Cisco Firewall :: Use Citrix Receiver For Java On ASA 5505 On SSL Web VPN?
Jan 9, 2011its possible use citrix receiver for java on asa 5505 on ssl web vpn?
View 1 Repliesits possible use citrix receiver for java on asa 5505 on ssl web vpn?
View 1 RepliesMy macbook pro recently upgraded to the last version of java and now I can open the ASDM for my Cisco ASA 5505, when I try open, only show me the window of Java 7 ..., and don't load the ASDM.
View 15 Replies View RelatedJust installed an ASA 5505 with AnyConnect Essentials. AnyConnect installation works fine on some windows boxes (All flavors) but have a couple machines with issues. This makes it clearly a computer side issue. When I try to log into the ASA to download the client with IE 9 the ASA just keeps asking for my logon credentials. If I I use Firefox my credentials work and I get as far as the "Using Sun java for installation" with instructions to click yes on the java security warning. The Java Security warning never arrives like on machines that don't have this problem. Firefox just hangs and has to be killed by task maanger. Remove and reinstall of both Java and Firefox fail to correct the problem. Any AnyConnect clientside recovery tips beyond Java and Browser reinstall?
A Google search show a few folks using Ubuntu and old PPC Macs seeing the same java error I get on these couple of windows boxen. [code]
My company has a cisco ASA 5510 and we have a Citrix remote desktop solution. In a nutshell I have users from outside our network accessing a virtual Citrix NetScaler inside our DMZ. There is a session reliability feature enabled on the Citrix solution. Session reliability uses tcp port 443. A user from outside the network connects to our network and is handed a virtual desktop to work with. When a remote user is working on their virtual desktop and there is a network connection issue the end user loses network connectivity for a brief period of time (in most cases just seconds) then the Citrix session reliability feature takes over and holds in a buffer all data destined for the end user . Once the connection is re-established then the buffer is emptied and the session goes on like before and the end user is able to use the virtual desktop. At least this is the way it should work.
In our case the connection never re-establishes between the end user outside the network and the NetScaler in our DMZ. We have been working with Citrix Support and they believe the issue is in our firewall. We have taken packets captures with Wire shark and we can see when the network failure occurs the NetScaler in the DMZ is holding information in a buffer and trying to communicate with the remote end user outside our network via packets and TCP port 443. We can also do the same packet captures from the end user computer and see where it is not receiving any packets from the NetScaler in our DMZ. The fire wall has an access list allowing any traffic in the outside port destined to the NetScaler Public IP on port 443. Then once in the firewall outside port we have a static rule pointing to the NetScaler IP in the DMZ.Everything is working quite well until we need to rely upon the session reliability. We have tried altering the TCP & Global Timeouts options in the firewall via the ASDM with no luck.
I have a question around pix 501 (6.3) configuration. I am trying to allow traffic from a single Citrix CAG across a variety of ports (80,443,9001-9005,27000,7279,1494,2598) from external (dmz) interface through to multiple addresses (on the same ports) on the internal (secure) network and dont know how to best approach it or if its possible. The only way I have found to allow traffic through is via Static Nat entries which I cant see will work for this requirement as we need some ports to be allowed into multiple addresses.
View 6 Replies View RelatedI have a Cisco 501 and I can not get into the configuration menu of the Java console appears to me this script
View 4 Replies View RelatedWe have built IPSEC VPN over MPLS P2P circuit between Head & Branch office using Cisco ASA 5510. Client systems at Branch office connects to Citrix app at Head office, but it gets disconnect intermittently for all user. if any recommendations/changes required for Citrix App whn passing over IPSEC VPN/ ASA.
View 2 Replies View RelatedA group of Citrix Clients connect to a Citrix Metaframe Server. The port numbers involved are Citrix Metaframe (TCP/UDP 1494) and MS Terminal Server (TCP/UDP 1604).
The network is configured such that the communication between the Citrix clients and server goes through a GRE tunnel. Traceroutes from client to server, and vice versa, confirm that it passes thru the GRE tunnel. There's no ACL, firewalls or NAT devices along the IP path, in both directions.
The issue is, all Citrix clients can ping to the server but some fail to log on to the server; some have no problem. Also, other applications, e.g. PCAnywhere, can go through. If the GRE tunnel is taken away, all Citrix clients can log on to the Citrix server.
Ive serched everywhere for this problem and couldnt find it, ive tried the basic troubleshooting, one of are users is using the 32 bit client of citrix and it is not lauching, other users have no issues with it, only her computer does. When I click to lauch the desktop it thinks a bit and then the receiver will shoot me an error saying :
"The network connection to your application was interrupted. Try to access your application later, or contact technical support." Her computer is running Windows 7 64 bit, IE8. Im really not sure what could be causing this error
My colleague wants to use our load balancers for VPN. We are coming off 3030s which are serving remote access IPSec as well as terminating LAN to LAN tunnels for like 7 sites.I want to secure the 5540s behind our front end 5585Xs when we move prod to the new dc.We have no immediate need for clientless but need to support osx lion and IPSec client does not. Thats all that's driving this effort currently. I already reminded mgmt that the 3030 and the IPSec client are end of life.I just think anyconnect is the better solution based on current skillset and the popularity of the solution.
View 2 Replies View RelatedWe're trying to access Citrix applications on customer`s server, but the error message attached pops up every time I try to access any application. Actually, this is the same error message when we try to use ssh protocol. I'm pretty sure I have loaded all the plugins for this. All the other functionalists are ok for this equipment.
View 1 Replies View RelatedWe run a hub&spoke network with dual GRE tunnels from each spoke site to seperate independant adsl routers at the hub.IPsec is enabled on each tunnel with crypto maps and then QOS is enabled with pre-classify for voice traffic priority. We also have defined a class for Citrix traffic by identifying port1494 traffic out and anything bound for our citrix servers IPs.Ok so the problem is that once the encryption comes up on the tunnels, the citrix programs wont connect. Take the crypto map off the tunnel and all works fine.
Here is the relevant config
crypto isakmp policy 1 encr 3des authentication pre-share group 2crypto isakmp key **** address *.*.*.*
crypto isakmp key **** address *.*.*.*
crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel to hub1
set peer *.*.*.*
set transform-set ESP-3DES-SHA match address 104 qos pre-classifycrypto map SDM_CMAP_1 2 ipsec-isakmp description Tunnel to hub2
set peer *.*.*.*
set transform-set ESP-3DES-SHA match address 105 qos pre-classify
[code]....
I deliberately weight EIGRP to favour Tun0 and have Tun1 as a failover. I was thinking of Route-mapping the Citrix traffic to Tun1?
We're setting up a Citrix Cloudstack/XenServer environment and having a heck of a time getting VLAN communication to work with the Cisco SG300-28 switches we've got. We have 4 hosts that are running physically connected to 2 SG300-28 switches.The Guest Network NICS are running on XenServer with a VLAN configuration. As you'll see below our problem lies in that the vm on Host1 (10.1.1.254) cannot communicate to the vm on Host2 (10.1.1.5).Our SG300-28 is currently in L2 mode with Trunked ports for the NICS. It's allowed the VLAN 133 as tagged. Here's the guest networking:here's how our SG300-28 are configured for VLAN traffic GE1,2,13,14 are the connected ports with VLAN133 being one of the tagged VLANS
View 8 Replies View RelatedCurrently using intel 5100 & 6200 client cards on multiple driver versions. WiSM is 7.0.116. APs are 1250 and 1260 series. Citrix is setup to send server-side keepalives for session reliability. Randomly, several times a day the client will get disconnected from the Citrix application session but maintain connectivity to the AP and other applications continue to work. Traces show the server-side keepalive reach the controller but are delayed from controller to client by 5-6 seconds. Just enough time for the Citrix server to timeout and tear down to session. Additional testing shows the delay most likely occurs somewhere from controller to AP. It occurs on multiple controllers on multiple campuses.
We have Dell/Broadcom clients that don't experience the problem. The only commonality seems to be the Intel cards. CCX? I know Intel has a special relationship with Cisco regarding CCX and have developed features not available on other cards. Tried disabling power save and other CCX features but hasn't solved the issue.
On CIsco ASA 5545x not able access finale application through SSL VPN, error shown is "class not found exception" and "bancs2000.bancs2000.class" default profile is used in VPN while we trying access HTTPS internal web server. Same behavior observed in version 8.6 and 9.1.
Above errors observed during JAVA loading process, browsers like Mozilla, Chrome and IE are tried.
I got problem with RVL200, he works good on my botch mac's witch OSX 10.5,10.6 and Firefox 3.6 but stop working after last java update. The machine witch 10.5 is working because I don't update Java but the other computer is up-to-date.
Problem is with lunching the Java applet ,all the rest is working.- I'm login to SSL VPN Tunnel- The new window is opening I accept applet to run.He try but nothing happends the window is bank with no connect / disconnect buttons. [code] I have all the rights / permission to vpclient catalogue and files in there.I try this on root to the same error
I'm installing a new platform LMS 4.0.1 under VMWare and Windows 2008 R2.
I installed via Windows 2008 R2 Patch without problem in LMS 4.0, then updated in LMS 4.0.1.
I'm facing several issues during this installation.
The first issue I have is the following:
When I launched topology services, java jre file jre-6u22-windows-i586-p_withjacorb.exe was downloaded and I saved it on disk.
I clicked on file to install it and get the following message during the installation:
Error 1330.A file that is required cannot be installed because the cabinet file C:UserslmsAppDataLocalLowSunJavajre1.6.0_22Data1.cab has an invalid digital signature. This may indicate that the cabinet file is corrupt.
It tried to install certificate without success. I have internet access to java.com but it seems publisher is not trusted.
I recently linked my dtv receiver to the internet through my laptop. My question is, since I'm now sharing the connection, do I need to make any adjustments in the "network and sharing center" to keep sensitive info on my laptop safe?I do have Norton Internet Security.
View 1 Replies View RelatedJust updated my DTV to a HD receiver which has the ability to access movies/shows via internet so I hard wired my belkin router to the TV receiver and I can't get it to connect. The router light does not go on showing me I am not connecting to the TV receiver. When I go into the DTV receiver it reads all my IP address and has an OK behind them, but says there is an error and the internet is not connected. When I plug the same cable into my PC or my laptop the light on the router does come on. Also my iphone does receive WIFI via the same router. I called DTV and they said everything on the receiver is correct. I called my router folks and they said everything is correct and that it must be the DTV receiver. I've been using this router for several years and their tech guy sounded like he knew what he was doing. how I can get the router to recognize the TV receiver?
Here are my router settings: I used the WAN IP info in my TV receiver. Home| Help| Logout Internet Status: Connected LAN SetupLAN SettingsDHCP Client ListInternet WANConnection TypeDNSMAC AddressWirelessChannel and SSIDSecurityUse as Access PointWireless BridgeFirewallVirtual ServersClient IP FiltersMAC Address FilteringDMZWAN Ping BlockingSecurity LogUtilitiesParental ControlRestart
[Code].......
I need a vpn address for Digital satellite receiver TITANIUM HD 20000.I have tested several address which are working on my pc windows but my satellite receiver can not connect to vpn server. what should i do?
View 5 Replies View RelatedOld Configuration:
A 2 Wire 2701HG-B DSL MODEM/Router Upstairs
Wired into 2 PCs upstairs
WiFi to a PC Downstairs.
I killed the DSL service and got U-verse, but that added a new Modem/WiFi downstairs. I still have the 2Wire upstairs, but it has no phone connection.Can I use the 2Wire to "Receive" and "distribute" the WiFi signal from downstairs?
I don't see how to turn off the DSL MODEM. If I put in the ID and Password for the WiFi router downstairs into the 2Wire upstairs, will it "Login" or will it conflict? Are there special settings for the PCs to access the U-Verse router through the 2Wire?Basically, I want to know if the upstairs 2Wire can receive the U-verse signal and convert it to wired signal for the 2 upstairs PCs.
Recently, I've been having some problems trying to play a couple games coded in Java, such as MineCraft. Every time the game loads, my internet immediately disconnects.There isn't any error dialogue or message, it simply disconnects me.Sometimes, I am able to stay on my internet connection and play the game for a short while, but most of the time, it disconnects me. I am on a wireless connection, with a router running the custom DD-WRT firmware.
View 5 Replies View Relatedis there a java download for android
View 3 Replies View RelatedASDM access to 5500 using Java was just a frustrating experience. If you manage only one device you may not notice the pain. But if you are managing multiple devices with some device 'forbidden' to update ASA firmware,
I spend few days looking at the issue and came to a conclusion and decided to post to guide all newer VPN admins who will go through the same pain and hopefully we can reduce some combined wasted time.
Recommended Beginning Setup for New Admin :
[code]...
So (foolishly) I let the software updater delete Java 6 (which only Apple provides), and I installed Java 7 from java.com. Was running ASDM 6.4.9, all I got was the Java 7 splash box. Updated ASDM to 6.4.9-103, same problem.
I can run ASDM in one of my VM's, but it's a pain.
I am in a community that has a wifi system and the club house is about 900ft awayWhat king of a receiver would I need to reach and receive that signal?
View 2 Replies View RelatedI want to create a site with which we can share a pics?
View 2 Replies View RelatedI'm trying to configure an snmp notification reciever on WCS 7.0, so that critical alarms get reported to our central console. Following the configuration guide I was able to add the reciever as northbound, but after adding it I get an alarm saying that it is unreachable by WCS so all alarm notification will be suspended. I have tested snmp and ping connectivity between the WCS box and the notification reciever and it works ok, is there some other traffic that I might be missing?. I've seen some packets going from the WCS box to TCP port 7 on the reciever, which as far as I know is the echo service, is that what WCS uses to test connectivity?
View 7 Replies View Relatedyesterday I tried to connect to our ASA 5520 using ASDM Launcher, which has alwasy worked before. For some reason ASDM Launcher is no longer working from both my Win XP desktop and Win XP laptop. I can open ASDM through the browser but not the launcher. Both desktop and laptop have Java 7 U 6. I'm not sure if I can back rev my Java.
View 4 Replies View RelatedWe have a WEB VPN running on Cisco ASA 5510 (SW = 8.2.1 / ASDM SW = 6.2.1). There are multiple internal (Web) applications are published on it and are working. One of the Web Application is working from internal network but from outside (or internet) through Web VPN, it is getting stuck and trying to load JAVA version. It is to be mentioned here, the latter web application is required Java Version 1.4.2 while the working applications are working with Java 1.5.1.
Is it possible to mount the more than on Java version on Cisco ASDM to be worked together ?
I have just configured a ASA5505 running 8.2.2 as a webvpn server for clientless VPN connections.
I need to setup a particular bookmark for a RDP session which forces the use of the java client for those who can't seem to get the ActiveX control working for some reason or another (virus scanners/firewalls/scerutiy policies etc).
I created a bookmark as follows, but it always tries to connect with the ActiveX control first when logging on from an IE client.
rdp://192.168.1.1/?force_java=yes
I have cisco wlc 2125 and external web autherthation was configured on it. When user disable the java script in browser cisco wlc do not redirect on my external page instead of wlc show page http://1.1.1.1/login.html with cisco logo. How can i resolve this problem? How to configure wlc redirect to external web auth site with disabled java in users browser?
View 3 Replies View RelatedIm trying to configure a SR520 with the CCA, but every time I try and apply the changes to the router i get the following error.
"java.lang.nullPointerException"
Using CCA 3.0(1) and Java Version 1.6.0_16 from Sun Microsystems Inc?I assume this is an issue with Java, as like with the SDM you had to use an Old Vertion.