NetScaler® ADM as an API proxy server
-
Validation of API requests. NetScaler ADM validates all API requests against configured security and role-based access control (RBAC) policies. NetScaler ADM is also tenant-aware and ensures that API activity does not cross tenant boundaries.
-
Centralized auditing. NetScaler ADM maintains an audit log of all API activity related to its managed instances.
-
Session management. NetScaler ADM frees API clients from the task of having to maintain sessions with managed instances.
How NetScaler ADM Works as an API Proxy Server
| Header values | Description |
|---|---|
| _MPS_API_PROXY_MANAGED_INSTANCE_NAME | Name of the managed instance. |
| _MPS_API_PROXY_MANAGED_INSTANCE_IP | IP address of the managed instance. |
| _MPS_API_PROXY_MANAGED_INSTANCE_ID | ID of the managed instance. |
| _MPS_API_PROXY_TIMEOUT | Timeout value for a NITRO API request. Set the timeout value in seconds. When you set a proxy timeout, ADM waits for the specified duration before it times out the request. |
| _MPS_API_PROXY_MANAGED_INSTANCE_USERNAME | User name to access the managed ADC instance. |
| _MPS_API_PROXY_MANAGED_INSTANCE_PASSWORD | Password to access the managed ADC instance. |
| _MPS_API_PROXY_MANAGED_INSTANCE_SESSID | Session ID to access the managed instance. |
-
Without modifying the request, NetScaler ADM forwards the request to the instance API proxy engine.
-
The instance API proxy engine forwards the API request to a validator and logs the details of the API request in the audit log.
-
The validator ensures that the request does not violate configured security policies, RBAC policies, tenancy boundaries, and so on. It performs extra checks, such as a check to determine whether the managed instance is available.
-
Navigate to Settings > Administration.
-
In System Configurations, select System, Time zone, Allowed URLs and Message of the day.
How to use NetScaler ADM as an API proxy server
-
Log in to NetScaler ADM
-
Obtain a session ID
-
Include the session ID in subsequent API requests.
POST /nitro/v1/config/login
Content-Type: application/json
{
"login": {
"username":"nsroot",
"password":"nsroot"
}
}
{
"errorcode": 0,
"message": "Done",
"operation": "add",
"resourceType": "login",
"username": "***********",
"tenant_name": "Owner",
"resourceName": "nsroot",
"login": [
{
"tenant_name": "Owner",
"permission": "superuser",
"session_timeout": "36000",
"challenge_token": "",
"username": "",
"login_type": "",
"challenge": "",
"client_ip": "",
"client_port": "-1",
"cert_verified": "false",
"sessionid": "##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D",
"token": "b2f3f935e93db6a"
}
]
}
Example 1: Retrieve load balancing virtual server statistics
GET /nitro/v1/stat/lbvserver
Content-type: application/json
_MPS_API_PROXY_MANAGED_INSTANCE_IP: 192.0.2.10
SESSID: ##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D
Example 2: Create a load balancing virtual server
POST /nitro/v1/config/lbvserver/sample_lbvserver
Content-type: application/json
Accept-type: application/json
_MPS_API_PROXY_MANAGED_INSTANCE_IP: 192.0.2.10
SESSID: ##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D
{
"lbvserver":{
"name":"sample_lbvserver",
"servicetype":"HTTP",
"ipv46":"10.102.1.11",
"port":"80"
}
}
Example 3: Modify a load balancing virtual server
PUT /nitro/v1/config/lbvserver
Content-type: application/json
Accept-type: application/json
_MPS_API_PROXY_MANAGED_INSTANCE_IP: 192.0.2.10
SESSID: ##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D
{
"lbvserver":{
"name":"sample_lbvserver",
"appflowlog":"DISABLED"
}
}
Example 4: Delete a load balancing virtual server
DELETE /nitro/v1/config/lbvserver/sample_lbvserver
Accept-type: application/json
_MPS_API_PROXY_MANAGED_INSTANCE_IP: 192.0.2.10
SESSID: ##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D
Example 5: Download the CLI running config on the ADC
GET /nitro/v1/config/nsrunningconfig
Accept-type: application/json
_MPS_API_PROXY_MANAGED_INSTANCE_IP: 192.0.2.10
SESSID: ##D2BF9C5F40E5B2E884A9C45C89F0ADE24DA8A8169BE6358D39F5D471B73D