Create SVCB and HTTPS records for a domain name
-
Reduced connection latency
-
Improved performance for HTTP-based applications
-
Native support for modern DNS standards
-
NetScaler 14.1-72.x and above deployments using:
-
Authoritative DNS (ADNS): Records are locally configured and served directly
-
Proxy Mode: Queries are forwarded to backend DNS servers, with responses cached for improved performance
-
Resolver Mode: Acts as a recursive DNS server (end resolver) that resolves domain names by querying root servers, caching results, and traversing the DNS hierarchy
-
Supported across standalone, HA, and cluster configurations.
-
-
HTTPS records are a specialized form of SVCB records and follow the same configuration model.
-
Multiple SVCB/HTTPS records can be configured per domain using priority values.
-
Lower priority values indicate preferred endpoints.
-
NetScaler version: 14.1 build 72.x or later
-
DNS feature enabled
-
For DNSSEC use cases, DNSSEC must be configured and enabled
Configure SVCB and HTTPS records by using CLI
add dns svcbRec <domain> -priority <value> -targetName <target-domain> -svcbType SVCB
add dns svcbRec <domain> -priority <value> -targetName <target-domain> -svcbType HTTPS -alpn h2 -port 443
show dns svcbRec
show dns svcbRec -svcbType HTTPS
Configure SVCB and HTTPS Records by using GUI
-
Navigate to Traffic Management > DNS > Records > SVCB Records.
-
Enter the details and click OK.
Limitations
-
Custom parameters: Custom SVCB parameter sets (
svcbParamSet) are not supported. Only standard parameters defined in RFC 9460 are supported. -
Unsupported RFC parameters: Parameters defined in RFCs later than RFC 9460 are not supported, including:
-
dohpath -
ohttp -
tls-supported-groups -
docpath
-
-
DNS answer logging: DNS answer logging includes only the priority and target name. Service parameters are not logged.
Use cases
Encrypted ClientHello (ECH)
HTTP/2 and HTTP/3 discovery
h2 or h3, in DNS, enabling clients to connect by using the most efficient protocol immediately.
QUIC and modern transport bootstrapping
Alternate and optimized service endpoints
0, act similarly to CNAME records but offer several advantages in many applications:
-
Zone apex aliasing (root domain redirection): CNAME records cannot coexist with other records at the root domain. AliasMode records work like a CNAME but allow redirecting the root domain to a CDN or Cloud Provider without violating DNS standards. This enables MX and TXT/SPF records to coexist and remain functional.
-
Delegating web traffic to a CDN or Cloud Provider: This mode can be used to delegate operational control of a service to a third-party provider.
-
Service-specific redirection: AliasMode can be used to redirect specific, non-default services, such as
_8443._https.example.comtobackend.example.net.
.. This setting specifies that the service parameters, such as ALPN and port, apply directly to the domain name queried. This provides advantages such as apex domain optimization, where all the properties apply to the apex instead of individual subdomains.