阳光网驿-企业信息化交流平台【DTC零售连锁全渠道解决方案】

 找回密码
 注册

QQ登录

只需一步,快速开始

扫描二维码登录本站

手机号码,快捷登录

老司机
查看: 3403|回复: 4

[求助] 请教下高手CITRIX连接问题

[复制链接]
  • TA的每日心情

    2011-7-29 18:04
  • 签到天数: 1 天

    [LV.1]初来乍到

    发表于 2009-11-17 16:41:13 | 显示全部楼层 |阅读模式
    环境是 一台跑CITRIX 5.0的服务器网关指向一台PC,PC通过拨号上网,在PC上开启了端口映射80和1494.DMZ里面设置的是TRANSPORT模式,用了域名解析。远地客户端通过WEB连接应用时,出现no route 的提示: p9 S2 Z0 c  |8 Y0 V
      请教这种环境DMZ该怎么设置    不甚感激
    楼主热帖
    启用邀请码注册,提高发帖质量,建设交流社区
  • TA的每日心情
    开心
    2014-5-29 13:26
  • 签到天数: 69 天

    [LV.6]常住居民II

    发表于 2009-11-17 22:37:56 | 显示全部楼层
    除了路由器设置DMZ或NAT外,XENAPP控制台需要配置外网访问方式。用记事本打开launch.ica看看主机IP是不是为XENAPP5服务器内网IP,是则外网肯定无法访问服务器。% G1 r, u; c4 |, W& a0 {+ y
    * ?6 C8 q2 Q0 V: Q& i9 L
    [ 本帖最后由 jjee 于 2009-11-17 22:42 编辑 ]
    启用邀请码注册,提高发帖质量,建设交流社区
  • TA的每日心情

    2011-7-29 18:04
  • 签到天数: 1 天

    [LV.1]初来乍到

     楼主| 发表于 2009-11-17 23:06:53 | 显示全部楼层
    没有使用路由器,PC做的内网网关,在Webinterface里面设置了translated模式,里面有6个选项。这种环境选哪种合适
    启用邀请码注册,提高发帖质量,建设交流社区
  • TA的每日心情
    奋斗
    2021-10-12 18:15
  • 签到天数: 849 天

    [LV.10]以坛为家III

    发表于 2009-11-17 23:48:31 | 显示全部楼层
    貌似还需要映射那个什么XX94、XX95端口,,忘记了
    启用邀请码注册,提高发帖质量,建设交流社区
  • TA的每日心情
    开心
    2014-5-29 13:26
  • 签到天数: 69 天

    [LV.6]常住居民II

    发表于 2009-11-18 20:27:45 | 显示全部楼层
    配置wi的外网访问(标准教程)2 o2 W/ o3 Z* M$ z: b% S
    Alternate address configuration implementation with web interface is two step procedures.
    # O, ]+ ^% r% i4 V9 \& bHear alternate address should be configured in Citrix and not on network adapter. I would assume you have configured it on network adapter.0 x0 t( ~) e1 V
    Let's understand how to do it.
      ~: E. @- u% |: k$ q' [! a6 d# Y* d2 W: a& x3 [2 K
    3 T% v; A: x- O8 l# J
    Step 1 : Use below command for all application servers that are required to be available on outside subnet.% w7 T. a: @5 l- q+ y
    步骤1:使用以下命令用于所有要求外网有效的应用程序服务器上。
    " I1 w- _: a* k0 c
    8 \9 r7 I# q) w" p. I: I# uALTADDR /SERVER:HostName /SET X.X.X.X /V
    8 B1 k: u8 ]/ g/ a& Q0 K' b! k6 EWhere,; _& |1 b% \/ W0 C
    这里,
    0 j* b% X+ w4 J* l7 {6 iHostName = Citrix Application Server HostName
    1 |6 ]& @8 `6 n6 A' W' X3 E主机名=思杰应用服务器主机名
    3 W! J1 q) s  G+ K/ IIn X.X.X.X = Alternate ip address for hostname specified.
    7 W5 k3 l0 d2 t# L& I% u0 O在X.X.X.X =为主机名指定交替IP地址- U0 ?7 B" n% w
    For my 32 bit subnet based alternate ip configuration, command were something like this.
    & r3 \* w% J9 j0 D9 q$ h因为32位子网基于交替IP配置,命令如下。
    & `. p* p# Z# M0 c/ i5 }ALTADDR /SERVER:ExampleServer1 /SET 172.16.190.37 /V
    4 T5 H" R) N' p6 r* Z" iALTADDR /SERVER:ExampleServer2 /SET 172.16.190.38 /V4 I6 P) N' T# V: r" g: R
    Where,* T' G% o6 m/ h
    这里,. ^4 P, a' U) I$ `* g% D, D
    ExampleServer1 & 2 = Name of my CitrixApplicationServer
    3 a' d8 U4 ^+ |  k8 z4 V172.16.190.X = are alternate IP address for respective Citrix Application Server.
    2 C" M* B7 B# _ExampleServer1 & 2 =思杰应用服务器名称
    7 s( {6 C4 L. s5 e172.16.190.X =是给每个思杰应用服务器的交替IP地址
    ( q' K, y8 g8 [: v; d: q4 B4 R" ANATing was to translate Client's public ip to 172.16.190.X ip address.$ l4 F& I! |) P) J2 }  G; r. z5 o- g
    NAT用于转换客户公网IP到172.16.190.X IP地址。
    ; L7 s8 O; J# Y/ F$ _- x5 |
    ( V$ [( V& v* E% gStep 2 : Create/re-configure webinterface website and enable alternate addressing.% i7 m. }! n9 s" n$ E4 O) ?
    For new website.
    % @  `. c, [% Y1) Open Access Management Console.4 f" {' V4 L( ~- W2 ]9 V
    2) Select Web Interface Node
    ( t  p4 U. o5 g! ]6 z+ c3) Click on "Manage secure client access - >Edit DMZ settings" under common tasks.
    + }- C4 M: q# T$ J. F; g4) For Default Client and set Access method "Alternate" for default client.
    9 G2 s4 R2 n. B2 n$ H步骤2:创建/重新配置WEB界面网站并非启动alternate交替地址功能。
    " q% ^7 n+ ?# O0 Y1 G# X' X, \用于新网站。7 E; j* |- I1 Q5 {
    1)启动“Access Management Console”。
    ! r9 C. e% n# |7 ?3 @2)选定“Web Interface”节点。' f) e6 C3 E4 C
    3)点击”common tasks“下面的“Web Interface - > Edit DMZ settings”。! [. J" x  n0 g2 E! y
    4)“default client”“Access method”设置为"Alternate" 。# @% M% ^* k, s- j' O" A
    4 J& v% y5 s  U% n
    or re-Configure existing by alternate addressing to specified client IP range.
    4 c' s$ Y) o/ ^* M( U+ i. _2 M, c
    : B4 D- C" n. p- a+ W1) Open Access Management Console." k. a8 `+ c7 ?4 \
    2) Select Web Interface Node
    ( R& n/ I& Y0 |% H3) Click on "Manage secure client access - >Edit DMZ settings" under common tasks.
    6 m9 H  Z( M2 Y4) Click on Add button and specify Client IP X.X.X.X and set Access method "Alternate".+ i& a9 h6 V( j
    或者重新配置原有设置,通过“alternate”轮换地址到指定的客户IP地址范围。9 V9 p( r5 {  X4 v% V/ z
    1)启动“Access Management Console”。
    4 ]+ y- P2 `5 x8 Z! G2)选定“Web Interface”节点。6 g9 w% }3 M: O" D
    3)点击”common tasks“下面的“Web Interface - > Edit DMZ settings”。
    4 j5 x) I8 ?8 |7 \* V1 g0 M4)点击“ADD”新增按钮来指定客户IP地址X.X.X.X,并设置“Access method”访问方式为"Alternate"。  u, J; T: E& N  T( h& ^4 u' j! m
    Now website will understand that if client IP is X.X.X.X, it should respond with alternate address of application server and not with primary ip address.1 T! v+ K5 o. ~
    现在网站自己清楚,如果客户端IP是X.X.X.X,它必须响应“alternate”交替地址而不是主IP地址。
    ' G# Q# O6 r, H9 p. F& f% s* F% P, P
    ==================================================================================================================4 z( r' {; ^5 V* f
    XenApp5 for Windows 2003 实验记录' V; M6 k+ M' r8 e+ `
    实验环境:1 n! r0 c) C% T  `( D; p) L
    路由器:Dynamic IP/WAN 192.168.0.254/LAN 1494/TCP 80/TCP5 h5 P: ]* n* y
    公网域名:JJEE.3322.ORG' X7 C; [1 s: s; m  H
    内部子网:192.168.0.0/24
    " \$ p, `" |- X$ Y% u3 O( {XenApp应用服务器IP:192.168.0.1
    3 |- e3 X2 ?. m! z3 f4 E操作步骤如下:; H+ R4 q: k, Y9 r$ E9 [
    1、CMD>ALTADDR /JJEE.3322.ORG
    ! a9 a+ R! O; t" i8 @8 {2、Manage secure client access - >XenApp节点- > Manager Secure Access:) G: |# p7 y! L4 G
    SpecifyAccessMethods:(192.168.0.0/24=Direct;Default=Translated)& D; @; @0 {! `1 e  P! Y
    SpecifyAddressTranslations:- >Client device route translation(Client device/192.168.0.1:1494/jjee.3322.org:1494)% x5 p$ A0 _6 c: f9 N, D8 B
    测试成功!7 S/ s0 o/ T/ x( \
    备注:(telnet 192.168.0.1 1494 检测XenApp服务是否开启1494端口), N9 K! \' v' H/ V- r1 d# ^
    5 @# m" G- h! q1 ?; @
    PNAgent连接配置:(开启1494端口)
    0 p! n0 T3 E) `. h1 cManage secure client access - >PNAgent节点- > Manager Secure Access:
    3 M8 I; U, C5 W9 F/ n" gSpecifyAccessMethods:(192.168.0.0/24=Direct;Default=Translated)$ E: p# T! Z$ Y( B( u6 g. b4 S2 Y
    SpecifyAddressTranslations:- >Client device route translation(Client device/192.168.0.1:1494/jjee.3322.org:1494)
    ; @. K  j9 D( ^& f7 r测试成功!
    1 o9 {3 K. @# w# K
    2 z$ T$ j6 _+ h. }. |  _9 O: t==================================================================================================================
    : Z' f9 _2 @* X: y7 t' |% cALTADDR [/SERVER: servername] [/SET AlternateAddress] [/V]
    3 P. u# |) W! x# L+ BALTADDR [/SERVER: servername] [/SET AdapterAddress AlternateAddress] [/V]
    / }8 F% ^# w0 w) B% D. vALTADDR [/SERVER: servername] [/DELETE [AdapterAddress]] [/V]
    ( ]; _1 R* W% t& B. S8 |* g( [! s% k9 f- c* ]& r" q# h3 N
    Query or set alternate network addresses for an application server& L5 x5 O+ f% Q4 ^
    The alternate address is an external address known to clients outside/ I5 u, R0 D6 A' ?# t8 b. ^
    a firewall.% t& T  e4 ]" v9 F

    - R' f* b$ K2 X! s- D7 r: ]Options:
    ; n; o* q& E1 R" ` [/SERVER:name]               - configure the specified server+ p, }6 G# Y6 n) j* z
    [/SET]                       - set alternate TCP/IP addresses
    1 ]9 M9 a, p2 [6 v [/DELETE [adapteraddress]]   - delete the default or specified adapter address" ?% T8 }4 O+ r& i1 [- ^4 Z
    [/V]                         - verbose display mode) f- t, b9 K, m( q
    [/?]                         - display help message! |7 s" A& B+ K& X% e7 q

    1 H+ G$ Y  o+ I7 Y) ?9 c- CWhen setting alternate addresses, specify a single IP address to4 Q8 f$ j- p! W2 w: i
    indicate the alternate IP address used by default for all adapters
    , _8 M. w( T3 }. _on the system, or specify a pair of IP addresses that indicate a5 P# o  A: p; I
    particular local IP address and its corresponding alternate address.
    启用邀请码注册,提高发帖质量,建设交流社区
    您需要登录后才可以回帖 登录 | 注册

    本版积分规则

    快速回复 返回顶部 返回列表