IP Tunnels
-
NetScaler as an Encapsulator (Load Balancing with DSR Mode): Consider an organization that has multiple data centers across different countries, where the NetScaler maybe at one location and the back-end servers are located in a different country. In essence, the NetScaler and the back-end servers are on different networks and are connected via a router.When you configure Direct Server Return (DSR) on this NetScaler, the packet sent from the source subnet is encapsulated by the NetScaler and sent via a router and tunnel to the appropriate back-end server. The back-end server decapsulates the packet and responds directly to the client, without allowing the packet to pass via the NetScaler.
-
NetScaler as a Decapsulator: Consider an organization having multiple data centers each having NetScalers and back-end servers. When a packet is sent from data center A to data center B it is usually sent via an intermediary, say a router or another NetScaler. The NetScaler processes the packet and then forwards the packet to the back-end server. However, if an encapsulated packet is sent, the NetScaler must be able to decapsulate the packet before sending it to the back-end servers. To enable the NetScaler to function as a decapsulator, a tunnel is added between the router and the NetScaler. When the encapsulated packet, with additional header information, reaches the NetScaler, the data packet is decapsulated i.e. the additional header information is removed, and the packet is then forwarded to the appropriate back-end servers.The NetScaler can also be used as a decapsulator for the Load Balancing feature, specifically in scenarios when the number of connections on a vserver exceeds a threshold value and all the new connections are then diverted to a back-up vserver.
Configure IP Tunnels
CLI procedures
-
add iptunnel \<name> \<remote> \<remoteSubnetMask> \<local> -type -protocol (ipoverip | GRE)
-
show iptunnel
-
add ip6tunnel \<name> \<remoteIp> \<local>
-
show ip6tunnel
GUI procedures
Customizing IP Tunnels Globally
CLI procedures
-
show ipTunnelParam
> set iptunnelparam –srcIP 12.12.12.22 -dropFrag Yes –dropFragCpuThreshold 50
Done
> set iptunnelparam -srcIPRoundRobin YES -dropFrag Yes –dropFragCpuThreshold 50
Done
-
show ip6tunnelparam
GUI procedures
-
Navigate to System > Network, in the Settings group, click IPv6 Tunnel Global Settings.
-
In the Configure IP Tunnel Global Parameters dialog box, set the parameters.
-
Navigate to System > Network, in the Settings group, click IPv6 Tunnel Global Settings.
-
In the Configure IP Tunnel Global Parameters dialog box, set the parameters.
GRE Payload Options in a GRE IP Tunnel
-
Ethernet with DOT1Q. Carry the Ethernet header as well the VLAN header. This is the default setting. For a tunnel bound to a netbridge, inner Ethernet header and VLAN header contains information from the ARP and bridge table of the NetScaler appliance. For a tunnel set as a next hop to a PBR rule, Inner Ethernet destination MAC address is set to zero and the VLAN header specifies the default VLAN. The encapsulated (GRE) packet sent from the NetScaler tunnel end point has the following format:localized image
-
Ethernet. Carry the Ethernet header but drop the VLAN header. Because the packets do not carry any VLAN information in the tunnel, for a tunnel with this setting and bound to a netbridge, you must bind an appropriate VLAN to the netbridge so that on receiving any packets on the tunnel, the NetScaler can forward these packet to the specified VLAN. If the tunnel is set as a next hop in a PBR rule, the NetScaler routes the packets that are received on the tunnel. The encapsulated (GRE) packet sent from the NetScaler tunnel end point has the following format:localized image
-
IP. Drop the Ethernet header as well as the VLAN header. Because tunnels with this setting do not carry Layer 2 headers, these tunnels cannot be bound to a netbridge but can be set as a next hop in a PBR rule. The peer tunnel endpoint device on receiving the packet either consumes or routes it. The encapsulated (GRE) packet sent from the NetScaler tunnel end point has the following format:localized image
-
show iptunnel \<tunnelname>
> add iptunnel IPTUNNEL-1 203.0.113.133 255.255.255.0 198.51.100.15 –protocol GRE –grepayload Ethernet -ipsecProfileName IPTUNNEL-IPSEC-1
Done
IPv6 Traffic through GRE IPV4 Tunnels
-
add ipTunnel \<name> \<remote> \<remoteSubnetMask> \<local> -protocol GRE
-
show ipTunnel \<name>
-
add ns pbr6 \<pbrName> ALLOW -srcIPv6 \<network-range> -dstIPv6 \<network-range> -ipTunnel \<tunnelName>
-
show pbr
Sample configuration
> add ipTunnel TUNNEL-V6onV4 10.10.6.30 255.255.255.255 10.10.5.30 -protocol GRE
-ipsecProfileName None
Done
> add ns pbr6 PBR6-V6onV4 ALLOW -srcIPv6 = 2001:0db8:1::1-2001:0db8:1::255 -destIPv6 =
1-2001:0db8:4::255 -ipTunnel TUNNEL-V6onV4
Send Response Traffic Through an IP-IP Tunnel
CLI procedures
-
add ns pbr \<pbr_name> ALLOW -srcIP = \<local_subnet_range> -destIP = \<remote_subnet_range> -ipTunnel \<tunnel_name>
-
apply ns pbrs
-
show ns pbr \<pbr_name>
-
enable ns mode MBF
-
show ns mode
GUI procedures
-
Navigate to System > Network > PBRs. On the PBRs tab, create a PBR rule.
-
While creating the PBR, set the Next Hop Type to IP tunnel and IP Tunnel Name to the configured IP-IP tunnel name.
-
Navigate to System > Settings, in Modes and Features, click Configure Modes.
-
On the Configure Modes page, select MAC-based forwarding.
Sample configuation
> add iptunnel NS1-NS2-IPIP 192.0.2.99 255.255.255.255 203.0.113.99–protocol IPIP
Done
> add pbr NS1-NS2-IPIP-PBR -srcIP 10.102.147.0-10.102.147.255 –destIP 10.20.1.0-10.20.1.255 –ipTunnel NS1-NS2-IPIP
Done
> apply pbrs
Done
> enable ns mode MBF
Done