Objective
This article describes how to configure automatic HTTP port 80 redirection to HTTPS port 443 for a server in which Secure Gateway and Web Interface are both installed.
To redirect listening local port 80 / HTTP to port 443 / HTTPS, you must have a redirection page listening on port 80. If this page is the same as the Web Interface page, which needs to listen on an accessible HTTP port, there will be a conflict. Only one service or main page can listen on the same port.This situation is typical for a server placed in a Demilitarized Zone (DMZ), where it has a purpose for external access only on port 443 / HTTPS but can be accessible on port 80 / HTTP. This design always opens secure HTTPS connections when users enter HTTP links.
Instructions
Use a different listening port within Internet Information Services (IIS) for the Web Interface page. The unsecure port would not be used because you need to redirect this port to secure access using HTTPS. Use any free port on the server.
The following example procedure uses port 8080:-
Open IIS manager and create new Web page.
-
Set the listening port to 8080 during the wizard.
-
Name it WI.
-
Create a new Web Interface page in the Access Management Console and select the NEW page.
-
Confirm all other necessary settings for the page.
-
Return to IIS Manager and open Properties of the page.
-
Set redirection to the Secure Gateway’s https address / externally accessible Fully Qualified Domain Name (FQDN).
As Secure Gateway is listening on the same server on HTTPS port 443, do not set port 443 for this page (or any other page).
Do not import SSL certificates to this IIS page.
As Secure Gateway is not an IIS service, if IIS attempts to listen on secure port 443, it would block Secure Gateway and create a conflict between both services. -
Run Secure Gateway, assign the certificate, and choose the 443 port.
-
In the section specifying the Web Interface page / server, select the destination port 8080 of the WI page.
-
Finish the wizard and test the server connection with a client computer.
-
Ensure that the client has access and can resolve the FQDN on both of the HTTP and HTTPS ports.
In addition, the Web Interface on port 8080 can be blocked by a firewall, or block incoming IP ranges in such a manner to only allow the same server’s IP address configured in the IIS page > Properties > Settings. The blocking of an unsecure port prevents anyone using a non-encrypted method from accessing the server.
Supporto Citrix
Traduzione automatica
Questo articolo ?? ¨ stato tradotto da un sistema di traduzione automatica e non ?? ¨ stata valutata da persone. Citrix fornisce traduzione automatica per aumentare l'accesso per supportare contenuti; tuttavia, articoli automaticamente tradotte possono possono contenere degli errori. Citrix non ?? ¨ responsabile di incongruenze, errori o danni derivanti dell'uso di articoli automaticamente tradotte.
Citrix技術支持
自動翻譯
這篇文章被翻譯由一個自動翻譯系統,並沒有受到人們的審查。 Citrix提供自動翻譯,增加獲得支持的內容;但是,自動翻譯的文章可能可以包含錯誤。思傑不負責不一致,錯誤或損壞因使用自動翻譯的文章的結果。
Поддержка Citrix
Tradução automática
Эта статья была переведена автоматической системой перевода и не был рассмотрен людьми. Citrix обеспечивает автоматический перевод с целью расширения доступа для поддержки контента; Однако, автоматически переведенные статьи могут может содержать ошибки. Citrix не несет ответственности за несоответствия, ошибки, или повреждения, возникшие в результате использования автоматически переведенных статей.
시트릭스 지원
자동 번역
이 문서 자동 번역 시스템에 의해 번역 된 사람들에 의해 검토되지 않았다. 시트릭스는 컨텐츠를 지원하기 위해 접근을 높이기 위해 자동 번역을 제공합니다; 그러나, 자동으로 번역 기사 오류를 포함 할 수있다. 시트릭스는 자동으로 번역 된 기사의 사용의 결과로 발생하는 불일치, 오류 또는 손해에 대해 책임을지지 않습니다.