Configure ICMP response suppression for virtual IP addresses
-
Improved network monitoring and troubleshooting capabilities.
-
Enhanced control over Virtual IP visibility and response behavior.
-
Flexible configuration options to match different deployment scenarios.
-
IP address related configuration
-
Virtual server related configuration
IP related configuration
-
NONE: Responds always to ICMP requests (default behavior).
-
ONE_VSERVER: Responds if at least one virtual server on the IP is UP.
-
ALL_VSERVER: Responds only if all virtual servers on the IP are UP.
-
VSVR_CNTRLD: Uses per-virtual server settings to determine response behavior.
Configure IPv4 address with ICMP response control by using CLI
add ip <IPAddress> <Netmask> -type vip -icmpresponse <NONE|ONE_VSERVER| ALL_VSERVERS|VSVR_CNTRLD>
add ns ip 3.4.5.6 255.255.255.255 -type VIP -icmpResponse NONE
add ns ip 3.4.5.7 255.255.255.255 -type VIP -icmpResponse ONE_VSERVER
add ns ip 3.4.5.8 255.255.255.255 -type VIP -icmpResponse ALL_VSERVERS
add ns ip 3.4.5.9 255.255.255.255 -type VIP -icmpResponse VSVR_CNTRLD
set ip <IPAddress> -icmpresponse <NONE|ONE_VSERVER| ALL_VSERVERS|VSVR_CNTRLD>
set ns ip 3.4.5.6 -icmpResponse ONE_VSERVER
set ns ip 3.4.5.7 -icmpResponse ALL_VSERVERS
set ns ip 3.4.5.8 -icmpResponse VSVR_CNTRLD
set ns ip 3.4.5.9 -icmpResponse NONE
unset ip <IPAddress> -icmpresponse
unset ns ip 3.4.5.6 -icmpresponse
unset ns ip 3.4.5.7 -icmpresponse
show ip <IPAddress>
show ns ip 3.4.5.6
show ns ip 3.4.5.7
Configure IPv4 address with ICMP response control by using GUI
-
Navigate to System > Network > IPs.
-
From the list of IP addresses, select the IPv4 address you want to configure.
-
Click Edit to open the IP configuration dialog.
-
Click the ICMP Response tab.
-
From the ICMP Response drop-down menu, select one of the following options:
-
NONE - No ICMP response
-
ONE_VSERVER - Response from one virtual server
-
ALL_VSERVERS - Response from all virtual servers
-
VSVR_CNTRLD - Virtual server controlled response
-
-
Click OK to save the configuration.
Configure IPv6 address with ICMP response control
add ip6 <IPv6Address>/<Prefix_length> -type vip -icmpresponse <NONE|ONE_VSERVER| ALL_VSERVERS|VSVR_CNTRLD>
add ns ip6 3f86::50/128 -type VIP -icmpResponse NONE
add ns ip6 3f86::51/128 -type VIP -icmpResponse ONE_VSERVER
add ns ip6 3f86::52/128 -type VIP -icmpResponse ALL_VSERVERS
add ns ip6 3f86::53/128 -type VIP -icmpResponse VSVR_CNTRLD
set ip6 <IPv6Address>/<Prefix_length> -icmpresponse <NONE|ONE_VSERVER| ALL_VSERVERS|VSVR_CNTRLD>
set ns ip6 3f86::50/128 -icmpResponse ONE_VSERVER
set ns ip6 3f86::51/128 -icmpResponse ALL_VSERVERS
set ns ip6 3f86::52/128 -icmpResponse VSVR_CNTRLD
set ns ip6 3f86::53/128 -icmpResponse NONE
unset ip6 <IPv6Address>/<Prefix_length> -icmpresponse
unset ns ip6 3f86::50/128 -icmpresponse
unset ns ip6 3f86::51/128 -icmpresponse
show ip6 <IPv6Address>
show ns ip6 3f86::50
show ns ip6 3f86::51
Virtual server related configuration
-
Load Balancing (LB)
-
Content Switching (CS)
-
Cache Redirection (CR)
-
Gateway/VPN virtual servers
-
PASSIVE: This virtual server doesn't influence ping decisions - NetScaler responds normally (default)
-
ACTIVE: This virtual server controls ping responses - NetScaler responds only when the service is UP.
-
Mixed PASSIVE and ACTIVE: NetScaler responds if any ACTIVE virtual server is UP (PASSIVE virtual servers are ignored in the decision)
Configure ICMP response behavior for virtual server
add lb/cs/cr/vpn vserver <name> <serviceType> <IPAddress> <port> -icmpVsrResponse <PASSIVE|ACTIVE>
add lb vserver web_vs HTTP 10.10.10.100 80 -icmpVsrResponse ACTIVE
add cs vserver content_vs HTTP 10.10.10.101 80 -icmpVsrResponse PASSIVE
add cr vserver cache_vs HTTP 10.10.10.102 80 -icmpVsrResponse ACTIVE
add vpn vserver ssl_vs SSL 10.10.10.103 443 -icmpVsrResponse PASSIVE
set lb/cs/cr/vpn vserver <name> -icmpVsrResponse <PASSIVE|ACTIVE>
set lb vserver web_vs -icmpVsrResponse PASSIVE
set cs vserver content_vs -icmpVsrResponse ACTIVE
set cr vserver cache_vs -icmpVsrResponse PASSIVE
set vpn vserver ssl_vs -icmpVsrResponse ACTIVE
unset lb/cs/cr/vpn vserver <name> -icmpVsrResponse
unset lb vserver web_vs -icmpVsrResponse
unset cs vserver content_vs -icmpVsrResponse
unset cr vserver cache_vs -icmpVsrResponse
unset vpn vserver ssl_vs -icmpVsrResponse