It is because Citrix is highly-protective of their intellectual property and refuses to allow 3rd party companies like Juniper to develop ICA proxy functionality. Otherwise we would have done it already. Citrix does offer a partner alliance but automatically denies entry to any of their competitors. We are investigating options on how to handle the proxy'ing of ICA traffic on iOS-based devices, but today ZanyTerp is correct that you will need to establish a Layer 3 VPN session via Junos Pulse prior to connecting to your Citrix XenApp/XenDesktop environment. Unfortunately, today, the ONLY official solution on the market that is capable of supporting this without a Layer 3 VPN tunnel is Citrix. The Citrix Receiver client solution contains a proxy in the client that works in conjunction with the proxy that operates on the Citrix Access Gateway. It is not the CAG that is doing 100% of the "heavy lifting" in terms of proxying the ICA traffic, so keep that part in mind as well.
... View more