• No results found

Deploying Citrix Secure Gateway A Workforce Mobility Solution

N/A
N/A
Protected

Academic year: 2020

Share "Deploying Citrix Secure Gateway A Workforce Mobility Solution"

Copied!
36
0
0

Loading.... (view fulltext now)

Full text

(1)

Citrix Confidential Citrix Confidential

Deploying

Citrix Secure Gateway

(2)

Citrix Confidential Citrix Confidential

Agenda

• What is Citrix Secure Gateway? • Components and Requirements • Implementation

• Think about this

(3)

Citrix Confidential Citrix Confidential

What is

Citrix Secure Gateway?

(4)

Citrix Confidential Citrix Confidential

What is Citrix Secure Gateway?

• Secure Remote Access Product

• Designed for use with MetaFrame only • Single IP access from the Internet

• SSL Encryption

• Communication over port 443

(5)

Citrix Confidential Citrix Confidential

Components of CSG Solution

• Citrix Secure Gateway Server • Citrix NFuse 1.6

• Secure Ticketing Authority

(6)

Citrix Confidential Citrix Confidential

Workforce Mobility

Components and Requirements

(7)

Citrix Confidential Citrix Confidential

Solution Components

• Citrix Secure Gateway Server

• NFuse 1.6 or later with Citrix Secure Gateway Components

• Hardware Load Balancer

• Verisign or other Authorized Certificate • ACE/RSA Secure ID Server

(8)

Citrix Confidential Citrix Confidential

Function of Citrix Secure Gateway

• Encrypt ICA Traffic

• Access Authorization (w/ STA) • Provide Connectivity

(9)

Citrix Confidential Citrix Confidential

Function of NFuse Web Server

• Provide Authentication Page

• Provide Application List from MetaFrame • Authenticate user against ACE/RSA Server • Accept NT/ADS/Novell Credentials

• Provide ICA Clients for download and install

(10)

Citrix Confidential Citrix Confidential

Function of Load Balancer

• Provide Fail-over capabilities to Citrix Secure Gateway and NFuse Servers

2 – Citrix Secure Gateway Servers 2 – NFuse 1.6 Servers

(11)

Citrix Confidential Citrix Confidential

Function of Certificates, Tickets, Login

Verisign or other CA Certificate

• Encryption Level Verification

NT Domain/Microsoft ADS/ Novell NDS

• MetaFrame Application Authentication

ACE/RSA Secure ID

• Provide Secure Authentication to Web Server

Secure Ticketing Authority

(12)

Citrix Confidential Citrix Confidential

Workforce Mobility

Implementation

(13)

Citrix Confidential Citrix Confidential

Server Specifications

Citrix Secure Gateway

• P700 Mhz with 1GB RAM

• Citrix Uses P933 with 1GB RAM

NFuse 1.6 Web Server

(14)

Citrix Confidential Citrix Confidential

Authentication Considerations

STA

• Should NOT be located in DMZ

• If compromised, can allow access to network • Should not be installed on Web Server

ACE/RSA

• Should NOT be installed on PDC

• Does not require LDAP link to ADS/NDS

(15)

Citrix Confidential Citrix Confidential

Architectural Considerations

• Java Client or 986 Win32 ICA Client Required

Install Java Client on Web Server for Java Applet access

• RSA is used to Secure Web Server Access

Logon to web server

Gain access to NFuse Application Set

• NT/ADS/NDS is used for

User Authentication for Application List from MetaFrame User Authentication to MetaFrame Connection

• STA used for machine level authentication

Used to prevent man in the middle attacks

(16)

Citrix Confidential Citrix Confidential

Communications Ports

Firewall (External to ICA Client)

• NFuse 1.6 – 443

• Citrix Secure Gateway – 443

Firewall (Internal to Secure Network)

• NFuse 1.6 to ACE/RSA Secure ID - 5500 • NFuse 1.6 Server to MetaFrame – 80

• NFuse 1.6 to STA – 80

• Citrix Secure Gateway to STA – 80

(17)

Citrix Confidential Citrix Confidential

Communication – Application Set

ICA Client NFuse Server Citrix Secure Gateway ACE/RSA STA MetaFrame Server Farm

and NT PDC

(18)

Citrix Confidential Citrix Confidential

Communication – ICA File Creation

D M Z In te rfa ce ICA Client NFuse Server Citrix Secure Gateway ACE/RSA STA MetaFrame Server Farm

and NT PDC

Fir

ew

(19)

Citrix Confidential Citrix Confidential

Communication – Connection

Fir ew all ICA Client NFuse Server Citrix Secure Gateway ACE/RSA STA MetaFrame Server Farm

and NT PDC

(20)

Citrix Confidential Citrix Confidential

Creating the Login Web Page

• Modify the ACE/RSA login page • Add NFuse Login Components

NT Username, Password

May want to configure Domain as static

• Some ICA Connection Properties

Need to be configured before logon

Cannot be stored in a Cookie because of this

(21)

Citrix Confidential Citrix Confidential

Configuring the Java Applet

• Run setup.class on your web server • Create HTML page for ICA session

• Note: Optimal config is Ultra Thin Web Client

For Internet Explorer users, the HTML page could look like this: <applet code=com.citrix.JICA width=640 height=480> <param name=cabinets value=JICA-coreM.cab>

<param name=address value=CitrixServer>

For Netscape Navigator users, the HTML page could look like this:

<applet code=com.citrix.JICA archive=JICA-coreN.jar width=640 height=480>

<param name=address value=CitrixServer>

Ref: Citrix ICA Java Client Administrators Guide

See Installing the Citrix ICA Java Client; Chapter 2, Page 21

(22)

Citrix Confidential Citrix Confidential

Additional Steps (ACE/RSA Secure ID)

• Install Net OS on Web Server

• Create Entry for Web Server on ACE/RSA

(23)

Citrix Confidential Citrix Confidential

Demo Time

(24)

Citrix Confidential Citrix Confidential

Workforce Mobility

Think About This

(25)

Citrix Confidential Citrix Confidential

NFuse

ICA Clients

• Install on NFuse Server for easy install

Java Applet

• Install on NFuse Server for Kiosk/Café Access • Universal Zero-Client Access

SSL to ICA Client

• HTTPS Web Site/Pages

• Encrypt Browser Communications

Secure ID Credentials

(26)

Citrix Confidential Citrix Confidential

Certificates

CA Authority

• Support by Microsoft OS by default

• Flexible use for Kiosk/Internet Café Access

Custom Certificates

• Distribution/Management Challenges

(27)

Citrix Confidential Citrix Confidential

MetaFrame XP,

Feature Release 2

(28)

Citrix Confidential Citrix Confidential

Features

• Delegated Administration

• Enhanced Web Administration

• Enhanced Systems Monitoring and Analysis • User Collaboration

• File Type Association • Smart Card Support

• Client/Server Drag and Drop

• Improved File Transfer/Client Drive Mapping • Client Customization Utilities

(29)

Citrix Confidential Citrix Confidential

Delegated Administration

Create specialized administrators to handle specific areas of MetaFrame administration

– Managing printers

– Published applications – User policies

(30)

Citrix Confidential Citrix Confidential

(31)

Citrix Confidential Citrix Confidential

User Collaboration

• One or many users may shadow a single user • Shadowing is not just for administrators any

(32)

Citrix Confidential Citrix Confidential

Content Redirection

CLIENT

SERVER

Local Application (Outlook, Word, IE)

Acrobat content located anywhere Published

(33)

Citrix Confidential Citrix Confidential

Enhanced Systems Monitoring & Analysis

• Summary Database

• Monitor health of Database Connection Server • Schedule the transfer of daily data

• Enable automated data purges

• Specify server metric per server basis

• Audit users to track user statistics, favorite applications, and server usage across the farm

• Setup Cost Centers, Fee structures • Generate reports, all within the CMC • Bill by domain or cost centers

• HTML report template

(34)

Citrix Confidential Citrix Confidential

(35)

Citrix Confidential Citrix Confidential

(36)

References

Related documents

As the performance of IDEA cipher depends entirely on the modulo(2n+1) multiplier design, the main objective is to design an efficient and fast modulo

Grace Chang, Student Member, IEEE, Bin Yu, Senior Member, IEEE, and Martin Vetterli, Fellow, IEEE,” Adaptive Wavelet Thresholding for Image Denoising and Compression ,”

This also has created a rift in the queer community between non- Aboriginals who feel entitled to use - the term two-spirited freely, and Aboriginals who believe it is

In a cloud computing environment, a user’s data can in addition be stored subsequent additional encryption, but if the storage and encryption of a known user’s

Akhil Tiwari will be graduating with a Bachelor's Degree in Engineering in computer science from Veermata Jijabai Technological Institute, Mumbai (India) in 2012. His areas

However, if we look at wom- en's work relative to men, we can see that although the percentage of women working in the aforementioned industries is high, the most

Basic features of images such as colour of pixel in image, texture of image, shapes in images and edges of shapes present in image are extracted from image and

As literacy levels increased in the study population, awareness about all the various methods of contraception increased- particularly about the temporary methods and