Apply NetScaler VPX configurations at the first boot of the NetScaler appliance in cloud
What is user data
-
Reads the user data.
-
Interprets the configuration provided in user data.
-
Applies the newly added configuration as it boots up.
How to provide preboot user data in cloud instance
Provide preboot user data using the AWS console
Provide preboot user data using AWS CLI
aws ec2 run-instances \
--image-id ami-0abcdef1234567890 \
--instance-type t2.micro \
--count 1 \
--subnet-id subnet-08fc749671b2d077c \
--key-name MyKeyPair \
--security-group-ids sg-0b0384b66d7d692f9 \
--user-data file://my_script.txt
Provide preboot user data using the Azure console
Provide preboot user data using the Azure CLI
az vm create \
--resource-group myResourceGroup \
--name MyVm \
--image debian \
--custom-data MyCloudInitScript.txt \
az vm create --resource-group MyResourceGroup -name MyVm --image debian --custom-data MyCloudInitScript.txt
Provide preboot user data using the GCP console
Provide preboot user data using the gcloud CLI
gcloud compute instances create INSTANCE_NAMES --metadata-from-file=startup-script=LOCAL_FILE_PATH
Preboot user data format
-
NetScaler configuration represented with the
<NS-CONFIG>tag. -
Custom bootstrapping the NetScaler represented with the
<NS-BOOTSTRAP>tag. -
Storing user-scripts in NetScaler represented with the
<NS-SCRIPTS>tag. -
Pooled licensing configuration represented with the
<NS-LICENSE-CONFIG>tag.
<NS-PRE-BOOT-CONFIG> tag as shown in the following examples.
<NS-PRE-BOOT-CONFIG>
<NS-CONFIG> </NS-CONFIG>
<NS-BOOTSTRAP> </NS-BOOTSTRAP>
<NS-SCRIPTS> </NS-SCRIPTS>
<NS-LICENSE-CONFIG> </NS-LICENSE-CONFIG>
</NS-PRE-BOOT-CONFIG>
<NS-PRE-BOOT-CONFIG>
<NS-LICENSE-CONFIG> </NS-LICENSE-CONFIG>
<NS-SCRIPTS> </NS-SCRIPTS>
<NS-BOOTSTRAP> </NS-BOOTSTRAP>
<NS-CONFIG> </NS-CONFIG>
</NS-PRE-BOOT-CONFIG>
<NS-CONFIG> tag to provide the specific NetScaler VPX configurations that needs to be applied to the VPX instance at the preboot stage.
<NS-CONFIG> section must have valid ADC CLI commands. The CLIs are not verified for the syntactic errors or format.
NetScaler configurations
<NS-CONFIG> tag to provide the specific NetScaler VPX configurations that needs to be applied to the VPX instance at the preboot stage.
<NS-CONFIG> section must have valid ADC CLI commands. The CLIs are not verified for the syntactic errors or format.
<NS-CONFIG> section has the details of the configurations. A VLAN of ID '5' is configured and bound to the SNIP (5.0.0.1). A load balancing virtual server (4.0.0.101) is also configured.
<NS-PRE-BOOT-CONFIG>
<NS-CONFIG>
add vlan 5
add ns ip 5.0.0.1 255.255.255.0
bind vlan 5 -IPAddress 5.0.0.1 255.255.255.0
enable ns feature WL SP LB RESPONDER
add server 5.0.0.201 5.0.0.201
add service preboot_s5_201 5.0.0.201 HTTP 80 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip
NO -useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NO
add lb vserver preboot_v4_101 HTTP 4.0.0.101 80 -persistenceType NONE -cltTimeout 180
</NS-CONFIG>
</NS-PRE-BOOT-CONFIG>
<NS-CONFIG> section as shown in the following illustrations.
User scripts
<NS-SCRIPTS> tag to provide any script that must be stored and ran in NetScaler VPX instance.
<NS-SCRIPTS> tag. Each script must be included within the <SCRIPT> tag. Each <SCRIPT> section corresponds to one script and contains all the details of the script using the following sub tags.
-
<SCRIPT-NAME>:Indicates the name of the script file that must be stored. -
<SCRIPT-CONTENT>:Indicates the content of the file that must be stored. -
<SCRIPT-TARGET-LOCATION>:Indicates the designated target location where this file must be stored. If the target location is not provided, by default, the file, or script is saved in the "/nsconfig" directory. -
<SCRIPT-NS-BOOTUP>:Specify the commands that you use to run the script.-
If you use the
<SCRIPT-NS-BOOTUP>section, the commands provided in the section are stored in "/nsconfig/nsafter.sh", and the commands are run after the packet engine boots up as part of "nsafter.sh" execution. -
If you do not use the
<SCRIPT-NS-BOOTUP>section, the script file is stored in the target location that you specify.
-
<NS-SCRIPTS> tag contains details of only one script: script-1.sh. The "script-1.sh" script is saved at the "/var" directory. The script is populated with the specified contents, and is run with the "sh /var/script-1.sh" command after packet engine boots up.
<NS-PRE-BOOT-CONFIG>
<NS-SCRIPTS>
<SCRIPT>
<SCRIPT-CONTENT>
#Shell script
echo "Running script 1" > /var/script-1.output
date >> /var/script-1.output
</SCRIPT-CONTENT>
<SCRIPT-NAME> script-1.sh </SCRIPT-NAME>
<SCRIPT-TARGET-LOCATION> /var/ </SCRIPT-TARGET-LOCATION>
<SCRIPT-NS-BOOTUP>sh /var/script-1.sh</SCRIPT-NS-BOOTUP>
</SCRIPT>
</NS-SCRIPTS>
</NS-PRE-BOOT-CONFIG>
<NS-SCRIPTS> tag contains details of two scripts.
-
The first script is saved as "script-1.sh" at the "/var" directory. The script is populated with the specified contents, and is run with command "sh /var/script-1.sh" after packet engine boots up.
-
The second script is saved as "file-2.txt" at the "/var" directory. This file is populated with the specified contents. But it is not run because the bootup execution command
<SCRIPT-NS-BOOTUP>is not provided.
<NS-PRE-BOOT-CONFIG>
<NS-SCRIPTS>
<SCRIPT>
<SCRIPT-CONTENT>
#Shell script
echo "Running script 1" > /var/script-1.output
date >> /var/script-1.output
</SCRIPT-CONTENT>
<SCRIPT-NAME> script-1.sh </SCRIPT-NAME>
<SCRIPT-TARGET-LOCATION> /var/ </SCRIPT-TARGET-LOCATION>
<SCRIPT-NS-BOOTUP>sh /var/script-1.sh</SCRIPT-NS-BOOTUP>
</SCRIPT>
<SCRIPT>
<SCRIPT-CONTENT>
This script has no execution point.
It will just be saved at the target location
NS Consumer module should consume this script/file
</SCRIPT-CONTENT>
<SCRIPT-NAME>file-2.txt</SCRIPT-NAME>
<SCRIPT-TARGET-LOCATION>/var/</SCRIPT-TARGET-LOCATION>
</SCRIPT>
</NS-SCRIPTS>
</NS-PRE-BOOT-CONFIG>
Licensing
<NS-LICENSE-CONFIG> tag to apply NetScaler pooled licensing while booting up the VPX instance. Use the <LICENSE-COMMANDS> tag within <NS-LICENSE-CONFIG> section to provide the pooled license commands. These commands must be syntactically valid.
<LICENSE-COMMANDS> section using the standard pooled licensing commands. For more information, see Configure NetScaler pooled capacity licensing.
<NS-LICENSE-CONFIG>, the VPX comes up with the requested edition upon boot, and VPX tries to check out the configured licenses from the license server.
-
If the license checkout is successful, the configured bandwidth is applied to VPX.
-
If the license checkout fails, the license is not retrieved from license server within 10–12 minutes approximately. As a result, the system reboots and enters an unlicensed state.
<NS-LICENSE-CONFIG>, the VPX comes up with the Premium edition upon boot, and VPX tries to check out the configured licenses from the license server (10.102.38.214).
<NS-PRE-BOOT-CONFIG>
<NS-LICENSE-CONFIG>
<LICENSE-COMMANDS>
add ns licenseserver 10.102.38.214 -port 2800
set ns capacity -unit gbps -bandwidth 3 edition platinum
</LICENSE-COMMANDS>
</NS-LICENSE-CONFIG>
</NS-PRE-BOOT-CONFIG>
Bootstrapping
<NS-BOOTSTRAP> tag to provide the custom bootstrapping information. You can use the <SKIP-DEFAULT-BOOTSTRAP> and <NEW-BOOTSTRAP-SEQUENCE> tags within the <NS-BOOTSTRAP> section. This section informs NetScaler appliance whether to avoid the default bootstrap or not. If the default bootstrapping is avoided, this section provides you an option to provide a new bootstrapping sequence.
Default bootstrap configuration
-
Eth0 - Management interface with a certain NSIP address.
-
Eth1 - Client-facing interface with a certain VIP address.
-
Eth2 - Server-facing interface with a certain SNIP address.
Customize bootstrap configuration
<NS-BOOTSTRAP> tag to provide the custom bootstrapping information. For example, you can change the default bootstrapping, where the Management interface (NSIP), Client-facing interface (VIP), and server-facing interface (SNIP) are always provided in certain order.
<SKIP-DEFAULT-BOOTSTRAP> and <NEW-BOOTSTRAP-SEQUENCE> tags.
SKIP-DEFAULT-BOOTSTRAP |
NEW-BOOTSTRAP-SEQUENCE |
Bootstrap behavior |
|---|---|---|
| YES | YES | The default bootstrapping behavior is skipped, and a new custom bootstrap sequence provided in the <NS-BOOTSTRAP> section is run. |
| YES | NO | The default bootstrapping behavior is skipped. The bootstrap commands provided in the <NS-CONFIG> section is run. |
-
Provide only the interface details
-
Provide the interface details along with IP addresses and subnet mask
-
Provide bootstrap related commands in the
<NS-CONFIG>section
Method 1: Custom bootstrap by specifying only the interface details
Custom bootstrap example for AWS
<NS-BOOTSTRAP> section contains only the interface details and not the details of IP addresses and subnet masks.
-
Navigate to the AWS Portal > EC2 instances, and select the instance that you have created by providing the custom bootstrap information.
-
In the Description tab, you can verify the properties of each network interface as shown in the following illustrations.


show nsip command in ADC CLI, and verify the network interfaces applied to the NetScaler VPX instance during the first boot of the ADC appliance.
Custom bootstrap example for Azure
<NS-BOOTSTRAP> section contains only the interface details and not the details of IP addresses and subnet masks.


<NS-BOOTSTRAP> section is applied. You can run the "show route" command to verify the subnet mask.
Custom bootstrap examples for GCP
<NS-BOOTSTRAP> section contains only the interface details and not the details of IP addresses and subnet masks.
-
Select the instance that you have created by providing the custom bootstrap information.
-
Navigate to the Network interface properties and verify the NIC details as follows:
show nsip command in ADC CLI, and verify the network interfaces applied to the NetScaler VPX instance during the first boot of the ADC appliance.
Method 2: Custom bootstrap by specifying the interfaces, IP addresses, and subnet masks
Custom bootstrap examples for AWS
-
Management interface: Interface - Eth1, NSIP - 172.31.52.88, and subnet mask - 255.255.240.0
-
Client facing interface: Interface - Eth0, VIP - 172.31.5.155, and subnet mask - 255.255.240.0.
-
Server facing interface: Interface - Eth2, SNIP - 172.31.76.177, and subnet mask - 255.255.240.0.
show nsip command in the ADC CLI, and verify that the new bootstrap sequence specified in the <NS-BOOTSTRAP> section is applied. You can run the "show route" command to verify the subnet mask.
Custom bootstrap example for Azure
-
Management interface (eth2), NSIP (172.27.2.53), and subnet mask (255.255.255.0)
-
Client facing interface (eth1), VIP (172.27.1.53), and subnet mask (255.255.255.0)
-
Server facing interface (eth0), SNIP (172.27.0.53), and subnet mask (255.255.255.0)


show nsip command in the ADC CLI, and verify that the new bootstrap sequence specified in the <NS-BOOTSTRAP> section is applied. You can run the "show route" command to verify the subnet mask.
Custom bootstrap example for GCP
-
Management interface (eth2), NSIP (10.128.4.31), and subnet mask (255.255.255.0)
-
Client facing interface (eth1), VIP (10.128.0.43), and subnet mask (255.255.255.0)
-
Server facing interface (eth0), SNIP (10.160.0.75), and subnet mask (255.255.255.0)
-
Select the instance that you have created by providing the custom bootstrap information.
-
Navigate to the Network interface properties and verify the NIC details as follows.
show nsip command in the ADC CLI, and verify that the new bootstrap sequence specified in the <NS-BOOTSTRAP> section is applied. You can run the "show route" command to verify the subnet mask.
Method 3: Custom bootstrap by providing bootstrap related commands in the <NS-CONFIG> section
<NS-CONFIG> section. In the <NS-BOOTSTRAP> section, you must specify the <NEW-BOOTSTRAP-SEQUENCE> as "No" to run the bootstrapping commands in the <NS-CONFIG> section. You must also provide the commands to assign NSIP, default route, and NSVLAN. In addition, provide the commands relevant for the cloud that you use.
Custom bootstrap example for AWS
<NS-CONFIG> section. The <NS-BOOTSTRAP> section indicates that the default bootstrapping is skipped, and the custom bootstrap information provided in the <NS-CONFIG> section is run. You must also provide the commands to create NSIP, add default route, and add NSVLAN.
<NS-PRE-BOOT-CONFIG>
<NS-CONFIG>
set ns config -IPAddress 172.31.52.88 -netmask 255.255.240.0
add route 0.0.0.0 0.0.0.0 172.31.48.1
set ns config -nsvlan 10 -ifnum 1/2 -tagged NO
add route 172.31.0.2 255.255.255.255 172.31.48.1
enable ns feature WL SP LB RESPONDER
add server 5.0.0.201 5.0.0.201
add service preboot_s5_201 5.0.0.201 HTTP 80 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip NO - useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NO
add lb vserver preboot_v4_101 HTTP 4.0.0.101 80 -persistenceType NONE -cltTimeout 180
</NS-CONFIG>
<NS-BOOTSTRAP>
<SKIP-DEFAULT-BOOTSTRAP>YES</SKIP-DEFAULT-BOOTSTRAP>
<NEW-BOOTSTRAP-SEQUENCE> NO </NEW-BOOTSTRAP-SEQUENCE>
</NS-BOOTSTRAP>
</NS-PRE-BOOT-CONFIG>
-
Navigate to the AWS Portal > EC2 instances, and select the instance that you have created by providing the custom bootstrap information.
-
In the Description tab, you can verify the properties of each network interface as shown in the following illustrations.


show nsip command in ADC CLI, and verify the network interfaces applied to the NetScaler VPX instance during the first boot of the ADC appliance.
Custom bootstrap example for Azure
<NS-CONFIG> section. The <NS-BOOTSTRAP> section indicates that the default bootstrapping is skipped, and the custom bootstrap information provided in the <NS-CONFIG> section is run.

<NS-PRE-BOOT-CONFIG>
<NS-CONFIG>
set ns config -IPAddress 172.27.2.61 -netmask 255.255.255.0
add route 0.0.0.0 0.0.0.0 172.27.2.1
set ns config -nsvlan 10 -ifnum 1/2 -tagged NO
add ns ip 172.27.0.61 255.255.255.0 -type SNIP
add route 169.254.169.254 255.255.255.255 172.27.0.1
add route 168.63.129.16 255.255.255.255 172.27.0.1
add vlan 5
bind vlan 5 -IPAddress 5.0.0.1 255.255.255.0
enable ns feature WL SP LB RESPONDER
add server 5.0.0.201 5.0.0.201
add service preboot_s5_201 5.0.0.201 HTTP 80 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip NO -useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NO
add lb vserver preboot_v4_101 HTTP 4.0.0.101 80 -persistenceType NONE -cltTimeout 180
</NS-CONFIG>
<NS-BOOTSTRAP>
<SKIP-DEFAULT-BOOTSTRAP>YES</SKIP-DEFAULT-BOOTSTRAP>
<NEW-BOOTSTRAP-SEQUENCE> NO </NEW-BOOTSTRAP-SEQUENCE>
</NS-BOOTSTRAP>
</NS-PRE-BOOT-CONFIG>


show nsip command in the ADC CLI, and verify that the new bootstrap sequence specified in the <NS-BOOTSTRAP> section is applied. You can run the "show route" command to verify the subnet mask.
Custom bootstrap example for GCP
<NS-CONFIG> section. The <NS-BOOTSTRAP> section indicates that the default bootstrapping is skipped, and the custom bootstrap information provided in the <NS-CONFIG> section is applied.
<NS-PRE-BOOT-CONFIG>
<NS-CONFIG>
set ns config -IPAddress 10.128.0.2 -netmask 255.255.255.0
add route 0.0.0.0 0.0.0.0 10.128.0.1
set ns config -nsvlan 10 -ifnum 1/1 -tagged NO
enable ns feature WL SP LB RESPONDER
add server 5.0.0.201 5.0.0.201
add service preboot_s5_201 5.0.0.201 HTTP 80 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip NO -useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NO
add lb vserver preboot_v4_101 HTTP 4.0.0.101 80 -persistenceType NONE -cltTimeout 180
</NS-CONFIG>
<NS-BOOTSTRAP>
<SKIP-DEFAULT-BOOTSTRAP>YES</SKIP-DEFAULT-BOOTSTRAP>
<NEW-BOOTSTRAP-SEQUENCE> NO </NEW-BOOTSTRAP-SEQUENCE>
</NS-BOOTSTRAP>
</NS-PRE-BOOT-CONFIG>
-
Select the instance that you have created by providing the custom bootstrap information.
-
Navigate to the Network interface properties and verify the NIC details as shown in the illustration.
show nsip command in ADC CLI, and verify that the configurations provided in the preceding <NS-CONFIG> section are applied at the first boot of the ADC appliance.