Logging and Monitoring DS-Lite
-
NetScaler owned IP address (NSIP address or SNIP address) from which the log message is sourced
-
Time stamp
-
Entry type (MAPPING)
-
Whether the DS-Lite LSN mapping entry was created or deleted
-
IPv6 address of B4
-
Subscriber's IP address, port, and traffic domain ID
-
NAT IP address and port
-
Protocol name
-
Destination IP address, port, and traffic domain ID might be present, depending on the following conditions:
-
Destination IP address and port are not logged for Endpoint-Independent mapping.
-
Only the destination IP address is logged for Address-Dependent mapping. The port is not logged.
-
Destination IP address and port are logged for Address-Port-Dependent mapping.
-
-
NetScaler owned IP address (NSIP address or SNIP address) from which the log message is sourced
-
Time stamp
-
Entry type (SESSION)
-
Whether the DS-Lite session is created or removed
-
IPv6 address of B4
-
Subscriber's IP address, port, and traffic domain ID
-
NAT IP address and port
-
Protocol name
-
Destination IP address, port, and traffic domain ID
-
NetScaler owned IP address (NSIP address or SNIP address) from which the log message is sourced
-
Time stamp
-
Entry type (MAPPING)
-
Whether the DS-Lite LSN mapping entry was created or deleted
-
IPv6 address of B4
-
Subscriber's IP address, port, and traffic domain ID
-
NAT IP address and port
-
Protocol name
-
Destination IP address, port, and traffic domain ID might be present, depending on the following conditions:
-
Destination IP address and port are not logged for Endpoint-Independent mapping.
-
Only the destination IP address is logged for Address-Dependent mapping. The port is not logged.
-
Destination IP address and port are logged for Address-Port-Dependent mapping.
-
-
NetScaler owned IP address (NSIP address or SNIP address) from which the log message is sourced
-
Time stamp
-
Entry type (SESSION)
-
Whether the DS-Lite session is created or removed
-
IPv6 address of B4
-
Subscriber's IP address, port, and traffic domain ID
-
NAT IP address and port
-
Protocol name
-
Destination IP address, port, and traffic domain ID
| LSN Log Entry Type | Sample Log Entry |
| DS-Lite session creation | Local4.Informational 10.102.37.115 08/14/2015:13:35:38 GMT 0-PPE-1 : default LSN LSN_SESSION 37647607 0 : SESSION CREATED 2001:DB8::3:4 Client IP:Port:TD 192.0.2.51:2552:0, NatIP:NatPort 203.0.113.61:3002, Destination IP:Port:TD 198.51.100.250:80:0, Protocol:TCP |
| DS-Lite session deletion | Local4.Informational 10.102.37.115 08/14/2015:13:38:22 GMT 0-PPE-1 : default LSN LSN_SESSION 37647617 0 : SESSION DELETED 2001:DB8::3:4 Client IP:Port:TD 192.0.2.51:2552:0, NatIP:NatPort 203.0.113.61:3002, Destination IP:Port:TD 198.51.100.250:80:0, Protocol: TCP |
| DS-Lite LSN mapping creation | Local4.Informational 10.102.37.115 08/14/2015:13:35:39 GMT 0-PPE-1 : default LSN LSN_EIM_MAPPING 37647610 0 : EIM CREATED 2001:DB8::3:4 Client IP:Port:TD 192.0.2.51:2552:0, NatIP:NatPort 198.51.100.250:80, Protocol: TCP |
| DS-Lite LSN mapping deletion | Local4.Informational 10.102.37.115 08/14/2015:13:38:25 GMT 0-PPE-1 : default LSN LSN_EIM_MAPPING 37647618 0 : EIM DELETED 2001:DB8::3:4 Client IP:Port:TD 192.0.2.51:2552:0, NatIP:NatPort 198.51.100.250:80, Protocol: TCP |
Displaying Current DS-Lite Sessions
To display all DS-Lite sessions by using the command line interface
show lsn session –nattype DS-Lite
To display selected DS-Lite sessions by using the command line interface
show lsn session –nattype DS-Lite [-clientname <string>] [-network <ip_addr> [-netmask <netmask>] [-td <positive_integer>]] [-natIP <ip_addr> [-natPort <port>]]
B4-Address SubscrIP SubscrPort SubscrTD DstIP DstPort DstTD NatIP NatPort Proto Dir
1. 2001:DB8::3:4 192.0.2.51 2552 0 198.51.100.250 80 0 203.0.113.61 3002 TCP OUT
2. 2001:DB8::3:4 192.0.2.51 3551 0 198.51.100.300 80 0 203.0.113.61 52862 TCP OUT
3. 2001:DB8::3:4 192.0.2.100 4556 0 198.51.100.250 0 0 203.0.113.61 48116 ICMP OUT
4. 2001: DB8::190 192.0.2.150 3881 0 198.51.100.199 80 0 203.0.113.69 48305 TCP OUT
Done
Configuration Using the Configuration Utility
-
Navigate to System > Large Scale NAT > Sessions, and click the DS-Lite tab.
-
For displaying DS-Lite sessions on the basis of selection parameters, click Search.
Clearing DS-Lite Sessions
To clear all DS-Lite sessions by using the command line interface
flush lsn session –nattype DS-Lite
show lsn session –nattype DS-Lite
To clear selected DS-Lite sessions by using the command line interface
flush lsn session –nattype DS-Lite [-clientname <string>] [-network <ip_addr> [-netmask <netmask>] [-td <positive_integer>]] [-natIP <ip_addr> [-natPort <port>]]
show lsn session –nattype DS-Lite
To clear all or selected DS-Lite sessions by using the configuration utility
-
Navigate to System > Large Scale NAT > Sessions, and click the DS-Lite tab.
-
Click Flush Sessions.
Logging HTTP Header Information
-
URL that the HTTP request is destined to
-
HTTP Method specified in the HTTP request
-
HTTP version used in the HTTP request
-
IPv4 address of the subscriber that sent the HTTP request
Configuration Steps
-
Create an HTTP header log profile. An HTTP header log profile is a collection of HTTP header attributes (for example, URL and HTTP method) that can be enabled or disabled for logging.
-
Bind the HTTP header to an LSN group of a DS-Lite LSN configuration. Bind the HTTP header log profile to an LSN group of an LSN configuration by setting the HTTP header log profile name parameter to the name of the created HTTP header log profile. The NetScaler appliance then logs HTTP header information of any HTTP requests related to the LSN group. An HTTP header log profile can be bound to multiple LSN groups, but an LSN group can have only one HTTP header log profile.
To create an HTTP header log profile by using the command line interface
add lsn httphdrlogprofile <httphdrlogprofilename> [-logURL ( ENABLED | DISABLED )] [-logMethod ( ENABLED | DISABLED )] [-logVersion ( ENABLED | DISABLED )] [-logHost ( ENABLED | DISABLED )]
show lsn httphdrlogprofile
To bind an HTTP header log profile to an LSN group by using the command line interface
bind lsn group <groupname> -httphdrlogprofilename <string>
show lsn group <groupname>
Sample Configuration
add lsn httphdrlogprofile HTTP-HEADER-LOG-1
Done
add lsn client LSN-DSLITE-CLIENT-1
Done
bind lsn client LSN-DSLITE-CLIENT-1 -network6 2001:DB8::3:0/100
Done
add lsn pool LSN-DSLITE-POOL-1
Done
bind lsn pool LSN-DSLITE-POOL-1 203.0.113.61 - 203.0.113.70
Done
add lsn ip6profile LSN-DSLITE-PROFILE-1 -type DS-Lite -network6 2001:DB8::5:6
Done
add lsn group LSN-DSLITE-GROUP-1 -clientname LSN-DSLITE-CLIENT-1 -portblocksize 1024 -ip6profile LSN-DSLITE-PROFILE-1
Done
bind lsn group LSN-DSLITE-GROUP-1 -poolname LSN-DSLITE-POOL-1
Done
bind lsn group LSN-DSLITE-GROUP-1 -httphdrlogprofilename HTTP-HEADER-LOG-1
Done
IPFIX Logging
-
Creation or deletion of an LSN session.
-
Creation or deletion of an LSN mapping entry.
-
Allocation or de-allocation of port blocks in the context of deterministic NAT.
-
Allocation or de-allocation of port blocks in the context of dynamic NAT.
-
Whenever subscriber session quota is exceeded.
Points to Consider before you Configure IPFIX logging
-
You must configure the AppFlow feature and IPFIX collector(s) on the NetScaler appliance. For instructions, see Configuring the AppFlow feature.
Configuration Steps
-
Enable LSN logging in the AppFlow® configuration. Enable the LSN logging parameter as part of AppFlow configuration.
-
Create an LSN log profile. An LSN log profile includes the IPFIX parameter that enables or disables the log information in IPFIX format.
-
Bind the LSN log profile to an LSN group of an LSN configuration. Bind the LSN log profile to one or multiple LSN group(s). Events related to the bound LSN group will be logged in IPFIX format.
To enable LSN logging in the AppFlow configuration by using the CLI
set appflow param -lsnLogging (ENABLED |DISABLED )
show appflow param
To create an LSN log profile by using the CLIAt the command prompt, type
set lsn logprofile <logProfileName> -logipfix ( ENABLED | DISABLED )
show lsn logprofile
To bind the LSN log profile to an LSN group of an LSN configuration by using the CLI
bind lsn group <groupname> -logProfileName <lsnlogprofilename>
show lsn group
To create an LSN log profile by using the GUI
To bind the LSN log profile to an LSN group of an LSN configuration by using the GUI
-
Navigate to System > Large Scale NAT > LSN Group, open the LSN group.
-
In Advanced Settings, click + Log Profile to bind the created Log profile to the LSN group.