Understanding default traffic plane behavior and override mechanisms
-
Net profile-based overrideA Net profile is a configuration object that forces a service or action to use a specific source IP address for outbound connections. When you assign a source IP (SNIP) from the target plane, NetScaler uses that plane's routing and network configuration, such as TD 0 for the Data plane or TD 4094 for the Management plane. This directs Net profile traffic through the selected plane. This method is commonly used to redirect traffic for services like Syslog, RADIUS, and LDAP.
-
Virtual server-based overrideCertain features or services are bound directly to a virtual server, such as a Load Balancing virtual server. Configure or bind services to a virtual server in your desired plane to direct feature traffic toward the target plane.
-
Policy-based routing (PBR) overridePolicy-based routing (PBR) provides a flexible way to redirect traffic using rules that filter traffic attributes such as source and destination IP, port, and protocol. PBR lets you intercept specific traffic flows and route them explicitly to a different Traffic Domain (TD) from their default assignment, with an optional next-hop gateway specification. This ensures precise control over traffic routing across planes.
Default traffic plane assignment and override methods for NetScaler features
| Feature | Default Traffic Plane | Override Methods | Override Implementation |
|---|---|---|---|
| AAA | Data plane | Virtual server-based override | Creates a backend authentication and authorization server service explicitly in the Management plane (TD 4094), allowing a Data plane LB virtual server to proxy to it. |
| Policy Based Routings (PBR) override | Uses PBR to explicitly force authentication and authorization traffic to the Management Traffic Domain (TD 4094). | ||
| Policy-based routing (PBR) override | For VPX on Linux platforms, user-defined authentication and authorization servers on non-standard ports require a PBR override rule to route authentication and authorization traffic through the appropriate plane. | ||
| User-defined monitors (VPX on Linux) | Data plane | Policy-based routings (PBR) override | For VPX on Linux platforms, user-defined monitors require a PBR override rule to route monitor traffic through the appropriate plane. |
| Application Firewall | Data plane | Virtual server-based override | Uses a Data plane LB virtual server to proxy APPFW import and update queries to backend APPFW servers in the Management plane. |
| PBR override | Intercepts APPFW traffic destined for a server and forces it into the Management Traffic Domain (TD 4094). | ||
| DNS | Data plane | Net profile-based override | Forces DNS queries to originate from the Management IP (NSIP), routing them through the Management plane. |
| Virtual server-based override | Uses a Data plane DNS load balancing virtual server to proxy queries to Management plane DNS resolvers, bridging the planes. | ||
| PBR override | Intercepts DNS traffic and forces it into the Management Traffic Domain (TD 4094). | ||
| IP Reputation | Data plane | Virtual server-based override | Uses a Data plane LB virtual server to proxy IP Reputation queries to backend proxy servers located in the Management plane. |
| PBR override (for proxy server traffic when not direct internet access) | Intercepts IP Reputation proxy traffic and forces it into the Management Traffic Domain (TD 4094). | ||
| SSL-CRLRefresh | Data plane | PBR override | Uses PBR to intercept CRL refresh traffic destined for a pre-resolved IP and forces it into the Management Traffic Domain (TD 4094). |
| SSL-HSM | Data plane | PBR override | Uses PBR to intercept HSM client traffic on a specific port and force it into the Management Traffic Domain (TD 4094). |
| AppFlow | Management plane | Virtual server-based override | Uses a Management plane LB virtual server to proxy AppFlow traffic to a Data plane service, bridging the planes. |
| Netprofile-Based override (Recommended) | Forces AppFlow traffic to originate from a Data plane SNIP, routing it through the Data plane. | ||
| Note: When Secure Management is Enabled, Analytics Logstream traffic over NSIP does not function as expected. Logstream traffic must be configured to flow through the Data plane for proper operation. | |||
| SNMP | Management plane | PBR override | Intercepts SNMP traps traffic destined for a Data plane manager and redirects it using a Data plane gateway, routing it through the Data plane. |
| SYSLOG | Management plane | Net profile-based override | Forces SYSLOG traffic to originate from a Data plane SNIP, routing it through the Data plane. |
| Virtual server-based override | Uses a Management plane LB virtual server to proxy SYSLOG traffic to a Data plane service, bridging the planes. |
Configuration examples for overriding the default traffic plane
-td specifies the source plane Traffic Domain and -targetTD specifies the destination plane Traffic Domain. You cannot use -targetTD and -nextHop in the same PBR rule. The -targetTD parameter routes the packet to the target plane, and the routing table of that plane then forwards the packet to the appropriate next hop.
Redirect Management plane traffic to the Data plane
add ns ip 10.106.221.55 255.255.255.128 -vServer DISABLED -td 4094
add lb vserver mgmt-syslog-udp-lb SYSLOGUDP -persistenceType NONE -lbMethod ROUNDROBIN -cltTimeout 120
add audit syslogAction mgmt-syslog-action -lbVserverName mgmt-syslog-udp-lb -logLevel ALL
add lb vserver mgmt-appflow TCP 10.106.231.56 4739 -persistenceType NONE -cltTimeout 9000 -td 4094
add service appflow-server-Dataplane 5.5.5.5 TCP 4739
bind lb vserver mgmt-appflow appflow-server-Dataplane
add pbr mgmt-syslog-override ALLOW -destIP 7.6.5.5 -td 4094 -targetTD 0
add netProfile dataplane-netprofile -srcIP 10.106.231.51 -MBF DISABLED
add audit syslogAction mgmt-syslog2-action 3.3.3.3 -logLevel ALL -mgmtlogLevel NONE -netProfile dataplane-netprofile
Redirect Data plane traffic to the Management plane
add service dns-mgmtplane-server TD_4094_10.106.221.66 DNS 53 -td 4094
add lb vserver DNS-Dataplane DNS 10.106.231.57 53 -persistenceType NONE -cltTimeout 120
bind lb vserver DNS-Dataplane dns-mgmtplane-server
add ns pbr dns-override-dataplane ALLOW -destIP 6.6.6.7 -targetTD 4094 -td 0 -priority 30
add netProfile "mgmt netprofile" -td 4094 -srcIP 10.106.221.55 -MBF DISABLED
add lb monitor DNS-Mgmt-monitor DNS -query . -queryType Address -LRTM DISABLED -netProfile "mgmt netprofile"
Use case: Management and Data plane exceptions
-
Create a load balancing virtual server in the Management plane.
-
Bind LDAP/RADIUS servers (in the Data plane) as backend services.
-
Configure the NSIP to use the load balancing VIP for authentication.