Getting Started with Citrix NetScaler
Deploy a Citrix NetScaler VPX instance
Install a Citrix NetScaler VPX instance on Microsoft Hyper-V servers
Install a NetScaler VPX instance on Linux-KVM platform
Prerequisites for Installing NetScaler VPX Virtual Appliances on Linux-KVM Platform
Provisioning the NetScaler Virtual Appliance by using OpenStack
Provisioning the NetScaler Virtual Appliance by using the Virtual Machine Manager
Configuring NetScaler Virtual Appliances to Use SR-IOV Network Interface
Configuring NetScaler Virtual Appliances to use PCI Passthrough Network Interface
Provisioning the NetScaler Virtual Appliance by using the virsh Program
Deploying NetScaler VPX Instances on AWS
Upgrade and downgrade a NetScaler appliance
-
-
-
-
-
Configure DNS resource records
Domain name system security extensions
Configure DNSSEC when the NetScaler ADC is authoritative for a zone
Configure DNSSEC for a zone for which the NetScaler ADC is a DNS proxy server
-
Overriding Static Proximity Behavior by Configuring Preferred Locations
Example of a Complete Parent-Child Configuration Using the Metrics Exchange Protocol
Configuring Global Server Load Balancing for DNS Queries with NAPTR records
Using the EDNS0 Client Subnet Option for Global Server Load Balancing
-
Persistence and persistent connections
Advanced load balancing settings
Gradually stepping up the load on a new service with virtual server–level slow start
Protect applications on protected servers against traffic surges
Use source IP address of the client when connecting to the server
Set a limit on number of requests per connection to the server
Configure automatic state transition based on percentage health of bound services
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
Use case 3: Configure load balancing in direct server return mode
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
Use case 7: Configure load balancing in DSR mode by using IP Over IP
Use case 10: Load balancing of intrusion detection system servers
Use case 11: Isolating network traffic using listen policies
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
Configuring CloudBridge Connector between Datacenter and AWS Cloud
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde.(Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique.(Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica.(Aviso legal)
此内容已经过机器动态翻译。放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다.책임 부인
Este texto foi traduzido automaticamente.(Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt.(Haftungsausschluss)
Ce article a été traduit automatiquement.(Clause de non responsabilité)
Este artículo ha sido traducido automáticamente.(Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Configure DNSSEC for a zone for which the NetScaler is a DNS proxy server
签署的过程区域的网络Scaler ADC is configured as a DNS proxy server depends on whether or not the ADC owns a subset of the zone information owned by the backend name servers. If it does, the configuration is considered apartial zone ownership configuration. If the ADC does not own a subset of the zone information, the NetScaler configuration for managing the backend servers is considered azone-less DNS proxy server configuration. The basic DNSSEC configuration tasks for both NetScaler configurations are the same. However, signing the partial zone on the NetScaler requires some additional configuration steps.
Note:The termszone-less proxy server configurationandpartial zoneare used only in the context of the NetScaler appliance.
Important:When configured in proxy mode, the ADC does not perform signature verification on DNSSEC responses before updating the cache.
If you configure the ADC as a DNS proxy to load balance DNSSEC aware resolvers (servers), you must set the Recursion Available option while configuring the DNS virtual server. If a DNSSEC query arrives with Checking Disabled (CD) bit set, the query is passed on to the server with the CD bit retained, and the response from the server is not cached. In releases prior to 10.5.e build xx.x, the ADC unset the CD bit before passing it to the server and also cached the server response.
Configure DNSSEC for a zone-less DNS proxy server configuration
For a zone-less DNS proxy server configuration, zone signing must be performed on the backend name servers. On the NetScaler, you configure the ADC as a DNS proxy server for the zone. You create a load balancing virtual server of protocol type DNS, configure services on the ADC to represent the name servers, and then bind the services to the load balancing virtual server. For more information about these configuration tasks, seeConfigure the NetScaler as a DNS proxy server.
When a client sends the ADC a DNS request with the DNSSEC OK (DO) bit set, the ADC checks its cache for the requested information. If the resource records are not available in its cache, the ADC forwards the request to one of the DNS name servers, and then relays the response from the name server to the client. Additionally, the ADC caches the RRSIG resource records along with the response from the name server. Subsequent requests from DNSSEC-aware clients are served from the cache (including the RRSIG resource records), subject to the time-to-live (TTL) parameter. If a client sends a DNS request without setting the DO bit, the ADC responds with only the requested resource records, and does not include the RRSIG resource records that are specific to DNSSEC.
Configure DNSSEC for a partial zone ownership configuration
在一些NetScaler配置,即使authority for a zone lies with the backend name servers, a subset of the resource records that belong to the zone might be configured on the NetScaler. The ADC owns (or is authoritative for) only this subset of records. Such a subset of records can be considered to constitute apartial zoneADC。ADC拥有部分区域。所有的都er records are owned by the backend name servers.
A typical partial zone configuration on the NetScaler is seen when global server load balancing (GSLB) domains are configured on the ADC, and the GSLB domains are a part of a zone for which the backend name servers are authoritative.
Signing a zone that includes only a partial zone on the ADC involves including the partial zone information in the backend name server zone files, signing the zone on the backend name servers, and then signing the partial zone on the ADC. The same key set must be used to sign the zone on the name servers and the partial zone on the ADC.
Sign the zone on the backend name servers
- Include the resource records that are contained in the partial zone, in the zone files of the name servers.
- Create keys and use the keys to sign the zone on the backend name servers.
Sign the partial zone on the NetScaler
Create a zone with the name of the zone that is owned by the backend name servers. When configuring the partial zone, set the proxyMode parameter to YES. This zone is the partial zone that contains the resource records owned by the ADC.
For example, if the name of the zone that is configured on the backend name servers is example.com, you must create a zone named example.com on the ADC, with the proxyMode parameter set to YES. For more information about adding a zone, seeConfigure a DNS zone.
Note
Do not add SOA and NS records for the zone. These records should not exist on the ADC for a zone for which the ADC is not authoritative.
- Import the keys (from one of the backend name servers) to the ADC and then add them to the /nsconfig/dns/ directory. For more information about how you can import a key and add it to the ADC, seePublish a DNS key in a zone.
- Sign the partial zone with the imported keys. When you sign the partial zone with the keys, the ADC generates RRSIG and NSEC records for the resource record sets and individual resource records in the partial zone, respectively. For more information about signing a zone, seesign and unsign a DNS zone.
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select Do Not Agree to exit.