OK, using SG I am getting the error above, from Citrix I get this solution
Symptom
Users receive the following error message when trying to launch applications through Secure Gateway:
Cannot connect to the Citrix server: The Citrix SSL relay name could not be resolved (SSL error 40)
Cause
The fully qualified domain name (FQDN) of the Secure Gateway server is not recognized by the client.
Reason
A DNS record was not made to resolve the FQDN name of the gateway
or
The FQDN of the Secure Gateway server entered in Web Interface/NFuseAdmin/server-side firewall/Secure Gateway for MetaFrame does not match the name on the certificate of the Secure Gateway server.
Resolution
Create a DNS record that resolves the FQDN of the Secure Gateway server or create an entry in the host file on the client devices.
Verify that the FQDN referenced in Web Interface/NFuseAdmin/server-side firewall/Secure Gateway for MetaFrame matches the name on the certificate of the Secure Gateway server.
**************** 1 Ok, I would create the DNS record to resolve the FQDN, but I can't figure that one out. The DNS server is 10.0.x.x the SG server 192.168.x.x (DMZ) FQDN CITRIX01.AMS.NET the citrix PS server 10.0.x.x FQDN SECUREGATE01.AMS.NET or 2 verify that the FQDN referenced in the web interface... matches the name of the certificate
cert name secure.billsmoonko.com ext ip 70.169.x.x
|