Book Image

Troubleshooting NetScaler

By : Raghu Varma Tirumalaraju
Book Image

Troubleshooting NetScaler

By: Raghu Varma Tirumalaraju

Overview of this book

NetScaler is a high performance Application Delivery Controller (ADC). Making the most of it requires knowledge that straddles the application and networking worlds. As an ADC owner you will also likely be the first person to be solicited when your business applications fail. You will need to be quick in identifying if the problem is with the application, the server, the network, or NetScaler itself. This book provides you with the vital troubleshooting knowledge needed to act fast when issues happen. It gives you a thorough understanding of the NetScaler layout, how it integrates with the network, and what issues to expect when working with the traffic management, authentication, NetScaler Gateway and application firewall features. We will also look at what information to seek out in the logs, how to use tracing, and explore utilities that exist on NetScaler to help you find the root cause of your issues.
Table of Contents (17 chapters)
Troubleshooting NetScaler
Credits
Notice
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Lightweight Directory Access Protocol


LDAP is very popular both as a directory service and for authentication and authorization. It provides an excellent level of flexibility in identifying whether a User exists, whether the credentials are correct, and what groups the User is a part of (this is called group extraction).

The ports used for LDAP are as follows:

  • TCP 389: Standard LDAP

  • TCP 636: Encrypted LDAP

  • TCP 3268: Global catalog, unencrypted

  • TCP 3269: Global catalog, encrypted

Authentication flow

The following Wireshark snapshot shows what the exchange between NetScaler and the LDAP server should look like:

LDAP

The steps here are as follows:

  • bindRequest: Here, the NetScaler is authenticating itself to the LDAP server

  • bindResponse: If the method used (usually SASLSimple Authentication and Security Layer) and the credentials provided are both okay, the LDAP server responds with a success

  • searchRequest: At this point, NetScaler runs through the User authentication; it starts by verifying...