Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Attiq786
Participant

R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix VPN users

Hi All,

I Updated 5800 Gateway to R80.40. VPN Clients could VPN in and authenticate via AD and OTP through Citrix portal but after sometime, everyone on Citrix will be kicked out and if they login again, all of them will get the same error "Invalid username and password"

Now if you reboot the gateway, then they can authenticate fine but only for a while, may be 15 minutes and then the same error appears if they try to login.

Disabling SecureXL resolved the issue.

Template creation stops at the exact rule which is responsible for client authentication to AD.

It almost seems like the previous Kerberos Ticket is carried forward by SecureXL and authentication fails.

I want to understand if Templates are disabled at that same rule, what else SecureXL is doing that users are getting invalid username or password error when SecureXL is enabled. Something different in R80.40 may be?

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

If disabling SecureXL "solves" any issue, the TAC should be involved.
Meanwhile, what is the precise rule you’re referring to?

0 Kudos
Attiq786
Participant

Hi

Thanks for your reply. TAC case is raised already. I was thinking may be someone else might have the same issue with R80.40.

The rule allows remote client addresses to contact AD. services include Kerberos as well in that rule.

0 Kudos
PhoneBoy
Admin
Admin

A screenshot would be helpful 

0 Kudos
Attiq786
Participant

Here is the screenshot please.

0 Kudos
PhoneBoy
Admin
Admin

Nothing in that rule should disable SecureXL that I’m aware of, but could be wrong.
The TAC SR in PM may be helpful. 

0 Kudos
Attiq786
Participant

Hi All,

the issue was resolved after installing HFA take 89 - something in base R80.40 image that would prevent SecureXL working as it should.

0 Kudos