Citrix ADC SDX

提供Citrix ADC实例

Note

The Citrix ADM service connect is enabled by default, after you install or upgrade the Citrix ADC SDX appliance to release 13.1. For more details, see Data governance and Citrix ADM service connect.

You can provision one or more Citrix ADC instances on the SDX appliance by using the Management Service. The number of instances that you can install depends on the license you have purchased. If the number of instances added is equal to the number specified in the license, the Management Service does not allow provisioning more Citrix ADC instances.

Note

You can configure up to 20 VPX instances on a network interface independent of the underlying hardware platform.

在对有关供应Citrix ADC VPX实例appliance comprises the following steps.

  1. Define an admin profile to attach to the Citrix ADC instance. This profile specifies the user credentials that are used by the Management Service to provision the ADC instance and later, to communicate with the instance to retrieve configuration data. You can also use the default admin profile.
  2. Upload the .xva image file to the Management Service.
  3. Add a Citrix ADC instance using the Provision Citrix ADC wizard in the Management Service. The Management Service implicitly deploys the Citrix ADC instance on the SDX appliance and then downloads configuration details of the instance.

Warning

Make sure that you modify the provisioned network interfaces or VLANS of an instance using the Management Service instead of performing the modifications directly on the instance.

Create an admin profile

Admin profiles specify the user credentials that are used by the Management Service when provisioning the Citrix ADC instances. These credentials are later used when communicating with the instances to retrieve configuration data. The user credentials specified in an admin profile are also used by the client when logging on to the Citrix ADC instances through the CLI or GUI.

Admin profiles also enable you to specify that the Management Service and a VPX instance communicate with each other only over a secure channel or using HTTP.

The default admin profile for an instance specifies the default admin user name. This profile cannot be modified or deleted. However, you must override the default profile by creating a user-defined admin profile and attaching it to the instance when you provision the instance. The Management Service administrator can delete a user-defined admin profile if it is not attached to any Citrix ADC instance.

ImportantDo not change the password directly on the VPX instance. If you do so, the instance becomes unreachable from the Management Service. To change a password, first create an admin profile, and then modify the Citrix ADC instance, selecting this profile from the Admin Profile list.

To change the password of Citrix ADC instances in a high availability setup, first change the password on the instance designated as the secondary node. Then change the password on the instance designated as the primary node. Remember to change the passwords only by using the Management Service.

To create an admin profile

  1. On theConfigurationtab, in the navigation pane, expandCitrix ADC Configuration, and then clickAdmin Profiles.

  2. In theAdmin Profiles锅e, clickAdd.

  3. TheCreate Admin Profiledialog box appears.

Admin profile SNMP

Set the following parameters:

  • Profile Name: name of the admin profile. The default profile name isnsroot. You can create user-defined profile names.
  • Password: the password used to log on to the Citrix ADC instance. Maximum length: 31 characters.
  • SSH Port: set the SSH port. The default port is 22.
  • Use global settings for Citrix ADC communication:Select if you want the setting to be defined in the System Settings for the communication between the Management Service and the Citrix ADC instance. You can clear this box and change the protocol to HTTP or HTTPS.

    • Select thehttpoption to use HTTP protocol for the communication between the Management Service and the Citrix ADC instance.

    • Select thehttpsoption to use the secure channel for the communication between the Management Service and the Citrix ADC instance.

4.下SNMP, select the version. If you select v2, go to step 5. If you select v3, go to step 6.

5. Under SNMP v2, add the SNMPCommunityname.

6. Under SNMP v3, addSecurity NameandSecurity Level.

7. UnderTimeout Settings, specify the value.

8. ClickCreate, and then clickClose. The admin profile you created appears in theAdmin Profiles锅e.

If the value in theDefaultcolumn is true the default profile is the admin profile. If the value is false, a user-defined profile is the admin profile.

If you do not want to use a user-defined admin profile, you can remove it from the Management Service. To remove a user-defined admin profile, in theAdmin Profiles锅e, select the profile you want to remove, and then click删除.

Upload a Citrix ADC .xva image

A .xva file is required for adding a Citrix ADC VPX instance.

上传Citrix ADC对有关.xva文件有关pliance before provisioning the VPX instances. You can also download a .xva image file to a local computer as a backup. The .xva image file format is:NSVPX-XEN-ReleaseNumber-BuildNumber_nc.xva.

In theCitrix ADC XVA Files锅e, you can view the following details.

  • Name:Name of the .xva image file. The file name contains the release and the build number. For example, the file nameNSVPX-XEN-12.1-56.22.xva.gzrefers to release 12.1 build 56.22.
  • Last Modified:Date when the .xva image file was last modified.
  • Size:Size, in MB, of the .xva image file.

To upload a Citrix ADC .xva file

  1. On theConfigurationtab, in the navigation pane, expandCitrix ADC Configuration, and then clickXVA Files.
  2. In theCitrix ADC XVA Files锅e, clickUpload.
  3. In theUpload Citrix ADC instance XVAdialog box, clickBrowseand select the XVA image file that you want to upload.
  4. ClickUpload. The XVA image file appears in theCitrix ADC XVA Files锅e after it is uploaded.

To create a backup by downloading a Citrix ADC .xva file

  1. In theCitrix ADC Build Files锅e, select the file that you want to download, and then clickDownload.
  2. In theFile Downloadmessage box, clickSave.
  3. In theSave Asmessage box, browse to the location where you want to save the file, and then clickSave.

Add a Citrix ADC instance

当你一个dd Citrix ADC instances from the Management Service, you need to provide values for some parameters. The Management Service implicitly configures these settings on the Citrix ADC instances.

SDX instance details

  • Name: Assign a name to the Citrix ADC instance.

  • CheckManage through internal networkto enable an independent internal always-on connectivity between the SDX Management Service and the VPX instance.

  • Select an IPv4 or IPv6 address or both IPv4 and IPv6 addresses to access the Citrix VPX instance for the management purpose. A Citrix ADC instance can have only one management IP (NSIP). You cannot remove an NSIP address.

  • Assign a netmask, default gateway, and next hop to Management Service for the IP address.

VPX IP details

Next, add the XVA file, Admin Profile, and a description for the instance.

Note:For a high availability setup (active-active or active-standby), Citrix recommends that you configure the two Citrix ADC VPX instances on different SDX appliances. Make sure that the instances in the setup have identical resources, such as CPU, memory, interfaces, packets per second (PPS), and throughput.

License allocation

In this section, specify the license you have procured for the Citrix ADC. The license can be Standard, Enterprise, and Platinum.

Note:An asterisk indicates required fields.

SDX VPX license allocation

If you need bandwidth bursting ability, selectBurstableunderAllocation Mode. For more information, seeBandwidth Metering in SDX.

Crypto allocation

Starting with release 12.1 48.13, the interface to manage crypto capacity has changed. For more information, seeManage crypto capacity.

Resource allocation

下resource allocation, assign total memory, packets per second, and CPU.

SDX VPX resource allocation

CPUAssign a dedicated core or cores to the instance, or the instance shares a core with other instances. If you select shared, then one core is assigned to the instance but the core might be shared with other instances if there is a shortage of resources. Reboot affected Instances if CPU cores are reassigned. Restart the instances on which CPU cores are reassigned to avoid any performance degradation.

From SDX release 11.1.x.x (MR4), if you are using the SDX 25000xx platform, you can assign a maximum of 16 cores to an instance. Also, if you are using the SDX 2500xxx platform, you can assign a maximum of 11 cores to an instance.

Note:For an instance, the maximum throughput that you configure is 180 Gbps.

The following table lists the supported VPX, Single bungle image version, and the number of cores you can assign to an instance:

Platform Name Total Cores Total Cores Available for VPX Provisioning Maximum Cores That Can Be Assigned to a Single Instance
SDX 8015, SDX 8400, and SDX 8600 4 3 3
SDX 8900 8 7 7
SDX 11500, SDX 13500, SDX 14500, SDX 16500, SDX 18500, and SDX 20500 12 10 5
SDX 11515, SDX 11520, SDX 11530, SDX 11540, and SDX 11542 12 10 5
SDX 17500, SDX 19500, and SDX 21500 12 10 5
SDX 17550, SDX 19550, SDX 20550, and SDX 21550 12 10 5
SDX 14020, SDX 14030, SDX 14040, SDX 14060, SDX 14080, and SDX 14100 12 10 5
SDX 22040, SDX 22060, SDX 22080, SDX 22100, and SDX 22120 16 14 7
SDX 24100 and SDX 24150 16 14 7
SDX 14020 40G, SDX 14030 40G, SDX 14040 40G, SDX 14060 40G, SDX 14080 40G, and SDX 14100 40G 12 10 10
SDX 14020 FIPS, SDX 14030 FIPS, SDX 14040 FIPS, SDX 14060 FIPS, SDX 14080 FIPS, and SDX 14100 FIPS 12 10 5
SDX 14040 40S, SDX 14060 40S, SDX 14080 40S, and SDX 14100 40S 12 10 10
SDX 25100A, 25160A, 25200A 20 18 9
SDX 25100-40G, 25160-40G, 25200-40G 20 18 16 (if version is 11.1-51.x or higher); 9 (if version is 11.1-50.x or lower; all versions of 11.0 and 10.5)
SDX 26100, 26160, 26200, 26250 28 26 16
SDX 26100-50S, 26160-50S, 26200-50S, 26250-50S 28 26 16
SDX 26100-100G, 26160-100G, 26200-100G, 26250-100G 28 26 26
15000-50G 16 14 14

Note: On the SDX 26000 platform, a maximum of 26 CPU cores can be assigned to a VPX instance. However, if crypto units are assigned to the instance, the maximum number of cores depends on the number of crypto units and data interfaces. For example, if you assign 24000 crypto units to an instance, you can assign 24 CPU cores and maximum two data interfaces to the instance. The SDX appliance considers data interfaces and crypto units as PCI devices. With 26000 crypto units, a VPX instance cannot be provisioned because there is no room for data interfaces.

Instance administration

You can create an admin user for the VPX instance by selectingAdd Instance AdministrationunderInstance Administration.

Instance admin

Add the following details:

User name:The user name for the Citrix ADC instance administrator. This user has superuser access but does not have access to networking commands to configure VLANs and interfaces.

Password:The password for the user name.

Shell/Sftp/Scp Access:The access allowed to the Citrix ADC instance administrator. This option is selected by default.

Network settings

  • Allow L2 Mode under network settings

You can allow L2 mode on the Citrix ADC instance. SelectAllow L2 ModeunderNetworking Settings. Before you log on to the instance and enable L2 mode. For more information, seeAllowing L2 Mode on a Citrix ADC instance.

Network settings

Note:

  • If you disable L2 mode for an instance from the Management Service, you must log on to the instance and disable L2 mode from that instance. Failure to do so might cause all the other Citrix ADC modes to be disabled after you restart the instance
  • You cannot delete the interface or channel on an ADC instance from the Management Service.

By default interface 0/1 and 0/2 are selected for management LA.

VLAN tag: specify a VLAN ID for the management interface.

Next, add data interfaces.

Note: The interface IDs of interfaces that you add to an instance do not necessarily correspond to the physical interface numbering on the SDX appliance. If the first interface that you associate with instance 1 is interface 1/4, it appears as interface 1/1 when you view the interface settings on the instance. The numbering changes because it is the first interface that you associated with instance 1.

Add-data-interface

  • Allowed VLANs:Specify a list of VLAN IDs that can be associated with a Citrix ADC instance.

  • MAC Address Mode:Assign a MAC address. Select from one of the following options:

    • Default:Citrix Hypervisor assigns a MAC address.
    • Custom:Choose this mode to specify a MAC address that overrides the generated MAC address.
    • Generated:Generate a MAC address by using the base MAC address set earlier. For information about setting a base MAC address, see Assigning a MAC Address to an Interface.
  • VMAC Settings (IPv4 and IPv6 VRIDs to configure Virtual MAC)

    • VRID IPV4:The IPv4 VRID that identifies the VMAC. Possible values: 1–255. For more information, see Configuring VMACs on an Interface.
    • VRID IPV6:The IPv6 VRID that identifies the VMAC. Possible values: 1–255. For more information, see Configuring VMACs on an Interface.

Management VLAN settings

Typically, the Management Service and the management address (NSIP) of the VPX instance are in the same subnetwork, and communication is over a management interface. However, if the Management Service and the instance are in different subnetworks, you have to specify a VLAN ID at the time of provisioning a VPX instance. This ID is required so that the instance can be reached over the network when it starts. If your deployment requires that the NSIP is accessible only by the interface selected at the time of provisioning the VPX instance, select the NSVLAN option.

Citrix recommends that you do not selectNSVLAN. You cannot change this setting after you have provisioned the Citrix ADC instance.

VPX management VLAN setting

Note:

  • HA heartbeats are sent only on the interfaces that are part of the NSVLAN.
  • You can configure an NSVLAN only from VPX XVA build 9.3 53.4 and later.

Important:If NSVLAN is not selected, running the “clear config full” command on the VPX instance deletes the VLAN configuration.

ClickDoneto provision the Citrix ADC VPX appliance.

Modify a Citrix ADC instance

To modify the parameter values of a provisioned ADC instance, in the Citrix ADC instances pane, select the instance that you want to modify, and then clickModify. In the Modify ADC Wizard, modify the parameters.

Note:If you modify the following parameters: number of SSL chips, interfaces, memory, and feature license, the Citrix ADC instance implicitly stops and restarts to bring these parameters into effect.

You cannot modify the Image and User Name parameters.

To remove an ADC instance provisioned on the SDX appliance, in theCitrix ADC instances锅e, select the instance that you want to remove, and then click删除. In theConfirmmessage box, clickYesto remove the Citrix ADC instance.

Restrict VLANs to specific virtual interfaces

The SDX appliance administrator can enforce specific 802.1Q VLANs on the virtual interfaces associated with Citrix ADC instances. This capability is especially helpful in restricting the usage of 802.1Q VLANs by the instance administrators. If two instances belonging to two different companies are hosted on an SDX appliance, you can restrict the two companies from using the same VLAN ID. By doing so, one company does not see the other company’s traffic. If an instance administrator tries to assign an interface to an 802.1Q VLAN, a validation is performed to verify that the VLAN ID specified is part of the allowed list.

By default, any VLAN ID can be used on an interface. To restrict the tagged VLANs on an interface, specify the VLAN IDs in the Network Settings at the time of provisioning a Citrix ADC instance. You can also specify it later by modifying the instance. To specify a range, separate the IDs with a hyphen (for example 10–12). If you initially specify some VLAN IDs but later delete all of them from the allowed list, you can use any VLAN ID on that interface. In effect, you have restored the default setting.

After creating a list of allowed VLANs, the SDX administrator does not have to log on to an instance to create the VLANs. The administrator can add and delete VLANs for specific instances from the Management Service.

Important: If L2 mode is enabled, the administrator must take care that the VLAN IDs on different Citrix ADC instances do not overlap.

To specify the permitted VLAN IDs

  1. In the Provision ADC Wizard or the Modify ADC Wizard, on the Network Settings page, inAllowed VLANs, specify one or more VLAN IDs allowed on this interface. Use a hyphen to specify a range. For example, 2–4094.
  2. Follow the instructions in the wizard.
  3. ClickFinish, and then clickClose.

To configure VLANs for an instance from the Management Service

  1. On theConfigurationtab, navigate to Citrix ADC > Instances.
  2. Select an instance, and then clickVLAN.
  3. In the details pane, clickAdd.
  4. In theCreate Citrix ADC VLANdialog box, specify the following parameters:
    • VLAN ID—An integer that uniquely identifies the VLAN to which a particular frame belongs. The Citrix ADC supports a maximum of 4094 VLANs. ID 1 is reserved for the default VLAN.
    • IPV6 Dynamic Routing—Enable all IPv6 dynamic routing protocols on this VLAN. Note: For theENABLEDsetting to work, you must log on to the instance and configure IPv6 dynamic routing protocols from the VTYSH command line.
  5. Select the interfaces that must be part of the VLAN.
  6. ClickCreate, and then clickClose.
提供Citrix ADC实例