OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NFR Wizards Archive: Re: Citrix ICA - Published apps

Re: Citrix ICA - Published apps


Jonathan Feldman (Jonathanwpo.co.chatham.ga.us)
Thu, 15 Apr 1999 15:20:10 -0400


Some folks use multi-homed servers, forbidding everything but TCP 1494, and UDP 1604 on that interface.

IANA also lists 2512, 2513, and 2598 (TCP/UDP) as belonging to Citrix, but so far as I know, these are not necessary for remote clients.

Anybody hear anything about ICA itself being dangerous? (Other than the fact that it gives folks a username/PW login box, nauseating, but heck, allowing anybody to login remotely is nauseating.)

I hope you start to have fun, Ken! ;-)

Cheers,

--Jonathan
"SAMS Teach Yourself Network Troubleshooting in 24 Hours"
http://feldman.org

>>> "Schultz, Ken" <KSchultzmsa.com> 04/14 5:25 PM >>>

Has anyone actually managed to make a Citrix Metaframe server - published
application actually work through a firewall? If so, would you mind sharing
a few of details?

We have been able to get access to the Metaframe server directly, but are
having one hell of a time trying to get access to the published app.

Alternatively, if anyone has any _good_ sources of info regarding the use of
the UDP/1604 traffic by the ICA clients and/or servers, in conjunction with
the master browser server, and/or "alternate address" configuration, that
would be very much appreciated.

Just not having any fun on this project...

Ken Schultz
kschultzmsa.com

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               !
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            



This archive was generated by hypermail 2.0b3 on Sat Jul 17 1999 - 07:18:22 CDT