This message was deleted.
# citrix-netscaler
s
This message was deleted.
c
DNS on the Netscaler.
Make sure the netscaler can resolve everything relevant that's defined in the policies
j
thanks, Mike.. I will double check.. my first check was the SF url in the session profile.. they are already using IPs but I'll review the other bits..
👍 1
o
Looks like sf url piece in session policy for where I have seen that
j
Same ozzy, sure Ive saw it before and fixed by using the IP vrs FQDN on the session profile but its already got the IPs. GSLB in play too, callback URLs etc look good and are in the SF host files, cheers
h
How is SAML configured? dynamic XML or static uploaded with cert? the first needs internet access from snip pov, and indeed DNS as always
l
This happens when the NS cannot reach a backend server. Looks like SF. When does it happen John?
c
We had the exact problem. We had SF SSL LB vip configured on our gateway vip. For some reason, certificate binding was missed on that SF LB vip which caused the vip to go down, resulting in the same error. When we mapped certificate to that lb vip, everything started to work.
j
Thanks, lads. The SF LB vips are on the internal Netscalers (1 HA pair in each DC), the two external Netscalers (1 in each DC/GSLB) is where most of my config has been on a test GW vserver. I have not seen the issue yet, Ive had my host file targeting each site at intervals for checks, I'll remove that and see how I go. From what I gather its intermittently (maybe a handful of times per week) affecting a couple of users, they have said if they hit the main test gateway URL again they get straight on to SF no issues. I'll have a look at the internal SF LB vips (they have been working fine in prod with standard LDAP auth), cheers
👍 2
f
@John Gallacher Hi John, what is the firmware version on your setup? I had the same random issue on 12.1 and 13.0. I upgraded yesterday to last 13.1 and no issue since.
and finaly still have the issue...🥲
j
Thanks for the feedback @François. @c4rm0 - This is my thread here... weird one! Cheers
c
Cheers @John Gallacher sounds like same issue my SF VIP is up and hasnt been flapping according to the newnslog and has cert bound and is valid , my session profile on the ADC points directly at the SF LB VIP IP for WI address so not using DNS to connect to SF
j
Same! Im on 13.0 by the way..