Question

Web Interface "There is no Citrix Metaframe server configured on the subnet"

Asked by: stamperb

Internally things work fine.  Externally they get the error above.  I know exactly whats wrong here but can't find the answer anywhere!!
My citrix servers are on my LAN behind my firewall.
My web interface server is on my lan behind my firewall as well.

The client is getting the launch.ica which contains a https:// connection to the local ip address rather than the external ip address of my fireall that i have port forwarded through.  

I don't have CSG, I don't have Access gateway.  Does anyone know how i get the web interface to hand off the ica connection with the right properties?  I've looked all over the management and all over the web but haven't had any luck?
Thanks,

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2006-03-30 at 08:32:11ID21795472
Tags

citrix

,

server

,

configured

,

address

,

web

Topic

Citrix

Participating Experts
1
Points
500
Comments
25

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Citrix - ICA Connection Security
    Hi, I have a question about our Citrix security. Our setup here is that our Citrix server is open on the firewall through the normal port. This is the only port open. Our remote home users have Citrix program neighbourhood installed. From here they have setup an ICA con...
  2. Cannot connect to the Citrix metaframe server. There is no…
    I have setup a test Presentation Server 4.0 (running everything including IIS) on our network. I am tiring to get the web interface to work. I can connect and run it on the LAN and from home via our VPN (using the internal IP address of the server) I have opened the follo...
  3. WI, CSG, IIS issue
    Right now I have the WI and CSG on one server in the DMZ. On the secure LAN we have 2 presentation servers. Ports open to the secure network are: 80,443,1494 Ports open to the External network are: 80,443 Right now the CSG is configured to listen on port 443 and IIS is co...
  4. Cannot connect to the Citrix Metaframe server. The Citrix …
    I trying to access an application using Web Interface an CSG, I get the following error. "Cannot connect to the Citrix Metaframe server. The Citrix SSL server you have selected is not accepting connections". My setup is as follows. I have 1 CSG and one WI in a DMZ....
  5. There is no Citrix Metaframe server configured on the speci…
    I am responsible for a Citrix server that was configured by an outside company which is increasingly difficult to contact. I'm concerned with the inability of users to connect from the outside into published applications there. Users are able to log into the web interface, ...
  6. cannot connect to the citrix metaframe server.  There is n…
    I am having a normal citrix setup , I used to connect to client locally thru the web interface i.e. http://test/Citrix/MetaFrame/auth/login.aspx and from internet i used to connect thru the link http://24.187.244.249:8067/Citrix/MetaFrame/auth/login.aspx as natting is defin...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: mgcITPosted on 2006-03-30 at 08:44:36ID: 16334137

Open the Access Suite Console (the Web Interface admin utility)

for your site click Manage secure client access > Edit DMZ Settings

Your default connection is probably set as "Direct"

The best way to set this up is to set the default to "Alternate" and then add additional rules for your internal LAN such as:

Client IP Address: 192.168.1.0 (or whatever your internal subnet is)
Mask: 255.255.255.0
Access Method: Direct

This way anyone coming from the outside will use the alternate addressing you have set up.  However, if they go to the web interface using the internal address, it will just use the normal Direct access.

 

by: stamperbPosted on 2006-03-30 at 08:55:29ID: 16334271

OK I feel i'm on the right track here.  So i've set up the following DMZ Settings:
Default  - Alternate
172.16.0.0/20 - Direct

172.16.0.0/20 is my LAN.

Now from ouside i get an error right away when i try to connect at the bottom of the login screen that says:
ERROR An error has occured while connecting to the requested resource.

Do i have to setup any address translations?

Here is some more detail:

Internet  -> Firewall -> Internal Router -> Web interface (172.16.0.10)
                                          |
                                          |-> Citrix Servers 10.11.34.2, 10.11.34.3, 10.11.34.4

I have port 443 forwarded thru to 172.16.0.10 on the lan for my Web Interface.  
 

 

by: mgcITPosted on 2006-03-30 at 09:14:56ID: 16334489

first of all what is the "/20".. I'm not familiar with that >> 172.16.0.0/20

secondly here's the steps you will need to take in order to have access externally:

1. set up an alternate address using the "altaddr" command on EACH of your PS 4.0 servers

2. set up the NAT in the firewall to point the external addresses (set up in step 1) to the internal IP Addresses of EACH of your citrix servers

3. open ports 1494, 80 (or whatever your xml port is), and 2598 (if using session reliability) on the firewall for EACH of the IP addresses

since you are not using Secure Gateway you need these ports open.  It won't just pass through the web interface on 443.  if you want to skip all that you can install SG.

 

by: stamperbPosted on 2006-03-30 at 09:16:53ID: 16334508

OK understandable.  Next question then.  Isn't doing what you said above pretty unsecure?  I mean nothing is encrypted?  Correct?
Thanks,

 

by: mgcITPosted on 2006-03-30 at 09:19:10ID: 16334535

and sorry one more thing yes you have to set up address translations using the admin console:

Manage secure client access > Edit Address Translations

these are the same IP translations as step 1 & 2 above

 

by: mgcITPosted on 2006-03-30 at 09:21:46ID: 16334559

>> Isn't doing what you said above pretty unsecure?

Although you can turn on encryption from the ICA Client / Citrix Farm yes I think it is.  I would strongly suggest installing Secure Gateway (by the way what version of citrix are you running?).  The first time you set up Secure Gateway it is a real pain and can be confusing but once you do it ( I suggest in a test environment first) it becomes pretty easy.  That will give you the most security - everything will go over port 443 and you won't need to open all the ports on the firewall.

 

by: stamperbPosted on 2006-03-30 at 09:47:01ID: 16334813

Very good thats what i'm after anyway!!!  I'm on a brand new farm w/ Presentation server 4.0.  

Here is a what would you do for ya!!  

I have 3 citrix servers.  I have my Web Interface Server.  How would you reccomend setting this up? See i'm short a server for a CSG box.  I really don't wanna go back up asking for another 3K or something for this server i forgot about cause i didn't plan my deployment well enough?  Could it be done w/ just the 3?  Do i need the web Interface server if I use CSG (I'm assuming yes?).  
THanks,
Brian

 

by: stamperbPosted on 2006-03-30 at 09:57:12ID: 16334906

Can csg and web interface possibly run on the same box?  Just another thought.  I'm trying to figure a way to make it work in the already purchased environment i have :-)

 

by: mgcITPosted on 2006-03-30 at 10:06:25ID: 16334996

yes it can be on the same box

 

by: mgcITPosted on 2006-03-30 at 10:23:07ID: 16335197

Here is the Admin guide: http://support.citrix.com/article/CTX106300

You'll probably want to go with a single-hop dmz method as that is the easiest to configure and requires less hardware.  Once you have downloaded the SG 3.0 install files from mycitrix.com let me know and I can help you through the install.

 

by: stamperbPosted on 2006-03-30 at 14:00:33ID: 16337369

OK so a few questions:
I have my ssl cert on the current box for the web interface.
I installed the csg portion of things.  Changed the SSL Port that IIS uses to 444 since CSG config was complaining about it being in use.  Then came to the STA part.  According to the directions of the setup i point this at my Presentation server 4.0?  Now its looking for that /Scripts/CtxSTA.dll.  Well IIS isn't even installed on my citrix box so i'm thinking somethings not right there.
That CtxSTA.dll exists in C:\program files\citrix\system32 on my presentation server but i'm still not thinkin thats right?


So is there something i need to do to install the STA on my presentation server?

 

by: mgcITPosted on 2006-03-30 at 14:07:25ID: 16337432

short answer: NO

STA is automatically installed now when you install PS 4.0.  And it won't use IIS so you don't need to configure that either.  The main thing you need to worry about is the name & port of the STA servers.  If your XML port is 80 then you don't need to worry about it but if not make sure to change it.

In the Web interface admin page you have to specify the STA servers as well.  Again if the XML port is 80 just specify the FQDN name of your servers.  Otherwise specify it like this:

server.myloc.hq:8080  (for example if your XML port is 8080).

 

by: mgcITPosted on 2006-03-30 at 14:14:32ID: 16337482

I read that back and it sounded a little confusing so hopefully this will clear it up if you were confused.

When configuring Secure Gateway it will ask for you STA servers.  Specify the FQDN name of all your PS 4.0 servers and also specify your XML port if it is something other than 80.

After that you will also need to specify the STA servers in the Web Interface Admin console.  To do that click Manage Secure Client access > Edit Secure Gateway Settings.  On this screen type in the FQDN name of your server and also specify the XML port if it's something other than 80.  So it will look like this:

http://server.myloc.hq:8080/scripts/ctxsta.dll

or just:

http://server.myloc.hq/scripts/ctxsta.dll  if your XML port is 80 (the default)

 

by: stamperbPosted on 2006-03-30 at 14:26:19ID: 16337565

OK my problem is when doing the STA for the CSG stuff.

When I put in the FQDN of the PS 4.0 Server I get the error:
The secure ticket authority can not be contacted.

To ignore the warning and enter the ID click continue.  

If i click continue the ID field opens up but I don't know what to put there?

 

by: mgcITPosted on 2006-03-30 at 14:43:47ID: 16337672

yea it should put the ID in automatically.  

Are the servers on the same LAN?  
Can you ping that FQDN from the Secure Gateway server?

are you checking the box that says "Secure traffic between..."?  If so uncheck this and just specify your normal XML port.

 

by: stamperbPosted on 2006-03-30 at 14:51:36ID: 16337742

They are on diff. subnets but yes on the same lan.  I can ping FQDN.  However i have 3 servers and the 3rd one put the id in and went fine.  Now i am getting errors in my event log about not being able to communicate w/ the config service on my first server.  I'm going to give them a reboot and see if that helps.

 

by: stamperbPosted on 2006-03-30 at 15:06:49ID: 16337858

OK now back to step 1.  When i go to connect i get to the page, get logged in, click to lauch my connection to the published desktop and get the error there is no citrix metaframe server configured on the specified address?

 

by: mgcITPosted on 2006-03-30 at 15:18:49ID: 16337938

ok go back to the WI admin console:

for your site click Manage secure client access > Edit DMZ Settings

change default to Secure Gateway Alternate

 

by: stamperbPosted on 2006-03-30 at 15:25:36ID: 16337989

I thought of that but every time I try to change it it says it lost contact to the server.  So i think maybe i have a problem w/ something on one of the PS 4.0 servers?  It wouldn't even let me remove the site to re-add it.

 

by: mgcITPosted on 2006-03-30 at 15:36:53ID: 16338060

does your site have a local configuration or centralized?

To see this click Local Site Tasks > Manage configuration source

or maybe it's just because you were rebooting your citrix servers and they haven't come back online yet.

 

by: stamperbPosted on 2006-03-30 at 19:39:10ID: 16339233

Its centralized.  I'm gonna do some work on it now. See what i can come up with

 

by: stamperbPosted on 2006-03-30 at 20:13:32ID: 16339364

So i've got things going now.  I'm not sure what caused all that but something w/ the setup stuff.  Had to run configure for just each server individually and remove the config.  Anyway back to being good now.  

So in the address translation stuff.  I need to set translation for the Secure gateway but what IP do I use for the LAN?  The PS 4.0 addresses? or the Web Interface address?  And then for the external do i put the external IP for my internet connection?

Thanks,

 

by: stamperbPosted on 2006-03-30 at 20:14:47ID: 16339370

Also what port external and what port internal for the translation?

 

by: mgcITPosted on 2006-03-31 at 07:16:05ID: 16343164

well actually you probably don't need that now.  Is your WI / SG server on the same subnet as the rest of your farm?

If so you can change the default access method to Secure Gateway Direct.  Then you can get rid of all your address translations because it will just be using the internal addresses.

 

by: stamperbPosted on 2006-03-31 at 08:36:42ID: 16343980

THANKS SO MUCH!!  I'VE GOT THIS ALL GOING!!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...