Jump to content
Welcome to our new Citrix community!

Site stuck on /cgi/setclient?wica and does not load further.


Recommended Posts

Hi,

I have just installed NS VPX and configured an AGEE site that should just automatically pass through to WI. What I get at the moment is that when I browse to the site externally with a URL https://server.fqdn it redirects to https://server.fqdn/cgi/setclient?wica and it never goes anywhere further than that.

It is configured to go to WI 5.4.2 on IIS6 on a Windows Server 2003 x86 server.

Does anyone have any ideas on how to fix this?

Cheers,
Hanré

Link to comment
Share on other sites

I've seen similar behavious with a partner organisation's Netscaler/virtual CAG EE to a 5.1 I think WI. It hangs at the setclient URL and then finally gets through after about 40 seconds. Not very user friendly nor help desk friendly. If you find the solution, please let us know what it is.

Edited by: soozws on 13/05/2012 7:08 AM

Link to comment
Share on other sites

  • 2 weeks later...
  • 3 months later...
  • 3 weeks later...

I had the same problem and had to capture traffic to figure out what was going on. I think there is an intelligence build in the Netscaler (in my case MPX 7500 build 9.2) that detect man-in-the-middle attack between itself and the web interface. It is nomally between client and Netscaler. If an alert is triggered it reset the TLS connect with the client by sending Encryption Alert message.The client would reconnect again. This cycle will continue until the browser times out

In my case the false positive was triggered because the IP address of the web interface was a windows NLB. The second case was a configuration setting of the network card teaming mechanism to load balance between 2 interface cards. When a Netscaler detect an asynchronous session it assumes a man-in-the-middle attack and reset the connection with the client. Firewalls, NAT can also cause asynchronous session

My solution
In case 1 we supplied the WI address instead of the NLB address.
In case 2 we reconfigure the teaming setting not to load balance between the interface.

Netscaler has a Loadbancing feature which can be used to achieve high availability of web interfaces.

Link to comment
Share on other sites

  • 2 years later...
  • 1 year later...
  • 2 years later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...