> Source: [sk181810](https://support.checkpoint.com/results/sk/sk181810)

# sk181810 - Citrix traffic does not pass through Check Point Security Gateways

| Property | Value |
|----------|-------|
| Solution ID | sk181810 |
| Date Created | 2023-12-18 |
| Last Modified | 2023-12-19 |
| Technical Level | General |
| Products | Hardware |
| Versions | Not Version-Specific |
| OS | Gaia |

## Symptoms

- * Citrix resources and webpages do not work, even though the traffic is marked as Accepted.

* Customers cannot connect to Citrix internal resources. The pages show error messages such as "*Page not Found*."

* Most commonly found in VM appliances trying to connect to a Citrix Resource.

## Cause

The Security Policy explicitly or implicitly blocks a core Citrix Port as a Random High Port.

## Solution

These ports and services are required for base Citrix function and should have explicit Allowed rules in the Access Control Policy:

* TCP 2598

* TCP 2512

* TCP 2513

* TCP 1494

* TCP 443

* TCP 80

**Procedure:**

1. Search for the required ports in the drop logs.

2. If present, create explicit rules and objects to allow for a match.

3. Install Policy for the rules to take effect.

For more ports used in Citrix communications, refer to:

<https://docs.citrix.com/en-us/tech-zone/build/tech-papers/citrix-communication-ports.html>

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
