+ Post New Thread
Results 1 to 11 of 11
Internet Related/Filtering/Firewall Thread, Smoothwall Citrix Filtering in Technical; Hi All, We have network gaurdian and have an issue with Citrix connectivity. We have offsite careers services that come ...
  1. #1
    ICTNUT's Avatar
    Join Date
    Jul 2005
    Location
    Hereford
    Posts
    1,419
    Thank Post
    196
    Thanked 249 Times in 122 Posts
    Rep Power
    62

    Smoothwall Citrix Filtering

    Hi All,

    We have network gaurdian and have an issue with Citrix connectivity.

    We have offsite careers services that come in 3 times a week and they connect to thier office via web based citrix.

    Now they can access the domain and login to the citrix web frontend however in order to launch outlook or office applications it launches the ICA32 Client which then promptly falls over saying it cannot connect to the proxy.

    I have tried allsorts to get this working anyone have any ideas??

  2. #2


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,461
    Thank Post
    866
    Thanked 845 Times in 667 Posts
    Rep Power
    195
    Try "do not authenticate for" the citrix domains? That would rule out auth, at least.

    A snippet of logs might also help.

  3. #3

    Ric_'s Avatar
    Join Date
    Jun 2005
    Location
    London
    Posts
    7,590
    Thank Post
    109
    Thanked 762 Times in 593 Posts
    Rep Power
    180
    For Citrix connectivity, you only need access on port 443 (i.e. HTTPS).

    I would recommend installing the ICA client on your desktops to rule that out too (the Java one is a bit sucky).

    Our careers people have no problems and they run their Citrix connection on one of our Citrix terminals!

  4. #4
    ICTNUT's Avatar
    Join Date
    Jul 2005
    Location
    Hereford
    Posts
    1,419
    Thank Post
    196
    Thanked 249 Times in 122 Posts
    Rep Power
    62
    Try "do not authenticate for" the citrix domains? That would rule out auth, at least.
    Had already done this no joy

    A snippet of logs might also help.
    Which do you need?

    I would recommend installing the ICA client on your desktops to rule that out
    Already done.

    My PC is the only unfiltered PC, i.e. does not go through the proxy, and it works for me so it must be a guardian issue.

  5. #5


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,461
    Thank Post
    866
    Thanked 845 Times in 667 Posts
    Rep Power
    195
    The web filter logs, as exported, for the minute around which the problem occurs - by email probably easiest! I'll reproduce any relevant bits here "for the record"!

  6. #6


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,461
    Thank Post
    866
    Thanked 845 Times in 667 Posts
    Rep Power
    195
    Have you tried it on a PC that is going through the proxy but is in an "unfiltered" group? would tell us if it is the filter or the proxy.

  7. #7


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,461
    Thank Post
    866
    Thanked 845 Times in 667 Posts
    Rep Power
    195
    Another thing to try, he says.. taking over the thread completely..

    Go to guardian/proxy/web proxy

    and in the box for
    Allow access to web servers on these additional ports:

    add in:
    2598
    1494

  8. #8
    ICTNUT's Avatar
    Join Date
    Jul 2005
    Location
    Hereford
    Posts
    1,419
    Thank Post
    196
    Thanked 249 Times in 122 Posts
    Rep Power
    62
    Quote Originally Posted by tom_newton View Post
    Another thing to try, he says.. taking over the thread completely..

    Go to guardian/proxy/web proxy

    and in the box for
    Allow access to web servers on these additional ports:

    add in:
    2598
    1494
    OK Done this and no change.

    I have had a look at the logs and it simply shows an exception for the URL and a status of 200 which is what I would expect.

    Hmmmm as he runs off to try something.......

  9. #9
    ICTNUT's Avatar
    Join Date
    Jul 2005
    Location
    Hereford
    Posts
    1,419
    Thank Post
    196
    Thanked 249 Times in 122 Posts
    Rep Power
    62
    Right I created a new security group in AD for the careers guys, added them to this group, then in gaurdian I added this goup as an "unfiltered" group and restarted the proxy.

    Went to the user and HELLO it works.

    So the up side is it must be the filter, the downside is that they are no longer filtered.

    Any ideas where next.

  10. #10


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,461
    Thank Post
    866
    Thanked 845 Times in 667 Posts
    Rep Power
    195
    In the logs.. can you uncheck the "ignore filter" - that will show any extra traffic we might have missed.

  11. #11
    ICTNUT's Avatar
    Join Date
    Jul 2005
    Location
    Hereford
    Posts
    1,419
    Thank Post
    196
    Thanked 249 Times in 122 Posts
    Rep Power
    62
    In the logs.. can you uncheck the "ignore filter" - that will show any extra traffic we might have missed.
    It was not check anyway.

SHARE:
+ Post New Thread

Similar Threads

  1. smoothwall filtering problems
    By linkazoid in forum Internet Related/Filtering/Firewall
    Replies: 14
    Last Post: 17th January 2011, 10:51 AM
  2. Replies: 27
    Last Post: 27th December 2006, 11:54 PM
  3. Citrix
    By danIT in forum Thin Client and Virtual Machines
    Replies: 7
    Last Post: 30th October 2006, 03:09 PM
  4. Goodbye Smoothwall Hello Smoothwall
    By Simcfc73 in forum Wireless Networks
    Replies: 2
    Last Post: 30th June 2006, 06:55 AM
  5. Citrix
    By paul in forum Thin Client and Virtual Machines
    Replies: 5
    Last Post: 18th January 2006, 10:45 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •