事前設定チェックツール
ns.conf)。
nspepiツールを使用して、クラシック構成を詳細構成に変換できます。実行が成功すると、ツールは 2 つのファイルを生成します。1 つは無効なコマンド用で、もう 1 つは廃止されたパラメーターまたはコマンド用です。無効なコマンドを含むファイルは、入力ファイルと同じ名前ですが、プレフィックスは「issues_」です。非推奨のコマンドを含むファイルには、「deprecated_」というプレフィックスが付いています。
-
コンテンツスイッチング、キャッシュリダイレクト、AppFW、SSL、および CMP 機能の従来のポリシー式。
-
フィルタ機能 (コンテンツフィルタとも呼ばれます)-アクション、ポリシー、およびバインディング。
-
HTTPプロファイルでSPDY、Sure Connect(SC)、プライオリティキューイング(PQ)、HTTPサービス拒否(DoS)、HTMLインジェクションの機能がある。
-
負荷分散永続性ルールのクラシック式。
-
書き換えアクションの「パターン」および「BypassSafetyCheck」パラメータ。
-
「patclass」設定エンティティ。
-
高度な定義式で引数なしの「HTTP.REQ.BODY」。
-
高度な定義式の Q および S プレフィックス。
-
cmp パラメータ設定用の「policyType」パラメータ。
-
非推奨のコマンドとパラメータ。
UNIX シェルで事前設定チェックツールを実行する
check_invalid_config <config_file> -buildVersion <build version>
-
<config file>はNetScaler構成ファイルを参照します。ファイルは、ns.confなどの保存済み設定から取得する必要があります。 -
<build version>は廃止されたコマンドと削除されたコマンドを知りたいビルドを指します。ビルドバージョンが指定されていない場合、ツールはデフォルトでNetScalerリリース13.1で廃止されたコマンドと削除されたコマンドを検出します。
root@ns# check_invalid_config /nsconfig/ns.conf 13.1
GUI を使用して事前設定チェックツールを実行する
無効なコマンドを含むサンプル出力
root@ns# check_invalid_config sample_conf_1.conf
The following configuration lines will get errors in 13.1 and both they and dependent configuration will be removed from the configuration:
add cmp policy cmp_pol -rule ns_true -resAction GZIP
add cs policy cs_pol_2 -rule ns_true
add cs policy cs_pol_3 -domain www.abc.com
add cs policy cs_pol_4 -url "/abc"
add rewrite action act_1 replace_all "http.req.body(1000)" http.req.url -pattern abcd
add rewrite action act_123 replace_all http.req.url ""aaaa"" -pattern abcd
add responder action ract respondwith "Q.URL + Q.HEADER("abcd")"
add appfw policy aff_pol_1 "http.req.body.length.gt(10)" APPFW_BYPASS
add appfw policy aff_pol ns_true APPFW_BYPASS
The nspepi upgrade tool can be useful in converting your configuration - see the documentation at https://docs.citrix.com/en-us/citrix-adc/current-release/appexpert/policies-and-expressions/introduction-to-policies-and-exp/converting-policy-expressions-nspepi-tool.html.
NOTE: the nspepi tool doesn't convert the following configurations:
1. SureConnect commands
2. PriorityQueuing commands
3. HTTP Denial of Service Protection commands
4. Classic SSL commands
5. HTMLInjection commands.
NOTE: No deprecated commands detected in the configuration.
nspepi アップグレードツールを使用して構成を変換するか、構成を手動で変換できます。詳細については、「 nspepi ツール」を参照してください。
nspepiツールは、NetScalerバージョン12.1、13.0およびそれ以降のバージョンでのみ実行できます。
無効なコマンドや廃止されたコマンドを含むサンプル出力
root@ns# check_invalid_config sample_conf_2.conf
The following configuration lines will get errors in 13.1 and both they and dependent configuration will be removed from the configuration:
add cmp policy cmp_pol -rule ns_true -resAction GZIP
add cs policy cs_pol_2 -rule ns_true
add cs policy cs_pol_3 -domain www.abc.com
add cs policy cs_pol_4 -url "/abc"
add rewrite action act_1 replace_all "http.req.body(1000)" http.req.url -pattern abcd
add rewrite action act_123 replace_all http.req.url ""aaaa"" -pattern abcd
add responder action ract respondwith "Q.URL + Q.HEADER("abcd")"
add appfw policy aff_pol_1 "http.req.body.length.gt(10)" APPFW_BYPASS
add appfw policy aff_pol ns_true APPFW_BYPASS
The nspepi upgrade tool can be useful in converting your configuration - see the documentation at https://docs.citrix.com/en-us/citrix-adc/current-release/appexpert/policies-and-expressions/introduction-to-policies-and-exp/converting-policy-expressions-nspepi-tool.html.
NOTE: the nspepi tool doesn't convert the following configurations:
1. SureConnect commands
2. PriorityQueuing commands
3. HTTP Denial of Service Protection commands
4. Classic SSL commands
5. HTMLInjection commands.
NOTE: some deprecated commands have also been detected in the config file, please check ./deprecated_sample_conf_2.conf file for the deprecated commands.
無効なコマンドはないが、廃止されたコマンドを含むサンプル出力
root@ns# check_invalid_config sample_conf_3.conf
The following configuration lines have been deprecated in 13.1 and will be removed in future releases:
[add authentication localPolicy lpol ns_true] command has been deprecated, please use the advanced authentication policy command
[add authentication certPolicy auth_pol_1 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication negotiatePolicy auth_pol_2 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication tacacsPolicy auth_pol_3 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication samlPolicy auth_pol_4 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication radiusPolicy auth_pol_5 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication ldapPolicy auth_pol_6 ns_true auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication webAuthPolicy auth_pol_1 -rule ns_true -action auth_act] command has been deprecated, please use the advanced authentication policy command
[add authentication dfaPolicy auth_pol_1 -rule ns_true -action auth_act] command has been deprecated, please use the advanced authentication policy command
For the complete deprecated commands, please see the output of ./deprecated_sample_conf_3.conf file.
No invalid config detected with the configuration.
検証エラーや警告のないサンプル出力
root@ns# check_invalid_config /var/tmp/new_ns.conf
No invalid or deprecated config detected with the configuration.