Network architecture for NetScaler VPX instances on Microsoft Azure
-
Public IP (PIP) address is the internet-facing IP address configured directly on the virtual NIC of the NetScaler® VM. This allows you to directly access a VM from the external network.
-
NetScaler IP (also known as NSIP) address is the internal IP address configured on the VM. It is non-routable.
-
Virtual IP address (VIP) is configured by using the NSIP and a port number. Clients access NetScaler services through the PIP address, and when the request reaches the NIC of the NetScaler VPX™ VM or the Azure load balancer, the VIP gets translated to internal IP (NSIP) and internal port number.
-
Internal IP address is the private internal IP address of the VM from the virtual network’s address space pool. This IP address cannot be reached from the external network. This IP address is by default dynamic unless you set it to static. Traffic from the internet is routed to this address according to the rules created on the network security group. The network security group integrates with the NIC to selectively send the right type of traffic to the right port on the NIC, which depends on the services configured on the VM.
Traffic flow through network address translation
Port usage guidelines
-
The NetScaler VPX instance reserves the following ports. You cannot define these as private ports when using the Public IP address for requests from the internet.Ports 21, 22, 80, 443, 8080, 67, 161, 179, 500, 520, 3003, 3008, 3009, 3010, 3011, 4001, 5061, 9000, 7000.However, if you want internet-facing services such as the VIP to use a standard port (for example, port 443) you have to create port mapping by using the network security group. The standard port is then mapped to a different port that is configured on the NetScaler for this VIP service.For example, a VIP service might be running on port 8443 on the VPX instance but be mapped to public port 443. So, when the user accesses port 443 through the Public IP, the request is directed to private port 8443.
-
Public IP address does not support protocols in which port mapping is opened dynamically, such as passive FTP or ALG.
-
High availability does not work for traffic that uses a public IP address (PIP) associated with a VPX instance, instead of a PIP configured on the Azure load balancer.