Deploy a NetScaler high-availability pair on Azure with ALB in the floating IP-disabled mode
-
An HA Independent Network Configuration (INC) configuration
-
The Azure Load Balancer (ALB) with:
-
Floating IP-enabled mode or Direct Server Return (DSR) mode
-
Floating IP-disabled mode
-
HA deployment architecture with ALB in the floating IP-disabled mode
Prerequisites
-
Azure terminology and network details. For more information, see Azure terminology.
-
Working of a NetScaler appliance. For more information, see NetScaler documentation.
-
NetScaler networking. For more information, see the ADC Networking.
-
Azure load balancer and load-balancing rule configuration. For more information, see Azure ALB documentation.
How to deploy a VPX HA pair on Azure with ALB floating IP disabled
-
Deploy two VPX instances (primary and secondary instances) on Azure.
-
Add client and server NIC on both the instances.
-
Deploy an ALB with load balancing rule whose floating IP mode is disabled.
-
Configure HA settings on both instances by using the NetScaler GUI.
-
Select the NetScaler version from Azure Marketplace (in this example, NetScaler release 13.1 is used).

-
Select the required ADC licensing mode, and click Create.
The Create a virtual machine page opens. -
Complete the required details in each tab: Basics, Disks, Networking, Management, Monitoring, Advanced, and Tags, for a successful deployment.

-
In the Networking tab, create a new Virtual network with 3 subnets, one each for: management, client, and server NICs. Otherwise, you can also use an existing Virtual network. Management NIC is created during the VM deployment. Client and server NICs are created and attached after the VM is created. For the NIC network security group, you can do one of the following:
-
Select Advanced and use an existing network security group that suits your requirements.
-
Select Basic and select the required ports.
Note:You can also change the network security group settings after the VM deployment is completed.
-
-
Click Next: Review + create >.After the validation is successful, review the basic settings, VM configurations, network and additional settings, and click Create.

-
After the deployment is complete, Click Go to Resource to see the configuration details.
Similarly, deploy a second NetScaler VPX instance.
-
Navigate to Networking > Attach Network Interface.You can select an existing NIC or create and attach a new interface.
-
For the NIC Network Security Group, you can use an existing network security group by selecting Advanced or create one by selecting Basic.

-
Go to the Load balancers page and click Create.
-
In the Create load balancer page, provide the details as required.In the following example, we deploy a regional public load balancer of Standard SKU.
Note:All public IPs attached to the NetScaler VMs must have the same SKU as that of ALB. For more information about ALB SKUs, see the Azure Load Balancer SKUs' documentation. -
In the Frontend IP configuration tab, either create an IP address or use an existing IP address.


-
In the Backend pools tab, select NIC-based backend pool configuration, and add the client NICs of both the NetScaler VMs.

-
In Inbound rules tab, click Add a Load balancing rule, and provide the frontend IP address and backend pool created in the previous steps. Select the protocol and port based on your requirement. Create or use an existing health probe. The floating IP option must be set as Disabled.

-
Click Review + Create. After the validation is passed, click Create.

-
Log on to the instance with user name
nsrootand password provided while deploying the instance. -
Navigate to Configuration > System > High Availability > Nodes, and click Add.
-
In the Remote Node IP address field, enter the private IP address of the management NIC of the secondary instance, for example: 10.4.1.5.
-
Select the Turn on INC (Independent Network Configuration) mode on self node check box.
-
Click Create.
-
Log on to the instance with user name
nsrootand password provided while deploying the instance. -
Navigate to Configuration > System > High Availability > Nodes, and click Add.
-
In the Remote Node IP address field, enter the private IP address of the management NIC of the primary instance, for example: 10.4.1.4.
-
Select the Turn on INC (Independent Network Configuration) mode on self node check box.
-
Click Create.
-
Navigate to System > Network > IPs > IPv4s, and click Add.
-
Add a primary VIP address by following these steps:
-
Enter the private IP address of the client NIC of the primary instance and netmask configured for the client subnet in the VM instance.
-
In the IP Type field, select Virtual IP from the drop-down menu.
-
Click Create.
-
-
Add a primary SNIP address by following these steps:
-
Enter the internal IP address of the server NIC of the primary instance, and netmask configured for the server subnet in the primary instance.
-
In the IP Type field, select Subnet IP from the drop-down menu.
-
Click Create.
-
-
Add a secondary VIP address by following these steps:
-
Enter the internal IP address of the client NIC of the secondary instance, and netmask configured for the client subnet in the VM instance.
-
In the IP Type field, select Virtual IP from the drop-down menu.
-
Click Create.

-
-
Navigate to System > Network > IPs > IPv4s, and click Add.
-
Add a secondary VIP address by following these steps:
-
Enter the internal IP address of the client NIC of the secondary instance, and netmask configured for the client subnet in the VM instance.
-
In the IP Type field, select Virtual IP from the drop-down menu.
-
-
Add a secondary SNIP address by following these steps:
-
Enter the internal IP address of the server NIC of the secondary instance, and netmask configured for the server subnet in the secondary instance.
-
In the IP Type field, select Subnet IP from the drop-down menu.
-
Click Create.

-
-
Navigate to System > Network > IP Sets > Add.
-
Add an IP set name and click Insert.
-
From the IPV4s page, select the virtual IP (secondary VIP) and click Insert.
-
Click Create to create the IP set.

-
Navigate to System > Network > IP Sets > Add.
-
Add an IP set name and click Insert.
-
From the IPv4s page, select the virtual IP (secondary VIP) and click Insert.
-
Click Create to create the IP set.

-
Navigate to Configuration > Traffic Management > Load Balancing > Virtual Servers > Add.
-
Add the required values for Name, Protocol, IP Address Type (IP Address), IP address (primary VIP), and Port.
-
Click More. Navigate to IP Range IP Set Settings, select IPset from the drop-down menu, and provide the IPset created in Step 3.
-
Click OK to create the load balancing virtual server.
-
Navigate to Configuration > Traffic Management > Load Balancing > Services > Add.
-
Add the required values for Service Name, IP Address, Protocol and Port, and click OK.
-
Navigate to Configuration > Traffic Management > Load Balancing > Virtual Servers.
-
Select the load balancing virtual server configured in Step 4, and click Edit.
-
In the Service and Service Groups tab, click No Load Balancing Virtual Server Service Binding.
-
Select the service configured in the Step 5, and click Bind.
-
Copy the ALB frontend IP address.
-
Paste the IP address on browser and make sure that the back-end servers are reachable.
-
On the primary instance, perform failover:From NetScaler GUI, navigate to Configuration > System > High Availability > Action > Force Failover.

-
Make sure that back-end servers are reachable after failover through ALB frontend IP used earlier.