What ports do I need to open between a Citrix Secure Gateway server in our DMZ to our internal network to allow XenDesktop connections?

I'm using Citrix Secure Gateway 3.2 and Web Interface 5.4 on a server in the DMZ, with ports 80, 1494, and 2598 open to the XenDesktop 5 DDC server on our internal network. Do I need to have any ports open to the virtual desktops as well? As it is, I get a protocol error when trying to connect to a virtual desktop from the external Web Interface and Event ID 104 in the Citrix Secure Gateway event log:

Log Name:      Citrix Secure Gateway
Source:        Citrix Secure Gateway
Date:          2/17/2011 2:20:32 PM
Event ID:      104
Task Category: (3)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      sg-svp02
Description:
Incoming Citrix Gateway Protocol upstream data could not be processed.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Citrix Secure Gateway" />
    <EventID Qualifiers="0">104</EventID>
    <Level>2</Level>
    <Task>3</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2011-02-17T20:20:32.000000000Z" />
    <EventRecordID>1482</EventRecordID>
    <Channel>Citrix Secure Gateway</Channel>
    <Computer>sg-svp02</Computer>
    <Security />
  </System>
  <EventData>
    <Data>Incoming Citrix Gateway Protocol upstream data could not be processed.</Data>
  </EventData>
</Event>
ABARKEAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
ABARKEConnect With a Mentor Author Commented:
Thanks for the replies. I ended up getting my network admin to open port 2598 from the SG servers in the DMZ to the individual virtual desktops and it fixed the problem. I though communication would go from the virtual desktops through the DDC, then to the Secure Gateway, but apparently not.
0
 
SleetishCommented:
1494.

That's the short answer. More detail is here.

http://support.citrix.com/article/CTX118175 
0
 
BxozConnect With a Mentor Commented:
Citrix XML TCP-8080
Citrix ICA  TCP-1494
TCP-2598
0
 
BxozCommented:
Not very fair play, i give you the right port
0
 
ModernMattCommented:
Bxoz,

With respect, your reply didn't explain exactly where to open port 2598 to, which was the substance of the question. Thus, I am going to award it half points.

ModernMatt
Experts Exchange Moderator
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.