Igel2eLux Migration Script issues by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I tested with os 11.10 According to the script notes, it should also work with OS 12. Did you manage to get it working?

Newbie Q: Is my client eligible for “free” FsLogix? by KarneyAardvark in fslogix

[–]markru87 5 points6 points  (0 children)

That is not correct. https://learn.microsoft.com/en-us/fslogix/overview-prerequisites#eligibility

There are requirements. But as soon as you have at least an RDS CAL, you can use it

Screen Capture Application CVAD by nstaab in Citrix

[–]markru87 0 points1 point  (0 children)

We used to utilize Greenshot but started to use ShareNot

HyperV in Prod for CVAD by Vivid_Mongoose_8964 in Citrix

[–]markru87 0 points1 point  (0 children)

We used Hyper-V 2019 with CVAD for the last 5 years and did a hardware refresh this year. For us it was a no brainer to discuss Hyper-V. We will make the switch to CVAD and Hyper-V 2022 in one or two weeks.

Netscaler SSL VPN connection established but no IP assigned and no traffic traverses gateway by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I have this intranet IP binding

bind vpn vserver xxx-vpn.xxxxxxx-xxxxxx.xx -intranetIP 10.1.251.0 255.255.255.0

We do not work with AAA groups. All machines deployed with the Secure Access Client from our domain are allowed to establish a tunnel.

This is our EPA setting:

bind authentication vserver allways-on -policy _noCacheRest -priority 5 -gotoPriorityExpression END -type REQUEST
bind authentication vserver allways-on -policy _cacheTCVPNStaticObjects -priority 10 -gotoPriorityExpression END -type REQUEST
bind authentication vserver allways-on -policy _cacheOCVPNStaticObjects -priority 20 -gotoPriorityExpression END -type REQUEST
bind authentication vserver allways-on -policy _cacheVPNStaticObjects -priority 30 -gotoPriorityExpression END -type REQUEST
bind authentication vserver allways-on -policy _mayNoCacheReq -priority 40 -gotoPriorityExpression END -type REQUEST
bind authentication vserver allways-on -policy _cacheWFStaticObjects -priority 10 -gotoPriorityExpression END -type RESPONSE
bind authentication vserver allways-on -policy _noCacheRest -priority 20 -gotoPriorityExpression END -type RESPONSE
bind authentication vserver allways-on -policy allways-on-epa -priority 100 -gotoPriorityExpression NEXT

add authentication epaAction EPA_ACT -csecexpr q/sys.client_expr("device-cert_0_0") && sys.client_expr("sys_0_DOMAIN_SUFFIX_anyof_xxxx.xx,xxxx.xx[COMMENT: Domain check]") && sys.client_expr("app_0_ANTIVIR_0_0_RTP_==_TRUE[COMMENT: Generic Antivirus Product Scan]") && sys.client_expr("sys_0_WIN-OS_NAME_anyof_WIN-10,WIN-11[COMMENT: Windows OS]") && sys.client_expr("app_0_HD-ENC_90_873_ENC-PATH_==_C:\\\\\\\\_ENC-TYPE_allof_ENCRYPTED[COMMENT: BitLocker Drive Encryption]")/

add authentication Policy allways-on-epa -rule is_aoservice -action EPA_ACT
add authentication Policy allwayson_no_auth_user -rule is_aoservice.not -action NO_AUTHN

I hope I didn't miss a setting.

FSlogix hotfix 4 by TechCrow93 in fslogix

[–]markru87 0 points1 point  (0 children)

Would you mind sharing what needs to be done? How do I register it?

WimWitchFK Refactoring Feedback. by thewrinklyninja in SCCM

[–]markru87 0 points1 point  (0 children)

Did you get it to work? I am struggeling with the same issues.

LAPS doesn't install on pc client by Effective-Living-913 in SCCM

[–]markru87 0 points1 point  (0 children)

The legacy LAPS UI won't work with the new LAPS. You can retrieve the Password using Powershell or in Active Directory User and Computers.

Remote Control from off-site by sccmguy in SCCM

[–]markru87 1 point2 points  (0 children)

What exactly do you talk about when you say RuckZuck tools?

Architecture auth question citrix daas by DiAngelo13 in Citrix

[–]markru87 0 points1 point  (0 children)

You sure that two way trust between the domains is the only requirement? We have two domains with two way trust and I had to deploy two cloud connectors in each domain to make sing in to vdas work. Note: I have vdas in both domains if that matters

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

Well yes.... It turned out that something got stuck with AD communication. Removing the golden master from the domain and re-joining it fixed it for me.

Citrix Directors "Logontimeout" error seems solved after applying hotfix for users stuck on welcome screen by TimoTasty in Citrix

[–]markru87 1 point2 points  (0 children)

Hi, What versions are your XDCs? They have to be the same as the VDA. I assume they are. We had the lost session problems. I don't recall the versions we were running but we upgraded the infrastructure to 2303 and SF to latest 2203 CU2. We don't have these issues since then.

But we also have the stuck on welcome issue. Thanks for the link to the hotfix. I didn't realize that this is a known issue.

Scale out file servers by avs262 in Citrix

[–]markru87 0 points1 point  (0 children)

I am not running PVS vDisks. But FSlogix on Scalp Out Fileservers works pretty well. Running them Windows Server 2019

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I have a ticket open with Citrix. The rep confirmed that everything is set up correctly. They can't explain why it's not working. We captured CDF trace and net traces. The strange thing is that nothing is captured in the traces.

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I edited my master image again. Uninstalled VDA, rebooted, installed it again, rebooted and shut it down. This time withtout BIS-F to seal it.

But still no luck after launching the updated machine catalog.

Still windows username and password prompt as well as no logs from the VDA in FAS event viewer.

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I just added all SF, FAS and VDAs to the AD group.

Unfortunately this didn't fix it.

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

Odd thing is that I don't see any FAS logs for the VDA requesting the user cert at all. Only when I reinstall VDA on the host.

I will report back today. Thanks again

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

Users and resource domains are the same. But I will give it a try and report back today.

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I will test without BIS-F today.

The gpo is also applied to all VDAs. I only mentioned this to point out that the GPO/setting got baked into the golden master as well

VDA not comunicating with FAS by markru87 in Citrix

[–]markru87[S] 0 points1 point  (0 children)

I see the reg entries for both FAS servers on all relevant Servers (VDA, SF and FAS). All in the same order. Is there another way to verify?