I'm not sure what your doing with that firewall (how are you encrypting ica?) Are you trying to proxy the web interface? Using CSG? Are you using NAT? Does every citrix server have an altaddr? Or is this for internal user's only? CSG doesn't require NAT, altaddr, or an additional web interface. It is very easy to setup. _____ From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On Behalf Of David Teague Sent: Tuesday, August 17, 2004 2:51 PM To: thin@xxxxxxxxxxxxx Subject: [THIN] Nfuse Design Help Ok Guys help me out here, am I doing this all wrong. here is my setup. I have a Nfuse 2.0 box and 3 mf xp 1.0 feature release 3 box on windows 2000. I have a Firewall that is publishing my web server on a published ip, it is behind the firewall with the citrix servers. I have port http and ica ports opened to the web box and ica(1494) opened in and out for the citrix servers. I seems to work most of the time, but I am getting some different error every now and then in the nfuse message center, about server not being available. Should I put the nfuse box infront of the fire wall and open xml to the citrix boxes? It seems that it would work better with everything behind the firewall. Suggestions Welcomed. Thanks!