<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Citrix Receiver on Globalprotect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/341139#M85603</link>
    <description>&lt;P&gt;Can you try creating an open policy and deny DTLS application with services set to any(or you can check with application-default) as well and let's see how it behaves. Put that policy on the top for specific users and destinations.&lt;/P&gt;&lt;P&gt;Just below that create a security policy and allow everything for&amp;nbsp;specific users and destinations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was somewhere close in accessing the&amp;nbsp;Citrix Receiver remote desktop.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 23:09:40 GMT</pubDate>
    <dc:creator>gpandit</dc:creator>
    <dc:date>2020-07-28T23:09:40Z</dc:date>
    <item>
      <title>Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/14221#M10455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I seem to have Globalprotect working fine for access to any internal resource.&lt;/P&gt;&lt;P&gt;The one thing that does not seem to be working is the connection Citrix Receiver (PNAgent legacy version 13.3) makes to our internal Citrix Web Interface / Services site.&lt;/P&gt;&lt;P&gt;I'm getting the error "citrix receiver could not contact the server. please check your network connection"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm starting to think this is a Globalprotect issue, because:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;On the internal LAN everything is fine.&lt;/LI&gt;&lt;LI&gt;Using an old style Windows VPN that terminates on one of our DC's, everything is fine.&lt;BR /&gt;The only difference with GP is that GP clients terminate at the firewall, so traffic has an extra route to the Citrix servers.&lt;/LI&gt;&lt;LI&gt;I can actually download the Citrix config.xml file over GP VPN. That's the file the Citrix client uses to find what resources are available.&lt;/LI&gt;&lt;LI&gt;All related Citrix servers (portal, xenapp servers) are all reachable over GP. Name resolution is fine (both netbios and fqdn names).&lt;/LI&gt;&lt;LI&gt;Policy is in testing phase, so everything between the GP zone and trusted zone is allowed.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone recognise this ? Anything else I can try ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 14:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/14221#M10455</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-16T14:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/318729#M81806</link>
      <description>&lt;P&gt;We had this problem also with some laptops. The issue was udp fragmentation. Some nic's didn't do udp fragmentation.&lt;/P&gt;&lt;P&gt;So they could see loginpage of frontstore of citrix and when logging in they could't coonnect to server backend.&lt;/P&gt;&lt;P&gt;We didn't have pathmtu on the connections and icmp was disabled. Solution was that citrixteam were goging to push smaller mtu on citrixreceiver via the config.xml file&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 14:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/318729#M81806</guid>
      <dc:creator>Infra_SRV</dc:creator>
      <dc:date>2020-03-26T14:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/341139#M85603</link>
      <description>&lt;P&gt;Can you try creating an open policy and deny DTLS application with services set to any(or you can check with application-default) as well and let's see how it behaves. Put that policy on the top for specific users and destinations.&lt;/P&gt;&lt;P&gt;Just below that create a security policy and allow everything for&amp;nbsp;specific users and destinations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was somewhere close in accessing the&amp;nbsp;Citrix Receiver remote desktop.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 23:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/341139#M85603</guid>
      <dc:creator>gpandit</dc:creator>
      <dc:date>2020-07-28T23:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/344916#M86256</link>
      <description>&lt;P&gt;Had this issues in a recent Citrix deployment.&amp;nbsp; Check to see if drop frag udp if set to drop in your zone protection profile for GP. That was my issue. I was able to connect on the receiver but unable to launch apps, would just saying connecting then time out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can confirm if this is your issue by doing a pcap of the ip of the vpn client and look at the drops. You will see&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"IP Fragmented IP Protocol" UDP/17 being dropped.&lt;/P&gt;&lt;P&gt;Just make a new zone protect policy and make sure ip frag drop is uncheck.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 10:04:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/344916#M86256</guid>
      <dc:creator>andresee</dc:creator>
      <dc:date>2020-08-21T10:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/377922#M89413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Andresee,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't seem to find this option under Zone Protection. Could you please point me to the right location?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Jan 2021 10:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/377922#M89413</guid>
      <dc:creator>KiranO</dc:creator>
      <dc:date>2021-01-05T10:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Citrix Receiver on Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/584367#M116729</link>
      <description>&lt;P&gt;This worked for me ! thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 19:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/citrix-receiver-on-globalprotect/m-p/584367#M116729</guid>
      <dc:creator>lfraij</dc:creator>
      <dc:date>2024-04-19T19:26:12Z</dc:date>
    </item>
  </channel>
</rss>

