Citrix's port number 1494 filtered by ISA. Can't get it to pass through.

starriol

Member
Jan 3, 2006
187
0
0
Good morning guys!

We have this problem at work; we connect to a Citrix Metaframe Presentation Server which servers the Terminal Services application.
When we click on it, it opens a .ICA file and trys to establish a connection to the remote server.
With ISA server in the middle, it fails. If I connect directly to the Internet, everything works OK and I can connect to the remote computer.

Checking ISA's Log, the problem is that it initiates a connection on port 2598 without any registered problems.
Then, the connection is denied on port 1494. The rule associated is one called "Full access to external", which provides unfiltered access to the Internet. I'm trying from a machine which has a user logged in with such privilege. This rule is the last one before the "deny all" final rule.
Why it is mentioning an allow traffic rule as the cause of the denial is a mystery to me...
What I see in the log also is that the Citrix connection launcher seems to try to go through ISA without a domain user name. May that be the problem? I tried adding user "Guest" to the rule "Full access to external", to no avail.

I tried quite a few ideas already... found a document at Citrix's support site recommending to run a VBS to allow unfiltered tunneled connections on additional ports. I configured port 2598 as a defined port, in order for it to not be filtered as unknown IP traffic, which helped get past that error... but not I'm stuck.

What do you think?
 

starriol

Member
Jan 3, 2006
187
0
0
Please check the following screenshot of Isa's log:
http://img219.imagevenue.com/i...untitled_122_260lo.JPG

"Acceso full a external" is the rule "Full access to external", in spanish.
At the bottom, you see the IP ending in .198 which is the one that gets the blocked connections.

Note: I disabled the proxy in Internet explorer and connected using the Isa Firewall client and got the exact same error in Isa's log.
 

qaa541

Senior member
Jun 25, 2004
397
0
0
If I were to guess with the issue, it seems that you need to get the Citrix client to launch with the domain credentials. If you don't match the username, then ISA wont let you through even if the other parts of the rule match. These rules are like all or nothing matches. I am guessing since the username is wrong, it fails to match to that rule and ends up hitting the default deny rule.
 

starriol

Member
Jan 3, 2006
187
0
0
Hey guys, I created a rule allowing traffic from internet to external, for the protocol denied and on all ports... the problem was that I DID create that rule, but the port was a different number.

Piece of cake (after solving it, LOL :d )
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |