Currently setting up fault-tolerance for multiple Citrix Access Gateway Appliances. If you can upgrade to (or have) Access Gateway version 5 then the built-in features will do the job here, but for version 4.x the in-built load-balancing does not work for CAGs operating as Secure Gateway replacements (it only works for full-blown VPN connections). 

We've therefore deployed the rather excellent, open-source HAProxy on a vSphere Linux VM as a load-balancer for a customer where Citrix Access Gateway version 5 is not an option at the moment. It makes a fantastic and low-cost alternative to expensive, proprietary, hardware load-balancers, and vSphere ensures availability of the load-balancer through VMware HA.