Mark, the Citrix XenApp of course has different Web Interface settings/setups for "Web Browser" access vs "PNAgent" (Receiver client) access.
I take it the two sites are configured the same, ie Direct Access mode ?, with the Auhentication setup the same ? If not, successfull browser access != successfull reciever access.
Also, can you confirm that alll auth systems are set to get correct time from NTP (incl the bigip)
Lastly, can you adjust the policy temporarily to just Auth againt AD to see if the connectivity is successful ?
Regards
Gary