Users successfully accessing internet sites via Cloud SWG using proxy forwarding access method.
A subset of users need to connect to 3rd party applications using Citrix.
After logging into Citrix Portal and selecting the applications, a Web based RDP client initialises but fails to connect.
Access logs would indicate authentication (401) and connectivity (503) errors as shown below:
Cloud SWG.
Proxy Forwarding access method.
Web based RDP Client.
Citrix.
3rd party issues going through a proxy server.
Although the Proxy could intercept and detect the HTTP methods, endpoints and user-agents, the connection never succeeded.
PCAPs confirmed that the connection to the endpoint would succeed but application level handshake must have failed resulting in a generic connectivity error being reported.
Disabled SSL interception to see if this would work, but this did not help.