This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
what do you see in your storefront logs?
do you have an LDAP extract in your nFactor that would dig out the on-prem ad username followed by a traffic policy that injects sth like userPrincipalName for the sso?
f
On Storefront I don't seem to see any events. No LDAP policies here, just SAML in the flow.
k
your session policy on the gateway is configured for StoreFront?
f
add vpn sessionAction ses_prof_vcc -sessTimeout 600 -splitTunnel ON -transparentInterception ON -defaultAuthorizationAction ALLOW -clientCleanupPrompt OFF -forceCleanup none -SSO ON -useMIP OFF -useIIP NOSPILLOVER -icaProxy OFF -wihome "h**<s://IP/Citrix/StoreWeb>" -clientlessVpnMode OFF -WindowsPluginUpgrade Never -MacPluginUpgrade Never -LinuxPluginUpgrade Never -iconWithReceiver ON
k
that's an LB IP or SF server IP directly?
f
for completeness of information, when fully operational it will point to a non-rotatable LBVS address, now for testing we are using a specific IP of an SF.
k
ok... I've seen some cases where this fails if you have an LB VS and GSLB and DNS based entries, but that's not the case for you
does it work if you disable the VPN and use just ICA proxy?
f
Actually it could be my case, we have GSLB in use, but for testing currently only 1 site is active.
We have not tried using ICA Proxy
j
I wouldn't do full vpn for ICA/Storefront.
f
Customer requirements. However, what I discovered now is that Saml assertion is not like the one I would expect to receive. The format I receive of the Name-ID is persistent while it should be in email format.
👍 1