Configure NetScaler to source FreeBSD data traffic from a SNIP address
-
Load balancing scriptable monitors
-
GSLB autosync
useNetprofileBSDtraffic. When you enable this parameter, the NetScaler features send traffic sourced from one of the SNIP addresses in a net profile associated with the feature.
Before you begin
-
Currently, the global Layer-2 parameter
useNetprofileBSDtrafficis supported only for load balancing scriptable monitors.For configuring NetScaler to source GSLB autosync traffic from a SNIP address, you can use extended ACL rules and RNAT rules as a workaround. -
The
useNetprofileBSDtrafficsupport for load balancing scriptable monitors is applicable only for net profiles bound to the related services. TheuseNetprofileBSDtrafficsupport is not applicable for net profiles bound to the related service groups.In other words, NetScaler does not use any SNIP address from the net profiles bound to the service groups for sourcing load balancing scriptable monitors traffic. -
The
useNetprofileBSDtrafficsupport is not applicable for SSL services.In other words, NetScaler does not use any SNIP address from the net profiles bound to the SSL services for sourcing load balancing scriptable monitors traffic.
Configure NetScaler to source scriptable monitors traffic from a SNIP address
-
Enable the global Layer-2 parameter
useNetprofileBSDtraffic. -
Create a net profile and bind at least one SNIP address to it.
-
Bind the net profile to the load balancing services.
-
set l2param -useNetprofileBSDtraffic (ENABLED / DISABLED) -
show l2param
-
add netProfile <name> -srcIP <string> -
show netProfile
-
set service <name> -netProfile <string> -
show service <name>
Sample configuration
set l2param -useNetprofileBSDtraffic ENABLED
add netprofile NETPROFILE-1 -srcip 198.51.100.20
add lb monitor USER-MONITOR-1 USER -scriptName nsftp.pl -scriptArgs "file=Index.gif;user=nsroot;password=nsroot" -dispatcherIP 127.0.0.1 -dispatcherPort 3013 -destIP 203.0.113.90 -destPort 21
bind service SERVICE-1 -monitorName USER-MONITOR-1
set service SERVICE-1 -netProfile NETPROFILE-1
Configure NetScaler to source GSLB autosync and other FreeBSD originated traffic from a SNIP address
-
Create an extended ACL rule. An extended ACL rule identifies the GSLB autosync packets. This identification is based on the source IP and destination IP addresses.
-
Apply ACLs. Applying ACLs activates the newly created ACL rule.
-
Create an ACL based RNAT rule. An RNAT rule changes the source IP address of these packets from the NSIP address to a SNIP address.
-
add acl <aclname> ALLOW -srcIP = <NSIP address> -destIP = <destination IP address of the packets> -
show acl <aclName>
-
apply acls
-
add rnat <name> <aclname> -
bind rnat <name> -natIP <SNIP address - source IP address for the packets> -
show rnat <name>
Sample configuration
add acl ACL-2 ALLOW -srcIP = 192.0.1.20 -destIP = 203.0.113.20
apply acls
add rnat RNAT-2 ACL-2
bind rnat RNAT-2 -natIP 198.51.100.20