Hi,
I did some additional debugging to get more error details before opening a TAC case, and found that just one user causes this error, but this user has no log entry in SmartConsole (a ghost it's rather hard to find). The login/logout timestamps and hostname of the TS from Citrix match the begin and end of the error logs on Check Point side at several days.
I checked the ia_client.log on the TS and there is a eye-cathing difference to the other users: the problematic users seems to have 140 group SIDs, all other users have significantly less group SIDs.The logs for this users ends up with
[ 3548 5552]@hostname[24 Jul 14:35:28] [PDP Connection Manager (TD::Events)] NAC::CLIENT::PDPCOMM::PDPConnectionManager::sendRequest: callerHandleFailure 0 from type SubSession
[ 3548 5552]@hostname[24 Jul 14:35:28] [PDP Connection Manager (TD::Events)] NAC::CLIENT::PDPCOMM::PDPConnectionManager::sendRequest: not sending request since there is a queue. waiting for previous calls to wait
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::User::addWindowsSessionID: Adding windows session 4 for user: xyz\xyz
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: session id: 0, username: , logon domain: (connect state: 6)
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: Failed to obtain session's handle
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: session id: 0, username: , logon domain: (connect state: 6)
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: Failed to obtain session's handle
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: session id: 0, username: , logon domain: (connect state: 6)
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::addCurrentlyLoggedInUsers: Failed to obtain session's handle
[ 3548 5552]@hostname[24 Jul 14:35:28] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::MUH2UserManager: Succeeded loading MUH driver service library
[ 3548 5552]@hostname[24 Jul 14:35:28] [AuthenticationManager (NAC::IS::TD::Events)] NAC::CLIENT::AUTH::AuthenticationManager::finishedLastAuthentication: scheduling re-authentication in 180000 ms for group MachineAuthMethods
[ 3548 5552]@hostname[24 Jul 14:35:28] [PDP Connection Manager (TD::Events)] NAC::CLIENT::PDPCOMM::PDPConnectionManager::Notify: firing connection notifiction trigger finished
[ 3548 5552]@hostname[24 Jul 14:35:28] [PDP Connection Manager (TD::Events)] NAC::CLIENT::PDPCOMM::PDPConnectionManager::eraseFromRequestNotificationMap: deleting request 2 connection notification
I cannot find a documented limit for the Terminal Server Identity Agent for group memberships. Are 140 groups really too many?
Best regards
Claudia