Book Image

Troubleshooting NetScaler

By : Raghu Varma Tirumalaraju
Book Image

Troubleshooting NetScaler

By: Raghu Varma Tirumalaraju

Overview of this book

NetScaler is a high performance Application Delivery Controller (ADC). Making the most of it requires knowledge that straddles the application and networking worlds. As an ADC owner you will also likely be the first person to be solicited when your business applications fail. You will need to be quick in identifying if the problem is with the application, the server, the network, or NetScaler itself. This book provides you with the vital troubleshooting knowledge needed to act fast when issues happen. It gives you a thorough understanding of the NetScaler layout, how it integrates with the network, and what issues to expect when working with the traffic management, authentication, NetScaler Gateway and application firewall features. We will also look at what information to seek out in the logs, how to use tracing, and explore utilities that exist on NetScaler to help you find the root cause of your issues.
Table of Contents (17 chapters)
Troubleshooting NetScaler
Credits
Notice
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Configuration checklist


Here's a quick checklist of the items that need to be in place for KCD to function properly:

  • On the Active Directory Server:

    • AD account representing the NetScaler as a system User that can obtain tickets for other users

    • Keytab for this NetScaler User

    • Constrained delegation enabled for the NetScaler system account

    • List of resources that the end User can delegate to NetScaler for authentication

  • On the Web Server:

    • Kerberos enabled on the site

    • Best practice is to have NTLM enabled as fallback

  • On the NetScaler:

    • Authentication on the LB VIP. The server is added on the NetScaler with its domain/hostname – this is very important. The domain controller should also be able to resolve the hostname correctly:

  • Authentication vServer with authentication and session/traffic policies

Kerberos deployment options

There are a couple of choices available for implementing Kerberos:

  • Impersonation versus Delegation: To impersonate a User in the impersonation scenario, NetScaler needs the credentials...