<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,When a user wants to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581867#M204218</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When a user wants to connect to a Citrix session using Citrix ICA client (citrix receiver) the ICA client uses port number 1494 and port number 2598 for session reliability.&lt;BR /&gt;Port number 1494 is default for ICA connection, allotted by IANA to Citrix.&lt;BR /&gt;&lt;BR /&gt;Session reliability contains a secure connection over SSL and it also has the ability to maintain the sessions during fail-over.&lt;/P&gt;&lt;P&gt;So, you need to permit these ports on user ASA to allow Citirx via ASA.&lt;BR /&gt;like:&lt;BR /&gt;access-list (name) permit tcp any any eq 1494&lt;BR /&gt;access-list (name) permit tcp any any eq 2598&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Rahul Chhabra&lt;BR /&gt;Network Engineer&lt;BR /&gt;Spooster IT Services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Nov 2014 16:27:14 GMT</pubDate>
    <dc:creator>Rahul Chhabra</dc:creator>
    <dc:date>2014-11-11T16:27:14Z</dc:date>
    <item>
      <title>Citrix Access via ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581866#M204216</link>
      <description>&lt;P&gt;We have a customer with a Cisco ASA5505 Firewall and they recently gone to a Citrix cloud environment. We are having a problem allowing the Citrix traffic through the ASA. Anyone with any ideas or "steps to take" would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581866#M204216</guid>
      <dc:creator>swoods227</dc:creator>
      <dc:date>2019-03-12T05:03:17Z</dc:date>
    </item>
    <item>
      <title>Hi,When a user wants to</title>
      <link>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581867#M204218</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When a user wants to connect to a Citrix session using Citrix ICA client (citrix receiver) the ICA client uses port number 1494 and port number 2598 for session reliability.&lt;BR /&gt;Port number 1494 is default for ICA connection, allotted by IANA to Citrix.&lt;BR /&gt;&lt;BR /&gt;Session reliability contains a secure connection over SSL and it also has the ability to maintain the sessions during fail-over.&lt;/P&gt;&lt;P&gt;So, you need to permit these ports on user ASA to allow Citirx via ASA.&lt;BR /&gt;like:&lt;BR /&gt;access-list (name) permit tcp any any eq 1494&lt;BR /&gt;access-list (name) permit tcp any any eq 2598&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Rahul Chhabra&lt;BR /&gt;Network Engineer&lt;BR /&gt;Spooster IT Services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 16:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581867#M204218</guid>
      <dc:creator>Rahul Chhabra</dc:creator>
      <dc:date>2014-11-11T16:27:14Z</dc:date>
    </item>
    <item>
      <title>Hello,  If you access the</title>
      <link>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581868#M204220</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you access the Citrix Cloud Enviroment from the inside hosts to the outside, you will need to permit that communication on the ASA on the Outside Access group, to the server, and Citrix uses specific TCP ports for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either ways I will give you 3&amp;nbsp;documents that have the Port numbers and another one for how to apply this access group to permit this communication, also remember the access group applied on the inside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Configuring TCP ports for Citrix communication:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;http://support.citrix.com/proddocs/topic/xenapp65-admin/ps-securing-cfg-tcp-ports.html&lt;/P&gt;&lt;P&gt;-&amp;nbsp;http://support.citrix.com/servlet/KbServlet/download/2389-102-704421/CTX101810_28th_June_2013.pdf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Permitting or Deniying Network Access:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/access_nw.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any questions let me know,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please don't forget to rate and to mark as correct the helpful post!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;David Castro,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 18:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/citrix-access-via-asa5505/m-p/2581868#M204220</guid>
      <dc:creator>David Johan Castro Fernandez</dc:creator>
      <dc:date>2014-11-11T18:43:26Z</dc:date>
    </item>
  </channel>
</rss>

