Typically, a GSLB setup has a few data centers with a GSLB site configured for each data center. In each NetScaler, participating in GSLB, configure one GSLB site as a local site and the others as remote sites. When you add another GSLB site at a later point, you must ensure that the configuration across all GSLB sites is identical. You can use the NetScaler's GSLB configuration synchronization option to synchronize the configuration across the GSLB sites.
The NetScaler appliance from which you use the synchronization option is referred to as the 'main site' and the GSLB sites on which the configuration is copied as the 'subordinate sites'. When you synchronize a GSLB configuration, the configurations on all the GSLB sites participating in the GSLB setup are made similar to the configuration on the main site.
Synchronization is done only on the parent sites. Synchronization does not affect GSLB child sites' configuration. This is because the parent site and the child site configurations are not identical. The child sites configuration consists only of its own and its parent site's details. Also, GSLB services are not always required to be configured in the child sites.
-
The main node finds the differences between the configuration of the main node and subordinate node, and changes the configuration of the subordinate node to make it similar to the main node.
If you force a synchronization (use the 'force sync' option), the appliance deletes the GSLB configuration from the subordinate node and then configures the subordinate to make it similar to the main node.
-
During synchronization, if a command fails, synchronization is not aborted and the error message are logged into a .err file in the /var/netscaler/gslb directory.
-
Synchronization is done only on the parent sites. Synchronization does not affect the GSLB child sites' configuration. This is because the parent site and the child site configurations are not identical. The child sites configuration consists only of its own and its parent site's details. Also, GSLB services are not always required to be configured in the child sites.
-
If you disable the internal user login, the GSLB auto sync uses the SSH keys to synchronize the configuration. But, to use GSLB auto sync in the partition environment, you must enable the internal user login and make sure that the partition user name in the local and remote GSLB sites is the same.
-
On the remote GSLB site RPC node, configure the firewall to accept auto-sync connections by specifying the remote site IP (cluster IP address for cluster setup) and port (3010 for RPC and 3008 for secure RPC). If the default route to reach the remote sites is in the management subnet, as in most cases, then NSIP is used as the source IP address.
To configure a different source IP address, you must have the GSLB site IP address and the SNIP in a different subnet. Also, you must have an explicit route defined to the remote site IP address through a GSLB site IP subnet.
For enhanced security, Citrix recommends that you change the internal user account and RPC node passwords. Internal user account password is changed through RPC node password. For details, see
Change an RPC node password.
If you use the saveconfig option, the sites that participate in the synchronization process automatically save their configuration, in the following way:
On the remote GSLB site RPC node, configure the firewall to accept auto-sync connections by specifying the remote site IP (cluster IP address for cluster setup) and port (3010 for RPC and 3008 for secure RPC). If the default route to reach the remote sites is in a management subnet, as in most cases, then NSIP is used as the source IP address.
To configure a different source IP address, you must have the GSLB site IP address and the SNIP in a different subnet. Also, you must have an explicit route defined to the remote site IP address through the GSLB site IP subnet. The source IP address cannot be synchronized across the sites participating in GSLB because the source IP address for an RPC node is specific to each NetScaler appliance. Therefore, after you force a synchronization (using the sync gslb config -forceSync command or by selecting the ForceSync option in the GUI), you have to manually change the source IP addresses on the other NetScaler appliances. Port 22 is also required for synchronizing the database files to the remote site.