Thanks again for the leads. I think for now I might just employ a rule on our firewall that allows only corporate Wi-Fi traffic into the Citrix host. Anyone who wants to work remotely outside of that can just e-mail me to whitelist them. What I'm not used to compared to the Cisco ASA is that any firewall NAT rule changes can't be done on the fly during production hours. Since all traffic that traverses the firewall is briefly interrupted. Our SIP phone registrations, active SIP calls, client/server traffic, etc. So have to do it off-hours. That's kinda a pain but it is what it is I guess.
... View more