-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Graceful shutdown of nodes
In a cluster setup, some of the existing connections (1/Nth connections, where N is the cluster size) at the cluster level or specific virtual server level are lost. This behavior is observed if a node leaves or joins the system. To address the loss, you must gracefully handle the existing connections. Graceful handling is done by configuring the retain connections on cluster option in the CLIP address and specifying a timeout interval in the node’s NSIP.
Graceful handling of connections is applicable in two scenarios:
-
Cluster upgrade
-
New node addition
Graceful handling of Nodes in cluster upgrade
To upgrade a cluster, you must upgrade one node at a time. Before upgrading a node, you must set it to passive state and then set it to active state after the upgrade. To avoid terminating existing connections when upgrading the node, shut it down gracefully with a configured timeout interval. Otherwise, 1/Nth (where N is the cluster size) of the cluster’s connections are terminated.
Note:
- If existing sessions are not completed within the configured timeout interval, they get terminated after the grace time.
- To check the timeout interval, you must use the CLIP or NSIP address of the node, which is set to passive.
Following are the steps to gracefully handle nodes in a cluster upgrade scenario:
-
Consider a cluster setup of five nodes (n0, n1, n2, n3, n4).
-
Before you shut down a node, you must configure the
retainConnectionsOnClusteroption. It helps to retain all existing connections of this node at the cluster level or virtual server level for a specific time interval.Example
On CLIP
```set cluster instance
–retainConnectionsOnCluster YES OR ```set lb vserver <vserver name> –retainConnectionsOnCluster Yes<!--NeedCopy--> -
Log on to the NSIP address of node n3 and set the node n3 to PASSIVE with a timeout internal.
Example
set cluster node n3 –state PASSIVE –delay 60 saveconfig <!--NeedCopy--> -
After the grace period expires, close all connections, shut down n3 and reboot the NetScaler appliance.
-
Upgrade the appliance. Then, with the CLI connected to the appliance’s NSIP address, set the node to ACTIVE.
Example
set cluster node n3 –state ACTIVE saveconfig <!--NeedCopy--> -
Repeat steps 3–6 for all nodes in the cluster.
-
After all nodes are upgraded and set to ACTIVE, reset the
retainConnectionsOnClusteroption from the CLIP address.Example
```set cluster instance
-retainConnectionsOnCluster NO ORset lb vserver
–retainConnectionsOnCluster NO saveconfig ```
Note:
If there is a version mismatch when upgrading a cluster, cluster propagation is automatically disabled and no commands are allowed on the CLIP.
Graceful handling of nodes during a new node addition
The graceful handling of nodes describes how a new node can be added to the existing NetScaler cluster. Consider you have a NetScaler cluster that is already serving traffic. And you want to add an extra appliance as a node to the cluster without terminating its existing connections. To accomplish the preceding scenario, set the option to retain existing connections either at a Global level or at a specific virtual server level. Once done, save the configuration. Now set the option to retain connections to NO, to allow existing connections from other nodes to be reassigned to the new node.
Following are the steps to gracefully handle nodes if a node newly added:
-
Save the existing configuration that has the
retainConnectionsOnClusteroption enabled. By doing so, you can retain all existing connections of this node at the cluster level or virtual server level for a specific time interval.On CLIP
set cluster instance x – retainConnectionsOnCluster YESOR
set lb vserver xxxx –retainConnectionsOnCluster Yes -
Add a node n5 to the cluster setup.
-
Disable the
retainConnectionOnClusteroption toNOfor distributing existing connections from other nodes to the newly added node n5.On CLIP
set cluster instance x – retainConnectionsOnCluster NOOR
set lb vserver xxxx –retainConnectionsOnCluster NO
Note:
The backplane steering depends on the type of traffic distribution mechanism (ECMP, CLAG, and USIP) on a cluster setup. The increase in backplane steering is based on the traffic type.
Configuring graceful shutdown of nodes in a cluster
To configure graceful shutdown of nodes in a cluster, do the following:
- Configure the
retainConnectionsonClusteroption at Global (cluster) level. - Configure the
retainConnectionsonClusteroption at the virtual server level. - Set the node (leaving the system) to the passive state with a graceful timeout interval specified in the node’s NSIP address.
- Monitor the existing connections to make sure all transactions are completed within the grace period.
To retain existing connections at the global (cluster) level by using the CLI
You can retain existing connections either at a global level or at a specific virtual server level. This option is configured to retain all existing connections at the global level. By default, this option is disabled.
At the command prompt type:
- set cluster instance <clusterID> –retainConnectionsOnCluster YES
- set cluster instance 60 – retainConnectionsOnCluster YES
To retain existing connections of a specific virtual server in the cluster by using the CLI
This option is configured to retain existing connections specific to a load balancing virtual server. To retain those connections, we enable this option at the virtual server level. By default, this option is disabled.
At the command prompt, type:
- set lb vserver <clusterID> –retainConnectionsOnCluster Yes
- set lb vserver v1 –retainConnectionsOnCluster Yes
To set a cluster node to passive state by using the CLI
To set a cluster node to passive state with a graceful timeout interval. This setting is performed in the node’s NSIP as propagation is disabled during cluster upgrade.
At the command prompt, type:
- set cluster node <clusterID> -state passive
-backplane <interface_name>@
-priority <positive_integer>
-delay <mins>
- set cluster node 4 –state PASSIVE -delay 60
- set cluster instance 60 – retainConnectionsOnCluster YES
- set lb vserver v1 –retainConnectionsOnCluster Yes
- set cluster node 4 –state PASSIVE -delay 60
Note:
You might observe the following behavior on a cluster node when it is set to passive with a delay option configured from a CLIP:
- After the timeout, the node shows as passive from the NSIP of the node.
- The show cluster instance command on CLIP displays the node as active from the CLIP. Whereas the show cluster node command on the CLIP displays the node as passive.
To configure graceful shutdown of nodes by using the GUI
- Navigate to Configuration > System > Cluster and click Manage Cluster.
- On the Manage Cluster page, select Retain Connections on Cluster option.
- Click OK, and then click Done.
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.