quote:
This is driven by the fact that our Citrix Admin does not want the clients to surf the net while in a Citrix session.
Three solutions, best to worse:
  • You must already have a firewall in place, so simply deny HTTP FTP etc. to the Citrix machines. Easy to implement, and impossible for clients to circumvent. If *some* of the citrix clients need Internet access, implement a proxy. Again this is very simple and has many benefits.
  • Set the proxy settings for Citrix IE clients to a dummy address, and allow direct connections for local addresses, and any external addresses which are deemed acceptable. Any attempt to access an external address will try to use the proxy - as this is a dummy address it will fail and the request will not be serviced.
  • Set the Citrix machines to use an internal only DNS server


[ 08. August 2003, 10:03: Message edited by: Richard H. ]