Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi All,

 

We have network gaurdian and have an issue with Citrix connectivity.

 

We have offsite careers services that come in 3 times a week and they connect to thier office via web based citrix.

 

Now they can access the domain and login to the citrix web frontend however in order to launch outlook or office applications it launches the ICA32 Client which then promptly falls over saying it cannot connect to the proxy.

 

I have tried allsorts to get this working anyone have any ideas??

Posted

For Citrix connectivity, you only need access on port 443 (i.e. HTTPS).

 

I would recommend installing the ICA client on your desktops to rule that out too (the Java one is a bit sucky).

 

Our careers people have no problems and they run their Citrix connection on one of our Citrix terminals!

Posted

Try "do not authenticate for" the citrix domains? That would rule out auth, at least.

 

Had already done this no joy

 

A snippet of logs might also help.

 

Which do you need?

 

I would recommend installing the ICA client on your desktops to rule that out

 

Already done.

 

My PC is the only unfiltered PC, i.e. does not go through the proxy, and it works for me so it must be a guardian issue.

Posted
The web filter logs, as exported, for the minute around which the problem occurs - by email probably easiest! I'll reproduce any relevant bits here "for the record"!
Posted

Another thing to try, he says.. taking over the thread completely..

 

Go to guardian/proxy/web proxy

 

and in the box for

Allow access to web servers on these additional ports:

 

add in:

2598

1494

Posted
Another thing to try, he says.. taking over the thread completely..

 

Go to guardian/proxy/web proxy

 

and in the box for

Allow access to web servers on these additional ports:

 

add in:

2598

1494

 

OK Done this and no change.

 

I have had a look at the logs and it simply shows an exception for the URL and a status of 200 which is what I would expect.

 

Hmmmm as he runs off to try something.......:bowl:

Posted

Right I created a new security group in AD for the careers guys, added them to this group, then in gaurdian I added this goup as an "unfiltered" group and restarted the proxy.

 

Went to the user and HELLO it works.

 

So the up side is it must be the filter, the downside is that they are no longer filtered.

 

Any ideas where next.

Posted

In the logs.. can you uncheck the "ignore filter" - that will show any extra traffic we might have missed.

 

It was not check anyway.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...