This message was deleted.
# citrix-vad
s
This message was deleted.
l
Session reliability enabled? 2598?
j
SR is enabled, and 2598 is also open from the Azure workstation >> session host
l
What version of the client is being used?
j
Tried several - latest, 1912, and 1812
All get the same response
l
I'd check STAs on Storefront just to be sure.
If you did a packet capture on both sides, client and VDA I may be able to potentially tell you what the issue is.
j
It's working for all other clients so not sure what would need to be changed on Storefront - I am in the process of getting a Wireshark and ProcMon, so might be able to share something when I get them
r
James is there an ADC being used or is it trying to open the VDA directly
j
Direct to on-premises Storefront, no NetScaler in the mix
r
And are any of the working endpoints in Azure or is this the only azure one
j
This is the only Azure one, and it is the only one that fails
l
Any Secure ICA involved? Only thing I can think of if you get the ICA file. Looks like a secure negotiation failed or something. Event logs on the VDA may lend a hand.
j
Let me check.....
m
Any additional firewall or proxy in the mix when using the azure workstation? e.g. SSL Inspection
j
Not as far as I could tell....will ask the admin to check again
There is an error logged on the VDA - not particularly helpful though
l
Looks like something in the middle is disrupting data, some sort of inspection. This isn't an SSL error so thats that ruled out.
r
Set MTU in the ICA file to 1350
i ran into this before.
1. OutBufLength=1350 2. udtMSS=1350
j
@Ryan Gallier - Yeah, same here. I recall disabling UDP and hard setting the MTU so it didnt adjust based on network conditions for certain sites/locations, cheers
j
Is there somewhere you can do that from a central config area? Is it a Storefront setting?
j
When I had this issue it was a couple of sites totalling about 15 users... from memory we bumped them into a DG with UDP/EDT disabled and the SD done some client config on the handful of users, cheers
j
managed to grab a Wireshark trace as well, I have told the admin to check the MTUs (although he's probably writing me a Teams message right now saying "I don't understand" 😀). Just wondering if the trace indicates that it is indeed an MTU issue (doesn't seem to tell me anything, but I hate networky stuff)
Do I just need to make this change by editing the ICA file directly, or does it need to be changed on Storefront in the default.ica file? We edited a downloaded ICA file manually and ran it, but it still generated the same error.....
l
There's no way of telling the MTU from a packet trace, could take an educated guess, but that's not what you want. I do, however, see malformed UDP packets, so this makes sense and lines up with what everyone else is saying.
I've seen this with Networking devices too in Azure, having to lower the MTU.
j
So can I simply edit the ICA file or do I need to make the change on the SF end?
(I edited the ICA file and it gave the same error)
l
Editing the ICA file should make the change. Yep.
j
Hmmm. It made no difference, using Receiver 4.11 so didn't need the additional Registry changes
l
You can also disable EDT MTU discovery on the VDA side with a registry key. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\icawd MtuDiscovery - DWORD - 0
j
So setting that should have the same net effect?
l
I am not sure on the behaviour with the combination of settings. Technically if you specify it in the ICA file you'd expect that to win, but if the feature is also enabled on the VDA side I am not sure what wins.
j
These VDAs are XenApp 6.5 as well
l
ha ha, Well - it says you need VDA 1912/2103 or later so you should be fine with that
j
will give it a bash
l
Workspace app 1912/2105 or later on the client
Discovery does overwrite manual settings.
But you're using a 6.5 farm agent so this should not be applicable.
https://support.citrix.com/article/CTX114680/event-log-error-an-error-occurred-when-processing-incoming-cgp-downstream-data This is for 6.5, I've not come across this before so it may or may not be related. Do you see event log errors on the VDA?
j
We see the CGP error earlier, yeah
l
🤷🏻‍♂️
Upgrade to a VDA and join it to the new farm?
j
Let me see what we can do with those reg changes.....will update when I hear more 🙂 New farm? 6.5 is the new farm......
l
Holy shit....
j
3.0 is gone and 5.0 is down to a few servers....consolidating on 6.5 🙂
☠️ 1
l
Oh god James! 😂 consolidating to 6.5. 😂
r
Well dang, sorry, was my best idea. Manually editing the ICA file should be fine. In my Azure enviornment i did edit the file in Storefront C:\inetpub\wwwroot\Citrix\<STORENAME>\App_Data\default.ica
j
Is there a setting equivalent to Storefront's "default.ica" on a Web Interface server? (No laughing at the back)
r
yes.... it's in inetpub somewhere as well
👍 1
i'm pretty sure it's just a default.ica file somewhere in there too
Inetpub\wwwroot\Citrix\XenApp\conf
👍 1
j
Damn - looks like this is a 6.5 issue, same Azure workstation can launch newer Citrix resources just fine
r
That's odd. Not sure why Azure would care?
j
Currently trying to build a 6.5 environment to see if it is something peculiar to their implementation......the joy
r
now that sounds terrible. I'm sure you have built 100 of them, like I have, but still a joy....
😄 1