Connection Interrupted, issue reported with different version of Citrix Virtual Apps and Desktops

Connection Interrupted, issue reported with different version of Citrix Virtual Apps and Desktops

book

Article ID: CTX319676

calendar_today

Updated On:

Description

You may see user sessions are getting disconnected at launch, incomplete ghost session with name "-" is seen on the VDA and Connection Interrupted error for user. if vda have Microsoft defender Anti virus.

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

  1. Microsoft has fixed the issue in the Microsoft Defender Antivirus (MDAV) Platform Update version 4.18.2201.10 (or newer).


What was optimized?  Microsoft added the AllowSwitchToAsyncInspection setting to Set-MpPreference. This policy enables a performance optimization, that allows synchronously inspected network flows, to switch to async inspection once they've been checked and validated.

Workaround:
1. Revert to Windows Defender update version 4.18.2105.4 

OR 

2. Disable Network protection and Network intrusion prevention on VDA:
Configure policy setting 
"Computer Configuration\Administrative Templates\Windows Components\Windows Defender Antivirus\Windows Defender Exploit Guard\Network Protection\Prevent users and apps from accessing dangerous websites" to "Audit Mode"


 

Problem Cause

The issue was caused by Network protection and Network intrusion prevention in Windows Defender.
It gets enabled after Windows Defender update version 4.18.2105.5.

 

Additional Information

Ensure AV exclusions are added as per following blog/tech-zone:

Citrix Recommended Antivirus Exclusions
https://www.citrix.com/blogs/2016/12/02/citrix-recommended-antivirus-exclusions/

Tech Paper: Endpoint Security, Antivirus, and Antimalware Best Practices
https://docs.citrix.com/en-us/tech-zone/build/tech-papers/antivirus-best-practices.html

Provisioning Services Antivirus Best Practices
https://support.citrix.com/article/CTX124185