Citrix XML Service DNS Address Resolution & Access Gateway Enterprise SSL error 38
Posted on April 9th, 2010
I recently set up a Citrix Access Gateway Enterprise solution on a pair of netscaler 7000 devices running v9.1 build 101.5.
It was set up in traditional ‘smart access’ configuration and the Web Interface site was configured for 3 seperate farms – XenApp4.5, XenDesktop 4 & Presentation Server 4.0.
Launching sessions through the CAG for the XenApp farm was fine, but I was getting an SSL error 38 – The proxy denied access to message for the other two farms.
In checking the settings I noticed that the farms that produced the error had the ‘XML Service DNS address resolution’ option selected in the farm properties.
Unselecting this option enabled remote connections to work as normal, however this option was required and needed to be re-enabled.
It turns out that the firewall rules had not been set up properly from the DMZ to the DNS servers, so the Netscaler devices were unable to perform DNS lookups. As soon as the Firewall settings were resolved, the Netscalers could perform DNS lookups and resolved the problem.
Tags: CAG Enterprise, Citrix Netscaler, DNS, ssl error 38, the proxy denied access to, XML Service DNS Address resolution
Filed under Citrix Access Gateway, Citrix Netscaler | No Comments »
