Launching ICA file failure in ICA proxy deployment integrated with Sangfor LB

Launching ICA file failure in ICA proxy deployment integrated with Sangfor LB

book

Article ID: CTX463606

calendar_today

Updated On:

Description

Launching ICA file failure in ICA proxy deployment integrated with Sangfor LB

Resolution

Sangfor's SSL protocol is equivalent to Citrix ADC's SSL_TCP protocol, and Sangfor's https protocol is equivalent to Citrix ADC's SSL protocol.
After changing the protocol of Sangfor LB from https to SSL, the issue is resolved.

Problem Cause

Topo:
Sangfor LB-----Citrix Gateway Vserver

According to nstrace, after ICA file request, Gateway Vserver did not receive the STA ticket verification request.
image.png
Sangfor LB's protocol is https, but the STA ticket verification traffic is not based on http, then Sangfor LB rejected the traffic.