

ASKER

Thanks CarlWebster for the security info, we are thinking of rebuilding our Citrix environment using 2008 servers and the latest version of Citrix maybe we will change our setup at that time and use the CSG as you suggested.

I'm still confused on the XML Broker/Data collector

Currently when i run qfarm /zone
I get Zone Name 192.168.1.0 and Data collector Citrix01 no backups ( which is probably my problem)

Is the data collector and XML broker the same thing ??

It seems that the webserver needs to contact the XML broker in order to display the published applications. Where in IIS do I look to see or change the location of the XML broker ?
One  more thing to add,  when i log into my web interface, it takes about 45-seconds before i see my published apps. Could this delay also be related to the webserver or XML Broker communication ???
ASKER CERTIFIED SOLUTION
Avatar of Carl Webster
Carl Webster
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial