This message was deleted.
# citrix-vad
s
This message was deleted.
j
To add, the FAS server also runs as a subordinate CA. All of these errors are on FAS02 which is 2nd on the list so it like its failing on FAS01, moving to FAS02 then generating the RPC error. Very strange its only happening a couple of times per day.. and fine for most folks, cheers
h
Sounds like firewall related or RPC not available: https://theitbros.com/the-rpc-server-is-unavailable-0x800706ba/
Are the CA’s using random dcom ports? You can also try and set a static one https://social.technet.microsoft.com/wiki/contents/articles/1559.how-to-configure-a-static-dcom-port-for-ad-cs.aspx
j
Thanks @Henry Heres. Looks promising, will do some testing 🙂
The VDAs have the domain firewall disabled, its enabled on the FAS servers via policy. I have temp disabled the domain FW via local policy for now to see if the errors go away, cheers
Arghhh, still seeing it this AM after disabling Windows firewall. I just found this, sounds like the issue: https://support.citrix.com/article/CTX461416/single-sign-on-not-working-when-going-through-one-fas-server-the-rpc-server-is-unavailable, I'll try this next, cheers
h
how is the health of the CA itself? can it validate all AIA/CDP locations?
and if it's a parent/child relationship do you have AES enabled? (or any hardening that disables the older ciphers in kerberos) have seen that one as well, and with the latest ADCS update you'll get the new hard matching capability (which is going to be enforced later on, but that's a logging entry at this time not RPC unavailable)
j
Hey Henry, CA looks good but that's an interesting call on the ciphers. Just found a LOAD of these:
I can see the client has got a CIS GPO attached to the OU housing the FAS servers...
h
can you do a check in het GPO for which allowed kerberos ciphers are being used, afaik this one disables the older ones
I had the same sort of impact at a customer where we implemented True SSO (VMware equivalent of FAS) which magically stopped working. Issue was hardening (CIS levels) put in place but not only on the clients also member servers etc. (the ADCS machines) and the issue was there that it had a parent/child relationship for the forest/domain. By default the forest doesn't enable AES, this is a check mark to be set which in turn forces it or you need to manual put it in with ksetup for legacy support if needed.
j
Thanks, Henry. This is whats in that CIS policy. Odd that its working for most, Ive been on this gateway for 2 months. Zero issues.. I am seeing about 20 on avg rpc errors per day and all those cipher errors..
Also has this...