Answered by:
DirectAccess with UAG and Citrix

Question
-
Hi,
We have got DirectAccess up and running, with UAG 2010 SP1, it all works well, except Citrix.
I have read some posts that suggests that setting up Citrix Secure Gateway is the solution, like these posts:
I can't find Secure Gateway on the Citrix site, and on the last of the two links above, one of the comments says that Secure Gateway is EOL-ed. Both of those links are about a year old, so has anything happened since then, what is the best way to get Citrix to work through DirectAccess today?
We use Presentation Server 4.0 at the moment, but we can upgrade if that is necessarily or makes things simpler.
Monday, August 22, 2011 10:58 AM
Answers
-
Hi Sirro,
afaik Citrix still doenst support DirectAccess (e.g. IPv6 addressing) based remote access. So the workaround outlined in the second link you've provided is still valid. You have to use a Citrix Secure/Access Gateway (CSG or CAG) to IPv6-to-IPv4 proxy the initial client request. Alternativily you can also use a CAG edge deployment where CAG and UAG run in a paralell configuration. In this case you will always bypass UAG DirectAccess (via NRPT) when accessing the CAG portal.
Regarding the EOL rumours of CSG i could provide those two web pages...
Citrix Secure Gateway Product Lifecycle (Published Mai. 2006)
http://support.citrix.com/article/CTX110115
Important Q&A Infos:
Q:
With the availability of the Citrix Access Gateway product, does Citrix plan to discontinue support for Secure Gateway component?
A:
Citrix recognizes many existing and new customers continue to rely on Secure Gateway to secure their Citrix environments. Therefore, Citrix plans to continue to include and support Secure Gateway as an integral component.
Latest Build: Secure Gateway 3.2.1 for Windows (Released Feb. 2011)
http://support.citrix.com/article/CTX126521
So i guess the CSG EOL is still a rumour. But i recommend you to contact some Citrix sales guys to get the most accurate/recent information ... ;)
-Kai
Monday, August 22, 2011 11:47 AM
All replies
-
Hi Sirro,
afaik Citrix still doenst support DirectAccess (e.g. IPv6 addressing) based remote access. So the workaround outlined in the second link you've provided is still valid. You have to use a Citrix Secure/Access Gateway (CSG or CAG) to IPv6-to-IPv4 proxy the initial client request. Alternativily you can also use a CAG edge deployment where CAG and UAG run in a paralell configuration. In this case you will always bypass UAG DirectAccess (via NRPT) when accessing the CAG portal.
Regarding the EOL rumours of CSG i could provide those two web pages...
Citrix Secure Gateway Product Lifecycle (Published Mai. 2006)
http://support.citrix.com/article/CTX110115
Important Q&A Infos:
Q:
With the availability of the Citrix Access Gateway product, does Citrix plan to discontinue support for Secure Gateway component?
A:
Citrix recognizes many existing and new customers continue to rely on Secure Gateway to secure their Citrix environments. Therefore, Citrix plans to continue to include and support Secure Gateway as an integral component.
Latest Build: Secure Gateway 3.2.1 for Windows (Released Feb. 2011)
http://support.citrix.com/article/CTX126521
So i guess the CSG EOL is still a rumour. But i recommend you to contact some Citrix sales guys to get the most accurate/recent information ... ;)
-Kai
Monday, August 22, 2011 11:47 AM -
Thank you Kai.
I have found that the Secure Gateway software is on the Presentation Server 4.0 CD2. I'm reading the documentation now and hope I have this up and running soon :)
Wednesday, August 24, 2011 12:47 PM