Policy extensions
-
Adding customized functions to existing Policies.
-
Implementing logical constructs for complex customer requirements.
| Policy Type | Mapped Policy Type | Output |
|---|---|---|
| TEXT_T | NSTEXT | String |
| BOOL_AT | NSBOOL | Boolean |
| NUM_AT | NSNUM | Number (double-precision floating point) |
| DOUBLE_AT | NSDOUBLE | Number (double-precision floating point) |
Prerequisites for using policy extensions
-
The function name must start with a letter and may contain numbers or underscores.
-
The function name is treated as case insensitive by NetScaler policies.
-
The function must return a single value even if the extension language returns multiple values.
-
Functions with a variable number of arguments are not supported.
How do policy extensions work?
-
The extension file is validated for syntax and other conditions.
-
If the validation fails, the error is reported to the user.
-
If the validation succeeds, the extension file is imported to the NetScaler appliance and its contents can be used in policy expressions, just like any built-in policy function
-
If the policy expression evaluation returns an error during runtime, it is reported as an undef event and the associated error counter is incremented.Note: If a policy undef event occurs and the policy rule contains one or more policy extension functions, the
show ns extension <name>command displays the undef hits when applied to those policy extensions. If the extension function is aborted, the abort counter value is incremented. -
If the policy expression evaluation is successful, expression evaluation resumes until the entire expression is evaluated, or until it is aborted because of an error.
-
-
Excessive CPU usage on the NetScaler appliance.
-
Excessive memory usage on the NetScaler appliance.
-
Usage of harmful built-in libraries or third-party libraries or binaries.
-
Long-running scripts that could potentially cause the NetScaler appliance to reboot.