[THIN] Re: Secure Gateway

  • From: Gene.I.Herman@xxxxxxxxxx
  • To: thin@xxxxxxxxxxxxx
  • Date: Wed, 26 Feb 2003 13:48:20 -0500

If you look on RSA's website there is a white paper on how they integrate
with NFUSE and CSG - there are some changes they suggest.

We were seriously looking at RSA last year - and were basically told that
our Security folks were comfortable with out going to RSA which is somewhat
expensive. Still what is the cost of having your data hacked - hmnnn

Gene Herman
Systems Engineer
Healthnet of the North East
(203) 381-6567


                                                                                
                                                       
                      "Jensen, Jay"                                             
                                                       
                      <jjensen@xxxxxxxx        To:       "'thin@xxxxxxxxxxxxx'" 
<thin@xxxxxxxxxxxxx>                                   
                      m>                       cc:                              
                                                       
                      Sent by:                 Subject:  [THIN] Re: Secure 
Gateway                                                     
                      thin-bounce@freel                                         
                                                       
                      ists.org                                                  
                                                       
                                                                                
                                                       
                                                                                
                                                       
                      02/26/2003 08:56                                          
                                                       
                      AM                                                        
                                                       
                      Please respond to                                         
                                                       
                      thin                                                      
                                                       
                                                                                
                                                       
                                                                                
                                                       





Another couple of Questions in the Secure Gateway environment:

The Ticket Authority or CA server is recommended to be internal to your
network.  If you don't have a STA server can our company use a 3rd-party
outside Certification company instead in the CSG / NFuse world?

We feel that Secure Gateway may not be as secure as we would like.  We are
looking at using a Secure ID Hard Token to give it a second layer of
security.  At what point will that come into play and how do we tell CSG
that we are using SecureID?

Thanks and sorry for the questions.
Jay

-----Original Message-----
From: Ron Oglesby [mailto:roglesby@xxxxxxxxxxxx]
Sent: Tuesday, February 25, 2003 4:08 PM
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: Secure Gateway



UH. Big IP is really a hardware load balancer and doesn't really accept
the SSL traffic as much as it routes it.=20

Your OWA setup most likely uses Big Ip to route users between a couple
OF OWA server just the way it would route connections between a pair of
CSG or IIS servers.


Ron Oglesby
Senior Technical Architect
=20
RapidApp
Office 312.372.7188
Mobile 312.961.2380
email roglesby@xxxxxxxxxxxx
=20


-----Original Message-----
From: Jensen, Jay [mailto:jjensen@xxxxxxxxx]=20
Sent: Tuesday, February 25, 2003 3:58 PM
To: Thin Client E-mail Group (E-mail)
Subject: [THIN] Secure Gateway



Question.

We were discussing getting Citrix Secure Gateway set up in our DMZ with
an External IIS server to run NFuse.  Our organization uses Big IP for
OWA and I was wondering if Big IP is configured to accept ICA HTTPS
traffic would there be a need for the CSG server?

Thanks in advance.=20
Jay
*********************************************************
This Week's Sponsor - ThinPrint
Simply the best print solution for Citrix
Metaframe and Microsoft Terminal Services! http://www.thinprint.com
**********************************************************

For Archives, to Unsubscribe, Subscribe or=20
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm
*********************************************************
This Week's Sponsor - ThinPrint
Simply the best print solution for Citrix
Metaframe and Microsoft Terminal Services!
http://www.thinprint.com
**********************************************************

For Archives, to Unsubscribe, Subscribe or
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm
*********************************************************
This Week's Sponsor - ThinPrint
Simply the best print solution for Citrix
Metaframe and Microsoft Terminal Services!
http://www.thinprint.com
**********************************************************

For Archives, to Unsubscribe, Subscribe or
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm






-- No attachments (even text) are allowed --
-- Type: text/plain


*********************************************************
This Week's Sponsor - ThinPrint
Simply the best print solution for Citrix
Metaframe and Microsoft Terminal Services!
http://www.thinprint.com
**********************************************************

For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm

Other related posts: