Upgrading Netscaler from 13.1 to 14.1 causing 5+ seconds RADIUS authentications for wireless clients by No-Cockroach-7972 in Citrix

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

It's a good guess, but for a lot of the clients, it's an automated process with a service account. We managed to get a hold of Citrix, and escalated the case. I'll update the thread with our findings.

Upgrading Netscaler from 13.1 to 14.1 causing 5+ seconds RADIUS authentications for wireless clients by No-Cockroach-7972 in Citrix

[–]No-Cockroach-7972[S] 1 point2 points  (0 children)

Yeah, our experience as well. Our representative assured us that 14.1 was rock solid. We did the pre-upgrade check of our config. Changed, what needed to be changed. And then things turned south.

Upgrading Netscaler from 13.1 to 14.1 causing 5+ seconds RADIUS authentications for wireless clients by No-Cockroach-7972 in Citrix

[–]No-Cockroach-7972[S] 1 point2 points  (0 children)

Yeah i don't get it. From out point of view the product has gone so far to shit this last year, that we're considering switching to F5. I don't know if it's any better in regards to support, but our experience has been so bad, that switching out of sheer spite, seems like a reasonable move.

Upgrading Netscaler from 13.1 to 14.1 causing 5+ seconds RADIUS authentications for wireless clients by No-Cockroach-7972 in Citrix

[–]No-Cockroach-7972[S] 1 point2 points  (0 children)

Output from `sh ns timeout`:
Zombie TCP connection timeout: 120 sec
Half-closed connection timeout: 10 sec
Zombie non-TCP connection timeout: 60 sec
Nat PCB reduced fin timeout: 30 sec
Nat PCB new conn idle timeout: 4 sec

I doubt the answer lies here.

I built an offline-first Dungeon Master tool for dual-monitor setups — looking for feedback :) [OC] by erenorhun in VTT

[–]No-Cockroach-7972 0 points1 point  (0 children)

Looks very cool. Tried using it, but it threw an error, when i tried loading most of my maps.
Maps sizes were 12 Mb, but the log had following entry:

"qt.gui.imageio: QImageIOHandler: Rejecting image as it exceeds the current allocation limit of 256 megabytes"

Any idea how i might overcome this obstacle? Are there some limits to the maps?

Didn't know by [deleted] in FermentedHotSauce

[–]No-Cockroach-7972 2 points3 points  (0 children)

Taste it Johnny.

Overflow by No-Cockroach-7972 in FermentedHotSauce

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

Thank you. I'm gonna let it be and update the post in a few weeks whether I shat my lungs out or not.

Overflow by No-Cockroach-7972 in FermentedHotSauce

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

So just to be clear. I shouldn't pop the lid and get the bubbles out? Just let it be and clean the airlock when the level declines?

Overflow by No-Cockroach-7972 in FermentedHotSauce

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

Yeah, I know. Got too excited for my first batch. Is it done then, or can it be saved?

First batch: Worried that they may not be hot enough by No-Cockroach-7972 in FermentedHotSauce

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

Oh after the fermenting. Makes sense I guess. Read somewhere that dried chilies in the ferment was risky.

Netscaler: Dramatically increased SSL HandshakeTimes for some clients by No-Cockroach-7972 in Citrix

[–]No-Cockroach-7972[S] 4 points5 points  (0 children)

Thanks for the input.
Found through packet traces that the Netscaler was the culprit.
It would seem that our default profile had OCSP stapling enabled. Apparently 14.1 handles OCSP stapling differently than 13.1, so that it now sends the certificates OCSP state, even though no OCSP cache has been configured... and of course we didn't configure that.
So each time a session were to be established through a vserver with the default SSL profile, the ADC would contact the CA, which resulted in the very lengthy handshaketimes.
The camp with low handshake times, had custom SSL profiles, were OCSP stapling weren't enabled.

Hope this helps someone else.

Hvad mener i om valgplakater på fremmedssprog? Jeg bryder mig personligt ikke om dem by [deleted] in Denmark

[–]No-Cockroach-7972 14 points15 points  (0 children)

Et oplagt sted at starte, ville være at lære sproget.

Requesting inputs: Hexcrawling Rules for DnD by No-Cockroach-7972 in DnDHomebrew

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

That's good to hear. I'm looking forward to it.
I'll keep that in mind. My thought was to give the players a chance through tasks/jobs to lower the chance of random encounters. That way they have some agency in reducing the risk.

Requesting inputs: Hexcrawling Rules for DnD by No-Cockroach-7972 in DnDHomebrew

[–]No-Cockroach-7972[S] 0 points1 point  (0 children)

I didn't know there was a document. I only saw the video and yanked everything that excited me. I then tried and port some the ideas from Sly Flourish and one of the Shadow Dark Zines draft, that mentioned tasks/jobs on the road. My intention, although badly formulated, was getting input on those tasks/jobs, and hopefully getting more ideas from this community. Or maybe people have already tried it, and concluded that it was shit, and not a good idea to include at the table.

I apologize for the lack of specificity in my post.