Jump to content
Updated Privacy Statement

Carl Stalhood

Members
  • Posts

    26
  • Joined

  • Last visited

Everything posted by Carl Stalhood

  1. HA between separate hardware models is not supported because the NICs are different. But some have reported success.
  2. The newer models only support 13.1 firmware. Here's one method of migrating - https://www.carlstalhood.com/migrate-citrix-adc-config-to-new-adc-appliances/
  3. MBF (Mac Based Forwarding) will send replies to the same MAC/interface/VLAN that the request came from. For Layer 3 outbound routing, NetScaler will use a SNIP on the same subnet as the next hop gateway/router. Add routes to the routing table. Another option is PBRs for traffic that have particular VIPs are source IP.
  4. Each object is removed separately. Some of the objects can be shared by multiple vServers so you don't want deletion of one vServer to affect objects being used by other vServers.
  5. See https://developer-docs.netscaler.com/en-us/adc-command-reference-int/current-release/lb/lb-vserver.html#set-lb-vserver There's a disable command. And the set command has -state disabled.
  6. Does your nFactor ask for user password? If so, send the user's password to StoreFront. If not, and if you don't enable FAS, then the VDA will ask the user to enter the user's password. This is separate from any password prompt at your IdP. StoreFront can show a user's icons even if the StoreFront never received the user's password because StoreFront can rely on the Gateway Callback.
  7. Does your nFactor ask for user password? If so, send the user's password to StoreFront. If not, and if you don't enable FAS, then the VDA will ask the user to enter the user's password. This is separate from any password prompt at your IdP.
  8. I think large enterprises can still order new pooled capacity. And you can renew existing pooled capacity.
  9. Citrix Gateway ICA Proxy allows a single protocol/port number: SSL 443 on front-end, ICA 2598 on back-end. The only internal machines that ICA Proxy connects to are Citrix VDAs. This is much more restrictive than a full VPN that allows a VPN client machine to connect to almost any internal machine on any protocol/port number.
  10. Thanks. If there are separate pages for each major NetScaler version, then the 14.1 page should only have 14.1 versions.
  11. Will 13.1 VPX support the latest ESX 7? Or will all ESX VPX customers be forced to upgrade to 14.1?
  12. Does this mean that only 14.1 is supported on latest ESX 7? https://docs.netscaler.com/en-us/citrix-adc/current-release/deploying-vpx/supported-hypervisors-features-limitations.html
  13. The admin login page for 14.1 also says Citrix ADC instead of NetScaler.
  14. When I upload a PFX at Settings > Administration > Install Cert, it says PKCS not supported.
  15. On SDX, VPXs ask for packets per second. Where can I find the maximum value for each hardware platform?
  16. Why is 14.1 called Citrix ADC instead of NetScaler?
  17. nspepi can convert config items that are removed from 13.1. https://github.com/citrix/ADC-scripts/blob/master/nspepi/README.md ​ However, most classic Gateway policies still exist in 13.1. If you want to convert them now, then you do it yourself by removing all classic policies and replacing them with advanced policies. Or wait until a future release of NetScaler and its nspepi tool that will probably convert those policies.
  18. The Gateway-only license is no longer available. The Standard Edition license is no longer available. However, Advanced Edition and Premium Edition are still available, and both include the Gateway feature.
  19. Any firewall that is inspecting outbound Internet? https://docs.netscaler.com/en-us/citrix-application-delivery-management-service/system-requirements.html#supported-ports has the URLs that need to be accessible by the ADM Agent.
×
×
  • Create New...