ADCで生成されたCookieに属性を挿入する
-
ロードバランシングCookie パーシステンス
-
負荷分散グループの Cookie パーシステンス
-
GSLB サイトパーシスタンス
-
コンテンツスイッチングクッキーの永続性
-
literaladcCookieAttribute: ADC が生成したクッキーに、他のクッキー属性を文字列として追加します。
-
ComputedADCCookieAttribute: ADC ns変数を使用して、クライアントまたはサーバーの属性(ユーザーエージェントのバージョンなど)に基づいて、ADCで生成されたCookieにCookie属性を条件付きで追加します。
使用事例:SameSite Cookie 属性の設定
-
なし: 安全な接続でのみクロスサイトコンテキストで Cookie を使用するようブラウザに指示します。
-
Lax: ブラウザが同じサイトコンテキストでのリクエストに Cookie を使用するように指示します。クロスサイトコンテキストでは、GETリクエストなどの安全なHTTPメソッドのみがCookieを使用できます。
-
Strict: 同じサイトのコンテキストでのみCookieを使用します。
-
Chrome51からChrome66までのChromeのバージョン(両端を含む)
-
Android の UC ブラウザのバージョン 12.13.2 より前のバージョン
ADCで生成されたCookieを構成する
-
負荷分散仮想サーバーを作成する
-
LB パラメータまたは LB プロファイルを使用して、負荷分散仮想サーバの ADC Cookie 属性を設定します。
-
LB プロファイルを使用する場合は、LB プロファイルを負荷分散仮想サーバーに設定します。
-
Computed ADC Cookie 属性を使用する場合は、関連する書き換えポリシーを設定してください。
-
ロードバランシングパラメータの ADC Cookie 属性の設定
-
ロードバランシングプロファイルの ADC Cookie 属性の設定
CLI を使用してロードバランシングパラメータで ADC Cookie 属性を設定する
set lb parameter -LiteralADCCookieAttribute <string>
set lb parameter -LiteralADCCookieAttribute SameSite=None
set lb parameter -ComputedADCCookieAttribute <ns variable>
add ns variable cookieattribute_var -type "text(100)" -scope transaction
set lb parameter -ComputedADCCookieAttributE "$cookieattribute_var"
add ns assignment samesiteassign -variable "$cookieattribute_var" -set ""SameSite=None""
add policy expression pol_iphone "(HTTP.REQ.HEADER("User-Agent").CONTAINS("iP") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/OS \d+\\_/).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).EQ(12).typecast_text_t ALT "false").eq("true"))"
add policy expression pol_chrome "(HTTP.REQ.HEADER("User-Agent").CONTAINS("Chrom") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/Chrom.*\d+./).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).BETWEEN(51,66).typecast_text_t ALT "false").eq("true"))"
add rewrite policy exception_samesite_attribute "pol_iphone || pol_chrome " NOREWRITE
add rewrite policy append_samesite_attribute true samesiteassign
bind rewrite global exception_samesite_attribute 90 110 -type RES_OVERRIDE
bind rewrite global append_samesite_attribute 100 110 -type RES_OVERRIDE
GUI を使用して変数を設定する
GUI を使用して課題を作成する
GUI を使用したロードバランシングパラメータでの ADC Cookie 属性の設定
CLI を使用したロードバランシングプロファイルでの ADC Cookie 属性の設定
add lb profile <profile name> -LiteralADCCookieAttribute <string>
add lb profile LB-Vserver-Profile-1 -LiteralADCCookieAttribute SameSite=None
add lb vserver LB-VServer-1 SSL 10.102.148.37 443 -persistenceType COOKIEINSERT -lbprofilename LB-Vserver-Profile-1
add lb profile <profile name> -ComputedADCCookieAttribute <ns variable>
add ns variable cookieattribute_var -type "text(100)" -scope transaction
add ns assignment samesiteassign -variable "$cookieattribute_var" -set ""SameSite=None""
add lb profile LB-Vserver-Profile-1 -ComputedADCCookieAttributE "$cookieattribute_var"
add policy expression pol_iphone "(HTTP.REQ.HEADER("User-Agent").CONTAINS("iP") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/OS \d+\\_/).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).EQ(12).typecast_text_t ALT "false").eq("true"))"
add policy expression pol_chrome "(HTTP.REQ.HEADER("User-Agent").CONTAINS("Chrom") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/Chrom.*\d+./).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).BETWEEN(51,66).typecast_text_t ALT "false").eq("true"))"
add rewrite policy exception_samesite_attribute "pol_iphone || pol_chrome " NOREWRITE
add rewrite policy append_samesite_attribute true samesiteassign
add lb vserver LB-VServer-1 SSL 10.102.148.37 443 -persistenceType COOKIEINSERT -lbprofilename LB-Vserver-Profile-1
bind lb vserver LB-VServer-1 -policyName exception_samesite_attribute -priority 90 -gotoPriorityExpression 110 -type RESPONSE
bind lb vserver LB-VServer-1 -policyName append_samesite_attribute -priority 100 -gotoPriorityExpression 110 -type RESPONSE
GUI を使用したロードバランシングプロファイルでの ADC Cookie 属性の設定
-
Traffic Management > Load Balancing > Virtual Serversに移動します。
-

-
「 プロファイル 」セクションで、「 追加 」をクリックして LB プロファイルを作成します。

-
リテラル ADC クッキー属性
-
計算された ADC クッキー属性

-
[OK] をクリックします。
-
作成したLBプロファイルを、 手順1で作成したLB仮想サーバーに設定します。
ns 変数設定の検証
| 警告メッセージ | 理由 |
|---|---|
| NS 変数は設定されていません。text () とタイプして変数にスコープトランザクションを設定してください | NS 変数はまだ設定されていません。 |
| 設定された NS 変数の範囲はトランザクションではありません。 | 変数は設定されていますが、スコープが「トランザクション」に設定されていません。 |
| 変数のタイプは Text () ではありません。 | 変数は構成されていますが、タイプが「テキスト」に設定されていません。 |
| NS 変数に設定された値の最大サイズが 255 を超えています。 | NS 変数に設定された値は 255 文字を超えています。注: ADCで生成されたCookieには、最大255文字の長さを追加できます。最大長を超える文字は切り捨てられます。 |
出力例
set lb parameter -ComputedADCCookieAttribute "$lbvar"
Warning: NS Variable is not configured. Please configure it with type text() and scope transaction
Done
show lb parameter 次のコマンドの出力に表示されます。
show lb parameter
Global LB parameters:
Persistence Cookie HttpOnly Flag: ENABLED
Use Encrypted Persistence Cookie: DISABLED
Use Port For Hash LB: YES
Prefer direct route: YES
Retain Service State: OFF
Start RR Factor: 0
Skip Maxclient for Monitoring: DISABLED
Monitor Connection Close: FIN
Use consolidated stats for LeastConnection: YES
Allow mac mode based vserver to pick thereturn traffic from services: DISABLED
Allow bound service removal: ENABLED
TTL for Domain Based Server: 0 secs
NetScaler Cookie Variable Name: $lbvar(NS Variable is not configured. Please configure it with type text() and scope transaction)
Done
GSLB デプロイメントに Cookie 属性を挿入するためのサンプル設定
-
LB プロファイル (LB-VServer-Profile-1) に ADC Cookie 属性を設定します。
-
LB プロファイルに「SameSite=None」などのリテラル ADC クッキー属性値を設定します。
-
LB プロファイルを GSLB サービスを表す負荷分散仮想サーバー (LB-VServer-1) に設定します。
add gslb vserver GSLB-VServer-1 SSL -backupLBMethod ROUNDROBIN -tolerance 0 -appflowLog DISABLED
add gslb site site1 10.102.148.4 -publicIP 10.102.148.4
add gslb service site1_gsvc1 10.102.148.35 SSL 443 -publicIP 10.102.148.35 -publicPort 443 -maxClient 0 -siteName site1 -sitePersistence HTTPRedirect -sitePrefix ss1 -cltTimeout 180 -svrTimeout 360 -downStateFlush ENABLED
bind gslb vserver GSLB-VServer-1 -serviceName site1_gsvc1
bind gslb vserver GSLB-VServer-1 -domainName www.gslb.com -TTL 5
add service service-1 10.102.84.140 SSL 443
add lb profile LB-Vserver-Profile-1 -LiteralADCCookieAttribute SameSite=None
add lb vserver LB-VServer-1 SSL 10.102.148.37 443 -persistenceType COOKIEINSERT -lbprofilename LB-Vserver-Profile-1
bind lb vserver LB-VServer-1 service-1
コンテンツスイッチングデプロイメントに Cookie 属性を挿入するための設定例
-
LB パラメータに ADC Cookie 属性を設定します。注:ADC Cookie 属性は LB プロファイルでも設定できます。
-
ns 変数を使用して、計算された ADC Cookie 属性をグローバル LB パラメータに設定します。
-
Cookie 属性を挿入するためのリライトポリシー (exception_samesite_attribute と append_samesite_attribute) をコンテンツスイッチング仮想サーバーに設定します。
add ns variable cookieattribute_var -type "text(100)" -scope transaction
set lb parameter -ComputedADCCookieAttributE "$cookieattribute_var"
add ns assignment samesiteassign -variable "$cookieattribute_var" -set ""SameSite=None""
add policy expression pol_iphone "(HTTP.REQ.HEADER("User-Agent").CONTAINS("iP") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/OS \d+\\_/).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).EQ(12).typecast_text_t ALT "false").eq("true"))"
add policy expression pol_chrome "(HTTP.REQ.HEADER("User-Agent").CONTAINS("Chrom") && (HTTP.REQ.HEADER("User-Agent").REGEX_SELECT(re/Chrom.*\d+./).REGEX_SELECT(re/\d+/).TYPECAST_NUM_T(DECIMAL).BETWEEN(51,66).typecast_text_t ALT "false").eq("true"))"
add rewrite policy exception_samesite_attribute "pol_iphone || pol_chrome " NOREWRITE
add rewrite policy append_samesite_attribute true samesiteassign
add lb vserver LB-VServer-1 SSL 10.102.148.35 443
add lb vserver LB-VServer-2 SSL 10.102.148.36 443
add cs vserver CS-VServer-1 SSL 10.102.148.42 443 -persistenceType COOKIEINSERT
add cs action act1 -targetLBVserver v1
add cs action act2 -targetLBVserver v2
add cs policy CS-policy-1 -rule "HTTP.REQ.URL.CONTAINS("file1.html")" -action act1
add cs policy CS-policy-2 -rule "HTTP.REQ.URL.CONTAINS("file2.html")" -action act2
bind cs vserver CS-VServer-1 -policyName CS-policy-1 -priority 1
bind cs vserver CS-VServer-1 -policyName CS-policy-2 -priority 2
bind cs vserver -policyname exception_samesite_attribute 90 110 -type RES_OVERRIDE
bind cs vserver -policyname append_samesite_attribute 100 110 -type RES_OVERRIDE


