Link to home
Start Free TrialLog in
Avatar of curious7
curious7

asked on

How to troubleshoot long delay in launching citrix virtualapp apps?

We have Citrix VirtualApp 7.15.
The internal URL takes user to the netscaler VIP.
There is only on DC configured to authenticate users and 1 RSA  server.

We are having issue where  apps open after 5 min or 10 minutes after clinking on them . Sometime if the users are logged off due to idle timeout , on next launch it takes time or it will not even launch.
Storefront server is not logging any errors.
User profile store is accessible.
If I login to the application servers through rdp then they seem to be fine.

How can I troubleshoot this issue?
Avatar of Dirk Kotte
Dirk Kotte
Flag of Germany image

first i would check director for logon-time statistics.
next enable "user logon debugging" and check the logfile for one user to find the gap.
last i would disable EDT (or adaptive HDX transport) within citrix policy. (EDT try to switch from TCP to UDP for Transport - already seen firewall problems)

i think with RDP you don't use NetScaler ... so the NetScaler may be the problem too.
What Firmware on Netscaler? and Licensing - are you Platinum?

Next, what license model on Virtual Apps?

Abridged version....
This can become very easy fast if you are somewhat familiar with Netscaler, HDX Insight, and Director.

This is contingent on your Firmware version on Netscaler but you basically want to download the Netscaler MAS appliance for your Hypervisor - formerly known as Netscaler Insight.  So it went from Insight, to MAS, to now Application Delivery Management Software.

ADM - If Netscaler firmware is 12.1.X
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/release-notes.html

MAS - If Netscaler 12.x
https://docs.citrix.com/en-us/netscaler-mas/12/netscaler-mas-licensing.html

If still 11.x then recommend upgrading and downloading MAS/ADM.  Free for up-to 30 virtual servers.  Enabling Appflow on Netscaler, HDX Insight, TCP Insight, Gateway Insight and so forth and then a few commands you run on Citrix Director to bring all this information in to your Networking Tab on Director.  

1.      MAS license allows for 30 virtual servers then must purchase in pack of 100.  
2.      Enable Appflow on your Secure Gateway VIP to capture all the HDX insight information and pull that into Director.  
3.      Consider doing the same for internal.  With all traffic passing through SG we get a better holistic view of all traffic – particularly when cutover to SDWAN if many of those remote sites are coming in by way of internet today.
4.      Enable ICA round-trip calculations in Citrix Policies for the client – server end user monitoring stats.

If you have platinum on Netscaler license and VirtualApps; on the MAS side that equates to a lot of features that we can enable and not using today but consumes a lot of disk space.  I think 8 vCPU and 32 GB of RAM is good most likely but perhaps on the disk configuration OS, core files, system log and so forth the 120GB default is sufficient but add separate vDisk (500GB) for the database and MAS logs.

Features that come to mind would be: (Each increases disk space and IO requirements)

HDX Insight
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/hdx-insight.html

WAN Insight (Future tense, SD-WAN analytics) – This is what I was referring to in that one email where we can optimize traffic flow.  
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/wan-insight.html

TCP Insight – would allow us to tweak or create “profiles” to optimize traffic by “region” for example depending on various bandwidth scenarios whether SD-WAN or Internet
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/tcp-insight.html

Gateway Insight – Pretty much every stat needed for troubleshooting failures or slowness but most effective if we have both internal and external users funneled through Access Gateway.  
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/gateway-insight.html 

Secure Web Gateway Analytics
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/secure-web-gateway-analytics.html

Application Firewall feature is currently turned off but would not hurt, IMO, to enable just the basic feature set of App Firewall.  Nothing fancy just the basic feature set is enough.
Then, Security Insight (I cannot think of a reason not to enable this on all Netscalers)
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/analytics/security-insight.html

I have not gone through all the configs but would like to have that discussion so that we are maximizing our use of the appliance.  Complete list:
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/licensing.html 

Not much difference here from 12.0 to this 12.1 Build 48.13 and that’s awesome that all the NetScaler’s themselves are build 48.13 as well.

And of course, the NITRO Service and API’s/SDK is in there as well – will come in handy.

Network Reporting
https://docs.citrix.com/en-us/citrix-application-delivery-management-software/12-1/networks/network-reporting.html

So if you have Netscaler Platinum license, same on Virtual Apps and you have Citrix Director up and running - all this can be done now.

This will allow you to see inside the ICA/FMA/HDX protocol and measure ICA Latency Times, see all errors, slow downs and pretty much anything associated with the traffic between the end-client, through the Netscaler, to the Citrix Server and everything in-between.
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.