Deploy NetScaler GSLB on AWS
DBS overview
Domain-name based services (DBS) with ELB
Configure AWS components
Security groups
-
Log in to the user AWS resource group and navigate to EC2 > NETWORK & SECURITY > Security Groups.
-
Click Create Security Group and provide a name and description. This security group encompasses NetScaler and Linux back-end web servers.
-
Add the inbound port rules from the following screenshot.Note:Limiting Source IP access is recommended for granular hardening. For more information, see Web Server Rules.
-
Amazon linux back-end web services
-
Log in to the user AWS resource group and navigate to EC2 > Instances.
-
Click Launch Instance using the details that follow to configure the Amazon Linux instance.Enter the details about setting up a Web Server or back-end service on this instance.
-
-
NetScaler Configuration
-
Log in to the user AWS resource group and navigate to EC2 > Instances.
-
Click Launch Instance and use the following details to configure the Amazon AMI instance.
-
-
Elastic IP ConfigurationNote:NetScaler can also be made to run with a single elastic IP if necessary to reduce cost, by not having a public IP for the NSIP. Instead, attach an elastic IP to the SNIP which can cover for management access to the box, in addition to the GSLB site IP and ADNS IP.
-
Log in to the user AWS resource group and navigate to EC2 > Network & Security > Elastic IPs.
-
Click Allocate new address to create a Elastic IP address.
-
Configure the Elastic IP to point to the user running NetScaler instance within AWS.
-
Configure a second Elastic IP and again point it to the user running NetScaler instance.
-
-
Elastic Load Balancer
-
Log in to the user AWS resource group and navigate to EC2 > Load Balancing > Load Balancers.
-
Click Create Load Balancer to configure a classic load balancer.
The user Elastic Load Balancers allow users to load balance their back-end Amazon Linux instances while also being able to Load Balance other instances that are spun up based on demand. -
Configure global server load balancing domain-name based services
Deployment types
-
Typical Deployments
-
GSLB StyleBook
-
With ADM
-
With GSLB (Route53 w/domain registration)
-
Licensing - Pooled/Marketplace
-
-
Use Cases
-
Three-NIC Deployments are used to achieve real isolation of data and management traffic.
-
Three-NIC Deployments also improve the scale and performance of the ADC.
-
Three-NIC Deployments are used in network applications where throughput is typically 1 Gbps or higher and a Three-NIC Deployment is recommended.
-
CFT deployment
Deployment steps
-
Three-NIC deployment for GSLB
-
Licensing
-
Deployment options
Three-NIC deployment for GSLB
-
A management subnet
-
A client-facing subnet (VIP)
-
A back-end facing subnet (SNIP)
Licensing
-
Free (unlimited)
-
Hourly
-
Annual
Deployment options
NetScaler global load balancing for hybrid and multi-cloud dployments
NetScaler hybrid and multi-cloud GSLB Solution
-
If users have an existing load balancing setup, it is up and running.
-
A SNIP address or a GSLB site IP address is configured on each of NetScaler GSLB nodes. This IP address is used as the data center source IP address when exchanging metrics with other data centers.
-
An ADNS or ADNS-TCP service is configured on each of NetScaler GSLB instances to receive the DNS traffic.
-
The required firewall and security groups are configured in the cloud service providers.
Security groups configuration
Capabilities of NetScaler hybrid and multi-cloud GSLB solution
Compatibility with other load balancing solutions
GSLB methods
-
Metric-based GSLB methods. Metric-based GSLB methods collect metrics from the other NetScaler nodes through the metrics exchange protocol.
-
Least Connection: The client request is routed to the load balancer that has the fewest active connections.
-
Least Bandwidth: The client request is routed to the load balancer that is currently serving the least amount of traffic.
-
Least Packets: The client request is routed to the load balancer that has received the fewest packets in the last 14 seconds.
-
-
Non-metric based GSLB methods
-
Round Robin: The client request is routed to the IP address of the load balancer that is at the top of the list of load balancers. That load balancer then moves to the bottom of the list.
-
Source IP Hash: This method uses the hashed value of the client IP address to select a load balancer.
-
-
Proximity-based GSLB methods
-
Static Proximity: The client request is routed to the load balancer that is closest to the client IP address.
-
Round-Trip Time (RTT): This method uses the RTT value (the time delay in the connection between the client’s local DNS server and the data center) to select the IP address of the best performing load balancer.
-
GSLB topologies
-
Active-passive topology - Provides disaster recovery and ensures continuous availability of applications by protecting against points of failure. If the primary data center goes down, the passive data center becomes operational. For more information about GSLB active-passive topology, see Configure GSLB for Disaster Recovery.
-
Parent-child topology – Can be used if customers are using the metric-based GSLB methods to configure GSLB and LB nodes and if the LB nodes are deployed on a different NetScaler instance. In a parent-child topology, the LB node (child site) must be a NetScaler appliance because the exchange of metrics between the parent and child site is through the metrics exchange protocol (MEP).
IPv6 support
Monitoring
Persistence
-
Source IP based persistence sessions, so that multiple requests from the same client are directed to the same service if they arrive within the configured time-out window. If the time-out value expires before the client sends another request, the session is discarded, and the configured load balancing algorithm is used to select a new server for the client’s next request.
-
Spillover persistence so that the backup virtual server continues to process the requests it receives, even after the load on the primary falls below the threshold. For more information, see Configure Spillover.
-
Site persistence so that the GSLB node selects a data center to process a client request and forwards the IP address of the selected data center for all subsequent DNS requests. If the configured persistence applies to a site that is DOWN, the GSLB node uses a GSLB method to select a new site, and the new site becomes persistent for subsequent requests from the client.
Configuration by using NetScaler ADM styleBooks
Workflow of NetScaler hybrid and multi-cloud GSLB solution configuration
-
Sign up for a NetScaler Cloud account.To start using NetScaler ADM, create a NetScaler Cloud company account or join an existing one that has been created by someone in your company.
-
After users log on to NetScaler Cloud, click Manage on the NetScaler Application Delivery Management tile to set up the ADM service for the first time.
-
Download and install multiple NetScaler ADM service agents.Users must install and configure the NetScaler ADM service agent in their network environment to enable communication between the NetScaler ADM and the managed instances in their data center or cloud. Install an agent in each region, so that they can configure LB and GSLB configurations on the managed instances. The LB and GSLB configurations can share a single agent. For more information on the above three tasks, see Getting Started.
-
Deploy load balancers on Microsoft AWS cloud/on-premises data centers.Depending on the type of load balancers that users are deploying on cloud and on-premises, provision them accordingly. For example, users can provision NetScaler VPX instances in an Amazon Web Services (AWS) virtual private cloud and in on-premises data centers. Configure NetScaler instances to function as LB or GSLB nodes in standalone mode, by creating the virtual machines and configuring other resources. For more information on how to deploy NetScaler VPX instances, see the following documents:
-
Perform security configurations.Configure network security groups and network ACLs in ARM and in AWS to control inbound and outbound traffic for user instances and subnets.
-
Add NetScaler instances in NetScaler ADM.NetScaler instances are network appliances or virtual appliances that users want to discover, manage, and monitor from NetScaler ADM. To manage and monitor these instances, users must add the instances to the service and register both LB (if users are using NetScaler for LB) and GSLB instances. For more information on how to add NetScaler instances in the NetScaler ADM, see Getting Started
-
Implement the GSLB and LB configurations using default NetScaler ADM StyleBooks.
-
Use Multi-cloud GSLB StyleBook to execute the GSLB configuration on the selected GSLB NetScaler instances.
-
Implement the load balancing configuration. (Users can skip this step if they already have LB configurations on the managed instances.) Users can configure load balancers on NetScaler instances in one of two ways:
-
Manually configure the instances for load balancing the applications. For more information on how to manually configure the instances, see Set up Basic Load Balancing.
-
Use StyleBooks. Users can use one of the NetScaler ADM StyleBooks (HTTP/SSL Load Balancing StyleBook or HTTP/SSL Load Balancing (with Monitors) StyleBook) to create the load balancer configuration on the selected NetScaler instance. Users can also create their own StyleBooks. For more information on StyleBooks, see StyleBooks.
-
-
Use Multi-cloud GSLB StyleBook for LB Node to configure GSLB parent-child topology in any of the following cases:
-
If users are using the metric-based GSLB algorithms (Least Packets, Least Connections, Least Bandwidth) to configure GSLB and LB nodes and if the LB nodes are deployed on a different NetScaler instance.
-
If site persistence is required.
-
Using styleBooks to configure GSLB on NetScaler LB nodes
-
A SNIP address or a GSLB site IP address is configured.
-
The required firewall and security groups are configured in the cloud service providers.
Configuring a child site in a parent-child topology by using multi-cloud GSLB styleBook for LB node
-
Navigate to Applications > Configuration > Create New.
-
Navigate to Applications > Configuration, and click Create New.The StyleBook appears as a user interface page on which users can enter the values for all the parameters defined in this StyleBook.Note:The terms data center and sites are used interchangeably in this document.
-
Set the following parameters:
-
Application Name. Enter the name of the GSLB application deployed on the GSLB sites for which you want to create child sites.
-
Protocol. Select the application protocol of the deployed application from the drop-down list box.
-
LB Health Check (Optional)
-
Health Check Type. From the drop-down list box, select the type of probe used for checking the health of the load balancer VIP address that represents the application on a site.
-
Secure Mode. (Optional) Select Yes to enable this parameter if SSL based health checks are required.
-
HTTP Request. (Optional) If users selected HTTP as the health-check type, enter the full HTTP request used to probe the VIP address.
-
List of HTTP Status Response Codes. (Optional) If users selected HTTP as the health check type, enter the list of HTTP status codes expected in responses to HTTP requests when the VIP is healthy.
-
-
Configuring parent site.
-
Provide the details of the parent site (GSLB node) under which you want to create the child site (LB node).
-
Site Name. Enter the name of the parent site.
-
Site IP Address. Enter the IP address that the parent site uses as its source IP address when exchanging metrics with other sites. This IP address is assumed to be already configured on the GSLB node in each site.
-
Site Public IP Address. (Optional) Enter the Public IP address of the parent site that is used to exchange metrics, if that site’s IP address is NAT’ed.
-
-
-
Configuring child site.
-
Provide the details of the child site.
-
Site name. Enter the name of the site.
-
Site IP Address. Enter the IP address of the child site. Here, use the private IP address or SNIP of NetScaler node that is being configured as a child site.
-
Site Public IP Address. (Optional) Enter the Public IP address of the child site that is used to exchange metrics, if that site’s IP address is NAT’ed.
-
-
-
Configuring active GSLB services (optional)
-
Configure active GSLB services only if the LB virtual server IP address is not a public IP address. This section allows users to configure the list of local GSLB services on the sites where the application is deployed.
-
Service IP. Enter the IP address of the load balancing virtual server on this site.
-
Service Public IP Address. If the virtual IP address is private and has a public IP address NAT’ed to it, specify the public IP address.
-
Service Port. Enter the port of the GSLB service on this site.
-
Site Name. Enter the name of the site on which the GSLB service is located.
-
-
-
Click Target Instances and select NetScaler instances configured as GSLB instances on each site on which to deploy the GSLB configuration.
-
Click Create to create the LB configuration on the selected NetScaler instance (LB node). Users can also click Dry Run to check the objects that would be created in the target instances. The StyleBook configuration that users have created appears in the list of configurations on the Configurations page. Users can examine, update, or remove this configuration by using the NetScaler ADM GUI.
CloudFormation template deployment
CFT three-NIC deployment
-
PrimaryCitrixADCManagementURL - HTTPS URL to the Management GUI of the Primary VPX (uses self-signed cert)
-
PrimaryCitrixADCManagementURL2 - HTTP URL to the Management GUI of the Primary VPX
-
PrimaryCitrixADCInstanceID - Instance Id of the newly created Primary VPX instance
-
PrimaryCitrixADCPublicVIP - Elastic IP address of the Primary VPX instance associated with the VIP
-
PrimaryCitrixADCPrivateNSIP - Private IP (NS IP) used for management of the Primary VPX
-
PrimaryCitrixADCPublicNSIP - Public IP (NS IP) used for management of the Primary VPX
-
PrimaryCitrixADCPrivateVIP - Private IP address of the Primary VPX instance associated with the VIP
-
PrimaryCitrixADCSNIP - Private IP address of the Primary VPX instance associated with the SNIP
-
SecondaryCitrixADCManagementURL - HTTPS URL to the Management GUI of the Secondary VPX (uses self-signed cert)
-
SecondaryCitrixADCManagementURL2 - HTTP URL to the Management GUI of the Secondary VPX
-
SecondaryCitrixADCInstanceID - Instance Id of the newly created Secondary VPX instance
-
SecondaryCitrixADCPrivateNSIP - Private IP (NS IP) used for management of the Secondary VPX
-
SecondaryCitrixADCPublicNSIP - Public IP (NS IP) used for management of the Secondary VPX
-
SecondaryCitrixADCPrivateVIP - Private IP address of the Secondary VPX instance associated with the VIP
-
SecondaryCitrixADCSNIP - Private IP address of the Secondary VPX instance associated with the SNIP
-
SecurityGroup - Security group id that the VPX belongs to
* against any parameter in the CFT implies that it is a mandatory field. For example, VPC ID* is a mandatory field.
-
Key Pair
-
3 unallocated EIPs
-
Primary Management
-
Client VIP
-
Secondary Management
Prerequisites
-
An AWS account to launch a NetScaler VPX AMI in an Amazon Web Services (AWS) Virtual Private Cloud (VPC). Users can create an AWS account for free at Amazon.
-
An AWS Identity and Access Management (IAM) user account to securely control access to AWS services and resources for users. For more information about how to create an IAM user account, see the topic: Creating IAM Users (Console).
-
ec2:DescribeInstances
-
ec2:DescribeNetworkInterfaces
-
ec2:DetachNetworkInterface
-
ec2:AttachNetworkInterface
-
ec2:StartInstances
-
ec2:StopInstances
-
ec2:RebootInstances
-
ec2:DescribeAddresses
-
ec2:AssociateAddress
-
ec2:DisassociateAddress
-
autoscaling:*
-
sns:*
-
sqs:*
-
iam:SimulatePrincipalPolicy
-
iam:GetRole
-
AWS CLI is required to use all the functionality provided by the AWS Management Console from the terminal program. For more information, see What Is the AWS Command Line Interface?. Users also need the AWS CLI to change the network interface type to SR-IOV.