Pages

Wednesday, 29 August 2012

Event ID 10128 on Master Image

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

In my POC environment I was getting the following event id that was stopping me from connecting to a virtual desktop


The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (http://+:80/wsman/) in HTTP.SYS.
No remote requests will be serviced on that URL.
User Action
Please use "netsh http" to check if ACL for URL (http://+:80/wsman/) is set to Network Service.
Additional Data
The error code received from HTTP.sys is 5: Access is denied.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Once I ran the below command on the golden image, shut it down and took a snapshot and updated the catalogue to the updated image I could connect to the virtual desktop without any problems.

winrm set winrm/config/Service @{EnableCompatibilityHttpListener="true"}


Error: Unable to contact the Hypervisor

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

I came across this error recently when doing a POC for XenDesktop on Vmware ESXi 5.

Error: Unable to contact the hypervisor. Check that the address, user name, and password are correct; the Controller and hypervisor are connected; and the SSL certificates have been set up correctly if you are using HTTPS.




To get around this issue I had to change the Proxy.xml file located on the Virtual Center to accept HTTP communication which is located in the following directory


C:\ProgramData\VMware\VMware VirtualCenter\proxy.xml


Find the following sections of the XML file and change them from "httpWithRedirect" to "httpAndHttps"



Now from the knowledge base article its a tad confusing which part of the xml file you need to change, ignore the id= part and just look for "/" and change the access mode and also look for "/sdk"and change the access mode.


http://support.citrix.com/article/CTX125578

Wednesday, 22 August 2012

Citrix XenApp failed to connect to the Data Store

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

Recently ran in to an error where I couldn't connect to any XenApp server using the AppCenter and I was getting the following errors within the system event log.

Event ID 3989
Citrix XenApp failed to connect to the Data Store. ODBC error while connecting to the database: 28000 -> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed. The login is from an untrusted domain and cannot be used with Windows authentication.

Event ID 3632
The server running Citrix XenApp failed to connect to the data store. Invalid database user name or password. Please make sure they are correct. If not, use DSMAINT CONFIG to change them.  Error: IMA_RESULT_ACCESS_DENIED  Indirect: 0  Server:   DSN file: C:\Program Files (x86)\Citrix\Independent Management Architecture\mf20.dsn

Event ID 3612
The server running Citrix XenApp failed to connect to the Data Store IMA_RESULT_ACCESS_DENIED. Invalid database user name or password. Please make sure they are correct. If not, use DSMAINT CONFIG to change them. 

Now it turns out that the farm was configured to use the administrator account for access to the datastore and when the domain administrator password was changed these errors start to appear.

To get round this issue (Not use the domain admin account!!!) run the following DSMAINT command and set the correct password for the administrator account.

DSMAINT CONFIG /user:domain\administrator /pwd:password

Ideally you should change the account used for this to a different account that is used for XenApp only.

Tuesday, 14 August 2012

Mobile Devices and CAG VPX

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

Ok have you run in to the lovely issue with trying to configure a mobile device such as an iOS device or android to connect to a XenApp service site via a CAG VPX?  We'll after reading all the edocs, multiple forums posts and just at of playing I finally got it working.

You may run in to an error and be presented with the following message
"The address given did not provide a valid App list. Please check the address, gateway settings, and your network connection.”"
I've spent a load of time on this and i could never find any documentation that specified what exactly was needed..... do I need to add config.xml to the basic logon point? Do use FQDN or Netbios....Ahh!

Anyways lets begin

Before you start
  1. A Web Interface of 5.4 but at least 5.x.
  2. Access Gateway 5.02 or above.
  3. FQDN certs and intermediate cert.
Web Interface
  1. Create a service site called /mobile but can be anything you choose.
  2. Name farm and add Servers to the site along with XML port and transport type.
  3. Configure the mobile site with "Gateway Direct" in secure access
  4. Add address of externally FQDN (cagaddress.domain.com)
  5. Set STA as http://XASrv.domain.com:port/scripts/ctxsta.dll
  6. Authentications point at Web Interface
  7. Set Authentication Method to Prompt
Access Gateway
  1. Configure ICA Access Control List - ICA and SR. 
  2. Configure STA - Exact setting you configured for the WI.
  3. Configure authentication profile you require.
  4. add cert and make sure you also add the intermediate cert and then Chain the certs.
  5. Create a Basic Logon Point called Mobile and check Authenticate with Web Interface
  6. Website Configuration:

  • Home Page - http://XASrv/mobile/config.xml
  • Web Address - http://XASrv/mobile/config.xml

Note: for the Web Address also try just "http://XASrv"

Citrix Receiver mobile
  1. The Root CA certificate that created the AG certificate must be present on the mobile device.
  2. iPad - URL https://cagaddress.domain.com/lp/mobile 
  3. iPhone - URL https://cagaddress.domain.com/lp/mobile/http/XASrv/mobile/config.xml



Use the Online URL Generator http://bit.ly/URL_Generator to create simple way of setting up the receiver. 

If you think i've missed something off please dont hesitate to let me know.

Wednesday, 1 August 2012

XenApp 6.5 Policies Best Practices

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

Well not as such but this is what I setup for a baseline for each and every XenApp server I setup.  It gives you a good starting point to work from and from this point you can then go on to create additional policy to suit your needs and then apply the additional policy with the use of filters so that it applies to the correct group.  This is a mixture of policies that are recommended by Citrix and some that i just like to add in, the Citrix policies were taken from CTX134081 but this article also gives you some great pointers on UPM and Windows GPO's.

If you have any other policies that you like to set in your baseline policies and/or WAN/LAN/Tablet please post them.

XenApp Baseline User Policy.

Apply this policy as your baseline to all users connecting to your XenApp farm.

ICA\Adobe Flash Delivery\Flash Redirection 

Flash acceleration - Enabled
Flash default behavior - Enable Flash Redirection
Flash event logging - Enabled
Flash intelligent fallback - Enabled
Flash latency threshold - 30 milliseconds
ICA\Audio 

Audio Plug N Play - Allow
Audio quality - Medium
Client audio redirection -  Allow
Client microphone redirection -  Prohibit
ICA\Desktop UI 

Desktop wallpaper - Allowed
Menu animation - Allowed
View window contents while dragging - prohibited
ICA\File Redirection 

Client floppy drives - Prohibit
Client optical drives - Prohibit
Host to client redirection  Disable
Read-only client drive access - Disable
Use asynchronous writes - Enabled
ICA\Port Redirection 

Auto connect client COM ports - Disable
Auto connect client LPT ports - Disable
Client COM port redirection - Disable
Client LPT port redirection - Disable
ICA\Printing 

Client printer redirection - Allow 
Default printer - Set to client’s main printer
Printer auto creation log preference - Errors
Wait for printers to be created (desktop) - Disabled
ICA\Printing\Client Printers 

Auto-create client printers - Default printer only
Auto-generate generic universal driver - Disabled
Client printer names - Standard names
Direct connections to print servers - enabled
Retained and restored client printers - Allowed
ICA\Printing\Drivers 

Automatic installation of in-bo printer drivers - Disabled
Universal driver usage - Use Universal Printing only if requested driver is unavailable
ICA\Printing\Universal Printing 

Universal printing EMF processing mode - Spool to printer
Universal printing image compression limit - Best Quality
Universal printing optimization defaults - Standard Quality
Caching of embedded images
Caching of embedded fonts
Universal printing preview preference - Use for auto-generated and generic
ICA\Session Limits 

Linger Disconnect Timer Interval - 5 Minutes
Linger Terminate Timer Interval - 10 Minutes
Pre-Launch Disconnect Timer Interval - 15 Minutes
Pre-Launch Terminate Timer Interval - 30 Minutes
ICA\Shadowing 

Log shadow attempts - Allow
Notify user of pending shadow connections - Allow
Users who can shadow other users - Defined by security
ICA\Time Zone Control 

Estimate local time for legacy clients - Enable
Use local time of client -  Use Client time zone
ICA\TWAIN devices 

Client TWAIN device redirection - Enabled
TWAIN compression level - low
ICA\Visual Display\Moving Images 

Moving Image Compression - Enabled
Server Session Settings
Session importance - Normal
Single Sign-on - Disabled

XenApp Baseline Computer Policy Setting.

Apply this policy as your baseline to all Servers in your XenApp farm.

ICA
ICA listener connection timeout - 120000 ms
ICA listener port number - 1494
ICA\Auto Client Reconnect 

Auto client reconnect - Allow 
Auto client reconnect authentication   Not required Require
Auto client reconnect logging   Disabled
ICA\End User Monitoring 

ICA round trip calculation - Enable
ICA round trip calculations for idle connections - Disable
ICA\Graphics 

Display memory limit   32768 KB
Display mode degrade preference - Degrade Color Depth First
Dynamic Windows preview - Enabled
Image caching - Enabled
Maimum allowed color depth   32 bit
Notify user when display mode is degraded - Disabled
Queuing and tossing - Enabled

ICA\Graphics Caching
Persistent Cache Threshold - 3000000 Kbps
ICA\Keep Alive 
ICA keep alive timeout - 60 seconds
ICA keep alives - Enabled
ICA\Multimedia 
Windows Media Redirection - Allowed
ICA\Session Reliability 
Session reliability connections - Prohibited
ICA Shadowing 

Shadowing - Allow
Licensing
License server host name - License Server name
License server port - 27000
Server Settings
DNS address resolution - Enabled
Full icon caching - enabled
Server Settings\Health Monitoring and Recovery 

Health Monitoring - Enabled
Health Monitoring tests - Use Defaults (please configure as you see fit.)
Server Settings\Memory/CPU 

CPU Management server lever - preferential load balancing
Memory optimization - Enabled
Memory optimization interval - enabled
Server Settings\Reboot Behaviour 

Reboot logon disable time - Choose a value to suit your clients
Reboot Schedule frequency - Choose a value to suit your clients
Reboot Schedule start date  - Reboot Schedule Choose first day of the reboot
Reboot Schedule time - Choose time to restart server
Reboot warning interval - Choose interval which the users are notified about pending restart
Reboot warning users - enabled
Scheduled Reboots - enabled
XML Service 

Trust XML requests - enabled
XML server port - 8080

XenApp WAN/External User Policy.

Apply this policy for users working from branch offices or remote locations with low bandwidth and/or high latency connections.

ICA\Adobe Flash Delivery\Flash Redirection 

Flash acceleration - Enabled
ICA\Audio 

Audio quality -  Medium 
ICA\Client Sensors\Location 

Allow applications to use the physical locations of the client device - allowed (Tablet Devices)
ICA\Desktop UI 

Desktop wallpaper - prohibited
Menu animation - prohibited
View window contents while dragging - prohibited
ICA\File Redirection  

Use asynchronous writes - Enabled 
ICA\Mobile Experience 

Automatic Keyboard Display - Enabled (Tablet Devices)
Launch touch-optimized desktop - Enabled (Tablet Devices)
Remote the combo box - Enabled (Tablet Devices)
ICA\Printing  Wait for printers to be created (desktop) - Disabled 
ICA\Printing\Universal Printing  

Universal printing optimization defaults - Standard Quality
Caching of embedded images
Caching of embedded fonts
ICA\TWAIN devices 

Client TWAIN device redirection - Disabled
ICA\Visual Display  

Max Frames per Second - 15 FPS
ICA\Visual Display\Still Images 

Extra Color Compression - Enabled
Extra Color Compression Threshold - 8192 kbps
Lossy compression level - High
Lossy compression level threshold value - Unlimited

Monday, 23 July 2012

How to find your Datastore for XenApp

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289.

Sometimes you inherit a customer/client that you have no details for and therefore cannot find out certain information quick enough!!!

If you need to find out where the Datastore is for a certain installation just check the following regkey. 

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Citrix\IMA\Database Settings.

Friday, 20 July 2012

Citrix Licensing Service will not start!!!

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

OK I know I've not been working with Citrix as long as some people but this is the first time I've come across this this problem...  For some reason on a customers Citrix environment the Citrix Licensing Service would not start...

you will get an event id something like the following


Faulting application name: lmadmin.exe, version: 11.9.0.0, time stamp: 0x4d6bbff6
Faulting module name: lmadmin.exe, version: 11.9.0.0, time stamp: 0x4d6bbff6
Exception code: 0xc0000005
Fault offset: 0x0005e222
Faulting process id: 0x2a58
Faulting application start time: 0x01cd65da86623391
Faulting application path: C:\Program Files (x86)\Citrix\Licensing\LS\lmadmin.exe
Faulting module path: C:\Program Files (x86)\Citrix\Licensing\LS\lmadmin.exe
Report Id: c469cc23-d1cd-11e1-ab7b-0050568070dc


The client was running License server 11.9.0 Build 11011 and to resolve this issue i had to rename the "C:\Program Files\Citrix\Licensing\LS\conf\concurrent_state.xml" and then start the licensing service again and all works fine.

The issue is resolved in License server 11.10

Monday, 16 July 2012

New Microsoft Excel 2010 Worksheets are Not Shown in Taskbar

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

I came across this today when you open a new Microsoft Excel 2010 worksheet, the new sheet is not shown on the taskbar, only the main Microsoft Excel icon is shown on the taskbar. 

This is because the Excel hook is not injected into any process because the seamless engine component (Sehook20.dll) responsible for the fix fails to load into the user session. Sehook20 fails to load because active accessibility hook is disabled in the Seamless Flags settings. Seamless flags are often used when troubleshooting problematic display issues.

I got round it by adding the following registry key.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Citrix\ExcelHook
Name: Enabled
Type: REG_DWORD
Data: 1


Get out the following article for more details.

http://support.citrix.com/article/CTX133198/

Friday, 15 June 2012

Citrix Session Monitoring & Control Console

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

I found this great article about Citrix Tool called "Citrix Session Monitoring & Control Console" from Thomas Koetzing that describes in detail the functions and use of SMCC.


You can also read a bit more about it on the edocs web page too.


The Situation:

You have performance problems with user session(s) and want to see what's going on in the session. Is the display not updated or the printing channel? Is speedscreen working or do I have network problems? You can use the performance monitor for that but there is also a GUI, the SMCC. 
  
The running SMCCAfter you have started the SMCC you have to select a specific ICA Session. I have selected the ICA-tcp#2 of the remotely logged in Administrator. Now you will see the overall Session Data of the selected ica session. Check out the Compession, the Session Line speed or even the session Latency and also the update time.

Image


Switch to the Session Channels 

Now take a deeper look in the Admin ICA session. Switch to the Session Channels and see every single Channel that is running in the session. It depends on your MetaFrame settings which channel is active or you have allowed. For example the "old" Printing Channels (CTXLPT1, CTXLPT2), "old" COM Ports Channels (CTXCOM1, CTXCOM2), Clipboard... etc. and the main ICA Control Channel (CTXCTL).
In the Session Channels you can take Control of the Session total Bandwidth therefore use the slider, but in the next step you can take Control of each Virtual Session Channel.


Image


Take Control of a Channel 

Click on the CTXCTL and you will get the Virtual Channel Control. Now you can take control of that specific channel. Here a quick try out, copy as the Admin some megs to the mapped client drive and when the system is copying the files, open the CTXCDM and set the Priority to low and apply it You will see the copy time will decrease.


Image


The SMCC might help you with your Thin Clients (Linux, Windows CE), Fat Client, PALM's or what ever you use for connecting to the Citrix MetaFrame Server and Montitor and Control the ICA Session for troubleshooting and pin point your problem.

Tuesday, 15 May 2012

XenApp 6.5 event ID 30107 and 10001

Please check out www.kaztechsolutions.co.uk for more of my technical posts, alternately please call us on 01932 268289. 

Ok so i started to get a XA 6.5 farm up and running for testing and i ran in to the following errors.

Event ID 30107


Site path: C:\inetpub\wwwroot\Citrix\PNAgent.

The Citrix servers reported that they are too busy to provide access to the selected resource. This message was reported from the XML Service at address http://CTXSERVER/scripts/wpnbr.dll [com.citrix.xml.NFuseProtocol.RequestAddress].  [Unique Log ID: db5427d9]

Event ID 10001

A usable server cannot be found on which to launch the application. Application: MyDesktop, Client: MYWORKSTATION (address: 10.10.10.10;;;), User DOMAIN. Check your worker group definitions and load balancing policies to verify appropriate servers are assigned for MyDesktop. 


How i got round this.

1.  Setup a worker containing my servers
2.  Applied a load evaluator to the App.
3.  Applied XA650W2K8R2X64001
4.  Restarted XA server

Also make sure you don't have 1 in the following regkey.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnections