Solved

How design a Citrix Netscaler deployment?

Posted on 2013-01-29
3
3,329 Views
Last Modified: 2016-10-25
Hello Everyone,

Just purchased a new Netscaler 8200.  We want to use this for reverse proxy, NLB and SSL vpn.  I am trying to figure out the best deployment scenario for our environment.  

Basic Setup:
The netscaler has a management nic.  Is this interface any different then the other interfaces?  Does having a management nic on different network mean that it would be a 2 arm deployment?

If everything is behind a firewall should I even bother with a management nic?  With the management nic routing becomes more complicated.

SSL VPN
For SSL vpn is it best to have a nic the inside and one on the DMZ?  Or should I just have a single nic in the DMZ?  

Reverse proxy
If we want to do reverse proxy in the DMZ for servers that reside on internal network is single arm ok?

Thanks
0
Comment
Question by:jdflory
3 Comments
 
LVL 4

Expert Comment

by:ChanduNelluri
ID: 38833695
Hi,

Following Citrix document will give you comprehensive details of how to setup SSL VPN and reverse proxy.

http://cdn.ws.citrix.com/wp-content/uploads/2008/09/Citrix_SSLVPN_DeploymentGuide.pdf
http://support.citrix.com/proddocs/topic/netscaler-cache-redirection-92/ns-cr-config-revrs-prx-redirct-tsk.html

Single arm should be okay for Reverse proxy setup. Single arm setup is easy to implement and troubleshoot; not many network changes required and provides good security..

-Chandu
0
 

Author Comment

by:jdflory
ID: 38835383
Is single arm ok for vpn?  Should I be looking at each service separately?  Like single arm for reverse proxy and dual arm for vpn?

If I have single arm for vpn would have to open all ports from netscaler to inside network?

Thanks
0
 
LVL 8

Accepted Solution

by:
gsmartin earned 500 total points
ID: 38835739
First, the NetScaler IP (NSIP) address is the IP address at which you access the NetScaler for management purposes. The NetScaler can have only one NSIP, which is also called the Management IP address. You must add this IP address when you configure the NetScaler for the first time. If you modify this address, you must reboot the NetScaler. You cannot remove an NSIP address. For security reasons, NSIP should be a non-routable IP address on your organization's LAN.  

FYI... This is Citrix's description of NSIP.  I have my Management IP (NSIP) configured and isolated on a separate internal management network.

Other interfaces have their specific purpose and it's important to understand each i.e. SNIP (Subnet IP), MIP (Mapped IP), VIP (Virtual IP).  SNIP is typically used as your VLAN IP, MIP is typically used as a Last resort proxy (atleast one MIP has to be configured), and VIP is used as a virtual IP address to virtually sit in front of your servers, which the client machines will communicate to.

http://support.citrix.com/article/CTX120318

Further, in respect to VPN, I have a single arm configuration for VPN with multiple VLANs on the same interface and it works very well with no problems.  The single arm configuration was easier to deploy when I was new to the Netscaler, but now I am working on switching over to the dual arm configuration.
0

Join & Write a Comment

Citrix XenDesktop, gold image, VMware, vSphere.
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now