Advanced policy expressions: IP and MAC addresses, throughput, VLAN IDs
Expressions for IP addresses and IP subnets
client.ip.src.in_subnet(147.1.0.0/16)
- add rewrite action URL1-rewrite-action replace "http.req.header(\"Host\")" "\"www.mycompany1.com\""
- add rewrite policy URL1-rewrite-policy "http.req.header(\"Host\").contains(\"www.test1.com\") && client.ip.src.in_subnet(147.1.0.0/16)" URL1-rewrite-action
- add rewrite action URL2-rewrite-action replace "http.req.header(\"Host\")" "\"www.mycompany2.com\""
- add rewrite policy URL2-rewrite-policy "http.req.header(\"Host\").contains(\"www.test2.com\") && client.ip.src.in_subnet(10.202.0.0/16)" URL2-rewrite-action
Prefixes for IPV4 addresses and IP subnets
| Prefix | Description |
|---|---|
| CLIENT.IP.SRC | Returns the source IP of the current packet as an IP address or as a number. |
| CLIENT.IP.DST | Returns the destination IP of the current packet as an IP address or as a number. |
| SERVER.IP.SRC | Returns the source IP of the current packet as an IP address or as a number. |
| SERVER.IP.DST | Returns the destination IP of the current packet as an IP address or as a number. |
Operations for IPV4 Addresses
About IPv6 expressions
9901:0ab1:22a2:88a3:3333:4a4b:5555:6666
http://[9901:0ab1:22a2:88a3:3333:4a4b:5555:6666]/
https://[9901:0ab1:22a2:88a3:3333:4a4b:5555:6666]:8080/
client.ipv6.src + server.ip.dst
ABCD:1234::ABCD, and the server destination IPv4 address is 10.100.10.100, the preceding expression returns "ABCD:1234::ABCD10.100.10.100".
Expression prefixes for IPv6 addresses
| Prefix | Description |
|---|---|
| CLIENT.IPV6 | Operates on the IPv6 address in with the current packet. |
| CLIENT.IPV6.DST | Returns the IPv6 address in the destination field of the IP header. |
| CLIENT.IPV6.SRC | Returns the IPv6 address in the source field of the IP header. Following are examples: client.ipv6.src.in_subnet(2007::2008/64) client.ipv6.src.get1.le(2008) |
| SERVER.IPV6 | Operates on the IPv6 address in with the current packet. |
| SERVER.IPV6.DST | Returns the IPv6 address in the destination field of the IP header. |
| SERVER.IPV6.SRC | Returns the IPv6 address in the source field of the IP header. Following are examples: server.ipv6.src.in_subnet(2007::2008/64) server.ipv6.src.get1.le(2008) |
Operations for IPv6 prefixes
| IPv6 Operation | Description |
|---|---|
<ipv6>.EQ(<IPv6_address> |
Returns a Boolean TRUE if the IP address value is same as the <IPv6_address> argument. Following is an example: client.ipv6.dst.eq(ABCD:1234::ABCD) |
<ipv6>.GET1. . .GET8 |
Returns a segment of an IPv6 address as a number. The following example expressions retrieve segments from the ipv6 address 1000:1001:CD10:0000:0000:89AB:4567:CDEF: client.ipv6.dst.get5 extracts 0000, which is the fifth set of bits in the address. client.ipv6.dst.get6 extracts 89AB. client.ipv6.dst.get7 extracts 4567. You can perform numeric operations on these segments. Note that you cannot perform numeric operations when you retrieve an entire IPv6 address. This is because expressions that return an entire IPv6 address, such as CLIENT.IPV6.SRC, return the address in text format. |
<ipv6>.IN_SUBNET(<subnet>) |
Returns a Boolean TRUE if the IPv6 address value is in the subnet specified by the <subnet> argument. Following is an example: client.ipv6.dst.eq(1000:1001:CD10:0000:0000:89AB:4567:CDEF/60) |
<ipv6>.IS_IPV4 |
Returns a Boolean TRUE if this is an IPv4 client, and returns a Boolean FALSE if it is not. |
<ipv6>.SUBNET(<n>) |
Returns the IPv6 address after applying the subnet mask specified as the argument. The subnet mask can take values between 0 and 128. For example: CLIENT.IPV6.SRC.SUBNET(24) |
Expressions for MAC addresses
Prefixes for MAC addresses
| Prefix | Description |
|---|---|
client.ether.dstmac |
Returns the MAC address in the destination field of the Ethernet header. |
client.ether.srcmac |
Returns the MAC address in the source field of the Ethernet header. |
Operations for MAC addresses
| Prefix | Description |
|---|---|
<mac address>.EQ(<address>) |
Returns a Boolean TRUE if the MAC address value is same as the <address> argument. |
<mac address>.GET1. . .GET4 |
Returns a numeric value extracted from the segment of the MAC address that is specified in the GET operation. For example, if the MAC address is 12:34:56:78:9a:bc, the following returns 34: client.ether.dstmac.get2 |
Expressions for numeric client and server data
| Prefix | Description |
|---|---|
| client.interface.rxthroughput | Returns an integer representing the raw received traffic throughput in kilobytes per second (KBps) for the previous seven seconds. |
| client.interface.txthroughput | Returns an integer representing the raw transmitted traffic throughput in KBps for the previous seven seconds. |
| client.interface.rxtxthroughput | Returns an integer representing the raw received and transmitted traffic throughput in KBps for the previous seven seconds. |
| server.interface.rxthroughput | Returns an integer representing the raw received traffic throughput in KBps for the previous seven seconds. |
| server.interface.txthroughput | Returns an integer representing the raw transmitted traffic throughput in KBps for the previous seven seconds. |
| server.interface.rxtxthroughput | Returns an integer representing the raw received and transmitted traffic throughput in KBps for the previous seven seconds. |
| server.vlan.id | Returns a numeric ID of the VLAN through which the current packet entered the NetScaler. |
| client.vlan.id | Returns a numeric ID for the VLAN through which the current packet entered the NetScaler. |