Thursday, March 3, 2011

CITRIX ACCESS ESSENTIALS 2.0

How to install Access Essentials 2.0 publish application, make the applications available on you LAN and also the Internet
Installing and configuring Access Essentials (CAE) 2.0 also called XenApp Fundamentals 2.0 is very simple compared to the other XenApp versions like XenApp 5 or 6. With CAE  you can publish applications for up to 75 users and also the license is bundled with Terminal services License.
These are the installation procedures
Prerequisites: You can install: IIS, Terminal services, .Netframework 3.5 SP1, java runtime 1.6 (Note that you don't have to manually install these, as they will be automatically installed during the CAE installation). It's not recommend to have the XenApp sever on a Domain Controller and also to have a static IP address for the CAE server.
Notice that it will display XAF_3_0_0 on the CD-ROM drive, that is because the media contains both the 2.0 and the 3.0 versions, when it detects that you are running a server 2008 then it installs XenApp fundamentals 3.0 but if it's a server 2003 then it install the 2.0 version. when you double click the installation media icon, on the CD-ROM drive, You are presented with this:

 Click install Access Essentials. Accept the license agreement, click Next. Since the machine is a member server, we shall select Application server. If the machine were not a domain member and on a separate Network then we could select Network Access (DMZ) server would be the appropriate option. Click Next twice.


Click Yes to restart when presented with the below message.

After the reeboot, click Finish to lunch the quick start tool.

Click Next twice and Finish.

NB: if you receive a failure error message with an X , just remove the machine from the domain and rejoin it. It's a Domain or DNS problem.
But if you don't receive any error message you should see the following tool called the "Quick Start".
The quick start tool is used in centrally configuring the XenApp Fundamentals 2.0 or 3.0. It's an easy interface where you can install the license, see the internal site, confihure the secure external site publish applications...You don't even need to use the other traditional tools like the Citrix Management Console or the Presentation Server unless you really know what you are doing or you are doing some troubleshooting.

This is how to publish an application from the Quick start



Once the application to publish has been selected, you can add the users that you want to allow access to the application.



Configuring External Access, so that users outside you network or on the internet can securely connect and lunch the application.
First don't forget to open "only" port 443 on the firewall, also make sure that you  NAT the internal IP address of the server is NAT to the external address of your firewall. ( Those things are to be done by the Network Infrastructure Admin).
Also make sure that you have an internal Root Certificate Authority otherwise you will have to buy a public certificate ( and i don't think you want to do that).
So when you set up an internal Root CA, any machine on you internal domain can request a certificate and install because they trust the CA.
Now i came to a scenario where the client machines Accessing the applications from the internet where not part of the domain. I struggled a lot before before i knew how to resolve the problem.
So will create another post where i will show how to install a Root CA and also how to configure machine from the internet to trust our internal CA.
For now let's just setup the external Access



Specify the public name, but make sure there is a certificate installed on the machine either from a public SSL service provider or in my case, i made the citrix server a Certificate authority and it assigned itself a certificate

Then you can either select the 30 days temporary cert from citrix or create a cert request file or...

Then Click OK and Finish

Thank you for your attention and don't hesitate to add comments, rectify me if any mistake (No man is perfect). You also have my email address for a direct contact.
You can also view my post on setting up a Root CA and request a cert chain and installing it on client machines on the internet if they are not from the internal domain.

No comments:

Post a Comment