cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
485
Views
0
Helpful
2
Replies

Citrix CSG and STA issue

pengfang
Level 1
Level 1

Hi all,

I got some problem with implementation PIX v7.21 with Citrix application server.My scenario is Citrix CSG server (Web interface Server) stays in DMZ,Citrix STA server stays in inside network,when I use static (inside,dmz) command to hide real IP of STA server, the CSG could not talk to mapped IP,it pop up some error message like " no specific IP address of the server found" ,I'm sure I can ping mapped IP from DMZ.then I changed staic command to "static (inside,dmz) Real-ip of STA server Real-ip of STA server", it is like no nat,so it works.My question is can I use static NAT for hidding inside IP in this Citrix case or Citrix hardcode the IP of STA we can not change ?

1 Accepted Solution

Accepted Solutions

Aaron Harrison
VIP Alumni
VIP Alumni

Hi

I've usually implemented CSG/STA with the traffic to the CSG natted and traffic from CSG to STA not natted.

It sounds like STA is responding with it's IP embedded in higher-layer protocol which isn't natted with the IP header...

Aaron

Please rate helpful posts...

Aaron Please remember to rate helpful posts to identify useful responses, and mark 'Answered' if appropriate!

View solution in original post

2 Replies 2

Aaron Harrison
VIP Alumni
VIP Alumni

Hi

I've usually implemented CSG/STA with the traffic to the CSG natted and traffic from CSG to STA not natted.

It sounds like STA is responding with it's IP embedded in higher-layer protocol which isn't natted with the IP header...

Aaron

Please rate helpful posts...

Aaron Please remember to rate helpful posts to identify useful responses, and mark 'Answered' if appropriate!

Thanks Aaron.