Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Citrix Secure Gateway

Status
Not open for further replies.

Sithl0rd

MIS
Oct 17, 2001
194
0
0
AU
I havent seen to many posts for Citrix Secure Gateway, so i hope someone can help me.
I have set up a web server with NFUSE classic 1.7 in my DMZ. I can get this working fine and external clients can logon and connect to the published apps.
I decided to implement Secure gateway to add a bit more security to the connections. I installed STA on a server on my internal network, I then installed Citrix Secure Gateway on a new server in the DMZ, installed my server certifcate on the Secure gateway server. I setup nfuse with the secure gateway details under the nfuseadmin webpage tool.
Now when i connect to a published app, i get an error saying 'The Citrix SSL Server is not accepting connections'
Can anyone help me ?
 
I actually just got my gateway solution running last week.
You need to install a packet sniffer on the dmz and see exactly at what step of the communication it is failing.
Let me know what you find out.
 
Hi Sithl0rd,
did you get any sollution for this problem?
I exp. the same, but yet found no sollution.

 
Hey
Done a fair amount of CSG work recently.
Had the same problem occur as you guys.

The NFuse server and the seperate CSG server both need Port 443 and FQDNs. These names can be registered on a public DNS (ie csg.mycompany.com etc) for Internet use, or via HOSTS files for testing purposes.
I also included a HOSTS file on both machines that including all the resolution info for all the serves involved.
x.x.x.x csg.mycompany.com ;csg server
n.n.n.n ww w.mycompany.com ;nfuse server
y.y.y.y sta.mycompany.com ;sta server

The STA server is actually on the internal network, but I prefer to reference it using a FQDN (its not actually registered on an external DNS though)

Now I found there was a typo in one of the HOSTS entries. This caused the error you have been getting.

Later,
Greenhoff's Knee, NZ
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top