This message was deleted.
# citrix-netscaler
s
This message was deleted.
s
the new vserver VIP is on the same netscaler and same network that the current one is on? id put my money on Firewall
c
did you configure the saml action using a idp metadata url or configured it manually? does unticking the import metadata populate the feilds such as redirect url / signout url if not pob FW
j
Thanks lads, same network/subnet and its done manually.. the action that is.. I think its FW.. just waiting to hear bacl, thanks guys
s
test-netconnection from the endpoint should show 'true'
👍 1
h
how is your routing? any pbr in place?
j
Just checked ... no PBR in place... they did say they will double check the rules.. thinking/hoping they have found an issue 🙂
h
Otherwise try MBF for shits and giggles
👍 1
j
Yeah, thats disabled at the mo:
l
What's the default route for the NS John? Does it head back to the firewall? Can you ping outside resources? Google DNS or something? It's almost definitely either bad Firewall config or routing.
A quick packet capture will help you externally though, see if you get a reset or a timeout. Do a packet trace on the NS also and you should see you connection coming in. If you don't it's firewall. If you do but still nothing loads you have a routing issue.
j
Nice one, thanks Lee.. I'll have a fresh look today brother! 🙂
l
Let me know if you want to jump on a call and have a nose together mate.
👍 1
j
Thanks Leee, 100% firewall.. Ive sent the admin screenshots from Wireshark showing this.. super obvious now, cheers bud
l
No worries bud
👍 1