cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2882
Views
0
Helpful
5
Replies

ASA Smart Tunnels and Citrix

raun.williams
Level 3
Level 3

I'm trying get the Smart Tunnels set up on our ASA, but there seems to be a serious lack of documentation. I did find a little bit in the 8.0 configuration guide, but that's about it. Basically, I've created the application list of the names. First we went with the path as described in the documenation; pn.exe and that's it but then i also tried the full path as well:

smart-tunnel list "CitrixW32-ProgramNeighborhood" "wfica32" "c:\Program Files\Citrix\ICA Client\wfica32.exe"

smart-tunnel list "CitrixW32-ProgramNeighborhood" "wfcrun32" "c:\Program Files\Citrix\ICA Client\wfcrun32.exe"

smart-tunnel list "CitrixW32-ProgramNeighborhood" "Citrix_PN" "c:\Program Files\Citrix\ICA Client\pn.exe"

smart-tunnel list "CitrixW32-ProgramNeighborhood" "wfica" "c:\Program Files\Citrix\ICA Client\wfica.exe"

smart-tunnel list "CitrixW32-ProgramNeighborhood" "wfcrun" "c:\Program Files\Citrix\ICA Client\wfcrun.exe"

I then attempted to apply the list to our group policy, which apparently doesn't work well in ASDM considering you apply it and then it doesn't show up in ASDM as applied, but here it is in CLI:

webvpn

url-list value WebVPN-Basic

filter none

port-forward disable

http-proxy disable

sso-server none

customization value FHS

http-comp none

hidden-shares none

smart-tunnel auto-start CitrixW32-ProgramNeighborhood

Now I'm guessing that's all that is needed?!!?! I setup Program Neighborhood agent to point towards the citrix server as usual, logged into webvpn and launched a basic Citrix Session that should goto a desktop as no application is specifed but I recieve an I/O error on the Program Neighborhood side as if something is being blocked. Any ideas?

Thanks,

Raun

5 Replies 5

irisrios
Level 6
Level 6

There are certain restrictions when considering implementation of Smart Tunnels. Refer to URL http://cisco.com/en/US/docs/security/asa/asa80/asdm60/user/guide/vpn_web.html#wp1073306 for more information.

Thank you, but as mentioned I did find what little information there was in the configuration guide.

Hi

did you ever get this working, I am looking at a similar setup.

Thanks

Arni

try this

Just an update that I got this working

used the same info as in the orginal post for the Smart Tunnels, but did not use the full path of the programs, just the name xyz.exe

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: