Configuring and Using Variables
To configure variables by using the command line interface
-
Create a variable.
add ns variable <name> -type <string> [-scope global] [-ifFull ( undef | lru )] [-ifValueTooBig ( undef | truncate )] [-ifNoValue ( undef | init )] [-init <string>] [-expires <positive_integer>] [-comment <string>]
add ns variable my_counter –type ulong -init 1
add ns variable user_privilege_map -type map(text(15),text(10),10000)
add ns assignment <name> -variable <expression> [-set <expression> | -add <expression> | -sub <expression> | -append <expression> | -clear] [-comment <string>]
add ns assignment inc_my_counter -variable $my_counter -add 1
add ns assignment set_user_privilege -variable $user_privilege_map[client.ip.src.typecast_text_t] -set sys.http.callout(get_user_privilege)
-
Invoke the variable assignment in a policy.There are two functions that can operate on map variables.
-
$name.valueExists(key-expression). Returns true if there is a value in the map selected by the key-expression. Otherwise returns false. This function will update the expiration and LRU information if the map entry exists, but will not create a new map entry if the value does not exist.
-
$name.valueCount. Returns the number of values currently held by the variable. This is the number of entries in a map. For a singleton variable, this is 0 if the variable is uninitialized or 1 otherwise.
Example: Invoke the assignment named "set_user_privilege" with a compression policy. -
add cmp policy set_user_privilege_pol -rule $user_privilege_map.valueExists(client.ip.src.typecast_text_t).not -resAction set_user_privilege
Use Case to Insert HTTP header in the Response Side
add ns variable http_req_data -type text(100) -scope transaction
add ns assignment set_http_req_data -variable $http_req_data -set http.req.body(100)
add rewrite action act_ins_header insert_http_header user_name $http_req_data.after_str("user_name").before_str("password")
add rewrite policy pol_set_variable true set_http_req_data
bind rewrite global pol_set_variable 10 -type req_dEFAULT
add rewrite policy pol_ins_header true act_ins_header
bind rewrite global pol_ins_header 10 -type res_dEFAULT
Assignment action
GET /client-access?<client-IP-address> which returns a response with “BLOCK” or “ALLOW” in the body. The HTTP callout is configured to include the IP address of the client that is associated with an incoming request. When the NetScaler appliance receives a request from a client, the appliance generates the callout request and sends it to the callout server, which hosts a database of blacklisted IP addresses and an HTTP callout agent that checks whether the client’s IP address is listed in the database. The HTTP callout agent receives the callout request, checks whether the client’s IP address is listed, and sends a response. The response is a status code, 200, 302 along with “BLOCK” or “ALLOW” in the body. Based on the status code, the appliance performs the policy evaluation. If the policy evaluation is true, the assignment action is triggered immediately and action sets the value to the variable. The appliance uses and sets this variable value for subsequent policy evaluation in the same module.
Use case for configuring assignment action
-
The access decision is provided by a separate web service, with the request which returns a response with BLOCK or ALLOW in the body.
GET /url-service>/url-allowed?<URL path> -
Set up a map variable to hold the access decisions for URLs.
add ns variable url_list_map -type 'map(text(1000),text(10),10000)' -
Set up an HTTP callout to send the access request to the web service.
add policy httpCallout url_list_callout -vserver url_vs -returnType TEXT -urlStemExpr '"/url-allowed?" + HTTP.REQ.URL.PATH' -resultExpr 'HTTP.RES.BODY(10)' -
Set up an assignment action to invoke the callout to get the access decision and assign it to the map entry for the URL.
add ns assignment client_access_assn -variable '$client_access_map[CLIENT.IP.SRC.TYPECAST_TEXT_T]' -set SYS.HTTP_CALLOUT(client_access_callout) -
Set up a responder action to send a 403 response if a URL request is blocked.
add responder action url_list_block_act respondwith '"HTTP/1.1 403 Forbidden\\r\\n\\r\\n"' -
Set up a responder policy to set the map entry for the URL if it is not already set. With the immediate action enhancement, the map entry value is set when this policy is evaluated. Prior to the enhancement, the assignment was not done until all responder policies had been evaluated decision is provided by a separate web service.
add responder policy url_list_assn_pol '!$url_list_map.VALUEEXISTS(HTTP.REQ.URL.PATH)' url_list_assn -
Set up a responder policy to block access to a URL if its map entry value is BLOCK. With the immediate action enhancement, the map entry set by the preceding policy is available for use in this policy. Prior to the enhancement, the map entry would still be unset at this point.
add responder policy client_access_block_pol '$client_access_map[CLIENT.IP.SRC.TYPECAST_TEXT_T] == "BLOCK"' client_access_block_act -
Bind the responder policies to the virtual server. Note: We cannot globally bind the policies because we don't want to execute them for the HTTP callout on a separate virtual server.
bind lb vserver vs -policyName client_access_assn_pol -priority 10 -gotoPriorityExpression NEXT -type REQUESTbind lb vserver vs -policyName client_access_block_pol -priority 20 -gotoPriorityExpression END -type REQUEST
To configure variables by using the configuration utility
-
Navigate to AppExpert > NS Variables, to create a variable.
-
Navigate to AppExpert > NS Assignments, to assign value(s) to the variable.
-
Navigate to the appropriate feature area where you want to configure the assignment as an action.