Provision NetScaler instances
-
Define an admin profile to attach to the NetScaler instance. This profile specifies the user credentials that are used by the Management Service to provision the ADC instance and later, to communicate with the instance to retrieve configuration data. You can also use the default admin profile.
-
Upload the .xva image file to the Management Service.
-
Add a NetScaler instance using the Provision NetScaler wizard in the Management Service. The Management Service implicitly deploys the NetScaler instance on the SDX appliance and then downloads configuration details of the instance.
Create an admin profile
Create an admin profile
-
On the Configuration tab, in the navigation pane, expand NetScaler Configuration, and then click Admin Profiles.
-
In the Admin Profiles pane, click Add.
-
The Create Admin Profile dialog box appears.
-
Profile Name: name of the admin profile. The default profile name is
nsroot. You can create user-defined profile names. -
Password: the password used to log on to the NetScaler instance. Maximum length: 31 characters.
-
SSH Port: set the SSH port. The default port is 22.
-
Use global settings for NetScaler communication: Select if you want the setting to be defined in the System Settings for the communication between the Management Service and the NetScaler instance. You can clear this box and change the protocol to HTTP or HTTPS.
-
Select the http option to use HTTP protocol for the communication between the Management Service and the NetScaler instance.
-
Select the https option to use the secure channel for the communication between the Management Service and the NetScaler instance.
-
Upload a NetScaler .xva image
NSVPX-XEN-ReleaseNumber-BuildNumber_nc.xva.
-
Name: Name of the .xva image file. The file name contains the release and the build number. For example, the file name
NSVPX-XEN-12.1-56.22.xva.gzrefers to release 12.1 build 56.22. -
Last Modified: Date when the .xva image file was last modified.
-
Size: Size, in MB, of the .xva image file.
To upload a NetScaler .xva file
-
On the Configuration tab, in the navigation pane, expand NetScaler Configuration, and then click XVA Files.
-
In the NetScaler XVA Files pane, click Upload.
-
In the Upload NetScaler instance XVA dialog box, click Browse and select the XVA image file that you want to upload.
-
Click Upload. The XVA image file appears in the NetScaler XVA Files pane after it is uploaded.
To create a backup by downloading a NetScaler .xva file
-
In the NetScaler Build Files pane, select the file that you want to download, and then click Download.
-
In the File Download message box, click Save.
-
In the Save As message box, browse to the location where you want to save the file, and then click Save.
Add a NetScaler instance
-
Name: Assign a name to the NetScaler instance.
-
Select Manage through internal network to enable an independent internal always-on connectivity between the SDX Management Service and the VPX instance. This feature is supported in 13.0-36.27 and higher version of VPX instances running on the SDX appliance.
-
Select an IPv4 or IPv6 address or both IPv4 and IPv6 addresses to access the NetScaler VPX instance for the management purpose. A NetScaler instance can have only one management IP (NSIP). You cannot remove an NSIP address.
-
Assign a netmask, default gateway, and next hop to Management Service for the IP address.
-
The Gateway and Nexthop to Management Service fields are optional under either of the following conditions, when VPX is provisioned with version 13.0–88.9 or 13.1–37.8, and their higher versions:
-
When Manage through internal network is enabled.
-
When the configured IPv4 address is in the same subnet as the Management Service IP address.
-
License allocation
Crypto allocation
Resource allocation
-
Select Dedicated (2 core) or more from the CPU list.
-
Select the Add an extra management CPU option.SDX VPX resource allocationCPU: Assign a dedicated core or cores to the instance, or the instance shares a core with other instances. If you select shared, then one core is assigned to the instance but the core might be shared with other instances if there is a shortage of resources. Reboot affected Instances if CPU cores are reassigned. Restart the instances on which CPU cores are reassigned to avoid any performance degradation.From SDX release 11.1.x.x (MR4), if you are using the SDX 25000xx platform, you can assign a maximum of 16 cores to an instance. Also, if you are using the SDX 2500xxx platform, you can assign a maximum of 11 cores to an instance.
-
For an instance, the maximum throughput that you configure is 180 Gbps.
-
For optimal performance, regardless of the license, it is recommended to allocate 4 GB of memory per packet engine (PE). For instance, a VPX with 6 PEs must have 24 GB of memory allocated.
| Platform Name | Total Cores | Total Cores Available for VPX Provisioning | Maximum Cores That Can Be Assigned to a Single Instance |
|---|---|---|---|
| SDX 8015, SDX 8400, and SDX 8600 | 4 | 3 | 3 |
| SDX 8900 | 8 | 7 | 7 |
| SDX 11500, SDX 13500, SDX 14500, SDX 16500, SDX 18500, and SDX 20500 | 12 | 10 | 5 |
| SDX 11515, SDX 11520, SDX 11530, SDX 11540, and SDX 11542 | 12 | 10 | 5 |
| SDX 17500, SDX 19500, and SDX 21500 | 12 | 10 | 5 |
| SDX 17550, SDX 19550, SDX 20550, and SDX 21550 | 12 | 10 | 5 |
| SDX 14020, SDX 14030, SDX 14040, SDX 14060, SDX 14080, and SDX 14100 | 12 | 10 | 5 |
| SDX 22040, SDX 22060, SDX 22080, SDX 22100, and SDX 22120 | 16 | 14 | 7 |
| SDX 24100 and SDX 24150 | 16 | 14 | 7 |
| SDX 14020 40G, SDX 14030 40G, SDX 14040 40G, SDX 14060 40G, SDX 14080 40G, and SDX 14100 40G | 12 | 10 | 10 |
| SDX 14020 FIPS, SDX 14030 FIPS, SDX 14040 FIPS, SDX 14060 FIPS, SDX 14080 FIPS, and SDX 14100 FIPS | 12 | 10 | 5 |
| SDX 14040 40S, SDX 14060 40S, SDX 14080 40S, and SDX 14100 40S | 12 | 10 | 10 |
| SDX 25100A, 25160A, 25200A | 20 | 18 | 9 |
| SDX 25100-40G, 25160-40G, 25200-40G | 20 | 18 | 16 (if version is 11.1-51.x or higher); 9 (if version is 11.1-50.x or lower; all versions of 11.0 and 10.5) |
| SDX 26100, 26160, 26200, 26250 | 28 | 26 | 16 |
| SDX 26100-50S, 26160-50S, 26200-50S, 26250-50S | 28 | 26 | 16 |
| SDX 26100-100G, 26160-100G, 26200-100G, 26250-100G | 28 | 26 | 25 |
| SDX 15000 | 16 | 14 | 14 |
| SDX 15000-50G | 16 | 14 | 14 |
| SDX 9100 | 10 | 9 | 9 |
| SDX 16000 | 32 | 30 | 16 |
Recommended practice for enabling extra management CPU for NetScaler VPX on SDX
Overview
-
The extra management CPU is implemented using a hyperthread, not a physical core.
-
It provides dedicated processing capacity for management plane operations.
-
It is distinct from legacy extra management CPU implementations used on other platforms.
-
Improved management plane responsiveness
-
Faster execution of CLI and API commands.
-
Reduced latency for configuration changes.
-
Improved responsiveness of GUI and automation workflows.
-
-
Enhanced stability
-
Reduces the likelihood of management plane contention under load.
-
Minimizes impact of high monitoring, logging, or automation activity.
-
-
No impact to data plane performance
-
Packet processing cores (packet engines) are not reduced or impacted.
-
Data plane throughput remains unchanged.
-
-
NetScaler version: NetScaler 13.1-63.x or later on both SDX and VPX instances.
-
VPX provisioning: At least 2 CPU cores must be allocated to each VPX instance.
-
Platform requirements: Hyper-Threading must be enabled on the SDX platform.
When to enable extra management CPU
| High management activity | Performance concerns |
|---|---|
| Continuous monitoring and telemetry collection | Slow CLI or GUI response times |
| Frequent configuration changes or automation | Delays in applying configurations |
| High API or orchestration activity | High management CPU utilization |
-
A VPX reboot is required after enabling or disabling the extra management CPU.
-
The behavior of the extra management CPU differs from NetScaler MPX and NetScaler VPX on hypervisors.
-
This feature applies specifically to VPX instances running on SDX.
-
Enabling an extra management CPU is a recommended, low-risk configuration.
-
It improves management plane performance and reliability.
-
It does not affect data plane throughput or packet engine allocation.
-
It is regarded as a best practice for most SDX deployments.
Instance administration
Network settings
-
Allow L2 Mode: You can allow L2 mode on the NetScaler instance. Select Allow L2 Mode under Networking Settings. Before you log on to the instance and enable L2 mode. For more information, see Allowing L2 Mode on a NetScaler instance.Network settingsNote:
-
If you disable L2 mode for an instance from the Management Service, you must log on to the instance and disable L2 mode from that instance. Failure to do so might cause all the other NetScaler modes to be disabled after you restart the instance
-
After an ADC instance is provisioned on SDX, you cannot delete an interface or channel from the ADC instance. However, you can add an interface or channel to the ADC instance.
-
-
Interface 0/1 and 0/2: By default, interface 0/1 and 0/2 are selected for management LA.
-
VLAN tag: Specify a VLAN ID for the management interface. Next, add data interfaces.Note:The interface IDs of interfaces that you add to an instance do not necessarily correspond to the physical interface numbering on the SDX appliance. If the first interface that you associate with instance 1 is interface 1/4, it appears as interface 1/1 when you view the interface settings on the instance. The numbering changes because it is the first interface that you associated with instance 1.
-
Allow untagged traffic: Select the Allow untagged traffic check box to enable the NetScaler instance to process the untagged traffic.Note:When the SDX appliance version is 13.1-24.x or later and the NetScaler instance version is earlier than 13.1-24.x, the ADC instance processes the untagged traffic on the Mellanox interfaces even if the Allow untagged traffic check box is cleared.
-
Allowed VLANs: Specify a list of VLAN IDs that can be associated with a NetScaler instance.
-
MAC Address Mode: Assign a MAC address. Select from one of the following options:
-
Default: Citrix Hypervisor™ assigns a MAC address.
-
Custom: Choose this mode to specify a MAC address that overrides the generated MAC address.
-
Generated: Generate a MAC address by using the base MAC address set earlier. For information about setting a base MAC address, see Assigning a MAC Address to an Interface.
-
-
VMAC Settings (IPv4 and IPv6 VRIDs to configure Virtual MAC)
-
VRID IPv4: The IPv4 VRID that identifies the VMAC. Possible values: 1–255. For more information, see Configuring VMACs on an Interface.
-
VRID IPv6: The IPv6 VRID that identifies the VMAC. Possible values: 1–255. For more information, see Configuring VMACs on an Interface.
-
Management VLAN settings
-
HA heartbeats are sent only on the interfaces that are part of the NSVLAN.
-
You can configure an NSVLAN only from VPX XVA build 9.3 53.4 and later.
Modify a NetScaler instance
-
You can edit the VPX instance and add one more management CPU only if you have two or more dedicated cores and both the VPX and SDX are on release 13.1 and build 53.x and later.
-
Selecting the Add an extra management CPU option for a VPX with the release earlier than 13.1-53.x results in an error. Upgrade the VPX instance to release 13.1-53.x and later to use this feature.
-
Before you downgrade a VPX instance to a build earlier than 13.1-53.x, you must disable the Add an extra management CPU option. Otherwise, the performance of the VPX instance is impacted.
-
If the Add an extra management CPU option is not disabled and the VPX instance is downgraded to a version earlier than 13.1-53.x, an alarm is generated.
-
If you modify the following parameters: number of SSL chips, interfaces, memory, and feature license, the NetScaler instance implicitly stops and restarts to bring these parameters into effect.
-
You cannot modify the Image and User Name parameters.
-
Interfaces or channels cannot be deleted from the ADC instance. However, new interfaces or channels can be added to the ADC instance.
-
To remove an ADC instance provisioned on the SDX appliance, in the NetScaler instances pane, select the instance that you want to remove, and then click Delete. In the Confirm message box, click Yes to remove the NetScaler instance.
Restrict VLANs to specific virtual interfaces
To specify the permitted VLAN IDs
-
In the Provision ADC Wizard or the Modify ADC Wizard, on the Network Settings page, in Allowed VLANs, specify one or more VLAN IDs allowed on this interface. Use a hyphen to specify a range. For example, 2–4094.
-
Follow the instructions in the wizard.
-
Click Finish, and then click Close.
To configure VLANs for an instance from the Management Service
-
On the Configuration tab, navigate to NetScaler > Instances.
-
Select an instance, and then click VLAN.
-
In the details pane, click Add.
-
In the Create NetScaler VLAN dialog box, specify the following parameters:
-
VLAN ID — An integer that uniquely identifies the VLAN to which a particular frame belongs. The NetScaler supports a maximum of 4094 VLANs. ID 1 is reserved for the default VLAN.
-
IPv6 Dynamic Routing — Enable all IPv6 dynamic routing protocols on this VLAN.
Note: For the ENABLED setting to work, you must log on to the instance and configure IPv6 dynamic routing protocols from the VTYSH command line. -
-
Select the interfaces that must be part of the VLAN.
-
Click Create, and then click Close.