Configure on-prem agents for multisite deployment
-
To install agents in remote data centers so that there is reduction in WAN bandwidth consumption.
-
To limit the number of instances directly sending traffic to primary NetScaler Console for data processing.
-
Installing agents for instances in remote data center is recommended but not mandatory. If necessary, users can directly add NetScaler instances to primary NetScaler Console.
-
If you have installed agents for one or more remote data centers, then the communication between the agents and the primary site is through floating IP address. For more information, see port.
-
You can install agents and apply pooled licenses to the instances at one or more remote data centers. In this scenario, the communication between the primary site and one or more remote data centers is through the floating IP address.
-
NetScaler Console on-premises agent doesn't support pooled licensing.
-
The instances are configured to agents so that the unprocessed data is sent directly to agents instead of primary NetScaler Console. Agents do the first level of data processing and send the processed data in compressed format to the primary NetScaler Console for storage.
-
Agents and instances are co-located in the same data center so that the data processing is faster.
-
Clustering the agents provides redistribution of NetScaler instances on agent failover. When one agent in a site fails, traffic from NetScaler instances is switched to another available agent in the same site.NoteThe number of agents to be installed per site depends on the traffic being processed.
Architecture
Enable basic authentication
-
Complete the initial registration of agents and disaster recovery nodes.
-
Initiate the License Activation System (LAS) checkout from the NetScaler GUI.
Configure basic authentication
-
Navigate to Settings > Administration > System Configurations > System, Time Zone, Allowed URLs and Agent Settings.
-
Click Basic Settings.
-
Select Enable Allow Basic Authentication.
-
Click OK.
Get started
-
Install the agent in a data center
-
Register the agent
-
Attach the agent to a site
-
-
Add NetScaler instances
-
Add new instance
-
Update an existing instance
-
Install the agent in a data center
-
Citrix Hypervisor™
-
VMware ESXi
-
Microsoft Hyper-V
-
Linux KVM Server
| Component | Requirement |
|---|---|
| RAM | 32 GB |
| Virtual CPU | 8 CPUs |
| Storage space | 30 GB |
| Virtual Network Interfaces | 1 |
| Throughput | 1 Gbps |
Ports
| Type | Port | Details | Direction of communication |
|---|---|---|---|
| TCP | 8443, 7443, 443 | For outbound and inbound communication between agent and the NetScaler Console on-prem server. | NetScaler agent to NetScaler Console |
| Type | Port | Details | Direction of communication |
|---|---|---|---|
| TCP | 80 | For NITRO communication between agent and NetScaler instance. | NetScaler Console to NetScaler and NetScaler to NetScaler Console |
| TCP | 22 | For SSH communication between agent and NetScaler instance. For synchronization between NetScaler Console servers deployed in high availability mode. | NetScaler Console to NetScaler and NetScaler agent to NetScaler |
| UDP | 4739 | For AppFlow communication between agent and NetScaler instance. | NetScaler to NetScaler Console |
| ICMP | No reserved port | To detect network reachability between NetScaler Console and NetScaler instances, or the secondary NetScaler Console server deployed in high availability mode. | |
| UDP | 161, 162 | To receive SNMP events from NetScaler instance to agent. | Port 161 - NetScaler Console to NetScaler |
| Port 162 - NetScaler to NetScaler Console | |||
| UDP | 514 | To receive syslog messages from NetScaler instance to agent. | NetScaler to NetScaler Console |
| TCP | 5557 | For Logstream communication between agent and NetScaler instances. | NetScaler to NetScaler Console |
Register the agent
-
Use the agent image file downloaded from the NetScaler site and import it in to your hypervisor. The naming pattern of the agent image file is as follows, MASAGENT-\<HYPERVISOR\>-\<Version.no\>. For example: MASAGENT-XEN-13.0-xy.xva
-
From the Console tab, configure NetScaler Console with the initial network configurations.
-
Enter the NetScaler Console host name, IPv4 address, and gateway IPv4 address. Select option 7 to save and quit the configuration.

-
After the registration is successful, the console prompts to log on. Use nsrecover/nsroot as the credentials.
-
To register the agent, enter /mps/register\_agent\_onprem.py. The NetScaler agent registration credentials are displayed as shown in the following image.
-
Enter the NetScaler Console floating IP address and the user credentials.

Attach an agent to a site
-
Select the agent and click Attach Site.
-
In the Attach site page, select a site from the list, or create a site using the plus (+) button.
-
Click Save.Note
-
By default, all newly registered agents are added to the default data center.
-
It is important to associate the agent with the correct site. In the event of an agent failure, the NetScaler instances assigned to it are automatically switched to other functioning agents in the same site.
-
Agent actions
Add NetScaler instances
-
NetScaler MPX
-
NetScaler VPX
-
NetScaler SDX
-
NetScaler CPX
-
NetScaler Gateway
-
Citrix SSL Forward Proxy
Attach an existing instance to the agent
-
Navigate to Infrastructure > Instances and select the instance type. For example, NetScaler.
-
Click Edit to edit an existing instance.
-
Click to select the agent.
-
From the Agent page, select the agent with which you want to associate the instance and then click OK.NoteEnsure to select the Site with which you want to associate the instance.
Access the GUI of an instance to validate events
NetScaler agent failover
-
Ensure the Agent Failover feature is enabled on your account. To enable this feature, see Enable or disable NetScaler Console features.
-
If an agent is running a script, ensure that script is present on all the agents in the site. Therefore, the changed agent can run the script after agent failover.
Configure agent unreachable threshold and notification
Secure communication between NetScaler® Console agents and NetScaler Console
-
Ensure that the Netscaler Console has SSL certificates configured.
-
Login to the NetScaler Console agent.
-
Place the CA root certificate at /mpsconfig/console_onprem_cacert. This is used to validate the server certificate. The name of the CA root certificate must be cacert.pem.
-
Configure the secure communication by running the following command. Configure_secure_communication_with_server.py
-
This prompts for FQDN(Fully Qualified Domain Name) or IP address of the Netscaler Console server.
-
Enter the FQDN or IP address to finish executing the script.

-
The script verifies the server certificate presented by an FQDN or IP address, using the provided CA root certificate. Secure communication is enabled if the certificate validation passes.
-
This script can be invoked either before or after the agent is registered with the NetScaler Console.