Hi All,
I Updated 5800 Gateway to R80.40. VPN Clients could VPN in and authenticate via AD and OTP through Citrix portal but after sometime, everyone on Citrix will be kicked out and if they login again, all of them will get the same error "Invalid username and password"
Now if you reboot the gateway, then they can authenticate fine but only for a while, may be 15 minutes and then the same error appears if they try to login.
Disabling SecureXL resolved the issue.
Template creation stops at the exact rule which is responsible for client authentication to AD.
It almost seems like the previous Kerberos Ticket is carried forward by SecureXL and authentication fails.
I want to understand if Templates are disabled at that same rule, what else SecureXL is doing that users are getting invalid username or password error when SecureXL is enabled. Something different in R80.40 may be?