-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
Setting up a NetScaler cluster
-
Creating a NetScaler cluster
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Creating a NetScaler cluster
To create a cluster, start by taking one of the NetScaler appliances that you want to add to the cluster. On this node, you must create the cluster instance and define the cluster IP address. This node is the first cluster node and is called the cluster configuration coordinator (CCO). All configurations that are performed on the cluster IP address are stored on this node and then propagated to the other cluster nodes.
The responsibility of CCO in a cluster is not fixed to a specific node. It can change over time depending on the following factors:
-
The priority of the node. The node with the highest priority (lowest priority number) is made the CCO. Therefore, if a node with a priority number lower than the existing CCO is added, the new node takes over as the CCO.
-
If the current CCO goes down, the node with the next lowest priority number takes over as the CCO. If the priority is not set or if there are multiple nodes with the lowest priority number, the CCO is selected from one of the available nodes.
Notes:
The configurations of the appliance (including SNIP addresses and VLANs) are cleared by implicitly running the
clear ns config extendedcommand. However, the default VLAN and NSVLAN are not cleared from the appliance. Therefore, if you want the NSVLAN on the cluster, make sure it is created before the appliance is added to the cluster and that the NSVLAN is same on all L2 cluster nodes. For an L3 cluster (cluster nodes on different networks), networking configurations are not cleared from the appliance.When forming a cluster, avoid making any other configuration changes until the cluster formation is complete. This helps prevent conflicts and ensures a smooth cluster formation process.
HA Monitor (HAMON) on a cluster setup is used to monitor the health of an interface on each node. The HAMON parameter must be enabled on each node to monitor the state of the interface. If the operational state of the HAMON enabled interface goes down due to any reason, the respective cluster node is marked as unhealthy (NOT UP) and that node cannot serve traffic.
Create a cluster by using the command line interface
-
Log on to a NetScaler appliance (for example, appliance with NSIP address 10.102.29.60) that you want to add to the cluster.
-
Add a cluster instance.
add cluster instance <clId> -quorumType <NONE | MAJORITY> -inc <ENABLED | DISABLED> -backplanebasedview <ENABLED | DISABLED> <!--NeedCopy--> -
The
-dfdretainl2paramsoption enables you to add the extended L2 headers for the backplane traffic.At the command prompt, type:
add cluster instance 1 -dfdretainl2params <ENABLED|DISABLED>The following command displays the status of the
-dfdretainl2params:show cluster instance <clusterid>Use the following command to enable or disable the
-dfdretainl2params:set cluster instance 1 -dfdretainl2params <ENABLED|DISABLED> -
The
-proxyarpstatusoption enables or disables the proxy arp functionality for cluster.At the command prompt, type:
add cluster instance 1 -proxyarpstatus <ENABLED|DISABLED>The following command displays the status of the
proxyarpstatus:show cluster instance <clusterid>You can use the following command to enable or disable the
proxyarpstatus:set cluster instance 1 -proxyarpstatus <ENABLED|DISABLED>
Note:
- The cluster instance ID must be unique within a LAN.
- The
-quorumTypeparameter must be set to MAJORITY and not NONE in the following scenarios:
- Topologies that do not have redundant links between cluster nodes. These topologies might be prone to network partition due to a single point of failure.
- During any cluster operations such as node addition or removal.
- For an L3 cluster, make sure the
-incparameter is set to ENABLED. The-incparameter must be disabled for an L2 cluster.- When the
-backplanebasedviewparameter is enabled, the operational view (set of nodes that serve traffic) is decided based on heartbeats received only on the backplane interface. By default, this parameter is disabled. When this parameter is disabled, a node does not depend on the heartbeat reception only on the backplane.
-
[Only for an L3 cluster] Create a node group. In the next step, the newly added cluster node must be associated with this node group.
Note:
This node group includes all or a subset of the NetScaler appliances that belong to the same network.
add cluster nodegroup <name> <!--NeedCopy--> -
Add the NetScaler appliance to the cluster.
add cluster node <nodeId> <IPAddress> -state <state> -backplane <interface_name> -nodegroup <name> <!--NeedCopy-->Note:
For an L3 cluster:
- The node group parameter must be set to the name of the node group that is created.
- The backplane parameter is mandatory for nodes that are associated with a node group that has more than one node, so that the nodes within the network can communicate with each other.
Example:
Adding a node for an L2 cluster (all cluster nodes are in the same network).
add cluster node 0 10.102.29.60 -state PASSIVE -backplane 0/1/1 <!--NeedCopy-->Adding a node for an L3 cluster that includes a single node from each network. Here, you do not have to set the backplane.
add cluster node 0 10.102.29.60 -state PASSIVE -nodegroup ng1 <!--NeedCopy-->Adding a node for an L3 cluster that includes multiple nodes from each network. Here, you have to set the backplane so that nodes within a network can communicate with each other.
add cluster node 0 10.102.29.60 -state PASSIVE -backplane 0/1/1 -nodegroup ng1 <!--NeedCopy--> -
Add the cluster IP address (for example, 10.102.29.61) on this node.
add ns ip <IPAddress> <netmask> -type clip <!--NeedCopy-->Example
add ns ip 10.102.29.61 255.255.255.255 -type clip <!--NeedCopy--> -
Enable the cluster instance.
enable cluster instance <clId> <!--NeedCopy--> -
Save the configuration.
save ns config <!--NeedCopy--> -
Warm reboot the appliance.
reboot -warm <!--NeedCopy-->Verify the cluster configurations by using the show cluster instance command. Verify that the output of the command displays the NSIP address of the appliance as a node of the cluster.
-
After the node is UP, login to the CLIP and change RPC credentials for both cluster IP address and Node IP address. For more information about changing an RPC node password, see Change an RPC node password.
To create a cluster by using the GUI
- Log on to an appliance (for example, an appliance with NSIP address 10.102.29.60) that you intend to add to the cluster.
- Navigate to System > Cluster.
- In the details pane, click the Manage Cluster link.
- In the Cluster Configuration dialog box, set the parameters required to create a cluster. For a description of a parameter, hover the mouse cursor over the corresponding text box.
- Click Create.
- In the Configure cluster instance dialog box, select the Enable cluster instance checkbox.
- In the Cluster Nodes pane, select the node and click Open.
- In the Configure Cluster Node dialog box, set the State.
- Click OK, and then click Save.
- Warm reboot the appliance.
- After the node is UP, login to the CLIP and change RPC credentials for both cluster IP address and Node IP address. For more information about changing an RPC node password, see Change an RPC node password.
Strict mode support for sync status of the cluster
You can now configure a cluster node to view errors when applying the configuration. A new parameter, “syncStatusStrictMode” is introduced in both the add and set cluster instance command to track the status of each node in a cluster. By default, the syncStatusStrictMode parameter is disabled.
To enable the strict mode by using the CLI
At the command prompt, type:
set cluster instance <clID> [-syncStatusStrictMode (ENABLED | DISABLED)]
<!--NeedCopy-->
Example:
set cluster instance 1 –syncStatusStrictMode ENABLED
<!--NeedCopy-->
To view the status of strict mode by using the CLI
>show cluster instance
1) Cluster ID: 1
Dead Interval: 3 secs
Hello Interval: 200 msecs
Preemption: DISABLED
Propagation: ENABLED
Quorum Type: MAJORITY
INC State: DISABLED
Process Local: DISABLED
Retain Connections: NO
Heterogeneous: NO
Backplane based view: DISABLED
Cluster sync strict mode: ENABLED
Cluster Status: ENABLED(admin), ENABLED(operational), UP
WARNING(s):
(1) - There are no spotted SNIPs configured on the cluster. Spotted SNIPs can help improve cluster performance
Member Nodes:
Node ID Node IP Health Admin State Operational State
------- ------- ------ ----------- -----------------
1) 1 192.0.2.20 UP ACTIVE ACTIVE(Configuration Coordinator)
2) 2 192.0.2.21 UP ACTIVE ACTIVE
3) 3 192.0.2.19* UP ACTIVE ACTIVE
<!--NeedCopy-->
To view the sync failure reason of a cluster node by using the GUI
- Navigate to System > Cluster > Cluster Nodes.
- In the Cluster Nodes page, scroll to the extreme right to view the details of the synchronization failure reason of the cluster nodes.
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.