-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
Setting up a NetScaler cluster
-
Adding a node to the cluster
-
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Adding a node to the cluster
You can seamlessly scale the size of a cluster to include a maximum of 32 nodes. When a NetScaler appliance is added to the cluster, the configurations from that appliance are cleared (by internally running the clear ns config -extended command). The SNIP addresses, MTU settings of the backplane interface, and all VLAN configurations (except the default VLAN and NSVLAN) are also cleared from the appliance.
The cluster configurations are then synchronized on this node. There can be an intermittent drop in traffic while the synchronization is in progress.
Important:
Before you add a NetScaler appliance to a cluster:
- To join a node to the cluster, the
nsrootaccount password of the configuration coordinator (CCO) node is required.- If the
nsrootaccount password of the joining node differs from thensrootaccount password of the CCO node, the CCO node’snsrootaccount password is applied to the joining node after a successful join and reboot.- Set up the backplane interface for the node. Check preceding topic.
- Check if the licenses that are available on the appliance match that are available on the configuration coordinator. The appliance is added only if the licenses match.
- If you want the NSVLAN on the cluster, make sure that the NSVLAN is created on the appliance before it is added to the cluster and that the NSVLAN is same on all L2 cluster nodes.
- Citrix® recommends that you add the node as a passive node. Then, after joining the node to the cluster, complete the node specific configuration from the cluster IP address. Run the force cluster sync command if the cluster has only spotted IP addresses. And which has L3 VLAN binding, or has static routes.
- When an appliance with a preconfigured link aggregate (LA) channel is added to a cluster, the LA channel continues to exist in the cluster environment. The LA channel is renamed from LA/x to nodeId/LA/x, where LA/x is the LA channel identifier.
To add a node to the cluster by using the CLI
Note:
When you add a node to a cluster setup, make sure that the default static route configured in the node is present in the cluster coordinator node (CCO). If the node has a static route not present in the CCO, the command fails with the following error.
Node cannot join cluster as static default gateway route is not present in CCO
- Log on to the cluster IP address, at the command prompt, do the following:
- Add the appliance (for example, 10.102.29.70) to the cluster.
Note:
For an L3 cluster:
- The node group parameter must be set to a node group that has nodes of the same network.
- If this node belongs to the same network as the first node that was added, then configure the node group that was used for that node.
- If this node belongs to a different network, then create a node group and bind this node to the node group.
- The backplane parameter is mandatory for nodes that are associated with a node group that has more than one node, so that the nodes within the network can communicate with each other.
add cluster node <nodeId> <IPAddress> -state <state> -backplane <interface_name> -nodegroup <name> Example: add cluster node 1 10.102.29.70 -state PASSIVE -backplane 1/1/1 <!--NeedCopy-->- Save the configuration.
save ns config <!--NeedCopy--> -
Log on to the newly added node (for example, 10.102.29.70) and join the node to the cluster.
Use the
nsrootaccount password for the configuration coordinator (CCO) as the password in the following command:join cluster -clip <ip_addr> -password <password> Example: join cluster -clip 10.102.29.61 -password nsroot <!--NeedCopy--> -
Configure the following commands on the CLIP.
-
Bind VLAN to an interface
bind vlan <id> -ifnum <interface_name> <!--NeedCopy-->Example:
bind vlan 1 -ifnum 2/1/2 <!--NeedCopy--> -
Add spotted IP address to the newly added node
add ns ip <IpAddress> <netmask> -ownerNode <positive_interger> <!--NeedCopy-->Example:
add ns ip 97.131.0.3 255.0.0.0 -ownerNode 2 <!--NeedCopy--> -
Verify VLAN on NSIP
show vlan <id> <!--NeedCopy-->Example:
show vlan 1 <!--NeedCopy-->
-
-
Perform the following configurations:
- If the node is added to a cluster that has only spotted IPs, the configurations are synchronized before the spotted IP addresses are assigned to that node. In such cases, L3 VLAN bindings can be lost. To avoid this loss, either add a striped IP or add the L3 VLAN bindings.
- Define the required spotted configurations.
- Set the MTU for the backplane interface.
-
Save the configuration.
save ns config <!--NeedCopy--> -
Warm reboot the appliance.
reboot -warm <!--NeedCopy--> -
After the node is UP and sync is successful, change RPC credentials for the node from the cluster IP address. For more information about changing an RPC node password, see Change an RPC node password.
set rpcNode <node-NSIP> -password <passwd> Example: set rpcNode 192.0.2.4 -password mypassword <!--NeedCopy--> -
Set the cluster node to Active.
set cluster node <nodeID> -state active. Example: set cluster node 1 -state active <!--NeedCopy-->
To add a node to the cluster by using the GUI
- Log on to the cluster IP address.
- Navigate to System > Cluster > Nodes.
- In the details pane, click Add to add the new node (for example, 10.102.29.70).
- In the Create Cluster Node dialog box, we recommend to configure the new node in a PASSIVE state. For a description of a parameter, hover the mouse cursor over the corresponding text box.
- Click Create. When prompted to perform a warm reboot, click Yes.
-
After the node is UP and sync is successful:
-
Change RPC credentials for the node from the cluster IP address. For more information about changing an RPC node password, see Change an RPC node password.
-
Ensure that you configure the necessary spotted configuration on the cluster nodes. For more information on the list of spotted configuration, see List of spotted configuration and Supportability matrix for NetScaler cluster.
-
Go to Configuration > System > Cluster and click Force cluster sync to avoid any configuration inconsistencies.
-
-
Navigate to System > Cluster > Nodes > Edit.
- Modify the State to ACTIVE and confirm.
To join a previously added node to the cluster by using the GUI
If you have used the CLI to add a node to the cluster, but have not joined the node to the cluster, you can use the following procedure.
Note
When a node joins the cluster, it takes over its share of traffic from the cluster and hence an existing connection can get terminated.
-
Log on to the node that you want to join to the cluster (for example, 10.102.29.70).
-
Navigate to System > Cluster.
-
In the details pane, under Get Started, click the Join Cluster link.
-
In the Join to existing cluster dialog box, set the cluster IP address and the
nsrootpassword of the configuration coordinator. For a description of a parameter, hover the mouse cursor over the corresponding text box. -
Click OK.
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.