Enlightened Data Transport Not working with Double Hop DMZ scenario

Enlightened Data Transport Not working with Double Hop DMZ scenario

book

Article ID: CTX231528

calendar_today

Updated On:

Description

EDT requires policy on the XenDesktop to be enabled and DTLS on the NetScaler to be ON. Also, StoreFront needs to be minimum Version 3.8 and Citrix Receiver at 14.7. So all the requirements are met.
At the XenDesktop Policy for "HDX Adaptive Transport" is set to "preferred", still connections fails to launch in EDT mode instead failing back to TCP.
On the NetScaler Gateway Vserver we see that Double hop is enabled:
User-added image
Checking the ICA connection we see that the ICA session is established as TCP:
User-added image

Resolution

The NetScaler 12.0.56.20 added support for EDT over DoubleHop DMZ setup. 

  • Check if the Hops are configured as per the standard configuration 
  • Also check if Double hop is enabled on a non DoubleHop setup, if yes please disable the "DoubleHop" checkbox if it's not a double hop setup.

Note: Support for EDT where users are landing on the 2nd hop directly in a double hop scenario will be available in the next 12.0 releasing Q1 2018.


Problem Cause

The issue can be due to several reasons as below:

  • Double hop is checked in a non double hop setup.
  • On a DoubleHop setup if DoubleHop option is enabled on both the 1st and 2nd hop Vservers, which should be enabled in the second hop only and first hop should have next hop defined.
  • If in a double hop scenario users are directly landing on the 2nd hop of a Double hop setup.

Issue/Introduction

EDT is not working even after enabling DTLS at the NetScaler and XenDesktop level in a double hop DMZ scenario. however the same is working with the TCP fail-back.

Additional Information