What ports do I need to open between a Citrix Secure Gateway server in our DMZ to our internal network to allow XenDesktop connections?

I'm using Citrix Secure Gateway 3.2 and Web Interface 5.4 on a server in the DMZ, with ports 80, 1494, and 2598 open to the XenDesktop 5 DDC server on our internal network. Do I need to have any ports open to the virtual desktops as well? As it is, I get a protocol error when trying to connect to a virtual desktop from the external Web Interface and Event ID 104 in the Citrix Secure Gateway event log:

Log Name:      Citrix Secure Gateway
Source:        Citrix Secure Gateway
Date:          2/17/2011 2:20:32 PM
Event ID:      104
Task Category: (3)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      sg-svp02
Incoming Citrix Gateway Protocol upstream data could not be processed.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <Provider Name="Citrix Secure Gateway" />
    <EventID Qualifiers="0">104</EventID>
    <TimeCreated SystemTime="2011-02-17T20:20:32.000000000Z" />
    <Channel>Citrix Secure Gateway</Channel>
    <Security />
    <Data>Incoming Citrix Gateway Protocol upstream data could not be processed.</Data>
Who is Participating?

Improve company productivity with a Business Account.Sign Up

ABARKEConnect With a Mentor Author Commented:
Thanks for the replies. I ended up getting my network admin to open port 2598 from the SG servers in the DMZ to the individual virtual desktops and it fixed the problem. I though communication would go from the virtual desktops through the DDC, then to the Secure Gateway, but apparently not.

That's the short answer. More detail is here.

BxozConnect With a Mentor Commented:
Citrix XML TCP-8080
Citrix ICA  TCP-1494
Not very fair play, i give you the right port

With respect, your reply didn't explain exactly where to open port 2598 to, which was the substance of the question. Thus, I am going to award it half points.

Experts Exchange Moderator
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.