Jump to content

MAS 12.0.51 no HDX and gateway insight menu point


Recommended Posts

I installed in my lab a fresh mas 12.0 build 51 on xenserver 7.1 along with a netscaler 12.0 build 51 VPX with a platinium license.

 

I added my vpx to MAS and enabled appflow logging for my vpn server (smartaccess mode and DTLS enabled)

 

I dont see any menu point for hdx insight and gateway insight. The only thing what i see is web insight and security insight.

Link to comment
Share on other sites

  • 1 month later...
  • 2 weeks later...

Hi Andrzej,

 

i found in my ns.log the following message:

Skipping ICA flow: Session GUID [undefined], Client IP/Port [92.11.29.99/23047], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [undefined], Client Type [0x0000], User [undefined], Client [92.11.29.99

], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134]

Sep 11 10:33:34 <local0.info> 192.168.233.100 09/11/2017:08:33:34 GMT ns 0-PPE-0 : default SSLVPN ICAEND_CONNSTAT 79971 0 :

 

 

In the knowledge base article, it sounds that xenapp version is incompatible. But i use xendesktop 7.15 with windows 10 creators update and remote pc VDA installation.

The same is by my windows 2016 and 2012 r2 server os.

 

Adapthive Display is set to off in the citrix policy.

My client is win 10 creators update with receiver 4.9

Link to comment
Share on other sites

  • 2 weeks later...
  • 4 weeks later...

Hi Stefan,

 

Did you notice any other skip codes other than 134?

You can search using the source-ip of the client machine. Make sure you know the public ip of client from which traffic is coming to gateway.

 

Also, check if ulfd mode is enabled on NetScaler. If yes, then disable it and check.

See if appflow policies hits are increasing when you pass traffic to the NetScaler gateway.

 

Regards,

Hitesh

Link to comment
Share on other sites

Hi Stefan,

 

Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS.

There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14

If already on this version, can you try disabling 'session reliability' on SF and check?

 

Regards,

Hitesh

Link to comment
Share on other sites

  • 2 weeks later...

Hi Hitesh,

 

On 26.10.2017 at 10:48 AM, Hitesh Mistry1709156740 said:

Hi Stefan,

 

Which version of Netscaler are you running? I see that you are using 12.0-51.x version of MAS.

There was a known issue with "ICA frame too large, exceeds 1460 bytes" and was fixed in NetScaler version 11.1-54.14

If already on this version, can you try disabling 'session reliability' on SF and check?

 

Regards,

Hitesh

 

I got the following error message in ns.log.

 

Oct 27 08:40:35 <local0.info> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default SSLVPN ICASTART 606299 0 :  Source 79.196.126.116:55388 - Destination 192.168.233.32:443 - username:domainname anonymous: - applicationName &lt;DATA_STORE&gt; - startTime "10/27/2017:06:40:35 GMT" - connectionId 96aa21
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606300 0 :  "NS_ICA_ERROR nsica_process "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606301 0 :  "ap_flags = 0x1000000, state = 1, prev_state = 0, track_flags = 0x80800000"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606302 0 :  "appflow_flags = 0x400000, pkt->pkt_bytes_left = 0x00c9"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606303 0 :  "dir = 0 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606304 0 :  "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606305 0 :  "cgp->type = 0x00, cgp->cgp_flags = 0x0000"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606306 0 :  "cgp->size = 0, cgp->offset = 0"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606307 0 :  "dir = 1 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606308 0 :  "ica->prev_pkt_bytes_left = 0x0000, ica->flags = 0x0"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606309 0 :  "cgp->type = 0x00, cgp->cgp_flags = 0x0000"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606310 0 :  "cgp->size = 0, cgp->offset = 0"
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606311 0 :  "Dumping data pointed to by the in-mem buffer LAST to FIRST "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606312 0 :  "Line No. : 2061, File no : 2 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606313 0 :  "16 03 03 00 c4 01 00 00 c0 03 03 59 f2 d4 f1 f3 3c 8c 9a 2f ee 15 02 6a fb "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606314 0 :  "03 0a 6f a7 db 50 e1 fe ac 39 c7 34 96 78 9b c8 05 89 20 4c 11 36 b8 b2 3f "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606315 0 :  "a1 f9 5c 4c 50 cb b0 90 1f ac 5b 09 f6 36 68 ff be d7 1d f3 37 6e 89 9b 30 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606316 0 :  "1b 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606317 0 :  "c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c 00 35 00 2f 00 0a 01 00 00 4d 00 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606318 0 :  "00 00 12 00 10 00 00 0d 63 61 67 2e 73 77 64 6c 61 62 2e 64 65 00 0a 00 08 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606319 0 :  "00 06 00 1d 00 17 00 18 00 0b 00 02 01 00 00 0d 00 14 00 12 04 01 05 01 02 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606320 0 :  "01 04 03 05 03 02 03 02 02 06 01 06 03 00 23 00 00 00 17 00 00 ff 01 00 01 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606321 0 :  "00 "
Oct 27 08:40:35 <local0.notice> 192.168.233.100 10/27/2017:06:40:35 GMT ns 0-PPE-0 : default ICA Message 606322 0 :  "Skipping ICA flow: Session GUID [Undefined], Client IP/Port [79.196.126.116/55388], Server IP/Port [192.168.233.32/443], MSI Client Cookie [Non-MSI],Session setup time [Undefined], Client Type [0x0000], User [Undefined], Client [79.196.126.116], Server [192.168.233.32], Ctx Flags [0x1000000], Track Flags [0x81800000], Skip Code [134]"

 

ULFD is disabled. I also disabled session reliability. But this also doesnt solve the issue.

 

Link to comment
Share on other sites

  • 2 weeks later...
  • 1 month later...
  • 1 year later...

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...