For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

babu_7813's avatar
babu_7813
Icon for Nimbostratus rankNimbostratus
May 14, 2015

ICA connection is

Dear All,

 

I have a wired problem on Citrix Infrastrucutre. We have Citrix Web Farm servers behind F5 LTM (11.6) with customized TCP profile in which we had increased both IDLE timeout from 300 sec to 36000 and Keep Alive Time out value from 1800 sec to 36000 sec. We have configured a VIP for ICA traffic with the same TCP IDLE and Keep Alive time out value. This change was done when we implemented Citrix setup long back and setup was working without any problem.

 

But last week we received multiple complaints from citrix end users that they are getting error "The network connection to your application was interrupted. Try to access your application later, or contact technical support" error every 25 minutes.

 

Even though we haven't done any change on either F5 LTM and Citrix application or servers, we received this error. But upon investigation we received an update from Web Interface server team that they rebooted the server after installing the Microsoft Patch. So we requested them to roll back the patch and reboot the server again. So even after rolling back the patch but still problem is not resolved.

 

Then when we bypassed F5 for ICA communication, we didn't any session time out value. So its very clear now that due to F5, ICA connection is getting timed out. Then when checked F5 ICA VIP properties we noticed that TCP profile for ICA is set with 1800 seconds for both IDLE and Keep Alive Time out value. Upon investigation we identified that this profile was changed almost 1 months before but not sure why Citrix users started getting "The network connection to your application was interrupted. Try to access your application later, or contact technical support" error only when server team rebooted the Citrix Web Interface server.

 

And why Citrix users not reported this problem when we changed the F5 ICA VIP TCP profile from customized to default TCP profile?

 

Can anyone of you through some light on this issue?

 

Regards Babu

 

2 Replies

  • perhaps there was another factor in play also. it is often difficult enough to explain something when it happens, going back in someone elses environment 2 week ago, sorry i doubt there is going to be an answer.