Application Delivery Management

Release Notes for NetScaler ADM 13.1–42.47 Release

This release notes document describes the enhancements and changes, fixed and known issues that exist for the NetScaler ADM release Build 13.1–42.47.

Notes

  • This release notes document does not include security related fixes. For a list of security related fixes and advisories, see the security bulletin.

What’s New

The enhancements and changes that are available in Build 13.1–42.47.

Infrastructure

Z License expiry information shown in NetScaler ADM

You can now view Z License expiry information of MPX and SDX instances in NetScaler ADM by navigating to Infrastructure > Pooled Licensing > Pooled Capacity > Z licenses.

[NSADM-80202]

Management and Monitoring

Support for changing agent password without current password

As a super administrator, you can now allow agent passwords to be changed without their current passwords.

Navigate to Settings > Administration > System Configurations > Agent Settings and select the Remove current password prerequisite for agent password change check box. The Change Agent Password page will no longer have the Current password field.

To display the Current password field again, clear the Remove current password prerequisite for agent password change check box.

[NSADM-92585]

Discontinued SD-WAN and HAProxy features in NetScaler ADM

NetScaler ADM no longer supports SD-WAN and HAProxy features. As a result, the associated features applicable for SD-WAN and HAProxy are now not available in the NetScaler ADM GUI.

[NSADM-90549]

NetScaler Syslog captures user information for configuration jobs completed by NetScaler ADM service

When a user runs a configuration job in NetScaler ADM service, the commands in the job are logged against the NetScaler ADM login user name and are stored in the NetScaler syslog file.

[NSADM-80418]

StyleBooks

New parameter type to represent subnet values

You can now specify parameters of type: ipnetwork when you create a StyleBook template. These parameters allow a subnet or a CIDR value to be provided as an input to a StyleBook. The StyleBook configuration GUI displays either of the following fields for this parameter:

  • IP address and the Netmask Length

  • IP address and the Netmask IP

You can choose to use a netmask length or a netmask IP through a toggle:

  • Enable the toggle to input netmask length

  • Disable the toggle to input netmask IP address

[NSADM-80696]

Fixed Issues

The issues that are addressed in Build 13.1–42.47.

Analytics

In Security > Security Violations > All Violations, when you view details for the following violations, an error message might get displayed:

  • HTTP Slow Loris

  • DNS Slow Loris

  • HTTP Slow Post

  • NXDOMAIN Flood Attack

  • HTTP Desync

  • Bleichenbacher Attack

  • Segment smack attack

[NSHELP-34006]

NetScaler ADM GUI does not display violations tagged as ‘WAF Miscellaneous’. As part of the fix, these violations now appear in Security > Security Dashboard > App Security Investigator > WAF Miscellaneous.

[NSHELP-33757]

High Availability

In a NetScaler ADM high availability deployment, when you change the password of the NetScaler ADM secondary node and restart the system, the NetScaler ADM secondary node gets reset to the old password.

[NSHELP-34016,NSHELP-34069]

For NetScaler ADM HA deployment, the statistics for the secondary node are not visible under Settings > Deployment.

With this fix, this issue is now resolved.

[NSHELP-32746]

Infrastructure

When you edit the applied cipher suites by navigating to Settings > Administration > Configure SSL Settings and clicking Cipher Suites under Edit Settings, an error message is displayed.

[NSADM-91382]

Management and Monitoring

  • Sometimes, in the NetScaler ADM HA setup, the file synchronization fails on the NetScaler ADM secondary server.

    [NSHELP-34070]

  • In Infrastructure > Network Functions, the Load Balancing page takes a long time to load. This issue occurs if you belong to the group that has regular expressions.

    As an administrator, you can add a regular expression in Settings > Users & Roles > Create System Group > Authorization Settings > Select Applications > Add Regular Expression for Application.

    [NSHELP-34035]

  • The number of entries displayed in Infrastructure > Network Reporting > Thresholds does not match the Items Per Page drop-down menu.

    [NSHELP-33895]

  • In Settings > Network Functions > Load Balancing, the search results take more time if you filter virtual servers by Hostname or Partition. This issue occurs if you belong to multiple groups.

    [NSHELP-33856]

  • In Infrastructure > Upgrade Jobs, when you select a completed job that has the pre-upgrade or post-upgrade script file name with special characters and then download the output scripts from the Select Action list, the File not found error message is displayed.

    [NSHELP-33854]

  • In NetScaler ADM GUI, you see the File [filename] does not exist error message when you navigate to Upgrade Jobs > Action > Download post-upgrade script output or Download post-upgrade post-failover script output.

    The error message is seen even after you perform the following actions:

    1. Navigate to Upgrade NetScaler > Custom Scripts

    2. Upload a script file for Pre upgrade.

    3. Select the Use same script as Pre Upgrade check box for Post upgrade pre failover and Post upgrade post failover.

    [NSHELP-33836]

  • In Infrastructure > Network Functions, the Load Balancing page displays all the virtual servers and entities. It happens even though an administrator creates a group by selecting Applications > All Applications of selected instances which must only display the applications that are bound to the instance.

    As an administrator, you can create a group in Settings > Users & Roles > Create System Group.

    [NSHELP-33809]

  • In a NetScaler ADM HA pair, the SNMP traps are not getting generated during the failover scenarios.

    [NSHELP-33678]

  • Users who are assigned appAdmin or appReadonly roles do not see all the features under Applications in the NetScaler ADM GUI.

    [NSHELP-33634]

  • After upgrading NetScaler ADM from 12.1 to 13.1 build 33.50, ADC event pruning fails. As a result, NetScaler ADM stops to respond while fetching reports.

    [NSHELP-33608]

  • After upgrading from NetScaler ADM 12.1 release to 13.1 release, a Not Authorized error is displayed on the NetScaler ADM GUI when you enable or disable the virtual servers in the Infrastructure > Network Functions page.

    [NSHELP-33592]

  • The Configure License page (Settings > Licensing & Analytics Configuration) displays all the virtual servers instead of only the virtual servers that were added while creating a group.

    As an admin, you can add the virtual servers in Settings > Users & Roles > Create System Group > Authorization Settings.

    [NSHELP-33584]

  • The Virtual Server page (Infrastructure > Network Functions > Load Balancing) displays all the applications instead of only the applications associated with a particular group. This issue occurs if an empty string is introduced in the Add Regular Expression for Application field (Settings > Users & Roles > Create/Modify System Group> Authorizations Settings > Applications > Specific Applications).

    [NSHELP-33556,NSHELP-33870]

  • After upgrading from NetScaler ADM 12.1 release to 13.1 release, all the applications are displayed in the Load Balancing page (Infrastructure > Network Functions) instead of only the authorized applications. This issue occurs because the regular expression configured for an application is not saved.

    As an admin, you configure regular expressions at Settings > Users & Roles > Create System Group > Authorization Settings > Create Applications > Add Regular Expression for Application.

    [NSHELP-33553]

  • Enable or disable operations cannot be done through NetScaler ADM even though permissions are defined in the access policies. The permissions are defined through this navigation path in NetScaler ADM GUI: Settings > Users & Roles > Access Policies > Infrastructure > Network Functions > Load Balancing > Virtual Servers > Enable-Disable.

    [NSHELP-33497]

  • In NetScaler ADM GUI, when you annotate a NetScaler HA pair from Infrastructure > Instances Dashboard > NetScaler> Select Action > Annotate, the annotation is saved only for the NetScaler primary instance. After an HA failover, the new primary NetScaler instance does not display the annotation.

    [NSHELP-33387]

  • The SSL encryption between NetScaler ADM and SMTP servers does not work as expected even after enabling the TLS 1.2 SSL protocol. As a result, incorrect ciphers are shown in the SSL traces.

    [NSHELP-33363]

  • The “mas_inventory” subsystem intermittently crashes.

    [NSHELP-33234]

  • The enabling and disabling of services or service groups in Infrastructure > Network Functions > Load Balancing fails if the service or the service group is not bound to any virtual server.

    [NSHELP-32999]

  • When NetScaler ADM receives the syslog messages from NetScaler with a bad URI syntax, the Syslog Messages page in Infrastructure > Event Summary appears blank.

    [NSHELP-32912]

  • Challenge based authentication for NetScaler ADM login is failing for external TACACS authentication servers.

    [NSHELP-33960]

  • Creating a group in NetScaler ADM GUI causes configuration errors because the API Gateway category appears in the Settings > Users & Roles > Groups > Add > Create System Group > Authorization Settings page. As part of the fix, the Authorization Settings page does not display API Gateway.

    [NSHELP-33524]

  • The NetScaler SDX instances are getting licensed incorrectly. As a result, SNMP traps are generated for the SDX instances that are not managed by the NetScaler ADM agent.

    [NSHELP-33415]

Provisioning

  • Asymmetric Crypto Units and Symmetric Crypto Units are now editable fields in the NetScaler ADM GUI. You can enter the number of ASUs and SCUs while provisioning a NetScaler VPX instance on the NetScaler SDX appliance with Intel Coleto (COL) chips.

    Navigate to Infrastructure > Instances > NetScaler, and on the SDX tab, select an SDX instance where you want to provision a NetScaler VPX instance. In Select Action, select Provision VPX and in the page that displays, enter the crypto capacity under Crypto Allocation

    [NSHELP-33297]

StyleBooks

  • When you create or update a configuration pack using a StyleBook created in version 13.0 or earlier, an error message unknown parameters received in payload appears.

    [NSHELP-33412]

User Interface

  • The primary and the secondary node status do not get updated in Infrastructure > Network Functions > Load Balancing after an HA failover for NetScaler VPX instances.

    [NSHELP-33798]

  • Messages were truncated in Settings > ADM System Events > MESSAGE column and you had to select the entry and click Details to know more about the message. With this fix, you can view the complete message in the MESSAGE column.

    [NSHELP-33772]

Known Issues

The issues that exist in release 13.1–42.47.

Management and Monitoring

  • “Not authorized” error is displayed when users who are assigned appAdmin or appReadonly roles navigate to Infrastructure > Load Balancing > Services/Service Groups and use the Name key as the search filter.

    [NSHELP-34194]

  • If you use VMware vMotion to schedule the ADM server migration on an ESXi hypervisor, the database streaming channel on the HA nodes is broken. As a result, you cannot access the ADM GUI.

    [NSHELP-32647]

  • The Modify System Group page (Settings > Users & Roles > Groups > Edit) takes a long time to load. This issue occurs if the group has two or more user roles and a regular expression associated with it.

    [NSADM-94279]

Orchestration

  • Deleting a load balancing virtual server from OpenStack fails because NetScaler ADM does not honor the delete request. This issue persists even after you delete the components bound to the load-balancing virtual server.

    [NSADM-89919]

Release Notes for NetScaler ADM 13.1–42.47 Release