[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] AW: [FW1] Re:Problem with ICA protocol
hola geraldo, por fin, what did worked for you? where i´m definetly sure about is that you must set altaddr and use alternate adress for citrix when using nat (equal hide or static) because the masterbrowser response sends the adresses of the servers in the DATA of the packet (where fw1 don´t care about). icmp is definetly not needed for citrix. where i´m confused are the rules needed. con muchos recuerdos y gracias stefan fassbender -----Ursprüngliche Nachricht----- Von: [email protected] [mailto:[email protected]]Im Auftrag von [email protected] Gesendet: Mittwoch, 4. April 2001 16:09 An: [email protected] Betreff: [FW1] Re:Problem with ICA protocol Tx to all who helped me with this one. Although the problem isn´t solved yet, I am following the hints you all sent me. If i am using static NAT, do I still need to set the AltAddr on the MetaFrame server? I´ve been asked if ICMP is enabled on the firewall, and that if it isn´t this could be the reason of the problem. Any thoughts on that? Wouldn´t make much sense for me, but... thanks again, Geraldo Fonseca Icatu-Hartford Seguros S.A. [email protected] ----- Repassado por Geraldo Fonseca/MTZ/IHSEG em 04/04/2001 10:54 ----- Geraldo Fonseca Para: [email protected] 03/04/2001 cc: 16:37 Assunto: Problem with ICA protocol Hi all, I am using FW-1 sp2, and I am not able to estabilish connections from the Internet to my MetaFrame server. I´ve created the following rule: any MetaFrameServer any allow I am allowing connections to any port only because this is a testing environment. The ICA client documentation says that ports 1494-tcp and 1604-udp are the only ones needed. In the FW-1 log i see the connection being accepted by the firewall, but the ICA client shows an error similar to a timeout after a while. Any ideas are welcome. Thanks in advance Geraldo Fonseca Icatu-Hartford Seguros S.A. [email protected] ============================================================================ ==== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ============================================================================ ==== ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|