SSL Insight
-
Determine configuration change impact on customer usage: The administrator can understand the impact on clients for making a configuration change like turning off SSLv3 or removing a cipher like RC4-MD5. This can be done by assessing the historic transaction data on this protocol and cipher.
-
Quantify client performance: Administrator can understand the impact on Application Response Time based on the SSL ciphers/protocol used or the certificates negotiated.
-
Application security: Assess if any of the applications has transactions running on low security protocols, ciphers, or weak key strength.
-
SSL Protocol version negotiated
-
Cipher negotiated, and the cipher strength
-
Signature Hash algorithm of the certificate used
-
Certificate Type & Size
-
SSL Front-end and Back-end errors
Prerequisites
-
The NetScaler instance on which you intend to configure SSL Insight must be running NetScaler software release 11.1 51.21 and higher. Run the following commands on the ADC instance running 11.1 51.21 to enable Logstream as a transport type for SSL Insight.
-
enable ns mode ulfd -
add ulfd server <IP Address of the ADM>For ADC instances running version 12.0 and above, select Logstream as the transport type while enabling AppFlow from ADM.
-
The NetScaler ADM version and build must be equal to or higher than the NetScaler version and build. For example, if you have installed NetScaler ADM 11.1 build 61.7, then ensure you have installed NetScaler 11.1 build 60.14 or earlier.
Configure SSL Insight
-
Enable AppFlow for Web Insight on each NetScaler instance.
-
Enable ULFD mode on each NetScaler instance.
-
Enable required AppFlow parameters on each NetScaler instance.
Enable the AppFlow feature
-
Navigate to Infrastructure > Instances > NetScaler, and select the instance type. For example, VPX.
-
Select the instance and from Select Action list, click Configure Analytics.
-
On the Configure Analytics on Virtual Server(s) page, select the virtual server, and click Enable Analytics.
-
On the Enable Analytics window:
-
Select Web Insight
-
Select Logstream as Transport ModeNoteFor NetScaler 12.0 or earlier, IPFIX is the default option for Transport Mode. For NetScaler 12.0 or later, you can either select Logstream or IPFIX as Transport Mode.For more information about IPFIX and Logstream, see Logstream overview.
-
The Expression is true by default
-
Click OK
Note-
If you select virtual servers that are not licensed, then NetScaler ADM first licenses those virtual servers and then enables analytics
-
For admin partitions, only Web Insight is supported
-
For virtual servers such as Cache Redirection, Authentication, and GSLB, you cannot enable analytics. An error message is displayed.
-
-
-
Navigate to Infrastructure > Instances > NetScaler, and select the NetScaler instance on which you want to enable analytics.
-
From the Select Action list, select Configure Analytics.

-
On the Configure Insight page:
-
Select the Application List for either Load Balancing or Content Switching.

-
Select the virtual server and click Enable AppFlow.

-
-
In the Enable AppFlow dialog box:
-
Enter true in the text box
-
Select Logstream as the transport modeNote Citrix recommends you to select Logstream as the transport mode
-
Select Web Insight and click OK.

-
Enable SSL Insight parameters
-
Navigate to Configuration \> System \> AppFlow, and click Change AppFlowSettings.
-
Select the following check boxes: HTTP Domain, HTTP Host, HTTP Method, HTTP URL, HTTP User-Agent, HTTP Content-Type.
-
Click OK.

View the SSL Insight metrics
-
An application. Navigate to Applications > Dashboard, click an application, and select Web Insight tab to view the detailed metrics. For more information, see Application Usage Analytics.
-
All applications. Navigate to Applications > Web Insight and click Applications and Clients tabs to view the SSL metrics.
Use case: Obtain an overview of the SSL transactions
-
SSL Certificates
-
SSL Protocols
-
SSL Cipher
-
SSL Key Strength
-
SSL Failure – Front end
-
SSL Failure – Back end

Use case: SSL metrics for clients