This message was deleted.
# citrix-vad
s
This message was deleted.
n
Is this something where I'd have to actually set that VC policy to Disabled and not leave it at the default?
should be fixed in 2203 CU2...
n
The VDA is definitely getting all policies, though
Launching a 1912 desktop now, but I believe it also happens on those VDAs, too.
b
Any other GPO related entry in the Application Eventlog?
n
Hmm, works in 1912. I'll give that registry key a shot.
💪 1
I see the usual CitrixCseEngine notifications saying that it processed RSOP for my user account, nothing weird.
I do think it's weird that the cloud console would show the VC policy as being disabled by default. I would have assumed that'd follow the newer VDAs since it's cloud.
Ha, I think my assumption was correct. If I manually add the registry key that disabled the VC policy, the VC opens.
Gonna test it out by setting the policy in Studio to actually confirm this the right way.
b
That means CTX Policies are failing.
n
This policy isn't set, though.
And that NoDomainGpoDetour policy didn't resolve it.
r
@Balint Oberrauch the article you are referring to is NOT applicable to 2203 LTSR, only 2206 / 2209
b
True, my fault
r
@Nick Panaccio, if I understand correctly, you never had the policy set and relied on the default value? 2203 CU1 -> This leads to value DISABLED 2203 CU2 -> This leads to value ENABLED Correct?
n
We never had that policy set, no, but I saw the same issue with both 2203 CU1 and CU2 - VCs do not open. 1912 CU2-CU5, they open fine.
Cloud studio says the default is Disabled, and we do not have that policy set (to enforce it). I'm going to see if I can set that policy today and keep it at the default Disabled to see if that works.
I'd expect it to work without me setting that policy, honestly.
r
Starting with Citrix Virtual Apps and Desktops 7 2109, virtual channel allow lists are enabled by default. https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/policies/reference/ica-policy-settings/virtual-channel-allow-list-policy-settings.html
👍🏻 1
n
From our Cloud policies:
Bear in mind, I'm a noob to Citrix Cloud.
l
By default custom virtual channels are disabled. Checkout what Rody sent.
n
I thought the default policy is now Enabled, meaning only entries within the policy (empty from the start) are allowed?
Setting it to Disabled allows any custom VC to work
l
Yeah but this is a custom virtual channel so you need to whitelist it.
Or you can whitelist them all. Depends on your security posture.
Got bit by this with bighands virtual channel after an upgrade.
r
Yeah the Custom Virtual channels are DISABLED by default. You need to DISABLE the VC Allow List to allow ANY VC to work again, or whitelist them
n
Okay, so that's what I'm looking at. The policy in Cloud studio says Disabled by default, so they should work.
Unless I just haven't had enough coffee this morning.
r
Can you test with forcing the policy to disabled?
👍🏻 1
The default leaves it up to the VDA, which in this case is ENABLED
n
That's what I want to do now. Just trying to confirm that I don't need to open a change request at work.
r
Let me get in touch with the team, I think this policy needs additional remarks
n
Ahhh, that makes more sense
Yes, I agree - that last comment you made needs to be added. That was the missing piece of info.,
Once I test this I'll report back
r
👍
n
Confirmed. Setting the policy in the console to "Disabled" allows all VCs, so now I know what we have to do for our environment.
l
👍🏻
r
If it's disabled by default as per the screen shot. I am wondering if it disabled by default why is it not allowing the List?
n
The good: VDI optimization in Webex now works
The bad: I still have to use Webex
Ray, Rody mentioned a few replies back that it basically tells the VDA to decide. And since the VDA is defaulted to blocking everything, that wins. That's certainly what I'm seeing in 2203.
r
Oh, ok. I did see that. But it did not click. Ok, that is good to know and may be why I had some issues. I only assumed based off the description in the policy that it would be disabled. So by actually setting it to disabled in this case told the VDA to actually ignore it in this case?
n
Yep, creating a policy and setting it to Disabled fixed it. Citrix policy > VDA default
r
Good to know. Monday morning learnings 🙂
n
Now I have to create this policy in literally a dozen different sites, lol
I've been meaning to look into this, but when another team started telling me that 2203 was broken because of the picadd event log entries, I had to correct them. Figured it was the right time to address this since we'll be rolling out 2203 CU2 in the next few weeks for testing.
m
I just ran into this and it’s incredibly obtuse wording. You’re disabling an allow list by default, which actually enables virtual channels, except if you’re on a certain version of the VDA, where it enables the allow list which actually disables virtual channels. There has to be a simpler way to word this without so many double negatives.
⤴️ 1
n
So I'm troubleshooting Webex causing BSOD's in 2203 (never listed as the faulting module, but always happens when I join a meeting), and I noticed something weird.
When these crashes happen, Webex is not optimized.
In the App event log, at the same timestamp, I see an info event for Citrix Group Policy starting RSOP calculation. The next event in System shows the picadd 'we tried opening blah blah' entries, and Webex will start opening unoptimized.
m
oh man, good luck, I had so many issues with webex optimization and webcam issues
n
Man, I'm not even using a webcam. I just don't want this piece of shit software blue screening our 2203 VDAs. And right now, it's doing it on most of them.
I'm just noticing a weird coincidence that may or may not matter.
Forcing gpupdate causes the VC to stop working. Just confirmed it, lolol
Bet if I launch a Webex meeting now it blue screens.
r
In all my collaboration tools. No of them can hold a candle to Zoom within a VDI setup.
Teams is the greatest though ha (jk)