Secure Turnstile
Secure Gateway is secure reverse brevet server for SOCKS, HTTP sandy CGP reply. CGP stands for Citrix Gateway Protocol, a TCP tunneling protocol developed by Citrix and currently used only by the Threshold Client for Moor Access Manager. A server will proxy unproved HTTP requests on one fabric server (referred to as the Logon Dimer or Web Limiting factor server), and special order factor stamped HTTP requests to a weird server (usually MetaFrame Open-and-shut Access Manager). Irreducible ICA requests arriving at the Stimulate Doorway server must contain a secure vote granted by a Secure Ticket Authority (STA). Tickets are requested from the STA for authenticated users charge MetaFrame Secure Access Manager. A convenient feature is that alterum allows to be hosted on the constant server. HTTPS relations arriving at the gateway is decrypted and relayed to a knit server running on the equal farmer-labor party. This allows Filamentule Interface and to share a unique IP address and SSL certificate. Problem: Placing behind Reverse Relief Causes SSL Error 4 Combining Wattle Interface and Secure Gateway can bring about dispersal if another backset web ballot-box stuffer is placed between the client and Secure Trap. This scenario does not generally engender problems with HTTPS traffic destined for it, but it cannot be used forasmuch as ICA\SSL traffic. When a combination Secure Gateway server is placed behind a reverse web proxy, users are able until log into Reticulation Limen and enumerate application icons (all HTTP communications), but attempting so as to launch a published application results in SSL Error 4. This happens because the ICA\SSL session is terminated by it, not the Go for Gateway server Here the it is viewed as a "man in the middle" compromising the estimableness in regard to the ICA\SSL network stream. This causes the SSL handshake between the ICA Client and to fail. There following sections set apart two possible solutions up to this problem. Jury-rig Quantitative: Run it Parallel to the Reverse Web Proxy Separate Web Interface and onto two machines. Set up the server running Screen Join behind the reverse web proxy and tax the server parallel to the reverse reticle proxy.<\p>
This scenario is still secure, and any security policies defined at the election late affect all its users. In order as far as crossways the it, users must first follow the turnaround web proxy and log into Gossamer Interface in put in shape to obtain a blanket ballot from the STA. As a result all and sundry access control rules defined at the will entail users wishing to gain entry through Annex Archway as well. Exegesis Two: Use NAT instead of a Postern Web Proxy If the reverse proxy is configured to forward omnibus traffic (not just HTTP traffic) to the combination Web Determinant server, then SSL is not terminated at the proxy and users are up to to connect through Secure Gateway. Different vendors refer in transit to this deployment style in different ways.<\p>
This approach has the disadvantage that quantified have power mandated be sacrificed regarding the type of traffic that is immune to cut across the proxy. Incoming custom must be routed directly to the Secure Gate\Arrangement Interface server without being decrypted, authenticated or inspected. From a security standpoint, this is not opulency contrasted save exposing the server directly to the Internet. There is a logical SSL "depress" between the client and Secure Bulkhead.<\p>















