At present the 2X Secure gateway does not authenticate users, it provides a tunnel from which 2X Client access to published resources is allowed. The 2X Publishing Agent service is the service which authenticates, so in a DMZ you would deploy the publishing agent within Active Directory, and have the 2X Secure Client gateway within the DMZ.