Use a specified source IP for back-end communication
-
A server can distinguish monitor probes from traffic if the source IP address used for monitor probes belongs to a specific set.
-
To improve server security, a server might be configured to respond to requests from a specific set of IP addresses or, sometimes, from a single specific IP address. In such a case, the appliance can use only the IP addresses accepted by the server as the source IP address.
-
The appliance can manage its internal connections efficiently if it can distribute its IP addresses into IP sets and use an address from a set only for connecting to a specific service.
-
When NetScaler uses a VIP address to communicate with a server, it uses session entries to identify whether the traffic destined to the VIP address is a response from a server or a request from a client.
-
You can bind a net profile to NetScaler Gateway VPN virtual servers. However, you need to note some points when binding a net profile. For more information, see Points to note when binding a net profile to VPN virtual server.
-
The net profile IPs bound to a service or service group are not only used for sending traffic towards the corresponding back-end servers, but also for the DNS requests that are triggered by any unresolved back-end FQDN.
Usage of a net profile for sending traffic
-
If there is no net profile on the virtual server or the service or service group, the appliance uses the default method.
-
If there is a net profile only on the service or service group, the appliance uses that net profile.
-
If there is a net profile only on the virtual server, the appliance uses the net profile.
-
If there is a net profile both on the virtual server and service or service group, the appliance uses the net profile bound to the service or service group.
-
If there is a net profile bound to the monitor, the appliance uses the net profile of the monitor. It ignores the net profiles bound to the virtual server or service or service group.
-
If there is no net profile bound to the monitor,
-
If there is a net profile on the service or service group, the appliance uses the net profile of the service or service group.
-
If there is no net profile even on the service or service group, the appliance uses the default method of selecting a source IP address.
-
If there is no net profile configured on the service or service group but configured on the virtual server, the appliance will not use the virtual server’s net profile. Instead, it uses the default method of selecting a source IP address.
-
-
Create IP sets from the pool of SNIPs and VIPs owned by the NetScaler appliance. An IP set can consist of both SNIP and VIP addresses. For instructions, see Creating IP Sets.
-
Create net profiles. For instructions, see Creating a Net Profile.
-
Bind the net profiles to the appliance entities. For instructions, see Binding a Net Profile to a NetScaler Entity.
-
A net profile can have only the IP addresses specified as SNIP and VIP on the NetScaler appliance.
-
Source IP persistence is not honored for NetScaler initiated packets.
Manage net profiles
-
For instructions on creating a network profile, see Creating a Network Profile.
-
For instructions on binding a network profile to a NetScaler entity, see Binding a Net Profile to a NetScaler Entity.
Create an IP set
To create an IP set by using the CLI
add ipset <name>
bind ipset <name> <IPAddress>
bind ipset <name> <IPAddress>
show ipset [<name>]
Examples
1.
> add ipset skpnwipset
Done
> bind ipset skpnwipset 21.21.20.1
Done
2.
> add ipset testnwipset
Done
> bind ipset testnwipset 21.21.21.[21-25]
IPAddress "21.21.21.21" bound
IPAddress "21.21.21.22" bound
IPAddress "21.21.21.23" bound
IPAddress "21.21.21.24" bound
IPAddress "21.21.21.25" bound
Done
3.
> bind ipset skpipset 11.11.11.101
ERROR: Invalid IP address
[This IP address could not be added because this is not an IP address owned by the NetScaler appliance]
> add ns ip 11.11.11.101 255.255.255.0 -type SNIP
ip "11.11.11.101" added
Done
> bind ipset skpipset 11.11.11.101
IPAddress "11.11.11.101" bound
Done
4.
> sh ipset
1) Name: ipset-1
2) Name: ipset-2
3) Name: ipset-3
4) Name: skpnewipset
Done
5.
> sh ipset skpnewipset
IP:21.21.21.21
IP:21.21.21.22
IP:21.21.21.23
IP:21.21.21.24
IP:21.21.21.25
Done
To create an IP set by using the GUI
Create a net profile
To create a net profile by using the CLI
add netprofile <name> [-srcIp <srcIpVal>]
set netprofile command.
Examples
add netprofile skpnetprofile1 -srcIp 21.21.20.1
Done
add netprofile baksnp -srcIp bakipset
Done
set netprofile yahnp -srcIp 12.12.23.1
Done
set netprofile citkbnp -srcIp citkbipset
Done
Bind a net profile to a NetScaler entity
To bind a net profile to a server by using the command line interface
set lb vserver <name> -netProfile <net_profile_name>
set cs vserver <name> -netProfile <net_profile_name>
Examples
set lb vserver skpnwvs1 -netProfile gntnp
Done
set cs vserver mmdcsv -netProfile mmdnp
Done
To bind a net profile to a virtual server by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers, and open the virtual server.
-
In Advanced Settings, click Profiles, and set a net profile.
To bind a net profile to a service by using the CLI
set service <name> -netProfile <net_profile_name>
Example
set service brnssvc1 -netProfile brnsnp
Done
To bind a net profile to a service by using the GUI
-
Navigate to Traffic Management > Load Balancing > Services, and open a service.
-
In Advanced Settings, click Profiles, and set a net profile.
To bind a net profile to a service group by using the CLI
set servicegroup <serviceGroupName> -netProfile <net_profile_name>
Example
set servicegroup ndhsvcgrp -netProfile ndhnp
Done
To bind a net profile to a service group by using the GUI
-
Navigate to Traffic Management > Load Balancing > Service Groups, and open a service group.
-
In Advanced Settings, click Profiles, and set a net profile.
To bind a net profile to a monitor by using the CLI
set monitor <monitor_name> -netProfile <net_profile_name>
Example
set monitor brnsecvmon1 -netProfile brnsmonnp
Done
To bind a net profile to a monitor by using the GUI
-
Navigate to Traffic Management > Load Balancing > Monitors.
-
Open a monitor, and set the net profile.