You can perform the following tasks to configure a URL set and restrict URLs on a NetScaler platform:
-
Import a URL set (download and encrypt it). Importing a URL set in a NetScaler appliance allows you:
-
To download the URL file.
-
To add the file to the appliance.
-
To encrypt the file. Until you add the URL set to the system, it is not visible to the user.
You can download a set in the following ways:
-
Download a URL set once from a remote server and specify it as http://myserver.com/file_with_urlset.csv
-
add a file under the /var/tmp/ path inside ADC and use the command, as in the example:
> shell cat /var/tmp/test_urlset.csv
example.com
google.com
> import policy urlset top10
k -url local:test_urlset.csv -delimiter "," -rowSeparator "n" -interval 10 -privateSet -canaryUrl http://www.in.gr
Done
The imported URL set is further categorized into different categories and category groups in the database. This is valid only if categories exist in the metadata of the URL set file.
Note: There can be a chance that you might have URL patterns without metadata.
Once you have imported the file, you can update, delete, or display file properties. After the file is pushed into the appliance, you can modify the entries by more adding rows.
The imported set is then stored in an encrypted file format on the NetScaler directory. The imported list contains millions of URL entries. To the following 'The imported list can contain up to 1 million URL entries. Otherwise, the appliance returns an error message saying that the value exceeds the limit. If the imported URL set has blacklisted entries with metadata, the metadata it is detected by the appliance when it is imported.
Once you import a URL set and add it into the appliance, the URL set is available for advanced policies to identify the correct URL set during incoming URL evaluation. HTTP.REQ.HOSTNAME.APPEND(HTTP.REQ.URL).URLSET_MATCHES_ANY(<URL set name>)
-
Updating a URL set on the NetScaler appliance. Once you have pushed the file into the appliance, at this interval you can manually update a URL file by using command line interface.
-
Exporting a URL set. If you prefer a backup of the URL set, you can export the list of URL patterns and save a copy of it to a destination URL. Before you export, check whether the URL set is marked as private. If is marked private, the URL set cannot be exported. Export functionality does not work with private set. So a new url set myurl would be imported without private set defined, and then it would be exported to another file in a local path, as below:
> shell touch /var/tmp/test_urlset_export.csv
Done
> shell cat /var/tmp/test_urlset_export.csv
Done
> shell cat /var/tmp/test_urlset.csv
example.com
google.com
Done
> export urlset myurl -url local:test_urlset_export.csv
> import urlset myurl -url local:test_urlset.csv
Done
(a non-private urlset is imported)
-
Removing a URL set. If you want to delete a URL set of blacklisted entries, you can use the remove command to delete the URL set from the NetScaler appliance.
-
Displaying a URL set. You can display the properties of a URL set by using the show command.
Note: URLs with query part are removed during import.
Example:
show urlset
Name: top100 PatternCount: 100 Delimiter: RowSeparator: Interval: 0
Done