Registered users    
MembershipMembership:
Latest New UserLatest:jenisa villarin
New TodayNew Today:13
New YesterdayNew Yesterday:9
User CountOverall:23322

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12890
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1770
Nick Pieters1425
Stewart Brown616
william warren598
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: Citrix ica client cannot connect through isa
Prev Next
You are not authorized to post a reply.

Author Messages
Bruce Green User is Offline
United States
Member since
11/24/2006

Registered Users
Posts: 22

1/17/2007 06:21 AM  
Having a lot of trouble with the Citrix ICA client not being about to go through the ISA server.  Have tried everything I can find on the net, but most of that is broken code.
 
1494 is the port number that I can telnet to on the Citrix server and as far as I can tell, the only real one it needs open to work unless I missed something.  I can access that server fine from a computer without ISA client firewall installed and not on the same network as the ISA.  With ISA, it will not connect.  I have opened up the port 1494 outbound using CEICW.  I have used the ISA Server tool to add ports to the config for 1494, 2598 and 9001, but still nothing.  Has anyone set this up.  Our accountants need it to work really bad and I don't want to have to go through another ISA unistall to give them the access. 
 
I have no problem accessing the internet, except we can't ping to outside addresses (which might be part of the problem), using Outlook over HTTP, RWW, etc...
 
Please help. 
Michael Patrick User is Offline
United States
Member since
10/26/2005

Platinum Membership
Posts: 1912

1/20/2007 08:37 PM  
Since you have ISA 2k4 installed, take a look at the logging to find out what rule is blocking and what ports its trying to access.... did that rule you create allow for incoming/outgoing from internal to external and external to internal?

Michael Patrick

"Technology Interpreter Extraordinaire"
CAD, BIM & SBS
Steve McGrath User is Offline
United States
Member since
6/23/2006

Platinum Membership
Posts: 49

2/14/2007 03:46 AM  
I have Citrix clients working through ISA firewall.  No special ports needed to be opened, but I do get prompted for authentication to get through the proxy, and the behavior is erratic.  No matter which machine, the authentication is rejected, but hitting cancel allows a connection.  On one machine however, similar behavior, but no connection.
Bruce Green User is Offline
United States
Member since
11/24/2006

Registered Users
Posts: 22

3/21/2007 08:26 PM  
Ok, we finally got it all working without any workarounds or hitches.  Basically, we went into ISA and created new custom access rules for 2598 tcp in and out, 1494 tcp in and out and 1604 udp sendreceive.  The from / to stuff was "internal" and "localhost" and "external depending on what direction was needed.  Don't really know if some of this could be left out, like localhost, but we quit messing around once it started working.  This is an ICA/Firewall client connecting through our SBS/ISA box to a remote Metaframe Server via IP address. 
Bruce Green User is Offline
United States
Member since
11/24/2006

Registered Users
Posts: 22

5/15/2007 03:59 AM  
OK, had time to check things out more closely and found that we had a lot opened that was unnecessary.

So, Create new access rule Citrix 1494 Out. Selected Protocol: SBS Custom TCP 1494 Outboud (Make this first). From Internal to External. Allow. Enable.
Program Neighborhood 9.2

SBS Custom TCP 1494 Outbound: TCP 1494 Outbound
Alan Winkel User is Offline
United States
Member since
12/27/2005

Platinum Membership
Posts: 10

5/22/2007 11:29 PM  
Hi. I am having the exact same problem you're having. I created the custom protocol and 'Citrix 1494 Out' access rule as you described, and am still being denied. Is it possible there is another step? I can provide logging if that helps.
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

8/13/2007 03:38 AM  
Hi Alan,
 
Were you able to figure this out yet?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Alan Winkel User is Offline
United States
Member since
12/27/2005

Platinum Membership
Posts: 10

8/13/2007 03:26 PM  
Thanks to Eriq Neale's assistance, we were able to determine that the only method that would allow this particular connection to work was to enable all outbound traffic. Since making this change, the application works flawlessly. Obviously we would have preferred to keep better control of the outbound traffic, but the issue was compounded by the fact that there was no way to modify the Citrix-side of the program, as it is supplied by a third party.
 
I would like to note that Eriq was terrific in troubleshooting this issue, and I look forward to working with him again some time. - Alan
You are not authorized to post a reply.
Forums > Microsoft Small Business Server 2003 & 2000 > ISA Server 2004 > Citrix ica client cannot connect through isa



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.