Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Citrix Farm problems after Active Directory upgrade

Status
Not open for further replies.

thavil

Programmer
Dec 27, 2001
19
US
Requesting some advice on a problem we ran into this past weekend after we upgraded our network to a 2003 Active Directory Domain from an NT domain. Our production Citrix Farm is 3 NT 4.0 SP6a TSE boxes. We are running Metaframe XPe with FR1/SP1. Our initial problem was that none of our legacy NT boxes could connect to the new domain (trust relationship error). After spending 3 hours on the phone with Microsoft, we were able to change the security policy enough to allow all of the NT boxes to communicate.

Once I was able to log onto to the network, I could not log into the Citrix Managment Console with my administrator account. I finally figured out to log into CMC with the local admin account. Once in the console, I went to Citrix Administrators section and each admin was listed as a question mark except for the local account. I then looked at individual apps that are published and the domain groups assigned to each app only listed the domain name and the actual group was blank.

From what I can see, my older version of Citrix can not see the new Active Directory domain properly. As a quick fix, we joined the 3 machines to a trusted NT domain for now and it is working without problems.

Has anyone else seen this problem or does anyone have any suggestions besides upgrading the farm (budget concerns at this government facility are keeping me from upgrading for now). I have read an article about installing Active Directory Services Interface (ADSI) 2.5 or higher on each box. Anybody have experience with this? Thank you!!
 
TSE, oh boy. Well my advice would be to bite the bullet and upgrade, actually, blow the lot away and start again. OK that may seem a bit drastic and rash, but believe me the futire features and reliability of 2K or 2K3 will make it all worth while. Do NOT upgrade from TSE a) because you can't and b) becuase then you get a clean build. Plan it right and it is a breeze.

[blue] Oh you know, just doing what I do.[/blue]

Cheers
Scott
 
Scott, thanks for your input. It makes a lot of sense but we do not have the money in our budget right now to upgrade the farm. All of the money is going to 2003 Active Directory, W3K boxes for DHCP/DNS/WINS, Exchange 2003 and getting rid of Novell. I guess I didn't do my homework well enough to see what AD would do to my legacy Citrix Farm. My task now is to keep the old farm running but get it off the trusted NT domain.

Thanks,
Tod
 
thavil, I think the reason you are seeing so many account issues is that you moved from a mixed mode ad to a native mode. the account, group objects etc. I'm pretty sure have a different structure.

did you migrate existing objects to the new domain? i.e. users, groups, computer accounts etc?
 
KCDave03, we migrated all existing objects to the new domain. Also, we are still in the mixed mode as we still have a few NT domain controllers on our network. Thanks for your input.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top