Admin partition
/nsconfig/partitions/<partitionName> directory. Other partition-specific files are stored in the /var/partitions/<partitionName> directories.
-
Downloaded files:
/var/partitions/<partitionName>/download/ -
Log files:
/var/partitions/<partitionName>/log/
/var/log/ directory.
-
SSL CRL certificate related files:
/var/partitions/<partitionName>/netscaler/ssl
User access and roles
Points to remember
-
NetScaler users accessing the GUI through the NSIP address uses the default partition authentication configuration to log on to the appliance.
-
Partition system users accessing the GUI through a partition SNIP address uses partition specific authentication configuration to log on to the appliance.
-
Partition user created in a partition cannot log in using the NSIP address.
-
The NetScaler user bound to a partition cannot log in using the partition SNIP address.
-
System users authenticating through an external authentication server ( for example, LDAP, RADIUS, TACACS) must access a partition through a SNIP address.
Use case for managing role based access in a partitioned setup
Configure roles and responsibilities for partition administrators
-
Creating an Administrative Partition – Before you create partition users in an administrative partition, you must first create the partition. As a root administrator, you can create a partition from the default partition using the configuration utility or a command line interface.
-
Switching user access from default partition to partition P2 – If you are partition administrator accessing the appliance from the default partition, you can switch from default partition to a specific partition. For example, partition P2 based on user binding.
-
Adding a SNIP address to the partition user account with management access enabled-Once you have switched your access to an administration partition. You create a SNIP address and provide management access to the address.
-
Creating and binding a partition System User with Partition Command Policy-If you are a partition administrator, you can create partition users and define the scope of user access. It is done by binding the user account to partition command policies.
-
Creating and binding partition user group with partition command policy - If you are a partition administrator, you can create partition user groups and define the scope of user access control. It is done by binding the user group account to partition command policies.
Benefits of using admin partitions
-
Allows delegation of administrative ownership of an application to the customer.
-
Reduces the cost of ADC ownership without compromising on performance and ease-of-use.
-
Safeguards from unwarranted configuration changes. In a non-partitioned NetScaler appliance, authorized users of the other application can intentionally or unintentionally change configurations that are required for your application. It can lead to undesirable behavior. This possibility is reduced in a partitioned NetScaler appliance.
-
Isolates traffic between different applications by the use of dedicated VLANs for each partition.
-
Accelerates and allows application deployments to scale.
-
Allows application-level or localized management and reporting.
User case 1: How admin partition is used in an enterprise network
-
Foo.com has a single NetScaler.
-
There are five departments and each department has one application that requires to be deployed with the NetScaler.
-
Each application must be managed independently by a different set of users or administrators.
-
Other users must be restricted from accessing the configurations.
-
The application or back-end must be able to share resources like IP addresses.
-
The global IT department must be able to control NetScaler-level settings which must be common to all partitions.
-
Applications must be independent of one another. An error in the configuration of one application must not affect the other.
Use case 2: How an admin partition is used by a service provider
-
BigProvider has 5 customers: 3 small enterprises and 2 large enterprises.
-
SmallBiz, SmallerBiz, and StartupBiz need only the most basic NetScaler functionality.
-
BigBiz and LargeBiz are larger enterprises and have applications that attract heavy traffic. They would like to use some of the more complex NetScaler functionality.
-
Using a NetScaler SDX appliance to bring up dedicated NetScaler instances for BigBiz and LargeBiz.
-
Using a single NetScaler which is partitioned into three partitions, one each for SmallBiz, SmallerBiz, and StartupBiz.