<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UAG breaks after a few days. They break 100% of the time. in Horizon Desktops and Apps</title>
    <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2893955#M96317</link>
    <description>&lt;P&gt;This issue is 4 years old, the UAG has changed a bit and you may not see this. If you have UAG stability issues you should open an SR&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 19:22:17 GMT</pubDate>
    <dc:creator>sjesse</dc:creator>
    <dc:date>2022-02-16T19:22:17Z</dc:date>
    <item>
      <title>UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486894#M77784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a new implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I currently have 2 UAG's deployed. Version 3.1 and 3.2 currently deployed to Production&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are behind a NetScaler load balancer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So after a few days the UAG's stop accepting connections on 443. &lt;STRONG&gt;I have to reboot these every night or the problem happens 100% of the time. At the moment I'm keeping 1 disabled on standby in case the other breaks during the workday. When these break, port 4172 remains open so any existing connections remain. It's only new connection attempts that fail.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an open case with VMWare but they've turned us over to Citrix support.&lt;STRONG&gt; &lt;/STRONG&gt;I wish they would actually want to know what is causing this, since obviously something is breaking their UAG. This is a passive aggressive remark in case your reading VMWare.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have&lt;STRONG&gt; 50&lt;/STRONG&gt; users. Yet see hundreds of stale connections on the UAG. We are not being DOS'ed as confirmed by our network team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Citrix NetScaler Load Balancer: 192.24.16.172&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;UAG: 192.24.17.184&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Citrix NetScaler Load Balancer is configured to perform a healthcheck per the recommended method via VMWare. Using GET /favicon.ico.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the UAG:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;netstat&lt;/STRONG&gt; shows hundreds of these close_wait connections:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:46864&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:29408&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:65027&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:16839&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:45761&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:44743&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 192.24.17.184:6443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.24.16.172:9926&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLOSE_WAIT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the UAG:&lt;/P&gt;&lt;P&gt;Hundreds of these in &lt;STRONG&gt;/opt/vmware/gateway/logs/SecurityGateway_blah_blah_&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:45.017+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:58952] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:47.187+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:24632] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:50.017+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:39938] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:52.187+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:3371] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:55.017+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:42301] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:42:57.188+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:47881] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;P&gt;2018-01-14T04:43:00.017+00:00&amp;gt; LVL:error&amp;nbsp;&amp;nbsp; : [C: 192.24.16.172:28791] *** SSIGServer::SSL handshake failure: End of file (2) error:00000002:lib(0):func(0):system lib&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2018 20:52:32 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486894#M77784</guid>
      <dc:creator>jrodsguitar</dc:creator>
      <dc:date>2018-01-15T20:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486895#M77785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I greatly dislike when I find a forum post with no answer so I will answer what the final solution to this was.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had done some digging into the UAG console and noticed the below messages. From what I had gathered the UAG has a built in mechanism that protects itself from DDOS type attacks. Our Citrix Netscaler Load Balancer health check was triggering this mechanism. So essentially the UAG thought the Load Balancer was attacking it so it shut itself down. The DosPreventionHandler kicked in. Port 4172 (PCOIP) remained open, existing users remained connected, but port 443 stopped accepting new connection. When I spoke to VMWare support they confirmed my suspicion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_1.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/78824i656410198AE17A7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_1.png" alt="pastedImage_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The workaround is to set the below settings to 0 in the UAG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_0.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/78823iC9F6237E6E4928FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_0.png" alt="pastedImage_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 23:43:59 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486895#M77785</guid>
      <dc:creator>jrodsguitar</dc:creator>
      <dc:date>2018-01-23T23:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486896#M77786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jrod,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was running into the exact same issue (3 UAGs in prod behind NetScaler ADC). Glad I found your post - good investigations on your end. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 20:57:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/486896#M77786</guid>
      <dc:creator>nburton935</dc:creator>
      <dc:date>2018-03-05T20:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2824421#M92899</link>
      <description>&lt;P&gt;Can confirm that you still have to do this in UAG 2009.&amp;nbsp; We had been doing it on our other UAG 3.9 appliances, but missed the setting in our initial deployment of 2009, and totally ran into this.&amp;nbsp; Annoying little thing to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 04:50:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2824421#M92899</guid>
      <dc:creator>chriskoch99</dc:creator>
      <dc:date>2021-01-21T04:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2893952#M96316</link>
      <description>&lt;P&gt;Do you happen to have the instructions used on the UAG to get to the screenshot below showing the DoSPreventionHandler was running?&amp;nbsp; I'm trying to prove out if we are having the same issue but VMware support doesn't currently know how to check what you showed below.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 19:18:14 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2893952#M96316</guid>
      <dc:creator>nixnac</dc:creator>
      <dc:date>2022-02-16T19:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2893955#M96317</link>
      <description>&lt;P&gt;This issue is 4 years old, the UAG has changed a bit and you may not see this. If you have UAG stability issues you should open an SR&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 19:22:17 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2893955#M96317</guid>
      <dc:creator>sjesse</dc:creator>
      <dc:date>2022-02-16T19:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2936800#M98071</link>
      <description>&lt;P&gt;-Log into the UAG Admin webui.&amp;nbsp; Click the Select button for configure manually.&amp;nbsp; Scroll down to the bottom and click the download button next to the option labeled Log Archive.&amp;nbsp; After a brief delay, the log bundle will be downloaded to the browser's default download location.&amp;nbsp; After extracting the .zip archive, the esmanager logs will be listed in the first folder.&amp;nbsp; The current log file will be named esmanager.log.&amp;nbsp; Older files which have been rotated out will be named esmanager.log.1, .2, .3, etc.&amp;nbsp; You can view these files with any text editor, such as Notepad++.&lt;BR /&gt;-Alternatively, you can log into the command line shell of the UAG appliance directly.&amp;nbsp; You can then view the log file by executing: more /opt/vmware/gateway/logs/esmanager.log.&amp;nbsp; If you want to try to grep for the relevant entries directly, you can execute cat /opt/vmware/gateway/logs/esmanager.log |grep -i&amp;nbsp;DoSPreventionHandler |less.&amp;nbsp; This will display the output one page at a time, where you can press the spacebar to move forward page-by-page.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 11:33:24 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2936800#M98071</guid>
      <dc:creator>alexanderdb</dc:creator>
      <dc:date>2022-11-04T11:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: UAG breaks after a few days. They break 100% of the time.</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2936801#M98072</link>
      <description>&lt;P&gt;nixnac-Log into the UAG Admin webui.&amp;nbsp; Click the Select button for configure manually.&amp;nbsp; Scroll down to the bottom and click the download button next to the option labeled Log Archive.&amp;nbsp; After a brief delay, the log bundle will be downloaded to the browser's default download location.&amp;nbsp; After extracting the .zip archive, the esmanager logs will be listed in the first folder.&amp;nbsp; The current log file will be named esmanager.log.&amp;nbsp; Older files which have been rotated out will be named esmanager.log.1, .2, .3, etc.&amp;nbsp; You can view these files with any text editor, such as Notepad++.&lt;BR /&gt;-Alternatively, you can log into the command line shell of the UAG appliance directly.&amp;nbsp; You can then view the log file by executing: more /opt/vmware/gateway/logs/esmanager.log.&amp;nbsp; If you want to try to grep for the relevant entries directly, you can execute cat /opt/vmware/gateway/logs/esmanager.log |grep -i&amp;nbsp;DoSPreventionHandler |less.&amp;nbsp; This will display the output one page at a time, where you can press the spacebar to move forward page-by-page.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 11:34:31 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-breaks-after-a-few-days-They-break-100-of-the-time/m-p/2936801#M98072</guid>
      <dc:creator>alexanderdb</dc:creator>
      <dc:date>2022-11-04T11:34:31Z</dc:date>
    </item>
  </channel>
</rss>

