Stefan Wendrich1709156509 Posted July 27, 2017 Share Posted July 27, 2017 I installed in my lab a fresh mas 12.0 build 51 on xenserver 7.1 along with a netscaler 12.0 build 51 VPX with a platinium license. I added my vpx to MAS and enabled appflow logging for my vpn server (smartaccess mode and DTLS enabled) I dont see any menu point for hdx insight and gateway insight. The only thing what i see is web insight and security insight. Link to comment Share on other sites More sharing options...
Andrzej Starmach1709152599 Posted August 28, 2017 Share Posted August 28, 2017 Hi Stefan, This somewhat seems to be related to the client browser. I'd advise trying few things like clearing cache, updating the browser to the latest version or test using a different browser (updated as well) altogether. Thanks, Andrzej Link to comment Share on other sites More sharing options...
Andrzej Starmach1709152599 Posted September 7, 2017 Share Posted September 7, 2017 Hi Stefan, Did you get that sorted in the end? Thanks Andrzej Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted September 8, 2017 Author Share Posted September 8, 2017 i updated to the latest build. Now i have the menu point "HDX Insight". But at the moment, there is no data collected. Also - no xenserver tools on xenserver 7.1 for the appliance.. very frustrated.. Link to comment Share on other sites More sharing options...
Andrzej Starmach1709152599 Posted September 8, 2017 Share Posted September 8, 2017 Please try to review the following "how-to" and see if there is an answer for no HDX Insight reporting HDX Insight Data is not captured by NetScaler MAS - https://support.citrix.com/article/CTX224502#T10 CTX215130- HDX Insight Diagnostics and Troubleshooting Guide Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted September 11, 2017 Author Share Posted September 11, 2017 Hi Andrzej, i found in my ns.log the following message: Skipping ICA flow: Session GUID [undefined], Client IP/Port [92.11.29.99/23047], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [undefined], Client Type [0x0000], User [undefined], Client [92.11.29.99 ], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134] Sep 11 10:33:34 <local0.info> 192.168.233.100 09/11/2017:08:33:34 GMT ns 0-PPE-0 : default SSLVPN ICAEND_CONNSTAT 79971 0 : In the knowledge base article, it sounds that xenapp version is incompatible. But i use xendesktop 7.15 with windows 10 creators update and remote pc VDA installation. The same is by my windows 2016 and 2012 r2 server os. Adapthive Display is set to off in the citrix policy. My client is win 10 creators update with receiver 4.9 Link to comment Share on other sites More sharing options...
Andrzej Starmach1709152599 Posted September 25, 2017 Share Posted September 25, 2017 Stefan, just checking - do you have SmartControl policy configured on NSG by any chance? Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted September 25, 2017 Author Share Posted September 25, 2017 No. It’s simple one session policy configured with clientless vpn. No smart access or smart control. Link to comment Share on other sites More sharing options...
Chuck Snyder Posted October 19, 2017 Share Posted October 19, 2017 Did you ever figure this out? I'm getting the same error Skip Code 134 on most but not all connections. I'm told by support that the message 134 means "ICA frame too large, exceeds 1460 bytes". Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted October 20, 2017 Author Share Posted October 20, 2017 Hi Chuck, sorry no. The problem still exists and i had no time to open a support case. How can the ica frame be reduced ? Link to comment Share on other sites More sharing options...
Hitesh Mistry Posted October 24, 2017 Share Posted October 24, 2017 Hi Stefan, Did you notice any other skip codes other than 134? You can search using the source-ip of the client machine. Make sure you know the public ip of client from which traffic is coming to gateway. Also, check if ulfd mode is enabled on NetScaler. If yes, then disable it and check. See if appflow policies hits are increasing when you pass traffic to the NetScaler gateway. Regards, Hitesh Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted October 25, 2017 Author Share Posted October 25, 2017 Hi Hitesh, i only get the skip error 134. Before updating netscaler 11.1 and mas 11.1 to 12.0 appflow was working fine. ULFD is disabled and appflow policies are increasing. Link to comment Share on other sites More sharing options...
Hitesh Mistry Posted October 26, 2017 Share Posted October 26, 2017 Hi Stefan, Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS. There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14 If already on this version, can you try disabling 'session reliability' on SF and check? Regards, Hitesh Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted October 26, 2017 Author Share Posted October 26, 2017 Hi Hitesh, at the moment i am running MAS with 12.0 build 53.6. Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted November 6, 2017 Author Share Posted November 6, 2017 Hi Hitesh, On 26.10.2017 at 10:48 AM, Hitesh Mistry1709156740 said: Hi Stefan, Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS. There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14 If already on this version, can you try disabling 'session reliability' on SF and check? Regards, Hitesh I got the following error message in ns.log. Oct 27 08:40:35 <local0.info> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default SSLVPN ICASTART 606299 0 : Source 79.196.126.116:55388 - Destination 192.168.233.32:443 - username:domainname anonymous: - applicationName <DATA_STORE> - startTime "10/27/2017:06:40:35 GMT" - connectionId 96aa21 Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606300 0 : "NS_ICA_ERROR nsica_process " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606301 0 : "ap_flags = 0x1000000, state = 1, prev_state = 0, track_flags = 0x80800000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606302 0 : "appflow_flags = 0x400000, pkt->pkt_bytes_left = 0x00c9" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606303 0 : "dir = 0 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606304 0 : "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606305 0 : "cgp->type = 0x00, cgp->cgp_flags = 0x0000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606306 0 : "cgp->size = 0, cgp->offset = 0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606307 0 : "dir = 1 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606308 0 : "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606309 0 : "cgp->type = 0x00, cgp->cgp_flags = 0x0000" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606310 0 : "cgp->size = 0, cgp->offset = 0" Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606311 0 : "Dumping data pointed to by the in-mem buffer LAST to FIRST " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606312 0 : "Line No. : 2061, File no : 2 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606313 0 : "16 03 03 00 c4 01 00 00 c0 03 03 59 f2 d4 f1 f3 3c 8c 9a 2f ee 15 02 6a fb " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606314 0 : "03 0a 6f a7 db 50 e1 fe ac 39 c7 34 96 78 9b c8 05 89 20 4c 11 36 b8 b2 3f " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606315 0 : "a1 f9 5c 4c 50 cb b0 90 1f ac 5b 09 f6 36 68 ff be d7 1d f3 37 6e 89 9b 30 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606316 0 : "1b 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606317 0 : "c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c 00 35 00 2f 00 0a 01 00 00 4d 00 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606318 0 : "00 00 12 00 10 00 00 0d 63 61 67 2e 73 77 64 6c 61 62 2e 64 65 00 0a 00 08 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606319 0 : "00 06 00 1d 00 17 00 18 00 0b 00 02 01 00 00 0d 00 14 00 12 04 01 05 01 02 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606320 0 : "01 04 03 05 03 02 03 02 02 06 01 06 03 00 23 00 00 00 17 00 00 ff 01 00 01 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606321 0 : "00 " Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606322 0 : "Skipping ICA flow: Session GUID [Undefined], Client IP/Port [79.196.126.116/55388], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [Undefined], Client Type [0x0000], User [Undefined], Client [79.196.126.116], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134]" ULFD is disabled. I also disabled session reliability. But this also doesnt solve the issue. Link to comment Share on other sites More sharing options...
Hitesh Mistry Posted November 15, 2017 Share Posted November 15, 2017 Hi Stefan, Make sure your NetScaler ADC is on version above 11.1-54.14. If yes, then i would recommend opening a case with support. Regards, Hitesh Link to comment Share on other sites More sharing options...
Stefan Wendrich1709156509 Posted December 31, 2017 Author Share Posted December 31, 2017 the same with the newest netscaler 12 build 56 version... Link to comment Share on other sites More sharing options...
Hitesh Mistry Posted January 2, 2018 Share Posted January 2, 2018 Hi Stefan, In that case, please open a support case to have a deeper analysis of the issue. Regards, Hitesh Mistry Link to comment Share on other sites More sharing options...
Alan Jorgensen Posted April 4, 2019 Share Posted April 4, 2019 Did you ever get this resolved? I am getting the same error and it seem the clients are getting dropped at the same time this error shows up. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.