Unable to Access StoreFront Apps After Upgrading to NetScaler 11.0 64.34

Unable to Access StoreFront Apps After Upgrading to NetScaler 11.0 64.34

book

Article ID: CTX207152

calendar_today

Updated On:

Description

Unable to access StoreFront apps after upgrading to NetScaler 11.0 64.34.

Resolution

Look for any SSL handshake errors with regards to TLS 1.2 and 1.1 version on StoreFront server under Event viewer. Only StoreFront 3.5 supports TLS1.2 as of now.
For more information refer to Citrix Documentation - https://docs.citrix.com/en-us/storefront/3-5/about-35.html

Upgrade your StoreFront server to version 3.5 or complete the following workaround to fix the issue:

  • Workaround is to disable TLSv1.1 and 1.2 on NetScaler.
  • If you are not load balancing StoreFront servers on NetScaler then we cannot disable TLS1.2/1.1 for backend traffic as this is a Gateway Vserver.
  • So create LB Vserver and bind StoreFront server as service. Then disable TLS1.1/1.2 at service level so that NetScaler will not send TLS1.1/1.2 in SSL handshake to backend StoreFront server.
  • Once LB Vserver is created, use that IP in the Session profile on Gateway Vserver.

Problem Cause

The issue is caused because TLS1.1/1.2 support got added in latest NetScaler builds which is used for backend StoreFront traffic.

Issue/Introduction

Unable to access StoreFront apps after upgrading to NetScaler 11.0 64.34.