If you look on RSA's website there is a white paper on how they integrate with NFUSE and CSG - there are some changes they suggest. We were seriously looking at RSA last year - and were basically told that our Security folks were comfortable with out going to RSA which is somewhat expensive. Still what is the cost of having your data hacked - hmnnn Gene Herman Systems Engineer Healthnet of the North East (203) 381-6567 "Jensen, Jay" <jjensen@xxxxxxxx To: "'thin@xxxxxxxxxxxxx'" <thin@xxxxxxxxxxxxx> m> cc: Sent by: Subject: [THIN] Re: Secure Gateway thin-bounce@freel ists.org 02/26/2003 08:56 AM Please respond to thin Another couple of Questions in the Secure Gateway environment: The Ticket Authority or CA server is recommended to be internal to your network. If you don't have a STA server can our company use a 3rd-party outside Certification company instead in the CSG / NFuse world? We feel that Secure Gateway may not be as secure as we would like. We are looking at using a Secure ID Hard Token to give it a second layer of security. At what point will that come into play and how do we tell CSG that we are using SecureID? Thanks and sorry for the questions. Jay -----Original Message----- From: Ron Oglesby [mailto:roglesby@xxxxxxxxxxxx] Sent: Tuesday, February 25, 2003 4:08 PM To: thin@xxxxxxxxxxxxx Subject: [THIN] Re: Secure Gateway UH. Big IP is really a hardware load balancer and doesn't really accept the SSL traffic as much as it routes it.=20 Your OWA setup most likely uses Big Ip to route users between a couple OF OWA server just the way it would route connections between a pair of CSG or IIS servers. Ron Oglesby Senior Technical Architect =20 RapidApp Office 312.372.7188 Mobile 312.961.2380 email roglesby@xxxxxxxxxxxx =20 -----Original Message----- From: Jensen, Jay [mailto:jjensen@xxxxxxxxx]=20 Sent: Tuesday, February 25, 2003 3:58 PM To: Thin Client E-mail Group (E-mail) Subject: [THIN] Secure Gateway Question. We were discussing getting Citrix Secure Gateway set up in our DMZ with an External IIS server to run NFuse. Our organization uses Big IP for OWA and I was wondering if Big IP is configured to accept ICA HTTPS traffic would there be a need for the CSG server? Thanks in advance.=20 Jay ********************************************************* This Week's Sponsor - ThinPrint Simply the best print solution for Citrix Metaframe and Microsoft Terminal Services! http://www.thinprint.com ********************************************************** For Archives, to Unsubscribe, Subscribe or=20 set Digest or Vacation mode use the below link: http://thethin.net/citrixlist.cfm ********************************************************* This Week's Sponsor - ThinPrint Simply the best print solution for Citrix Metaframe and Microsoft Terminal Services! http://www.thinprint.com ********************************************************** For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link: http://thethin.net/citrixlist.cfm ********************************************************* This Week's Sponsor - ThinPrint Simply the best print solution for Citrix Metaframe and Microsoft Terminal Services! http://www.thinprint.com ********************************************************** For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link: http://thethin.net/citrixlist.cfm -- No attachments (even text) are allowed -- -- Type: text/plain ********************************************************* This Week's Sponsor - ThinPrint Simply the best print solution for Citrix Metaframe and Microsoft Terminal Services! http://www.thinprint.com ********************************************************** For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link: http://thethin.net/citrixlist.cfm