[THIN] Re: ICA Keep Alive and Cisco routers...

  • From: "Dennis van Turnhout" <turnhout@xxxxxxxxxx>
  • To: <thin@xxxxxxxxxxxxx>
  • Date: Tue, 24 Feb 2004 12:44:18 +0100

This is what a cisco employee mailed me:

# On the Interface BRI0 there will be at least 2 commands for on-demand
dialling/routing

dialer load-threshold xx outbound (xx depends on your configuraton)
dialer-group 1=20
=20
# Dialer-group 1 points to the 'dialer-list' command which points to the
access-list command that blocks or accepts certain traffic

Other config:
access-list 101 deny tcp any any eq 123
access-list 101 deny udp any any eq ntp
access-list 101 deny udp any any eq 20
access-list 101 deny igmp any any
access-list 101 permit ip any any
dialer-list 1 protocol ip list 101

# I think this is the way that the router decides what to route or what
to block and therefore connecting the ISDN line to the central dial-in
routers. Now you need to know what the portnumbers for Citrix traffic or
ICA keepalives. I'm pretty sure they use different ports.

---

Which leads to the next question, what port does ICA Keepalive use?


-----Original Message-----
From: Eric Pylko [mailto:eric@xxxxxxxxxxxxxxxxxxx]=20
Sent: dinsdag 24 februari 2004 12:19
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: ICA Keep Alive and Cisco routers...


The idea with Cisco routers doing dial-up is that you create an =3D
access-list (a list of patterns that matches specific traffic) to define
your "interesting" traffic.  When there is a match, your idle-time is
reset =3D to 0.

If the ICA keepalives are keeping your ISDN line up, the access-list =3D
needs to have a deny statement for ICA Keepalives.  If you know what =3D
protocol/port (e.g.  UDP port 38291) then creating the access-list is
easy.  There =3D must already be one on the router if it is doing =
dial-on
demand, so just a =3D small tweak should be needed.

-Eric

--
Eric Pylko                            eric@xxxxxxxxxxxxxxxxxxx
CCIE #5827                                      (585) 747-2446

-----Original Message-----
From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On =
=3D
Behalf Of Dennis van Turnhout
Sent: Tuesday, February 24, 2004 5:37 AM
To: thin@xxxxxxxxxxxxx
Cc: duittenb@xxxxxxxxx
Subject: [THIN] ICA Keep Alive and Cisco routers...


I've got the following problem at a customer of ours.
A while back the router disconnected the line when there was no data for
=3D 10 minutes. Due to unknown reasons reconnection to a disconnected
server stopped to work. This happend in a period wherin we did no
maintenance =3D to the server, the IT department at the customer says it
didn't change a =3D thing.

No problem ICA keepalive can't fix so we enabled this function. Problem
solved, sort of... When you manualy shut down the router, Citrix detects
this after a while and sets the user session from Active/Idle to
Disconnected. Switch on the router and the WBT resumes the connection.

Yesterday I noticed that every 15 to 20 seconds the router recieves and
sends data across the ISDN line. The router detects this as "trafic" and
keeps the line up?

Cisco says the router should be able to spot the difference between =3D
ordinary citrix trafic and ICA Keepalive. I'm that not sure that ICA
Keepalive is =3D the source of our problems though.

I've been reading Cisco manuals for the 801 and 3620 but found myself
reading way to much=3D20 stuff I know to little about.

Could use some help at this moment...

Bye,

Dennis

********************************************************
This weeks sponsor triCerat Inc.
triCerat makes your job easier by offering essential applications to
eliminate your printing, policy and profile, and your application =3D
management problems. http://www.triCerat.com=3D20
**********************************************************
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
***********************************************************
For Archives, to Unsubscribe, Subscribe or=3D20
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm

********************************************************
This weeks sponsor triCerat Inc.
triCerat makes your job easier by offering essential applications to
eliminate your printing, policy and profile, and your application
management problems. http://www.triCerat.com=20
**********************************************************
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
***********************************************************
For Archives, to Unsubscribe, Subscribe or=20
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm
********************************************************
This weeks sponsor triCerat Inc.
triCerat makes your job easier by offering essential
applications to eliminate your printing, policy and profile,
and your application management problems.
http://www.triCerat.com 
**********************************************************
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
***********************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm

Other related posts: