IMHO - you better believe it For openers - you have one point of failure Certs would be a pain to manage since you normally don't have IIS on the CSG except when you generate the certs I think it would be a security risk since I would put the Nfuse and CSG in the DMZ and STA on the same segment as the Citrix boxes. You don't need huge boxes either - I run mine with DL360G2 and mirrored drives dual P1.4 with 2 gb memory and 2 18 gb drives