Book Image

Troubleshooting NetScaler

By : Raghu Varma Tirumalaraju
Book Image

Troubleshooting NetScaler

By: Raghu Varma Tirumalaraju

Overview of this book

NetScaler is a high performance Application Delivery Controller (ADC). Making the most of it requires knowledge that straddles the application and networking worlds. As an ADC owner you will also likely be the first person to be solicited when your business applications fail. You will need to be quick in identifying if the problem is with the application, the server, the network, or NetScaler itself. This book provides you with the vital troubleshooting knowledge needed to act fast when issues happen. It gives you a thorough understanding of the NetScaler layout, how it integrates with the network, and what issues to expect when working with the traffic management, authentication, NetScaler Gateway and application firewall features. We will also look at what information to seek out in the logs, how to use tracing, and explore utilities that exist on NetScaler to help you find the root cause of your issues.
Table of Contents (17 chapters)
Troubleshooting NetScaler
Credits
Notice
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Performance issues when enabling AppFirewall


The following are the performance issues when AppFirewall is enabled:

  • A very tempting expression when configuring AppFirewall policies, is the expression true. This is useful during troubleshooting, since it provides a guaranteed way for AppFirewall to trigger. However, if used for actual production, depending on how much traffic and how comprehensive the protection policies, this can easily result in a significant performance hit. A better practice is to create policies that match the profile of requests, such as: HTTP.REQ.HOSTNAME.EQ("example.com").

  • Similarly, Regex, which is a particular favorite of administrators coming from the scripting world, is very tempting to use and is sometimes absolutely necessary to achieve a certain level of flexibility. However, Regex too when applied to too many requests has a performance impact. Where possible, use literal matches and the fastmatch option we talked about in the Signatures section.

  • A final performance...