?
Solved

citrix firewall issue

Posted on 2011-03-08
9
Medium Priority
?
1,794 Views
Last Modified: 2012-05-11
Testing a third party fw issue and posting here as another admin is having issues configuring his fw. My question is, I can telent to port 1494 but cannot connect thru citrix client, gives "no connection to citrix xenapp server" despite establishing a socket on 1494 could there be an alternate fw rule to consider?
0
Comment
Question by:davesnb
  • 6
  • 3
9 Comments
 
LVL 37

Expert Comment

by:Carl Webster
ID: 35076269
Do the users connect via Web Interface or directly to the server?

If Web Interface you will need to open TCP ports 80 or 443.

If they are using Session Reliability, then you need TCP 2598 open.

Port 1494 is the standard ICA port.
0
 

Author Comment

by:davesnb
ID: 35076983
Yes it is web portal. Can get on the site but when I click the desktop app, the client app launches but met with error described above
0
 

Author Comment

by:davesnb
ID: 35082671
Will try that, here is the latest log, it is trying to connect and failing on 6101, what service is on that port? Why is it trying to connect on that, I though it was port 10000

[4004] 03/09/11 05:45:40 BETCPConnection::LoopThroughListAndConnect: Could not connect to remote address "192.168.32.201" Error:10061.
[4004] 03/09/11 05:45:40 @@@@@@@MyCloseSocket called with sockfd = 640(0x280)      retval = 0
[4004] 03/09/11 05:45:40 BETCPConnection::CreateConnectionFromHostAndPort: Remote Host: "SQLBU": There were no addresses returned, belonging to family: IPv6
[4004] 03/09/11 05:45:40 BETCPConnection::CreateConnectionFromHostAndPort: Could not create a connection to "IASSQLBU" because attempts with both IPv4 and IPv6 protocols failed
[4004] 03/09/11 05:45:40 Could not create a BETCPConnection object from address: SQLBU error=An error occurred during a socket connect operation: Error Code: 10061, System Error Message: No connection could be made because the target machine actively refused it.
[4004] 03/09/11 05:45:40 NrdsAdvertiserThread: connect to target=SQLBU port=6101 failed
0
Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

 

Author Comment

by:davesnb
ID: 35082688
disregard previous post , wrong thread, sorry
0
 

Author Comment

by:davesnb
ID: 35083970
I am able to get on thru the program neighborhood application set creation process, however cannot get on via the web portal . The ports that are open where i am trying to connect is ;

8080/tcp open   http          Citrix Metaframe ICA Browser
1494/tcp open   citrix-ica    Citrix Metaframe XP ICA
443/tcp  open   ssl/http      Microsoft IIS webserver 5.0
80/tcp   open   http          Microsoft IIS webserver 5.0
541/tcp  open   osiris        osiris host IDS agent
3389/tcp open   microsoft-rdp Microsoft Terminal Service

He was merely changing the fw, the metaframe server did not change. However,  cannot get on via web browser now that the new fw is in place. Here is the contents of the ICA file from web browser ,scrubbed version. Again, I can log into the sight , but when i click the application icon "admin desktop" the web error is "cannot connect to citrix xenapp server, no server configured on specified address" .

[Encoding]
InputEncoding=ISO8859_1
[WFClient]
Version=2
ClientName=domain-user9999

RemoveICAFile=yes


[ApplicationServers]
Admin Desktop=

[Admin Desktop]
Address=192.168.1.6:1494
InitialProgram=#Admin Desktop
LongCommandLine=
DesiredColor=2
TransportDriver=TCP/IP
WinStationDriver=ICA 3.0



AutologonAllowed=ON
Username=user9999
Domain=\ENCRYPTED
ClearPassword=\ENCRYPTED



DesiredHRES=800
DesiredVRES=600
TWIMode=Off


EncryptionLevelSession=EncRC5-128


SessionsharingKey=2-rc5-128-none-domain-user9999-citrixFarm

[EncRC5-0]
DriverNameWin16=pdc0w.dll
DriverNameWin32=pdc0n.dll

[EncRC5-40]
DriverNameWin16=pdc40w.dll
DriverNameWin32=pdc40n.dll

[EncRC5-56]
DriverNameWin16=pdc56w.dll
DriverNameWin32=pdc56n.dll

[EncRC5-128]
DriverNameWin16=pdc128w.dll
DriverNameWin32=pdc128n.dll

[Compress]
DriverNameWin16=pdcompw.dll
DriverNameWin32=pdcompn.dll
0
 
LVL 37

Expert Comment

by:Carl Webster
ID: 35084043
Can the user get to your server at IP 192.168.1.6 from their location?  I seriously doubt it.
0
 

Author Comment

by:davesnb
ID: 35084146
Good point, why is the ica file being generated have adderess as Address=192.168.1.6:1494 . i checked that against a working ica file to another site and address= a proper public ip. The ica file is telling my client to connect to 192.168.1.6 , which obviously i will not be able to connect to across the net.So how is this resolved?
0
 
LVL 37

Accepted Solution

by:
Carl Webster earned 2000 total points
ID: 35084300
0
 

Author Comment

by:davesnb
ID: 35128879
further info , NFuse_IPv4AddressAlternate I set the correct external ip in the template.ica file on web, that corrected it. In my case, we do not use the secure gateway.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Internet Explorer #Enterprise Mode #IE 11 #IE 8
CITRIX XENAPP 6.5 FARM CUSTOM POLICY - CHANGE MANAGEMENT WINDOW REBOOT SCHEDULE
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

750 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question