Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SSL Decryption problem

Status
Not open for further replies.

Duudson

MIS
Sep 13, 2002
6
FI
Hi Everybody,

I have weird problem with our Metaframe. Everything else works fine but when You try to transfer files from local machine to metaframe or vice versa session disconnects with SSL decryption failure.

Funniest thing is that this problem does NOT occur when moving .txt files. So I can transfer 100mb folders easily as long as all the files all .txt files. If I try to move anything else (like .exe or .bmp or .whatever) in 99% of the cases session is disconnected. Sometimes even browsing through files can cause disconnect.

These entrys are found at eventviewer when I try file transfer:
CSG0401 Accepted connection from client >Client:22834<

CSG0402 Client >Client:22834< sent ticket >;10;STA01;85C91E479B3D50771CE42000D0786278<.

CSG0403 Request STA >STA01< to resolve ticket
>85C91E479B3D50771CE42000D0786278<.

CSG0404 Successful connection to server >Server:1494< for client >Client:22834<.

CSG0310 Connection from client >Client:22834< failed SSL
decryption.

CSG0405 Closed connection from client >Client:22834< to server >Server:1494<.

CSG0405 Closed connection from client >Client:21155< to server >Server:1494<.

(I wonder why two closing connections?!?)

Server is not under heavy load (yet) max 5 active connections. Cannot launch this service before this is solved.

Problem occurs same way with Full ICA client, PNAgent and
java-applet or through NFuse portal. I doesn´t matter if I use commandline tool or fileexplorer. Also transfering big files to applications cause disconnection.

Performance monitor doesn´t show anything unusual.

Other curiosity is that I can use this service from home with my ADSL connection without any problem even though Im behind PAT and NAT. I just transfered 150 megabyte folder with mixed files to our metaframe server.
I also tried to &quot;tune down&quot; my NICs to 10 mb connections but the result was still the same...So the problem is not propably about the bandwidth.

CSG and NFuse is at DMZ , STA and Metaframe server is at protected area. Inner infrastructure behind firewall is in gigabyte switch and GB NICs. External connections are 100 NICs and Firewall and switches.

Solve this, be my hero, be a supernerd.

-Duudson
 
Is port 443 open on the firewall at the client end? - I notice this happens just after the ICA connection through 1494, so could be that you haven't allowed SSL traffic.

Hope this helps CitrixEngineer@yahoo.co.uk
 
Hi again,

This is not the case in here. Like I said earlier connections work very well as long as You don´t try to down- or upload any files.
Maybe there is something in the proxy settings that is messing the whole thing. My setting is currently on auto, I have to try some other options. Shitty part here is that there is many different organizations involved here and everyone has its own settings and proxies. As far as I know You can manually set only one proxy to conf file. Does anyone know is this true?

Most of the proxies are running on Squid. Does it support proxying SSL traffic?

-Duudson
-Duudson
 
What version of MF are you on, hotfixes, etc, include MS service packs...

any hotfixes on the CSG? Is it intel or solaris?

what version are the clients?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top