Posted July 27, 20177 yr I installed in my lab a fresh mas 12.0 build 51 on xenserver 7.1 along with a netscaler 12.0 build 51 VPX with a platinium license. I added my vpx to MAS and enabled appflow logging for my vpn server (smartaccess mode and DTLS enabled) I dont see any menu point for hdx insight and gateway insight. The only thing what i see is web insight and security insight.
August 28, 20177 yr Hi Stefan, This somewhat seems to be related to the client browser. I'd advise trying few things like clearing cache, updating the browser to the latest version or test using a different browser (updated as well) altogether. Thanks, Andrzej
September 8, 20177 yr Author i updated to the latest build. Now i have the menu point "HDX Insight". But at the moment, there is no data collected. Also - no xenserver tools on xenserver 7.1 for the appliance.. very frustrated..
September 8, 20177 yr Please try to review the following "how-to" and see if there is an answer for no HDX Insight reporting HDX Insight Data is not captured by NetScaler MAS - https://support.citrix.com/article/CTX224502#T10 CTX215130- HDX Insight Diagnostics and Troubleshooting Guide
September 11, 20177 yr Author Hi Andrzej, i found in my ns.log the following message: Skipping ICA flow: Session GUID [undefined], Client IP/Port [92.11.29.99/23047], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [undefined], Client Type [0x0000], User [undefined], Client [92.11.29.99 ], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134] Sep 11 10:33:34 <local0.info> 192.168.233.100 09/11/2017:08:33:34 GMT ns 0-PPE-0 : default SSLVPN ICAEND_CONNSTAT 79971 0 : In the knowledge base article, it sounds that xenapp version is incompatible. But i use xendesktop 7.15 with windows 10 creators update and remote pc VDA installation. The same is by my windows 2016 and 2012 r2 server os. Adapthive Display is set to off in the citrix policy. My client is win 10 creators update with receiver 4.9
September 25, 20177 yr Stefan, just checking - do you have SmartControl policy configured on NSG by any chance?
September 25, 20177 yr Author No. It’s simple one session policy configured with clientless vpn. No smart access or smart control.
October 19, 20177 yr Did you ever figure this out? I'm getting the same error Skip Code 134 on most but not all connections. I'm told by support that the message 134 means "ICA frame too large, exceeds 1460 bytes".
October 20, 20177 yr Author Hi Chuck, sorry no. The problem still exists and i had no time to open a support case. How can the ica frame be reduced ?
October 24, 20177 yr Hi Stefan, Did you notice any other skip codes other than 134? You can search using the source-ip of the client machine. Make sure you know the public ip of client from which traffic is coming to gateway. Also, check if ulfd mode is enabled on NetScaler. If yes, then disable it and check. See if appflow policies hits are increasing when you pass traffic to the NetScaler gateway. Regards, Hitesh
October 25, 20177 yr Author Hi Hitesh, i only get the skip error 134. Before updating netscaler 11.1 and mas 11.1 to 12.0 appflow was working fine. ULFD is disabled and appflow policies are increasing.
October 26, 20177 yr Hi Stefan, Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS. There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14 If already on this version, can you try disabling 'session reliability' on SF and check? Regards, Hitesh
November 6, 20177 yr Author Hi Hitesh, On 26.10.2017 at 10:48 AM, Hitesh Mistry1709156740 said: Hi Stefan, Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS. There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14 If already on this version, can you try disabling 'session reliability' on SF and check? Regards, Hitesh I got the following error message in ns.log. Oct 27 08:40:35 <local0.info> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default SSLVPN ICASTART 606299 0 : Source 79.196.126.116:55388 - Destination 192.168.233.32:443 - username:domainname anonymous: - applicationName <DATA_STORE> - startTime "10/27/2017:06:40:35 GMT" - connectionId 96aa21 Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606300 0 : "NS_ICA_ERROR nsica_process " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606301 0 : "ap_flags = 0x1000000, state = 1, prev_state = 0, track_flags = 0x80800000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606302 0 : "appflow_flags = 0x400000, pkt->pkt_bytes_left = 0x00c9" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606303 0 : "dir = 0 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606304 0 : "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606305 0 : "cgp->type = 0x00, cgp->cgp_flags = 0x0000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606306 0 : "cgp->size = 0, cgp->offset = 0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606307 0 : "dir = 1 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606308 0 : "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606309 0 : "cgp->type = 0x00, cgp->cgp_flags = 0x0000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606310 0 : "cgp->size = 0, cgp->offset = 0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606311 0 : "Dumping data pointed to by the in-mem buffer LAST to FIRST " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606312 0 : "Line No. : 2061, File no : 2 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606313 0 : "16 03 03 00 c4 01 00 00 c0 03 03 59 f2 d4 f1 f3 3c 8c 9a 2f ee 15 02 6a fb " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606314 0 : "03 0a 6f a7 db 50 e1 fe ac 39 c7 34 96 78 9b c8 05 89 20 4c 11 36 b8 b2 3f " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606315 0 : "a1 f9 5c 4c 50 cb b0 90 1f ac 5b 09 f6 36 68 ff be d7 1d f3 37 6e 89 9b 30 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606316 0 : "1b 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606317 0 : "c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c 00 35 00 2f 00 0a 01 00 00 4d 00 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606318 0 : "00 00 12 00 10 00 00 0d 63 61 67 2e 73 77 64 6c 61 62 2e 64 65 00 0a 00 08 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606319 0 : "00 06 00 1d 00 17 00 18 00 0b 00 02 01 00 00 0d 00 14 00 12 04 01 05 01 02 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606320 0 : "01 04 03 05 03 02 03 02 02 06 01 06 03 00 23 00 00 00 17 00 00 ff 01 00 01 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606321 0 : "00 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606322 0 : "Skipping ICA flow: Session GUID [Undefined], Client IP/Port [79.196.126.116/55388], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [Undefined], Client Type [0x0000], User [Undefined], Client [79.196.126.116], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134]" ULFD is disabled. I also disabled session reliability. But this also doesnt solve the issue.
November 15, 20177 yr Hi Stefan, Make sure your NetScaler ADC is on version above 11.1-54.14. If yes, then i would recommend opening a case with support. Regards, Hitesh
January 2, 20187 yr Hi Stefan, In that case, please open a support case to have a deeper analysis of the issue. Regards, Hitesh Mistry
April 4, 20196 yr Did you ever get this resolved? I am getting the same error and it seem the clients are getting dropped at the same time this error shows up.
Archived
This topic is now archived and is closed to further replies.