Brian Madden Logo
Your independent source for application and desktop virtualization.
advertisement

Who is seeing what on gateway, in the Citrix Web Interface forum on BrianMadden.com

rated by 0 users
This post has 15 Replies | 2 Followers

Top 500 Contributor
Points 1,100
Chopper Posted: Fri, Feb 11 2011 8:33 AM

Hi people,

 

I have a weird issue which may be resolved. We have two gateways for external use but only one farm.

Company A has a specific url to get to the gateway A and login.

When compnay A accidentally goes to our main url (gateway B) they can still see their apps.

 

I would only like them to see their published apps via their own specific url (gateway A)

 

Can this be done?

 

Many thanks

  • | Post Points: 35
Top 10 Contributor
Points 48,676

More than likely, you can do what you are looking for.  What kind of "gateway" are you using, though?  that will determine how easy or difficult this might be.

Dan

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 20
Top 500 Contributor
Points 1,100
Chopper replied on Fri, Feb 11 2011 10:24 AM

It's a basic Citrix secure gateway setup (free version)

 

 

 

Hope this helps

 

Cheers Dan

  • | Post Points: 20
Top 25 Contributor
Points 7,475

Assuming single domain and both sites configured identically, then, unfortunately, there is no way to distinguish users with CSG.

  • | Post Points: 20
Top 10 Contributor
Points 48,676

Do both sets of users get the same published apps, or are they different?

Dan

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 5
Top 10 Contributor
Points 48,676

And.. do they both end up pointing to the same site?

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 20
Top 500 Contributor
Points 1,100

Company A only knows one url and can access their apps.

 

Company B can access both url's and see all apps via both url's. We only want them to come in via one url even though they know the other .

 

Thanks

  • | Post Points: 20
Top 25 Contributor
Points 7,475

With Web Interface, there is no way to restrict users. As long as they can authenticate, they can log in.

There may be a third party mod you can try to restrict users, but this would not be officially supported.

  • | Post Points: 20
Top 150 Contributor
Points 1,680

the best option would be to use the web interface mod for this. The one i use is Here

  • | Post Points: 20
Top 10 Contributor
Points 48,676

You could use application fitering.  But, as I asked before... are they using different apps, or the same ones? Are they pointing to the same Web INterface site, or different ones?

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 20
Top 500 Contributor
Points 1,100

Hi Dan,

 

Same App but two different WI's poiting to the same farm.

 

Really apprecaite your help guys

 

Thanks

  • | Post Points: 20
Top 10 Contributor
Points 48,676

Since they are the same apps, there's no easy way to filter them. What you could do is:

1. Publish apps with two unique names (one for A users and one for B users).

2. Publish only the "A" named apps to the A users, and "B" names apps to the B users.

3. Added filtering to each site so it only shows the apps you want to have show up for that particular site.

A little more administration, but that should work.

Dan

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 20
Top 500 Contributor
Points 1,100

Thanks Dan,

 

Either i have read your reply wrong or i have not been clear, apologies either way.

 

 

Problem is that user B does not exist.

User A is seeing his apps on both URLs....

1st url is supported by their IT dept....second one is not but their users still have access to it.

We as a hosting site only want them to come in via their specific url not the general one.

However, having only one farm means which ever URl you use you wil stillseee your apps.

 

Thanks

  • | Post Points: 20
Top 10 Contributor
Points 48,676

OK.  I think I may own YOU the apology... but now I understand the issue. It's still possible to use application filtering if your don't plan on providing access to those same published apps to anyone else.  You can filter out those apps on your "general" site so they don't show up, thus forcing those users to use their specific URL.  Does that make sense.  Again, you may want to look at publishing the apps slightly differently to accomodate this, but it does add a layer of complexity to the administration of said apps.

Dan

Why is it called "Common Sense"? It doesn't seem all that common!

  • | Post Points: 20
Top 150 Contributor
Points 1,680

I still maintain that it would be best to prevent the users from being able to log into the site they aren't supposed to be able to. I do this myself and i use http://www.thomaskoetzing.de/index.php?option=com_content&task=view&id=57&Itemid=97

  • | Post Points: 5
Page 1 of 2 (16 items) 1 2 Next > | RSS