-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
Implement strict separation of Management and Data planes in NetScaler
-
Configure to source NetScaler FreeBSD data traffic from a SNIP address
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Secure management: Implement strict separation of Management and Data planes in NetScaler
The NetScaler® Secure Management feature is designed to significantly strengthen system security by fully isolating the management network from the data network. This enhancement provides a logical separation of all NetScaler functions into distinct Management and Data plane categories. When enabled, each plane operates with its own dedicated routing table, ensuring that management traffic is kept entirely separate and distinct from data traffic.
Note:
Starting with NetScaler release 14.1-72.x, the Secure Management feature is also supported on the NetScaler VPX on Linux platforms.
This feature provides the following key benefits:
- Minimizes the risk of unauthorized access and protects sensitive management functions by preventing intermingling of management and data traffic.
- Ensures a clear distinction between management and data paths, preventing unauthorized access and improving network clarity.
- By separating functionalities, it enhances both the security and operational efficiency of NetScaler.
- Allows users to customize traffic handling and routing according to their specific network security and operational needs.
- Enables the creation and control of separate management and Data plane routing tables, effectively mitigating various security threats.
NetScaler topology: Separation of Management and Data Planes
The topology diagram visually represents how NetScaler separates the Management plane and Data plane to ensure efficient traffic handling and security. NetScaler automatically assigns features to the appropriate plane based on the peer device. The Management plane handles non-user traffic, such as API calls, CLI commands, GUI interactions, and logs. NetScaler IP (NSIP) is the dedicated IP for management access. The administrator connects to NSIP over SSH, GUI, or API. The Data plane handles actual application traffic flowing between clients and backend servers. Clients send requests to VIP on NetScaler. NetScaler forwards traffic to backend application servers using SNIPs.

Overview of Management and Data plane features in NetScaler
The Management and Data planes in NetScaler each provide distinct sets of features to ensure secure administration and efficient traffic handling.
Management plane features
The Management plane in NetScaler is responsible for the configuration, administration, and monitoring of the device, ensuring secure and efficient operations. Administrators can securely manage NetScaler through the NSIP using HTTPS for the GUI or NITRO API, SSH for CLI access, and SCP/FTP for transferring configuration files.
- SNMP
- System logging (syslog)
- Audit logging/NSLOG
- Web logging
- AppFlow®
- High Availability
- Clustering
- Network Time Protocol (NTP)
- Precision Time Protocol (PTP)
- DHCP
- Licensing
- Secure Virtual Machine (SVM)
- MASTools
- Console Advisory Connect
- Console Management and Monitoring
- Metric Export
- Management Log Export
- Events Export
Data plane features
Data plane features refer to all the features excluding those related to the Management plane.
Automatic role assignment between Management and Data plane features
Certain features can operate as both Management and Data plane features, depending on the peer device. NetScaler automatically determines this classification without the need for any user configuration.
Switch or override features between Management and Data planes
We provide the flexibility to seamlessly override Management plane features with Data plane features, and conversely. The available override options vary depending on the specific feature. Certain features require user configuration to enable or adjust the override. For more information, see Understanding default traffic plane behavior and override mechanisms.
Configure the Secure Management feature
The Secure Management feature is disabled by default. For enhanced security, this feature can only be configured through the CLI and not using the GUI.
Note:
Configuring the
NSVLANandifnumvalues is mandatory to enable the Secure Management feature. By default, theTDvalue is set to4094. If a different value is required, you can configure it accordingly.
To enable the feature, use the following command:
set ns config -secureManagementTraffic ENABLED -secureManagementTD <TD_value> -nsvlan <nsvlan-id> -ifnum <interface name> ...[-tagged (Yes | No)]
Example:
set ns config -secureManagementTraffic ENABLED -secureManagementTD 300
The following command parameters are used to enable the Secure Management feature:
- -secureManagementTraffic ENABLED: Enables the Secure Management feature.
-
-secureManagementTD
<TD_value>: Specifies the traffic domain value. -
-nsvlan
<nsvlan-id>: Specifies the NSVLAN ID. If NSVLAN is already configured, this feature uses the existing value, which can be modified if needed. -
-ifnum
<interface name>: Specifies the interface names. - -tagged (Yes/No): (Optional) Indicates whether the interface is tagged.
Note:
After enabling the Secure Management feature, make sure to save the configuration and reboot the system.
Two distinct routing tables
When Secure Management is enabled, NetScaler creates two separate planes, each with its own routing table: one for management and one for data. Management entities such as NSIP and SNIPs with management access are included in the management routing table. All other SNIPs and VIPs are included in the data routing table.
To manage routes in the data routing table, use the standard add route and rm route commands. To manage routes in the management routing table, use the same commands with the new -mgmt parameter.
add route 200.1.1.0 255.255.255.0 1.1.1.1 -mgmt
rm route 200.1.1.0 255.255.255.0 1.1.2.2 -mgmt
set route 200.1.1.0 255.255.255.0 1.1.1.2 -cost 30 -mgmt
unset route 200.1.1.0 255.255.255.0 1.1.1.1 -cost -mgmt
show route -mgmt
<!--NeedCopy-->
You can view the two separate routing tables created by this feature using the following commands:
> show route
Network Netmask Gateway/OwnedIP VLAN State Traffic Domain Type
------- ------- --------------- ----- ----- -------------- ----
1) 127.0.0.0 255.0.0.0 127.0.0.1 0 UP 0 PERMANENT
> show route -mgmt
Network Netmask Gateway/OwnedIP VLAN State Traffic Domain Type
------- ------- --------------- ----- ----- -------------- ----
1) 10.102.37.0 255.255.255.0 10.102.37.238 0 UP 4094 DIRECT
2) 0.0.0.0 0.0.0.0 10.102.37.1 0 UP 4094 STATIC
<!--NeedCopy-->
To disable the Secure Management feature, run the following command:
unset ns config -secureManagementTraffic
<!--NeedCopy-->
After disabling, save the configuration and manually reboot NetScaler for the changes to take effect. After the reboot, the system reverts to a single routing table, with all entities reassigned to the Data plane’s routing table.
Verify Secure Management feature status
The status of the feature can be verified using the show ns config command.
Without the feature enabled, the command output shows the SecureManagement feature as DISABLED.
> show ns config
NetScaler IP: 10.102.37.239 (mask: 255.255.255.0)
Number of MappedIP(s): 0
Node: Standalone
SecureManagementTraffic:DISABLED SecureManagementTD:0
System Time: Wed Jul 23 07:47:09 2025
Last Config Changed Time: Tue Jul 22 05:42:28 2025
Last Config Saved Time: Mon Jul 21 09:17:08 2025
Config Changed since Last Saved Config: TRUE
Done
<!--NeedCopy-->
When the feature is enabled, the command output shows the SecureManagement feature as ENABLED along with the NSVLAN and SecureManagementTD information.
> show ns config
NetScaler IP: 10.102.37.238 (mask: 255.255.255.0)
Number of MappedIP(s): 0
Node: Standalone
NetScaler IP Vlan: 4000 Tagged: NO Bound Ports: 1/1
SecureManagementTraffic:ENABLED SecureManagementTD:4094
System Time: Wed Jul 23 07:42:32 2025
Last Config Changed Time: Tue Jul 22 05:04:53 2025
Last Config Saved Time: Tue Jul 22 08:04:53 2025
Config Changed since Last Saved Config: FALSE
Done
<!--NeedCopy-->
Important considerations when enabling or disabling Secure Management
- Carefully review and update configurations when enabling or disabling this feature to avoid disruptions.
- Enabling Secure Management separates the network into two distinct planes—a secure Management plane and a Data plane—following industry best practices. Assign functions to each plane according to your network design (for example, update NetProfiles for analytics traffic).
- Enabling this feature also configures NSVLAN. If using a tagged NSVLAN, ensure that upstream networks and routers are configured to maintain connectivity.
- Disabling the feature removes Management plane configuration settings, which cause conflicts in a single-plane environment.
- Disabling Secure Management also removes the NSVLAN, which can result in connectivity loss if upstream networks are not properly configured.
-
When enabling or disabling the feature, verify that all required default routes for connectivity exist in the appropriate planes.
Example: Default route configuration and routing table merge
Consider a scenario where you have configured separate default routes for each plane:
-
Data plane: Default route through gateway
192.168.1.1 -
Management plane: Default route through gateway
10.0.0.1
When the Secure Management feature is disabled, both default routes are merged into a single routing table:
- Default route through gateway
192.168.1.1 - Default route through gateway
10.0.0.1
Having multiple default routes in the same routing table can cause unpredictable routing behavior and connectivity issues. Always review and adjust your network configuration before enabling or disabling the Secure Management feature to prevent routing conflicts.
-
Data plane: Default route through gateway
- With Secure Management enabled, SNIPs with management access are permitted only on the Management plane.
-
In high availability (HA) deployments, enable Secure Management on each node individually before forming the HA pair. As with build upgrades, enable the feature first on the secondary node, then on the primary node.
Example: Configuring Sync VLAN for HA deployments
To configure Sync VLAN for HA deployments, the following configuration can be done assuming Management plane is TD=4094 and sync VLAN is 100:
add vlan 100 bind ns trafficdomain 4094 -vlan 100 set HA node -syncvlan 100 <!--NeedCopy--> - Entities intended for the Management plane, such as IP addresses, virtual servers, and network profiles must be configured within the Management traffic domain.
-
When configuring dynamic routing protocols, such as BGP or OSPF with Secure Management enabled, more filtering configurations are required at the vtysh level to maintain proper traffic plane separation.
BGP configuration requirements: Configure route-maps to ensure proper traffic isolation.
- Implement route-maps to prevent Data plane subnet traffic from routing through the management interface.
- Configure route-maps to block Management plane subnet traffic from routing through data interfaces.
OSPF configuration requirements: Configure access-lists to maintain traffic plane boundaries:
- Apply access-lists to prevent Data plane subnet traffic from being advertised or routed through the management interface.
- Implement access-lists to restrict Management plane subnet traffic from traversing Data plane interfaces.
These filtering mechanisms are essential to preserve the security boundaries established by the Secure Management feature when using dynamic routing protocols.
Upgrading and Downgrading with Secure Management
To upgrade from an older build to one that supports the Secure Management feature, follow the standard upgrade procedure. If Secure Management is already enabled on the device, ensure that all configurations are saved before starting the upgrade.
If you downgrade from a build with Secure Management enabled to an older build that does not support this feature, existing configurations might be disrupted. Review your setup and consider disabling the Secure Management feature before performing the downgrade.
Limitations
The following features are not supported when the Secure Management feature is enabled in NetScaler:
- Clustering
- Call Home
- Admin partition
- Traffic domains
- DHCP
Note:
The Secure Management feature is not supported in NetScaler BLX™ and NetScaler CPX™ platforms.
Share
Share
In this article
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.