Solved

XenApp 6 : securing internet surfing

Posted on 2010-08-23
5
830 Views
Last Modified: 2013-11-16
Hello !

I've got some workstations with critical informations which I would like to isolate from Internet. Currently, their users don't have any network connexion and use separate computer for internet surfing.

I'd like to simplify this, and use virtualisation instead.

I've thought of XenApp, and publish a browser such IE8, Firefox or whatever, which will run on a server inside the DMZ.
Unfortunatly, I don't have any experiences with Citrix.

1- Is this a good  idea ? Will the security be safe enough ?

2- What about the user experience ? (e.g. : the user click on a hypertext link, will XenApp intercept it and run it in the streamed browser ?) Of course, I'd like a solution as transparent as possible for the users...

Thank you for your opinions,


Best regards
0
Comment
Question by:DL_Stephane
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 10

Expert Comment

by:yasserd
ID: 33508477
I have no idea about XenApp. But this is what I thought about using virtualization as that's what you want.

You could install a virtual guest OS and an additional NIC on each PC. Configure the guest OS to use the new NIC and connect it to the Internet network.

This way all internet traffic would go through a different route and there would be no connection between the OS used for internet and the one containing the critical information.

Regards
0
 

Author Comment

by:DL_Stephane
ID: 33508846
Yes, I've thought of that too, but I'd like to find a solution as transparent as possible for the user and some of the computers are thin client so I can't add a new NIC...

Thx anyway.

Nobody here with good XenApp skills ?






0
 
LVL 7

Accepted Solution

by:
dnsguru44 earned 500 total points
ID: 33519106
In regards to you question #1, yes, citrix ica client is as secure as you want it to be, it has up to 256-bit encryption but even in it's default (basic) state if the stream was intercepted the only thing that is being transferred are key/mouse strokes and pixel views.  Of course, your corporate firewall will play a key role as well.

#2 - I would need to understand more about your farm architecture, but quick and dirty answer is yes, this can be accomplished via client to server redirection.
0
 
LVL 38

Expert Comment

by:younghv
ID: 34580879
This question has been classified as abandoned and is being closed as part of the Cleanup Program.  See my comment at the end of the question for more details.
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Internet Protocol Security question 3 117
Search all sub-folder 4 46
Looking for a program called HoneyMine. 3 73
Behavior-based and anomalies detection for Microsoft 3 41
Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
Examines three attack vectors, specifically, the different types of malware used in malicious attacks, web application attacks, and finally, network based attacks.  Concludes by examining the means of securing and protecting critical systems and inf…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question