Configure admin partitions
-
Only superusers are authorized to create and configure admin partitions.
-
Unless specified otherwise, configurations to set up an admin partition must be done from the default partition.
-
NetScaler superusers and other non-partition users are taken to the default partition.
-
Users of all the 512 partitions can log in simultaneously.
Tip
-
Add the certificate to the NetScaler.
add ssl certKey ns-server-certificate -cert ns-server.cert-key ns-server.key -
Bind it to a service named
nshttps-<SNIP>-3009, where<SNIP>must be replaced with the SNIP address, in this case 100.10.10.1.bind ssl service nshttps-100.10.10.1-3009 -certkeyName ns-server-certificate
Partition resource limiting
-
Partition memory. It is the maximum allocated memory for a partition. You make sure to specify the values when creating a partition.NoteFrom NetScaler 12.0 onwards, when you create a partition, you can set the memory limit to Zero. If a partition is already created with a specific memory limit, you can reduce the limit to any value or set the limit as Zero.Parameter: maxMemLimitMaximum memory is allocated in MB in a partition. A zero value indicates the memory is unlimited on the partition and it can consume up to the system limits.Default value: 10
-
Partition bandwidth. Maximum allocated bandwidth for a partition. If you specify a limit, make sure it is within the appliance’s licensed throughput. Otherwise, you are not limiting the bandwidth that is used by the partition. The specified limit is accountable for the bandwidth that the application requires. If the application bandwidth exceeds the specified limit, packets are dropped.NoteFrom NetScaler 12.0 onwards, when you can create a partition, you can set the partition bandwidth limit to Zero. If a partition is already created with a specific bandwidth, you can reduce the bandwidth or set the limit as Zero.Parameter: maxBandwidthMaximum bandwidth is allocated in Kbps in a partition. A zero value indicates the bandwidth is unrestricted. That is, the partition can consume up to the system limits.Default value: 10240Maximum Value: 4294967295
-
Partition connection. Maximum number of concurrent connections that can be open in a partition. The value must accommodate the maximum simultaneous flow expected within the partition. The partition connections are accounted from the partition quota memory. Previously, the connections were accounted from the default partition quota memory. It is configured only on the client-side, not on the back-end server-side TCP connections. New connections cannot be established beyond this configured value.NoteFrom NetScaler 12.0 onwards, you can create a partition with the number of open connections set to Zero. If you have already created a partition with a specific number of open connections, you can reduce the connection limit or set the limit as Zero.Parameter: maxConnectionsMaximum number of concurrent connections that can be open in the partition. A zero value indicates no limit on the number of open connections.Default value: 1024Minimum value: 0Maximum Value: 4294967295
Configure an admin partition
To access in an admin partition by using the CLI
-
Log on to the NetScaler appliance.
-
Check if you are in the correct partition. The command prompt displays the name of the currently selected partition.
-
If yes, skip to the next step.
-
If no, get a list of the partitions with which you are associated and switch over to the appropriate partition.
-
show system user <username> -
switch ns partition <partitionName>
-
-
Now, you can perform the required configurations just as a non-partitioned NetScaler.
To access an admin partition by using the GUI
-
Log on to the NetScaler appliance.
-
Check if you are in the correct partition. The top bar of the GUI displays the name of the currently selected partition.
-
If yes, skip to the next step.
-
If no, navigate to Configuration > System > Partition Administration > Partitions, right-click the partition to which you want to switch, and select Switch.
-
-
Now, you can perform the required configurations just as a non-partitioned NetScaler.
Add an admin partition
To create an administrative partition by using the CLI
add partition <partitionname>
Switch user access from default partition to an admin partition
Switch ns partition <pname>
Adding SNIP address to a partition user account with management access enabled
> add ns ip <ip address> <subnet mask> -mgmtAccess enabled
Create and Bind a partition user with partition command policy
> add system user <username> <password>
Done
Creating and binding partition user group with partition command policy
> add system group <groupName>
> bind system group <groupname> (-userName | -policyName <cmdpolicy> <priority> | -partitionName)
Configuring external server authentication for external users
> add authentication tacacsaction <name> -serverip <IP> -tacacsSecret <secret key> -authorization ON -accounting ON
> add authentication policy <policname> -rule true -action <name>
> bind system global <policyname> -priority <value>1
Configure a partition system user account in a partition by using the GUI
To create a partition user account in a partition by using the GUI
To create a partition user group account in a partition by using the GUI
To configure external server authentication for external users by using the GUI
Sample configuration
> add partition Par1
> switch ns partition Par1
> add ns ip 10.102.29.203 255.255.255.0 -mgmtAccessenabled
> add system user John Password
> bind system user Jane partition-read-only -priority 1
> add system group Retail
> bind system group Retail -policyname partition-network 1 (where 1 is the priority number)
> bind system group Retail –username Jane
> add authentication tacacssaction tacuser –serverip 10.102.29.200 –tacacsSecret Password –authorization ON –accounting ON
> add authentication policy polname –rule true –action tacacsAction
> bind system global polname –priority 1
Command policies for a partition users and partition user groups in administrative partition
| Commands to authorize a user account inside administrative partition | Command policies available inside an administrative partition (built-in policies) | User account access type |
|---|---|---|
| add system user | Partition-admin | SNIP (with management access enabled) |
| add system group | Partition-network | SNIP (with management access enabled) |
add authentication <action, policy>, bind system global <policy name> |
Partition-read-only | SNIP (with management access enabled) |
| remove system user | Partition-admin | SNIP(with management access enabled) |
| remove system group | Partition-admin | SNIP (with management access enabled) |
bind system cmdpolicy to system user; bind system cmdpolicy to system group |
Partition-admin | SNIP (with management access enabled) |
Configure an LACP Ethernet channel on the default admin partition
-
Active. A port in active mode sends LACPDUs. Link aggregation is formed if the other end of the Ethernet link is in the LACP active or passive mode.
-
Passive. A port in passive mode sends LACPDUs only when it receives LACPDUs. The link aggregation is formed if the other end of the Ethernet link is in the LACP active mode.
-
Disable. Link aggregation is not formed.
-
LACP Mode. Active, passive, or disable.
-
LACP timeout. The waiting period before timing out the partner or actor. Possible values: Long and Short. Default: Long.
-
Port Key. To distinguish between the different channel. When the key is 1, LA/1 is created. When the key is 2, LA/2 is created. Possible values: Integer from 1 through 8. 4 through 8 is for cluster CLAG.
-
Port Priority. Minimum value: 1. Maximum value: 65535. Default: 32768.
-
System Priority. Uses this priority along with the system MAC to form the system ID to uniquely identify the system during LACP negotiation with the partner. Sets system priority from 1 and 65535. The default value is set to 32768.
-
Interface. Supports 8 interfaces per channel on NetScaler 10.1 appliance and supports 16 interfaces per channel on NetScaler 10.5 and 11.0 appliances.
Configure and verify LACP
To configure and verify LACP on a NetScaler appliance by using the CLI
-
Enable LACP on each interface.
set interface <Interface_ID> -lacpMode PASSIVE -lacpKey 1When you enable LACP on an interface, the channels are dynamically created. Also, when you enable LACP on an interface and set lacpKey to 1, the interface is automatically bound to channel LA/1.NoteWhen you bind an interface to a channel, the channel parameters take precedence over the interface parameters, so the interface parameters are ignored. If a channel is created dynamically by LACP, you cannot perform the add, bind, unbind, or remove operations on the channel. A channel dynamically created by LACP is automatically deleted when you disable LACP on all interfaces of the channel. -
Set the system priority.
set lacp -sysPriority <Positive_Integer> -
Verify that LACP is working as expected.
show interface <Interface_ID>show channelshow LACPNoteIn some versions of Cisco Internetwork Operating System (iOS), running the switchport trunk native VLAN \<VLAN_ID> command causes the Cisco switch to tag LACP PDUs. It causes the LACP channel between the Cisco switch and the NetScaler appliance to fail. However, this issue does not affect the static link aggregation channels configured in the previous procedure.
Save configuration of all admin partitions from the default partition
Save all admin partitions from default partition by using the CLI
save ns config -all
Support for partition and cluster based custom reports
To view the custom reports of the current partition or cluster in the GUI
-
Navigate to Reporting tab.
-
Click Custom Reports to view the reports created in the current partition or in the cluster.
Support to bind VPN global certificates in a partitioned setup for OAuth IdP
To bind the certificates in Partitioned setup by using the CLI
bind vpn global [-certkeyName <string>] [-userDataEncryptionKey <string>]