Secure Management FAQs
How can I maintain access to NetScaler after enabling Secure Management?
-
Confirm that a return route exists for NSIP management traffic.
-
Add a Management plane default route, if one is required:
add route 0.0.0.0 0.0.0.0 <mgmt-gateway> -mgmt -
Alternatively, add a specific Management plane route to the administrator network:
add route <admin-network> <mask> <mgmt-gateway> -mgmt
What is the role of NSVLAN, and how do heartbeats and redundancy work in high availability after enabling Secure Management?
-
It must be placed in the management traffic domain.
-
It must not carry any IP addresses.
add vlan 100
bind ns trafficdomain 4094 -vlan 100
set HA node -syncvlan 100
What happens to my existing PBRs after enabling Secure Management?
-
PBRs that reference Data-plane IP addresses: No change is required. These PBRs continue to work after the feature is enabled.
-
PBRs that reference Management-subnet IP addresses: Update them after enabling the feature, based on where the traffic must go:
-
If the traffic stays within the Management plane: Convert the PBRs to static routes in the management routing table.
add route <network> <mask> <gateway> -mgmt -
If the traffic requires a plane override and must exit through the Data plane: Add a PBR to the management traffic domain that keeps the rule in the Management plane while directing matched traffic to it.
add ns pbr <name> ALLOW ... -td <mgmt-TD> -targetTD <mgmt-TD>Here,-tdkeeps the PBR in the Management plane, and-targetTDsends the matched traffic to the specified traffic domain. The-targetTDparameter cannot be combined with-nextHop.
-
How do I configure a SNIP on the Management plane?
add ns ip <SNIP> <subnet-mask> -td 4094 -mgmtAccess ENABLED