Saturday, January 10, 2009

[THIN] Download Pick: Remote Server Administration Tools for Windows 7

If you are running the Windows 7 beta you are going to want this...
http://www.microsoft.com/downloads/details.aspx?FamilyID=82516c35-c7dc-4652-b2ea-2df99ea83dbb&DisplayLang=en


Jim Kenzig
Blog: http://www.techblink.com

Friday, January 9, 2009

[THIN] Off-Topic - Re: 64-bit Windows 2008 and XenApp

I know this is wayyyyy off-topic, but I actually saw Paul Allen’s “yacht” around this time last year.

 

I was on the island of Bonaire in the Caribbean, and it docked there.

 

His “boat” was the size of a Princess Cruise Liner and looked like it was outfitted like a Naval Electronic Warfare Destroyer…

 

I could easily see how he’d have an “in” with the Navy…

 

Troy

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Joe Shonk
Sent: Friday, January 09, 2009 3:21 PM
To: thin@freelists.org
Subject: [THIN] Re: 64-bit Windows 2008 and XenApp

 

Doesn’t Paul Allen have an in with the Navy?

 

Joe

 




Regional Health's mission is to provide and support health care excellence in partnership with the communities we serve.

Note: The information contained in this message, including any attachments, may be privileged, confidential, or protected from disclosure under state or federal laws . If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the Sender immediately by a "reply to sender only" message and destroy all electronic or paper copies of the communication, including any attachments.

[THIN] Re: 64-bit Windows 2008 and XenApp

Doesn’t Paul Allen have an in with the Navy?

 

Joe

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Friday, January 09, 2009 2:50 PM
To: thin@freelists.org
Subject: [THIN] Re: 64-bit Windows 2008 and XenApp

 

you get to go with 2008? lucky dog. doesn't look like the army will let us anytime soon.

On Sat, Jan 10, 2009 at 7:43 AM, Minero, Hector B CIV NSWCDD, K55 <hector.minero@navy.mil> wrote:

 

Hi all,

Is anyone running 64-bit Windows 2008 with PS 4.5 or XenApp  or XenApp?
I need to upgrade my servers and I'm kind of debating whether to go 64-bit or 32-bit.
Mainly using: Microsoft Office, Acrobat, IE, Exceed, Tumbleweed Desktop Validator, ActivClient.

I don't want to buy 64-bit servers and find out the these apps. Don't work.

 

Thanks,

_______________________________
Hector Minero
NSWCDD K55

 

[THIN] Re: 64-bit Windows 2008 and XenApp

you get to go with 2008? lucky dog. doesn't look like the army will let us anytime soon.

On Sat, Jan 10, 2009 at 7:43 AM, Minero, Hector B CIV NSWCDD, K55 <hector.minero@navy.mil> wrote:

Hi all,

Is anyone running 64-bit Windows 2008 with PS 4.5 or XenApp  or XenApp?
I need to upgrade my servers and I'm kind of debating whether to go 64-bit or 32-bit.
Mainly using: Microsoft Office, Acrobat, IE, Exceed, Tumbleweed Desktop Validator, ActivClient.

I don't want to buy 64-bit servers and find out the these apps. Don't work.


Thanks,

_______________________________
Hector Minero
NSWCDD K55


[THIN] Re: 64-bit Windows 2008 and XenApp

XenApp 5 is the only version that works on Windows 2008.  As far as application compatibility,  you can download an evaluation version of Windows 2008 and test the application on Terminal Server.

 

Joe

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Minero, Hector B CIV NSWCDD, K55
Sent: Friday, January 09, 2009 12:44 PM
To: thin@freelists.org
Subject: [THIN] 64-bit Windows 2008 and XenApp

 

 

Hi all,

Is anyone running 64-bit Windows 2008 with PS 4.5 or XenApp  or XenApp?
I need to upgrade my servers and I'm kind of debating whether to go 64-bit or 32-bit.
Mainly using: Microsoft Office, Acrobat, IE, Exceed, Tumbleweed Desktop Validator, ActivClient.

I don't want to buy 64-bit servers and find out the these apps. Don't work.

 

Thanks,

_______________________________
Hector Minero
NSWCDD K55

[THIN] 64-bit Windows 2008 and XenApp


Hi all,

Is anyone running 64-bit Windows 2008 with PS 4.5 or XenApp  or XenApp?
I need to upgrade my servers and I'm kind of debating whether to go 64-bit or 32-bit.
Mainly using: Microsoft Office, Acrobat, IE, Exceed, Tumbleweed Desktop Validator, ActivClient.

I don't want to buy 64-bit servers and find out the these apps. Don't work.


Thanks,

_______________________________
Hector Minero
NSWCDD K55

[THIN] Re: Windows 7 beta

And you can find me here: http://social.technet.microsoft.com/Forums/en/category/w7itpro/ for all your beta questions?

 

Joe

 

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Jim Kenzig http://thin.ms
Sent: Friday, January 09, 2009 11:54 AM
To: windows2000@freelists.org; vista@freelists.org; THIN
Subject: [THIN] Windows 7 beta

 

FYI
Windows 7 Beta Is here but server is BUSY!!!
http://technet.microsoft.com/en-us/evalcenter/dd353205.aspx#

Technet Plus People can get it here
http://technet.microsoft.com/subscriptions/downloads/default.aspx?pv=36:350
Jim Kenzig
Blog: http://www.techblink.com

[THIN] Windows 7 beta

FYI
Windows 7 Beta Is here but server is BUSY!!!
http://technet.microsoft.com/en-us/evalcenter/dd353205.aspx#

Technet Plus People can get it here
http://technet.microsoft.com/subscriptions/downloads/default.aspx?pv=36:350
Jim Kenzig
Blog: http://www.techblink.com

[THIN] Re: Need some PS4 licenses

I *think* you buy licenses for the current version and they are good for the older ones.  

On Fri, Jan 9, 2009 at 10:42 AM, Angus Macdonald (IM&T) <Angus.Macdonald@nww-tr.wales.nhs.uk> wrote:

Hi guys. Long time no post.

I need some more PS4 licenses for my main farm. Can I assume it's still possible to buy them?

Thanks

Angus

Gallair e-bost yma gynnwys gwybodaeth gyfrinachol a/neu ddeunydd hawlfraint.  Os ydych chin meddwl eich bod wedi derbyn yr e-bost yma drwy gamgymeriad rydym yn ymddiheuro am hyn; peidiwch os gwelwch yn dda a datgelu, anfon ymlaen, printio, copio na dosbarthu gwybodaeth yn yr e-bost yma na gweithredu mewn unrhyw fodd drwy ddibynnu ar ei gynnwys: gwaherddir gwneud hynnyn gyfan gwbl a gallai fod yn anghyfreithlon. Rhowch wybod ir anfonwr fod y neges yma wedi mynd ar goll cyn ei dileu.

Mae unrhyw safbwynt neu farn a gyflwynir yn eiddo ir awdur ac nid ydynt o anghenraid yn cynrychioli safbwynt neu farn Ymddiriedolaeth GIG Gogledd Orllewin Cymru.

Gallai cynnwys yr e-bost yma gael ei ddatgelu Ir cyhoedd o dan Ddeddf Rhyddid Gwybodaeth 2000.  Ni does modd gwarantu cyfrinachedd y neges ac unrhyw ateb

Bydd y neges yma ac unrhyw ffeiliau cysylltiedig wedi cael eu gwirio gan feddalwedd canfod firws cyn eu trosglwyddo.  Ond rhaid ir sawl syn derbyn wirio rhag firws ei hun cyn agor unrhyw ymgysylltiad.  Nid ywr Ymddiriedolaeth yn derbyn unrhyw gyfrifoldeb am unrhyw golled neu niwed a allai gael ei achosi gan firws meddalwedd.


This e-mail may contain confidential information and/or copyright material.  If you believe that you have received this e-mail in error please accept our apologies; please do not disclose, forward, print, copy or distribute information in this e-mail or take any action in reliance on its contents: to do so is strictly prohibited and may be unlawful.  Please inform the sender that this message has gone astray before deleting it.

Any views or opinions presented are to be understood as those of the author and do not necessarily represent those of the North West Wales NHS Trust.

The contents of this e-mail may be subject to public disclosure under the Freedom of Information Act 2000. The confidentiality of the message and any reply cannot be guaranteed.

This message and any attached files will have been checked with virus detection software before transmission.  However, recipients must carry out their own virus checks before opening any attachment.  The Trust accepts no liability for any loss or damage, which may be caused by software viruses.


[THIN] Need some PS4 licenses

Hi guys. Long time no post.

I need some more PS4 licenses for my main farm. Can I assume it’s still possible to buy them?

Thanks

Angus

[THIN] Re: Access Gateway Enterprise Edition - Password expiry notification

 
Password changing is working fine with secure LDAP, but my question was about expiry notification.
 
Looks like no one has got it?

--- On Thu, 1/8/09, peter_dibbens@yahoo.co.uk <peter_dibbens@yahoo.co.uk> wrote:
From: peter_dibbens@yahoo.co.uk <peter_dibbens@yahoo.co.uk>
Subject: [THIN] Re: Access Gateway Enterprise Edition - Password expiry notification
To: thin@freelists.org
Date: Thursday, January 8, 2009, 3:03 PM

Hi Saravanan,

 

The AG-EE will just prompt you to change the Password when it has expired as you stated no warning. This works just fine with LDAP and Radius (Radius didn't work properly in the past but works just fine at least a few firmware updates ago J).

 

You will need to point your LDAP query to 389 and not 3268 (Global Catalog) assuming that you are using AD for the LDAP directory.

 

Oh and by the way I never use 389 only use secure LDAP on 636 as a best practice I have done quite a number of these implementations for some larger organisations all of which have been reviewed by external third part security companies.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Saravanan Srinivasan
Sent: Friday, 9 January 2009 2:58 AM
To: thin@freelists.org
Subject: [THIN] Access Gateway Enterprise Edition - Password expiry notification

 

We are moving from Citrix Access Gateway Advanced edition to Enterprise edition.

 

We just realized enterprise edition doesn't support the password expiry notification. But it allows to change the password once it is expired.

 

Has anyone tried this before?

 

Thanks

Saravanan S


 

 

 

[THIN] Re: Access Gateway Enterprise Edition - Password expiry notification

I am running AGEE 8.1 patch 63.

--- On Thu, 1/8/09, Steve Greenberg <steveg@thinclient.net> wrote:
From: Steve Greenberg <steveg@thinclient.net>
Subject: [THIN] Re: Access Gateway Enterprise Edition - Password expiry notification
To: thin@freelists.org
Date: Thursday, January 8, 2009, 3:05 PM

What version of AG-E are you going to?

 

It is weird a few features are actually better in Advanced then Enterprise but  Enterprise is way more scalable and robust and catching up….

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Saravanan Srinivasan
Sent: Thursday, January 08, 2009 9:58 AM
To: thin@freelists.org
Subject: [THIN] Access Gateway Enterprise Edition - Password expiry notification

 

We are moving from Citrix Access Gateway Advanced edition to Enterprise edition.

 

We just realized enterprise edition doesn't support the password expiry notification. But it allows to change the password once it is expired.

 

Has anyone tried this before?

 

Thanks

Saravanan S


 

 

 

Thursday, January 8, 2009

[THIN] Re: netscalers and smartcards (CAC) - who's using them?

Might be possible - I had to set the pnagent to just use pass-through in order to work with passing through smart card credentials - I'll give that a whirl for kicks

On Fri, Jan 9, 2009 at 10:29 AM, Steve Greenberg <steveg@thinclient.net> wrote:

Is it possible to have the Netscaler handle the authentication with the smart card and then just treat WI the normal way, i.e. pass through the AD credentials??

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 2:14 PM


To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

Correct, although we were hoping that pass-through would work. I'm pretty sure we tried both ways for the WI (pass-through and not-pass-through) and both ways it (the WI) keeps prompting for credentials.

On Fri, Jan 9, 2009 at 8:57 AM, Steve Greenberg <steveg@thinclient.net> wrote:

Just to be clear, you do not have the Netscaler handling authentication for the WI? Is that correct? I.e. you login in to the SSL VPN and then you login with your smart card to the WI??

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 1:43 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

I.m perusing it and trying to compare - the interface is quite different for 8.1

The on diff I so see is the Configure Auth Server - they had me enter SubjectAltName:PrincipalName in the user field and left the group field blank

I don't know if that's something that will vary with CACs/certs, but it's worth a try.

On Thu, Jan 8, 2009 at 4:03 PM, <peter_dibbens@yahoo.co.uk> wrote:

Hi,

 

Have you seen this article http://support.citrix.com/article/ctx116373.

I can vouch that the certificates components work as expected. You must also configure all the prerequisites for WI Pass-through.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, 8 January 2009 10:40 AM


To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?



We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.

 

 


[THIN] Re: netscalers and smartcards (CAC) - who's using them?

Is it possible to have the Netscaler handle the authentication with the smart card and then just treat WI the normal way, i.e. pass through the AD credentials??

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 2:14 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

Correct, although we were hoping that pass-through would work. I'm pretty sure we tried both ways for the WI (pass-through and not-pass-through) and both ways it (the WI) keeps prompting for credentials.

On Fri, Jan 9, 2009 at 8:57 AM, Steve Greenberg <steveg@thinclient.net> wrote:

Just to be clear, you do not have the Netscaler handling authentication for the WI? Is that correct? I.e. you login in to the SSL VPN and then you login with your smart card to the WI??

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 1:43 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

I.m perusing it and trying to compare - the interface is quite different for 8.1

The on diff I so see is the Configure Auth Server - they had me enter SubjectAltName:PrincipalName in the user field and left the group field blank

I don't know if that's something that will vary with CACs/certs, but it's worth a try.

On Thu, Jan 8, 2009 at 4:03 PM, <peter_dibbens@yahoo.co.uk> wrote:

Hi,

 

Have you seen this article http://support.citrix.com/article/ctx116373.

I can vouch that the certificates components work as expected. You must also configure all the prerequisites for WI Pass-through.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, 8 January 2009 10:40 AM


To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?



We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.

 

 

[THIN] Re: Borland Dos apps with vista and server 2008

And how did you come across this...?

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of M
Sent: 07 January 2009 21:55
To: Thin@Freelists.org
Subject: [THIN] Borland Dos apps with vista and server 2008

 

 

Crikey i wonder who is still using Dos based borland apps.



SUBJECT TO CONTRACT

[THIN] Re: Access Gateway Enterprise Edition - Password expiry notification

What version of AG-E are you going to?

 

It is weird a few features are actually better in Advanced then Enterprise but  Enterprise is way more scalable and robust and catching up….

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Saravanan Srinivasan
Sent: Thursday, January 08, 2009 9:58 AM
To: thin@freelists.org
Subject: [THIN] Access Gateway Enterprise Edition - Password expiry notification

 

We are moving from Citrix Access Gateway Advanced edition to Enterprise edition.

 

We just realized enterprise edition doesn't support the password expiry notification. But it allows to change the password once it is expired.

 

Has anyone tried this before?

 

Thanks

Saravanan S


 

 

 

[THIN] Re: Access Gateway Enterprise Edition - Password expiry notification

Hi Saravanan,

 

The AG-EE will just prompt you to change the Password when it has expired as you stated no warning. This works just fine with LDAP and Radius (Radius didn’t work properly in the past but works just fine at least a few firmware updates ago J).

 

You will need to point your LDAP query to 389 and not 3268 (Global Catalog) assuming that you are using AD for the LDAP directory.

 

Oh and by the way I never use 389 only use secure LDAP on 636 as a best practice I have done quite a number of these implementations for some larger organisations all of which have been reviewed by external third part security companies.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Saravanan Srinivasan
Sent: Friday, 9 January 2009 2:58 AM
To: thin@freelists.org
Subject: [THIN] Access Gateway Enterprise Edition - Password expiry notification

 

We are moving from Citrix Access Gateway Advanced edition to Enterprise edition.

 

We just realized enterprise edition doesn't support the password expiry notification. But it allows to change the password once it is expired.

 

Has anyone tried this before?

 

Thanks

Saravanan S


 

 

 

[THIN] Re: netscalers and smartcards (CAC) - who's using them?

Just to be clear, you do not have the Netscaler handling authentication for the WI? Is that correct? I.e. you login in to the SSL VPN and then you login with your smart card to the WI??

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 1:43 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

I.m perusing it and trying to compare - the interface is quite different for 8.1

The on diff I so see is the Configure Auth Server - they had me enter SubjectAltName:PrincipalName in the user field and left the group field blank

I don't know if that's something that will vary with CACs/certs, but it's worth a try.

On Thu, Jan 8, 2009 at 4:03 PM, <peter_dibbens@yahoo.co.uk> wrote:

Hi,

 

Have you seen this article http://support.citrix.com/article/ctx116373.

I can vouch that the certificates components work as expected. You must also configure all the prerequisites for WI Pass-through.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, 8 January 2009 10:40 AM


To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?



We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.

 

[THIN] Re: netscalers and smartcards (CAC) - who's using them?

I.m perusing it and trying to compare - the interface is quite different for 8.1

The on diff I so see is the Configure Auth Server - they had me enter SubjectAltName:PrincipalName in the user field and left the group field blank

I don't know if that's something that will vary with CACs/certs, but it's worth a try.

On Thu, Jan 8, 2009 at 4:03 PM, <peter_dibbens@yahoo.co.uk> wrote:

Hi,

 

Have you seen this article http://support.citrix.com/article/ctx116373.

I can vouch that the certificates components work as expected. You must also configure all the prerequisites for WI Pass-through.

 

Thanks Pete

 

From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, 8 January 2009 10:40 AM


To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?



We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.

[THIN] Re: netscalers and smartcards (CAC) - who's using them?

That's how it's supposed to work, yes. Under the Access Gateway\Policies\Session\Profile on the Client Experience tab it's put in as the home page.

On Fri, Jan 9, 2009 at 8:36 AM, Steve Greenberg <steveg@thinclient.net> wrote:

By this do you mean that a VPN tunnel is established and then you present the actual WI server page as a redirect/forward to the user automatically?

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 1:07 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

from the client it's a SSL VPN to the NS through the FW, the NS sits entirely in the DMZ, external FW allows 443 through and is doing NAT. From the DMZ to the inside (where the WI and citirix farm is) we allow 1494, 3010, 443, 80, 22, 53 & 2598. The client PC can use PN to get to the farm and launch apps with smart card auth, so it's just the WI that's not cooperating.

We're trying to use the WI has the default web page that the NS presents to the user.

On Thu, Jan 8, 2009 at 3:26 PM, Steve Greenberg <steveg@thinclient.net> wrote:

How is it configured exactly? Is it a pure VPN connection and not an ICA proxy? I.e. does the client have a tunnel to the WI box directly? If so, have you opened the ports need for the smart card software?? ( I have no idea what they would be)

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Wednesday, January 07, 2009 5:40 PM
To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?

We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.

 


[THIN] Re: netscalers and smartcards (CAC) - who's using them?

By this do you mean that a VPN tunnel is established and then you present the actual WI server page as a redirect/forward to the user automatically?

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Thursday, January 08, 2009 1:07 PM
To: thin@freelists.org
Subject: [THIN] Re: netscalers and smartcards (CAC) - who's using them?

 

from the client it's a SSL VPN to the NS through the FW, the NS sits entirely in the DMZ, external FW allows 443 through and is doing NAT. From the DMZ to the inside (where the WI and citirix farm is) we allow 1494, 3010, 443, 80, 22, 53 & 2598. The client PC can use PN to get to the farm and launch apps with smart card auth, so it's just the WI that's not cooperating.

We're trying to use the WI has the default web page that the NS presents to the user.

On Thu, Jan 8, 2009 at 3:26 PM, Steve Greenberg <steveg@thinclient.net> wrote:

How is it configured exactly? Is it a pure VPN connection and not an ICA proxy? I.e. does the client have a tunnel to the WI box directly? If so, have you opened the ports need for the smart card software?? ( I have no idea what they would be)

 

 

Steve Greenberg

Thin Client Computing

34522 N. Scottsdale Rd D8453

Scottsdale, AZ 85266

(602) 432-8649

www.thinclient.net

steveg@thinclient.net

 


From: thin-bounce@freelists.org [mailto:thin-bounce@freelists.org] On Behalf Of Steve Snyder
Sent: Wednesday, January 07, 2009 5:40 PM
To: thin@freelists.org
Subject: [THIN] netscalers and smartcards (CAC) - who's using them?

 

and what did you have to do to get the WI to come up properly?

We're trialing a NS 8.1 in our DMZ - the VPN tunnel connects and it starts to load the WI site but the smartcard (CAC) authentication just doesn't fly. Citrix is scratching their heads.