To communicate with other NetScaler appliances, each appliance requires knowledge of the other appliances, including how to authenticate on NetScaler appliance. RPC nodes are internal system entities used for system-to-system communication of configuration and session information. One RPC node exists on each NetScaler appliance and stores information, such as the IP addresses of the other NetScaler appliance and the passwords used for authentication. The NetScaler appliance that contacts the other NetScaler appliance checks the password within the RPC node.
After you upgrade a NetScaler appliance to release 13.1 build 33.x or later from one of the following builds, the secure option for the RPC node is enabled or disabled on the basis of the TLS 1.2 setting (enabled or disabled) present for the internal RPCS and KRPCS services.
The RPC communication is encrypted between the NetScaler nodes of the following setups if the Secure option is enabled:
-
High availability
-
Cluster
-
GSLB
The secure option uses secure protocol TLS1.2 and port numbers 3008 and 3009 for the RPC connection between the NetScaler nodes.
For ensuring secure RPC communication, Citrix® recommends performing the following operations before upgrading these setups:
You can enable or disable the secure option using the NetScaler CLI or the GUI.