Smart Firewall blocking Thinlinc/Citrix Gateway - how do I find out which rule is blocking traffic

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract:Smart Firewall is blocking application traffic on Thinlinc/Citrix Gateway

Detailed description:

I’m using Citrix Gateway then Thinlinc to connect to a Linux server. If I turn of smart firewall it works fine. If I turn it on, then Citrix appears to work, Thinlinc starts, but at the point it tries to connect it can’t get through to the server. I’ve gone into the settings Security>Advanced>Smart Firewall Program Control Tab and set Citrix and Thinlinc to Allow but it still doesnt work. Securiy History doesn’t show anything, so how can I find what’s blocking traffic?

Product & version number:Norton 360 Premium

OS details:Windows 11 Home

What is the error message you are seeing?

If you have any supporting screenshots, please add them:

You ask an excellent question, and have looked for clues where I would. norton is not good with the user viewing details it seems. I hope you get answers to how to find what’s blocking traffic, because I need to know how as well. We are going through similar issues.

For me screen cast used to work, but some recent norton update has broken that W11 function. I have a Case # with norton, detailed the problem, uploaded a debug file, but so far no solution or even feedback is forthcoming. I will try to post a link to my thread in case any of my actions give you inspiration in your own efforts:

Well it looks like the link is to the latest post, but at least it is in the correct thread. Best of luck with a resolution!

P

@Stephen_Mills View the screenshot below, then open your Norton UI to Security>Advanced>Smart Firewall>Program Control tab. Locate the entries there for Citrix and Thinlinc. Move your mouse slowly to the right past network access radio button until an V appears. Click it, find the “default rule” for each client separately and change / edit them to “allow”. Save and close the Norton UI, reboot and recheck.

IMA that as @paul_murphy2 posted not a lot is changeable with the Firewall in the new versions. FWIW. Thinlinc requires port 22 server side, if I am not mistaken. Or, are you HTML5 and using port 300? Try creating a “new rule” similar to the one shown below. Add the address and local port. Reboot, retest.

SA

SA, saw your great new rule suggestion here on the citrix thread, thought I would try that over in my circus. Unfortunately norton is blocking this as well. As soon as I hit Save the ports disappear, and then the Access button rolls to custom, and when Allow is selected the new rule has entirely disappeared. norton is not allowing me any changes.

@Stephen_Mills, I’m interested to know if you are able to have this new rule accepted in your case? I hope it works for you.

P

Thanks for the post back Paul.

Edited: Leave the address field blank Paul, I did so and the rule stays.

SA

Paul/SA thanks for the advice. I’ve managed to solve my problem in a slightly different manner.

To answer your questions, Yes I was able to change the rule, I’ve already had it set up to allow all traffic, and had set reporting to reporting to notification, I assume that means it would pop something up if it was that rule that was blocking it.

However that led me to looking at all the Traffic rules, and I noticed that lots of things were blocked on Public networks. Looking back at the network tab, I had two networks, my Local home network which was down as Private, and the network across the Citrix Virtual Adapter which was down as Public. As soon as I switched that network to Private everything started working. Slightly less secure than I’d want, but a compromise that I’m happy to make.

Interesting!! I had thought about that earlier but opted to go another avenue with things. I’m seriously glad your issues are resolved. Maybe @paul_murphy2 can give your solution a go and report his results as well.

SA