Deploy a NetScaler® for Azure DNS private zone
Overview of Azure DNS
Why NetScaler GSLB for Azure DNS private zone?
Use case
Use case solution
-
Seamless DNS-based failover.
-
Phased migration from On-premises to cloud.
-
A/B testing a new feature.
-
Round Robin
-
Static proximity (Location based server selection). It can be deployed in two ways:
-
EDNS Client Subnet (ECS) based GSLB on NetScaler.
-
Deploy a DNS forwarder for every virtual network.
-
Topology
Configuring NetScaler for Azure DNS private zone
| Product | Version |
|---|---|
| Azure | Cloud Subscription |
| NetScaler VPX | BYOL (Bring your own license) |
Prerequisites
-
Microsoft Azure portal account with a valid subscription.
-
Ensure connectivity (Secure VPN Tunnel) between On-prem and Azure cloud. To set up a secure VPN tunnel in Azure, see Step-By-Step: Configuring a site-to-site VPN Gateway between Azure and on-premises.
Solution description
-
Configure Azure and On-premises Setup.
-
NetScaler appliance on Azure virtual network.
Configure Azure and On-premises Setup
-
Create an Azure private DNS zone with domain name (mysite.net).
-
Create two virtual networks (VNet A, VNet B) in a Hub and Spoke model in an Azure region.
-
Deploy App Server, DNS forwarder, Windows 10 Pro client, NetScaler in VNet A.
-
Deploy an App Server and deploy a DNS forwarder if any clients are in VNet B.
-
Deploy an App server, DNS forwarder, and Windows 10 pro client on On-premises.
Azure private DNS zone
-
Log in to the Azure portal and select or create a dashboard.
-
Click create a resource and search for DNS zone to create (mysite.net in this case) Azure private DNS zone with domain name (mysite.net).
Azure virtual networks (VNet A, VNet B) in Hub and spoke model
-
Create two virtual networks.
-
Select the same dashboard and click create a resource and search for virtual networks to create two virtual networks namely VNet A, VNet B in the same region and peer them to form a Hub and Spoke model as shown in the following image. For more information on how to set up a hub and spoke topology, See Implement a hub-spoke network topology in Azure.


VNet A to VNet B peering
-
Click Peerings from the Settings menu of VNet A and peer VNet B.
-
Enable Allow forwarded traffic and Allow gateway transit as shown in the following image.

VNet B to VNet A peering
-
Click Peerings from the Settings menu of VNet B and peer VNet A.
-
Enable Allow forwarded traffic and use remote gateways as shown in the following image.
Deploy App server, DNS forwarder, Windows 10 Pro client, NetScaler in VNet A
-
Select the same dashboard, click Create a resource.
-
Search for the respective instances and assign an IP from VNet A subnet.
App server
sudo apt install apache2
Windows 10 Pro Client
NetScaler
DNS forwarder
-
After deploying forwarder, change the DNS server settings of virtual network A from default to custom with VNet A DNS forwarder IP as shown in the following image.
-
Modify the
named.conf.optionsfile in VNet A DNS forwarder to add forwarding rules for domain (mysite.net) and subdomain (ptm.mysite.net) to the ADNS IP of NetScaler GSLB. -
Restart the DNS forwarder to reflect the changes made in the file
named.conf.options.
VNet A DNS forwarder settings
zone "mysite.net" {
type forward;
forwarders { 168.63.129.16; };
};
zone "ptm.mysite.net" {
type forward;
forwarders { 10.8.0.5; };
};
Deploy App server and a DNS forwarder if any clients are in VNet B
-
For virtual network B, select the same dashboard, click create a resource.
-
Search for the respective instances, and assign an IP from VNet B subnet.
-
Launch App server and DNS forwarder if there is static proximity GSLB load balancing similar to VNet A.
-
Edit the VNet B DNS forwarder settings in
named.conf.optionsas shown in the following setting:VNet B DNS forwarder settings:
zone "ptm.mysite.net" {
type forward;
forwarders { 10.8.0.5; };
};
Deploy app server, DNS forwarder, and Windows 10 pro client on On-premises
-
For On-premises, launch the VMs on bare metal and bring the App server, DNS forwarder and Windows 10 pro client similar to VNet A.
-
Edit the On-premises DNS forwarder settings in the
named.conf.optionsas shown in the following example.
On-Premises DNS forwarder settings
zone "mysite.net" {
type forward;
forwarders { 10.8.0.6; };
};
zone "ptm.mysite.net" {
type forward;
forwarders { 10.8.0.5; };
};
mysite.net, we have given DNS forwarder IP of VNet A instead of Azure private DNS zone server IP because it is a special IP address that is not reachable from On-premises. Hence this change is required in the DNS forwarder setting of On-premises.
Configure the NetScaler on Azure virtual network
Configuring NetScaler GSLB
-
Create ADNS Service.
-
Create local and remote sites.
-
Create services for the local virtual servers.
-
Create virtual servers for the GSLB services.
Add ADNS service
-
Log in to the NetScaler GUI.
-
In the Configuration tab, navigate to Traffic Management > Load Balancing > Services.
-
Add a service. We recommended you to configure the ADNS service both in TCP and UDP as shown in the following image:


Add GSLB sites
-
Add local and remote sites between which GSLB will be configured.
-
On the Configuration tab, navigate to Traffic Management > GSLB > GSLB Sites. Add a site as shown in the following example and repeat the same procedure for other sites.



Add GSLB services
-
Add GSLB services for the local and remote virtual servers which load balances App servers.
-
On the Configuration tab, navigate to Traffic Management > GSLB > GSLB Services.
-
Add the services as shown in the following examples.
-
Bind HTTP monitor to check server status.


-
After creating the service, go to the Advanced settings tab inside the GSLB service.
-
Click Add Monitor to bind the GSLB service with an HTTP monitor to bring up the state of service.
-
Once you bind with the HTTP monitor, the state of the services is marked as UP as shown in the following image:
Add GSLB virtual server
-
On the Configuration tab, navigate to Traffic Management > GSLB > GSLB Virtual Servers.
-
Add the virtual servers as shown in the following example.
-
Bind GSLB services and domain name to it.

-
After creating the GSLB virtual server and selecting the appropriate load balancing method (Round Robin in this case), bind GSLB services and domains to complete the step.

-
Go to the Advanced settings tab inside the virtual server and click Add Domains tab to bind a domain.
-
Go to Advanced > Services and click the arrow to bind a GSLB service and bind all three services (VNet A, VNet B, On-premises) to virtual server.
After binding GSLB services and domain to the virtual server it appears as shown in the following image:
rr.ptm.mysite.net from either cloud client machine or On-premises client machine. If you access it from cloud windows client machine ensure that the on-premises App server is accessed in a private DNS zone without any need for third party or custom DNS solutions.