|
Q What is license pooling and sharing?
A License pooling accumulates all available user licenses and makes the grand total available across the deployment. A central Access Gateway appliance can pool and share licenses for all the other Access Gateway appliances in the same DMZ. Likewise, a license server on the internal network can pool and share licenses for all servers in multiple server farms.
If the license server fails, or the appliance hosting the licenses fails, a thirty day grace period is provided. If a central appliance goes down, each of the remaining appliances will be provisioned with the total number of licenses. When the central appliance is again functioning normal pooling and sharing is re-established.
Q How are licenses consumed?
A A user session managed by the Access Gateway appliance consumes a base user license for Access Gateway. A user session managed by the Advanced Access Control option consumes a base license for Access Gateway as well as an option license for Advanced Access Control.
Q How do MetaFrame Secure Access Manager Customers migrate to Citrix Access Gateway?
A Existing MetaFrame Secure Access Manager customers with a valid Subscription Advantage membership can use MyCitrix to obtain licenses and software for Citrix Access Gateway and Advanced Access Control. If Subscription Advantage has expired, customers will need to get current before requesting.
Q Does the Access Gateway have the same security risk in bridging networks as the network extension option of SSL VPNs?
A No. The network extension option of SSL VPNs has a security exposure because it exposes the IP address of the remote network to the client. The Access Gateway does not expose IP addresses in the remote network, which effectively blocks worms from traversing.
Q I cannot use my IPSec VPN to connect back to my network when I am at a customer or partner site. Does the Access Gateway have this same limitation?
A The Access Gateway can traverse any firewall that has SSL (port 443) open. This is the same port that is used to access secure Web sites such as airline reservations, extranets, etc. It is nearly always open. The Access Gateway also works in cases where ISPs or home networks block IPSec VPN traffic.
Q Does the Access Gateway force users into an artificial “portal view” of their applications?
A No. The Access Gateway provides the same experience that users have when they are sitting at their desks at work. Applications, file shares, Web applications, etc. are all accessed normally, which eliminates the need to re-train users on a different interface.
Q How is the Access Gateway different from other SSL VPNs in the market?
A The Citrix® Access Gateway provides users and IT administrators with all of the advantages of both IPSec VPNs and SSL VPNs, and none of the shortcomings. This means users do not have to think about starting, stopping, reconnecting or different modes, and administrators do not face the significant IT burden of a typical SSL VPN deployment. SSL VPNs use a complex and confusing mixture of four essentially inoperable technologies — Web proxying, application translation, port forwarding and network extension — to attempt to accomplish secure remote access. However, because each of these technologies has different benefits and limitations, the administrator and user must decide which technology to configure and use in different situations. This leads to a great deal of complexity, maintenance and management. In addition, many organizations continue to maintain an IPSec VPN deployment for applications that are not supported by any of the four SSL VPN technologies, further increasing the administrative burden and costs.
In contrast, the Access Gateway combines into a single product the functionality of all four SSL VPN technologies and the benefits of IPSec VPNs as well, simplifying secure remote access for both administrators and users without compromising security.
Q What is the scalability of the Access Gateway?
A The Access Gateway supports up to 2,000 concurrent users at 300 Mbps per gateway. Actual numbers of users supported depends upon the level of activity and amount of user traffic. Support for more than 2,000 concurrent users is accomplished via multiple gateways. The Access Gateway employs Active/Active failover between gateways.
Q What applications are supported by the Access Gateway?
A The Access Gateway supports any application or protocol without any development work, webification, customer connectors, or other restrictions. This also includes the ability to run an IP soft phone.
Q What level of encryption does the Access Gateway use?
A The Access Gateway uses industry standard 128/168-bit Secure Socket Layer (SSL) and Transport Layer Security (TLS) to encrypt traffic. See the Citrix Access Gateway technical specifications for complete details on the encryption used.
|