Pages

Showing posts with label Citrix. Show all posts
Showing posts with label Citrix. Show all posts

Wednesday, January 11, 2012

Xenapp 6.0: "A device attached to the system is not functioning."



We had a user call our help desk stating that they weren't able to log into their XenApp 6.0 published desktop.  It accepted their credentials, started going through the motions of applying group policy, etc., but before the desktop actually appeared, the session disappeared completely.  After doing some testing, I noticed that an error message was popping up, for less than a second, right before the session closed.  With my trigger finger, I was able to snap a screen shot to discover the following error: "A device attached to the system is not functioning."
After poking around the Citrix Delivery Services Console, I discovered the that the user had a Disconnected session out there, that was obviously in a completely cheddared state.  So, when the user was logging in, they were being reconnected to their broken session, and were never able to log in.  After logging off the disconnected session, the user was able to start a brand new session and log in successfully.

Wednesday, September 21, 2011

XenApp 6.0: Printers Fail to Autocreate on a Mac

I got a call from one of our users that has a Mac at home and connects to our Citrix XenApp farm through our Access Gateway.  Apparently, everything was working fine, except that the printers locally attached to his Mac would not auto-create in his Citrix session.

While I enjoy using my Macbook at home, we have no Apple gear here in our office, so I was unable to do any tests in our lab environment.  That's when I decided to call on the power of Google for help, and stumbled across the following Citrix article: Printers Defined on a Mac Client Fail to Auto-Create when Connecting to XenApp 5.0 on Windows 2008

Basically, the issue was that a printer driver (the HP Color Laserjet 4500 PS for XenApp 5, or the HP Color Laser Jet 2800 Series PS for XenApp 6) was no longer installed on our XenApp servers.  Early on, before we learned about the pains of printing in Citrix, we freely installed drivers for printers.  After finding out that was a very bad idea, I went on a driver purging spree, only allowing battle-tested drivers that were absolutely necessary to be installed on our farm.  I must have deleted the required driver in this process, as it is apparently installed by XenApp automatically.

For those curious, the reason why you need these HP drivers in the first place is because, for the time being, the driver that Citrix uses for their Universal Print Driver is not compatible with Macs.  So -- if you find that your Mac printers are not auto-creating, double check to make sure the required driver is installed!

Friday, July 15, 2011

This is the XenApp 6.0 Hotfix you are looking for

Basically, this is just a quick update to my previous post on Citrix servers freezing.  In looking at the dates, I now realize that I have been waiting over two months for this hotfix!

Anyway -- the hotfix to resolve a LOT of stability issues was released this morning (XA600W2K8R2X64046) and can be obtained at the following site:
http://support.citrix.com/article/CTX128342

Happy patching!

Monday, May 9, 2011

Citrix XenApp 6.0 Servers Freezing

When we finally made our way through our XenApp 5.0 farm freezes, I never thought that I would revisit such a problem so quickly.  When we made our upgrade to XenApp 6.0 and Windows Server 2008 R2 I thought for sure we would be jumping into a much more stable environment.  Unfortunately, I was wrong.

Shortly after making the upgrade we noticed that our Citrix servers became unresponsive at random times throughout the day: you could ping them, but that's about it.  Any attempt to RDP or log in even at the console level was an absolute failure.  If you are experiencing this problem, I would recommend upgrading your servers to Server 2008 R2 SP1, and applying the following Microsoft Hotfix: KB 2465772.  In addition, you're going to want to install at LEAST this Citrix Hotix as well: CTX127023.  But really, I would install as many Public Hotfixes for XenApp 6.0 as possible that apply to your environment.

If that would have been the end of the freezing saga, I would have been content.  However, the freezing dragon decided to rear its ugly head again: whenever we tried to shut down a Citrix server after having a decent amount of load on it, it froze.  Basically, it would sit on the Windows "Shutting down..." screen with the spinning circle to never fully shut down or recover without a hard power off.

After working with Microsoft and Citrix, it turns out that there is a Citrix Hotfix that's working its way toward becoming public (supported by Citrix), that should be available in the coming weeks.  If you are experiencing this same issue (freezing when shutting down) you're going to want to keep your eye out for Hotfix 46 (full name: XA600W2K8R2X64046).

UPDATE: I've added a new post that provides links to this hotfix.

In the meantime, there are a couple pages you should be keeping an eye on:
  1. The list of Public Hotfixes currently available for XenApp 6.0
  2. A list of recommended Microsoft Citrix Hotfixes for XenApp 6.0 and Server 2008 R2
Both of these get updated from time to time, so you'll want to bookmark them and see what's new whenever you get a chance.

As always, this is what worked for me, in our environment, so your mileage may vary and I won't be responsible for any problems this post may cause :)

Wednesday, May 26, 2010

Held Hostage By Symantec

In our Citrix environment, we needed good Anti-Virus/Anti-Malware protection since there will be a huge wave of users inhabiting each server on a daily basis. Our first choice was to deploy Symantec Endpoint Protection since we've already had pretty decent success with the product across our PCs. So, we dove in to adding it to our Citrix Environment.

A few weeks in we noticed some very odd things happening: Users access to network shares was excruciatingly slow. It would literally take minutes to enumerate all of the items in a given folder. Since our Start Menus were also redirected on the network, this meant their start menu would not show up for quite some time. Between this, slow log-on and log-off times and slow access to network shares (a main part of our business), this performance was unacceptable.

Naturally I started down the path of getting support. Now, Symantec support is pretty bad in my opinion in terms of wait times, turn-around-times, etc., but that's a different story. To make a very long story (approximately 3 months in time) shorter, it boiled down to the fact that there is a defect in their code that causes network scanning to stay turned on (in File-system auto-protect) even when you uncheck the box in the policy settings. So, in the end, Symantec acknowledged the defect, but as of now, still is unwilling to create the fix for it, or even provide a timeline for when this fix may show up in a future version. Since we've already had several hold ups on this project, this kind of indefinite wait was just unacceptable.

So -- now we're on to looking at our options. At the moment, Kaspersky is looking pretty good. How about any of you? Any experience deploying anti-virus in a Xenapp 5 environment running on Windows Server 2008 x64?

Friday, January 15, 2010

Windows Server 2008 Freezes -- Finally Solved!


In our environment at work, we have a Citrix farm that users connect to that is running on Windows Server 2008 x64.  During our testing phase while we still had a relatively light load of users on the farm, things went pretty smoothly.  As we added more and more users to the Citrix environment, different issues cropped up here and there, but none as horribly evil as our servers freezing to the point of becoming completely unresponsive.  At that point, all sessions that users were in would lock up, forcing them to lose any unsaved data and restart their sessions again.  As you can imagine, management did not see this as an enhancement to their productivity.

So, for the last several months we have been troubleshooting this issue.  There was no pattern in regards to when servers would freeze.  At any given time, any of the four servers we have in production would freeze.  There was also no consistent user base on the server that would freeze (the only consistency being that they weren't too happy when it would happen).  After bringing in several consultants that helped set up this environment initially, we took our case to Citrix.  Several log and memory dump files later, they came to the conclusion that Internet Explorer was causing our servers to lock up.  Naturally, I then presented this information all to Microsoft support.  Upon further analysis, they discovered that we were experiencing a bug that has been resolved by a hotfix:
http://support.microsoft.com/kb/976674

Basically, the hotfix resolves an issue that occurs when Server 2008 or Windows Vista is under a heavy load and there are a lot of network share accesses going on.  Well, in our case, the user profile is a network share, plus their Outlook PST files were out on a network share, plus their other file shares were network shares, and the list goes on.  After applying this hotfix (which was a little over two weeks ago) we have not experienced any freezes.  Good news for everyone.

If anyone is interested in the detailed symptoms:

  • Users sessions (terminal services/Citrix) would become completely unresponsive
  • The server would become unresponsive even at the console level
  • The server would respond to pings
  • Apparently anything in memory at the time of the freeze would continue to function -- as soon as you tried to access something else, the session would freeze
  • The only workaround when this occurred was to hard reboot the server

Wednesday, September 16, 2009

Users Unable to Change Expired Passwords on Windows Server 2008

In our environment, we have Citrix XenApp 5.0 publishing desktops from Windows Server 2008.  Our users connect to these published desktops via thin client or through the web interface.  We recently decided to put our password policy into effect, which included expiring user passwords once a month.

When the first user experienced the password expiration interface in Server 2008 after coming back to a locked workstation, they received the following message:
"The password for this account has expired. To change the password, click Cancel, click Switch User, and then log on."

However, there was no cancel button to click on, and no apparent way for them to either change their password or log off and log on again to do so.  The only way we could get around this was for them to call the help desk, we'd manually reset their passwords in Active Directory and then they could log in again using that new password.  An unacceptable solution in my opinion :)

So, I started to do some digging and found the following Microsoft KB article:
http://support.microsoft.com/kb/958900
which has an associated hotfix, that we applied and users were able to happily go on changing their passwords when they expired.

But then, we noticed something else.  Users that had two monitors set up at their station were experiencing an interesting symptom now: When the Server 2008 login screen came up, the dialog was now centered in between the two monitors (instead of only being in the primary), and it only showed the left half of the dialog in the primary monitor.  The secondary monitor was just completely black.

Oddly enough, the solution was to upgrade to Server 2008 SP2.  The service pack includes the previously mentioned hotfix, but for some reason did not have the same affect on dual monitors that the hotfix alone had.

I spent several hours scouring the web for a solution and didn't find anything -- so hopefully this will help you!

Tuesday, June 9, 2009

Getting around the Windows Rearm Limit with Sysprep and Altiris

We are currently in the process of deploying 9 IBM Blade servers as a Citrix XenApp farm for our employees. After evaluating the options for maintaining the servers, and their images, we settled on using Altiris. The past several weeks has been consumed with coming up with a "Golden" image that we can use across all 9 servers so that each user's experience will be consistent and predictable (well, as much as possible anyway). Coming up with this "Golden" image required going through a few iterations of a Server 2008 build, installing applications, customizing options and updates, etc. We finally came to the point yesterday when we were ready to make one last change and take a final image -- and this is when I ran into a problem. For the life of me, I could not get Altiris to take the image properly from the "Golden" server.

For the record, we've never used Altiris before, so for the most part we kept most of the default settings: we chose a path to save the image to, we chose to sysprep (using the default answer file) the server, and then take the image. I was finally able to narrow down the problem to sysprep not running correctly. So, at that point, I went on to the server to try and manually run sysprep and got a fatal error! (A full description of the problem can be found in this MS knowledgebase article).

Basically, it boils down to these facts: When Altiris syspreps a server it generalizes it (as it should since this strips out all of the uniqueness of the server, so it can be applied to other servers), resetting the licensing information (or rearming it), and whatever else it does to prepare the image. Now, this is all well and good except for the fact that Microsoft limits the number of rearms to 3 for any given Vista/Server2008 image. So, not really being exposed to this world before, I burned up these 3 rearms very quickly :)

At that point I scoured the internet for workarounds for this problem, since I had a golden image, but could not sysprep it. I tried the answer file solution proposed in the knowledgebase article above, but could not get it to work for whatever reason. Finally after much searching I came across this article, which describes how to get around this limitation.

So, to solve this problem (if you've read the entire post until this point, well done -- but if you just skipped down here to the solution, I don't blame you), I just went into the registry on the "Golden" server and set the following key to a value of "1":
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurentVersion\SL\SkipRearm (For Windows 7: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SoftwareProtectionPlatform\SkipRearm, thanks Mike!)
Without a restart, I was able to run the Altiris imaging job again successfully. It cost me a day of work, so I hope someone finds this helpful. If you have any questions, feel free to leave a comment below.

Note: I also noticed that I had to do this registry change EVERY time before taking an image. The image does not retain this value, it gets reset after doing the sysprep.

Tuesday, November 11, 2008

Attack of the Thin Clients!

So, for my latest project at work, I'm working on transitioning our company to Server Based Computing and thin clients.  There are many pieces to this puzzle, especially considering the fact that the company is not yet even on a domain.  I'm in the process of evaluating several pieces of software (Ericom's WebConnect, Provision Network's Virtual Access Suite and of course the almighty Citrix's XenApp) and several pieces of hardware (Wyse and HP thin clients).  Not to mention the whole Windows domain infrastructure that will also need to be in place :)

Anyway, I thought it may be a good idea to keep track of my findings -- and see if anyone out there might have any advice or suggestions for our journey ahead... as I'm sure there are plenty of people out there who have already done, or are in the process of doing the same thing.

We've decided to build all of this on top of Windows Server 2008, so I have already set up a test Active Directory domain, and Terminal Services on separate servers.  I was able to install WebConnect as well as XenApp on the Terminal Services box, and have been able to give both a little bit of a test run.  WebConnect was very easy to set up and get up and running since it is fairly simple.  And while that is a strength, it also limits the possibilities of what you can do with it.  Then, on the complete opposite end of the spectrum you have XenApp, which has so many options and possible customizations that it took a day with a Citrix employee to configure.... and that's just XenApp.  There are apparently quite a few different modules that can be used in conjunction with XenApp to enhance the functionality and feature set even more.

We've also purchased a Wyse Thin Client, which is running Wyse's Thin OS on it.  It's been configured to boot, get info for an FTP server from DHCP and pull all of the settings for connecting to Citrix, etc from that FTP server.  So, at this point, we can literally take the thin client with all its factory default settings, turn it on, and within 15 seconds be looking at a published desktop.  How crazy is that?

Now, we're waiting for the HP thin client to come in so that we can compare and contrast :)

Again, any input, suggestions, questions or advice are welcome!