Configure layer 7 content switching
http://example-sports.com/about-us is served by a pool of servers hosting content about the company and the services, while a user browsing to http://example-sports.com/shopping-cart-football is served by a different pool of servers that allows the users to make online purchases.
L7 Rules
-
Host name: The host name in the HTTP request is compared against the value parameter in the rule. For example, "www.example-sports.com."
-
path: The path portion of the HTTP URI is compared against the value parameter in the rule. For example, "www.example-sports.com/shopping-cart/football_pump.html"
-
file\_type: The last portion of the URI is compared against the value parameter in the rule. For example, txt, html, jpg, PNG, xls, and others.
-
header: The header defined in the key parameter is compared against the value parameter in the rule.
-
cookie: The cookie named by the key parameter is compared against the value parameter in the rule. The cookie request-header field value contains a name and value pair of information stored for that URL; the general syntax is as follows - Cookie: name=value. For example, a rule that is looking for a cookie named "stores" with the value starting with "football-" will look like: type = Cookie, compare_type=StartsWith, key = stores value = football-.
Comparison Types
-
regex: Perl type regular expression matching
-
starts\_with: String start with
-
ends\_with: String ends with
-
contains: String contains
-
equal\_to: String equals
L7 Policies
-
Redirect to pool - Forward the request to the application server pool identified by the rules associated with the L7 policy. That is, you can create an application rule to direct requests to a specific load balancer pool according to domain name. For example, you can create a rule that directs some requests to example-football.com to pool\_1, and other requests to example-sports-online\_purchase.com to pool\_2.
-
Redirect to URL - Send the client a redirect HTTP response in which the location response header contains the new location. The browser will update the address bar with the new location and issue a new request. The use cases are many. For example, if a website address has changed, you can redirect requests to the new address instead of dropping. Or, during website maintenance, you can redirect the users to a read-only site.
-
Reject - Rejects the request and takes no further action. For example, you can return a 401 Unauthorized response to deny access to the users for restricted webpages.
Mapping Between OpenStack L7 Policies and NetScaler Entities
| OpenStack | NetScaler Entity | Description |
| L7 policy with action REDIRECT_TO_POOL | Content switching policy > Content switching action | NetScaler ADM creates a content switching policy that is bound to the content switching virtual server and associated with a content switching action that specifies the target pool of application servers for content retrieval and presentation to the user. |
| L7 policy with action REDIRECT_TO_URL | Responder policy > Responder action | NetScaler ADM creates a responder policy that is bound to the content switching virtual server and associated with a responder action that specifies the target URL to be presented to the users. |
| L7 policy with action REJECT | Responder policy > Drop the request | NetScaler ADM creates a responder policy that is bound to the content switching virtual server and associated with a responder action that drops the request. |
Policy Positioning
-
If you assign a new policy the same priority as an existing policy, the new policy takes that priority. The existing policy's priority is lowered. If necessary, the priorities of other policies are also lowered to retain the order in which the policies are evaluated.
-
If you create a new policy without specifying a position, the new policy will just be appended to the list.
-
If you create a new policy and assign it a position that is greater than the number of policies already in the list, the new policy will be appended to the list, that is, the new policy always takes the next available priority. For example, if there are three policies A, B, and C with priorities 1,2, and 3, and if you create a policy and assign a priority of 8, the new policy's priority becomes 4.
-
If you add a policy to the list or delete a policy from the list, the policy position values are re-ordered from 1 without skipping numbers. For example, if policy A, B, C, and D have position values of 1, 2, 3, and 4, and if you delete policy B from the list, policy C now takes the second position, and policy D takes the third position.
csvserver with a priority of 1. This default policy specifies the number of TCP connections that an lbvserver processes at any given point of time. Therefore, when the corresponding responder policies and content switching policies are created in NetScaler, they are always assigned a priority 1 greater than the priority of the corresponding L7 policy. For example, when an L7 policy with a priority of 1 is evaluated and a content switching policy is created with a priority of 2. Similarly, when an L7 policy with a priority of 2 is evaluated and a responder policy is created with a priority of 3.
csvserver with a priority of 1. This default policy specifies the number of TCP connections that an lbvserver processes at any given point of time. Therefore, when the corresponding responder policies and content switching policies are created in NetScaler, they are always assigned a priority 1 greater than the priority of the corresponding L7 policy. For example, when an L7 policy with a priority of 1 is evaluated and a content switching policy is created with a priority of 2. Similarly, when an L7 policy with a priority of 2 is evaluated and a responder policy is created with a priority of 3.
Configuration Tasks
Create L7 Policy to Drop Requests
neutron lbaas-l7policy-create --name <L7 policy name> --listener <listener name> --action<action-name>
Create L7 Policy to Redirect Requests to Particular URL
neutron lbaas-l7policy-create --name <L7 policy name> --listener <listener name> --action <action-name> --redirect-url <redirect-url>
http://example-sports/about-us.html
neutron lbaas-l7rule-create --type HOST_NAME --compare-type CONTAINS --value <value-string> <L7 policy name>
neutron lbaas-l7rule-create --type PATH --compare-type CONTAINS --value <value-string> <L7 policy name>
Create L7 Policy to Redirect Requests to a Pool
neutron lbaas-l7policy-create --name <L7 policy name> --listener <listener name> --action <action-name> --redirect-pool <redirect-pool>