Link to home
Start Free TrialLog in
Avatar of compdigit44
compdigit44

asked on

Netscaler 9.3 Source IP and Firewalls

I am not a networking expert but was hoping of someone could clarify this for me.

We are using a Citric Netscaler 9.3 which has one of it load balanced services set to use Source IP.  This is needed so we see the clients actually IP address instead of seeing all connections in the log as coming from the Netscaler. Anyway now  this is working perfectly but I was told that by default a route will drop a packet if the source IP differs from what is was received on....

I do not manage our firewall but am interested to learn more about his for my own knowledge.
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of compdigit44
compdigit44

ASKER

Wow this is a great reason.... I have to admit thought you answer was do in-depth it was a bit over my head.

So does using USIP on a Netscaler require any changes on the firewall????
no changes as NS is to send over the actual Src IP as stated. The key takeaway is the FW has to assume the syn attack and surge protection which NS can do as well but due to this change of retaining Src IP, the benefits are not of effect from NS anymore or minimal.