This article is a summary of how to configure Access Gateway Enterprise Edition to support simultaneous remote access using all versions of Receiver, by all relevant access methods. This can be done with a single virtual server.
Network Architecture
The network architecture for this configuration is meant to be representative of many environments, from basic to advanced configurations.
A XenApp farm is used to host applications and a XenDesktop farm is used to access XenDesktops (XenDesktop can be accessed, though some of the pooled assignment models and functionality like desktop restart do not work with Storefront Services.)
A Storefront server sits in front of XenApp and XenDesktop, and is joined to the same Active Directory forest. LAN-based client machines using native Receiver can access Storefront directly or connect through a browser to the Receiver for web URL. A Program Neighborhood Agent Protocol interface is also available in Storefront, to support Mac OS X, iOS, and other similar Receivers.
Access Gateway Enterprise Edition is deployed in the DMZ, and Storefront Services is configured to accept connections from the Access Gateway Enterprise Edition.

Component Versions
The configuration documented here has been confirmed to work with the following Access Gateways:
The configuration documented here has been confirmed to work with the following clients:
Basic Storefront Services VPN-less Configuration – LDAP Authentication
In this scenario, a remote user can connect to Receiver for Web using an Access Gateway URL using a browser, or can connect to the Storefront Server with Citrix Receiver for Windows using the native service protocols, or can connect to Storefront Server with Citrix Receiver for other platforms using the legacy Program Neighborhood Agent protocol. In all three cases, the user does not need to establish a Virtual Private Network (VPN) connection, connections are made in VPN-less / clientless mode.
VPN-less access to Receiver for Web
A remote user launches a browser and enters the Access Gateway Enterprise Edition URL https://agee.tek.com and after successfully authenticating with Domain credentials, the user is able to access the Receiver for Web portal https://ds.tek.com/Citrix/StoreWeb. The user can now launch Auto-Provisioned applications or subscribe to published applications or desktops.
Click here to read the full Citrix Support Article
This maintenance release updates Access Gateway 5.0. Please note that this maintenance release is applicable to the Model 2010 appliance and Access Gateway VPX that supports Access Gateway 5.0.

Read more: Citrix releases a maintenance release for Access Gateway 5.0.4
I have been seeing a lot of support forums and problems around running the 2 latest versions of Citrix Receiver for Android together with Access Gateway 5.x VPX.
Now, after trying and trying to get it to work, I finally found a solution to the issue. It's more of a certificate issue than something else!
So, make sure that you have imported the certificate on the Android device. I downloaded the Astro file manager on the Android device, because it can also extract a zip directory. The reason for this is that I had a certificate zip file, and Outlook don't want to send .crt files... or just rename the license file... my zip file also included 5 other certificates.
Once you have installed them on the Android device, we are good to go to the management console of the Access Gateway 5.0.3 VPX.
Please note that I will not go thru the certification process!
Log in with your admin account!
Now go to your Certificates.
Now, I had a lot of problems getting this to work, and it turns out that some certificates actually needs to be Chain'ed on the CAG to work on the Android platform!
So, I finally found a solution to my Android issue. Depending on the certificate you are using (in my case, one from Comodo) you need to install a "cross root CA" cert and Chain/bind it as the CA to your site certificate. Now, this was not the case for either Linux, Windows, MAC or iPad/iPhone, but it seems that the Android is different when it comes to accepting certificates. I actually saw some blog posts about hacking the root CA part of it to get other solutions working...
So, that's it folks, this is what you need to do. When that is said, if you choose to use verisign certs. you will not get any errors browsing the website from any Android device. That's because the Android OS has a limited built in "trust" list of CA's to trust.
Access Gateway and Access Gateway VPX 5.0.3 has some new features from the older versions, here is a quick overview of the new features.
New Features available in Access Gateway version 5.0 include:
Important Licensing Changes
Platform License Required
Each appliance running Access Gateway 5.0 requires a platform license in order to function. Without the platform license installed, the gateway will not allow logins after a 48-hour grace period. Platform licenses are delivered electronically when an appliance is ordered. If you have an existing Access Gateway Model 2010 appliance covered by Warranty, you can obtain your Access Gateway Platform License using the Upgrade My Products toolbox on MyCitrix.
User Licenses Optional
The required Access Gateway platform license enables unlimited logins through Basic logon points. Each concurrent login to a SmartAccess logon point requires an Access Gateway user license. Access Gateway Standard Edition or Access Gateway Universal licenses may be used for this purpose.
Subscription Advantage Eligibility Date
To use your existing Access Gateway licenses with this version, the Subscription Advantage on those licenses must be valid on or after September 1, 2010.
Supported Platforms
Access Gateway 5.0 is supported only on the following appliance platforms:
Access Gateway VPX 5.0 is a virtual appliance for Citrix XenServer or VMWare ESX/ESXi that provides secure access to virtual desktops, applications and data while allowing users to work from anywhere. It offers the same capabilities as an Access Gateway physical appliance (Model 2010) while giving greater flexibility and more deployment options to IT administrators. Access Gateway VPX is the best choice for organizations who need to rapidly provision secure access, reduce infrastructure requirements, and minimize power consumption.
The Access Gateway imaging tool now exists as a .zip file containing all files necessary for reimaging the appliance. You download the .zip file, extract the files, and run the tool. The tool indicates the location of the USB drive. By using the .zip file, you no longer need to select an ISO file.
If you attempt to import an intermediate certificate to Access Gateway where the Subject field is longer than 128 characters, you receive the error message "Value too long for type character varying (128)."
You can now configure up to 25 servers running the Secure Ticket Authority (STA).
You can now add up to 256 static routes on the Access Gateway appliance.
You can now upgrade Access Controller from Version 5.0 or Version 5.0.1 to Version 5.0.2 without removing the previous version.
You can configure Access Gateway to use a XenApp Services site, giving users access to virtual applications from their computer desktop or mobile device when they authenticate through the Web Interface.
Click here to learn more ( may require a valid mycitrix.com account! )
![]()
Connect on Twitter