Configuring high availability secure heartbeats
-
Replay-attack prevention using sequence numbering with forward and backward protection
-
Authentication of peer HA nodes before accepting heartbeat packets
-
Integrity validation of heartbeat data after decryption
-
Improved HA security
-
Reduced risk of denial-of-service conditions
-
Prevention of unauthorized HA failovers without changing standard HA behavior
Prerequisites
-
NetScaler appliances must already be configured as an HA pair.
-
Secure HA heartbeats must be configured separately on each HA node.
-
A pre-shared key (PSK) of length 8–15 characters is required.
-
The same PSK must be configured on both the Primary and Secondary nodes.
Limitations
-
Secure HA heartbeats depend on correct PSK configuration on both high availability nodes.
-
Heartbeat packets failing replay-window checks, authentication, or integrity validation are dropped.
-
Incorrect enable or disable sequencing might temporarily affect HA communication.
Configuring high availability secure heartbeats by using CLI
set HA secureheartbeats -state ENABLED -haPSK <pre-shared-key>
-
Enable Secure HA heartbeats on the Primary node first, followed by the Secondary node.
-
Disable Secure HA heartbeats on the Secondary node first, followed by the Primary node.
> show ha secureheartbeats
State: ENABLED HaPSK: 213a988866bc16833026d3fa30288b9ef6651c1720285bf1b43742a540ce3312afc48542
Done
set HA secureheartbeats -state DISABLED
Monitoring and troubleshooting
-
Verify that Secure HA heartbeats are enabled on both HA nodes.
-
Ensure that the same PSK is configured on both nodes. If both nodes do not have the same PSK, then it might lead to a 'dual primary' scenario.
-
Confirm that the recommended enable or disable sequence is followed. If the sequence is not followed, it might lead to HA failover.