This message was deleted.
# citrix-netscaler
s
This message was deleted.
e
From my experience (atleast if you are not using http compression, as in my case) - you can safely ignore the "bind cmp*" stuff and proceed with .\nsinstall -y
c
Hi yes i am not using any extra compression / content filtering polices those are all out of the box polices. So i should be ok going from 12.1 to 13.1 by just running the firmware upgrade and I dont have to fix them prior to firmware upgrade ??. Does the firmware upgrade automatically upgrade/remove those polices ? what about my authorization polices bound to my AAA groups for our VPN? will i have to convert them to advanced expressions eg REQ.IP.DESTIP == 10.129.0.0 -netmask 255.255.0.0" to "CLIENT.IP.DST.IN_SUBNET(10.129.0.0/16)" ?
e
Looks like the upgrade process automatically removes them. Just confirmed on a VPX I upgraded earlier (13.0 --> 13.1) The filter stuff did not show up for me when running the pre configuration check, but it sounds safe to proceed if it is all out of the box stuff you are not using. I do not think classic policies for authorization are removed yet. Maybe that is why nspepi is not picking up on it.
c
"_ESNS" policies are HTML Injection, cmp are compression. All of that looks like default NS config to me that's been carried forward from older code.
c
Cool so should be straightforward update from 12.1 to 13.1 is it worth me changing the authorization polices to advanced expressions ? or will they continue to work on classic policy expressions
c
I would personally update to advanced expressions before a 13.1 upgrade regardless. They may not have completely removed classic policies yet in 13.1 (don't know the latest details) but the second you encounter any trouble you'll almost certainly be told to convert to advanced before they can do further troubleshooting.
👍 1
o
@c4rm0 yea, same boat here and I have a ton of authorization policies I have sorted through. Will be removing any that can be cleaned out entirely and then for the rest, I need to get them converted to advanced policy is my plan on those here first. I already did the same for the authentication workflow (moving to advanced) and now need to sort through all of these auth policies next.
👍 1
s
I found the same issue recently upgrading from 13.0 --> 13.1 I just unbound the compression policies to get round this. I'm doing another upgrade soon where the the NetScaler is using lots of classic policies for EPA scans which I think will remain post upgrade. I built a test 13.0 NS and upgraded to test, also had to use the -Y switch to force the install. There was issues with some rewrite policies used: add rewrite action AD_replace_rewrite_action replace_all "http.RES.BODY(120000).SET_TEXT_MODE(ignorecase)" "\"AD Password\'\"" -pattern "\"Password\"" -refineSearch q/extend(50,50).REGEX_SELECT(re![ ]*\'[ ]*\+[ ]*_\(\"Password\"\)[ ]*!)/ add rewrite action Safeword_replace_rewrite_action replace_all "http.RES.BODY(120000).SET_TEXT_MODE(ignorecase)" "\"Secure token:\'\"" -pattern "\"Password2\"" -refineSearch q/extend(50,50).REGEX_SELECT(re![ ]*\'[ ]*\+[ ]*_\(\"Password2\"\)[ ]*!)/ add rewrite action AD_delete_rewrite_action delete_all "http.RES.BODY(120000).SET_TEXT_MODE(ignorecase)" -pattern "document.write(\' 1\');" add rewrite policy AD_rewrite_pol "http.req.url.path.endswith(\"vpn/login.js\")" AD_replace_rewrite_action add rewrite policy AD_delete_pol "http.req.url.path.endswith(\"vpn/login.js\")" AD_delete_rewrite_action add rewrite policy Safeword_rewrite_pol "http.req.url.path.endswith(\"vpn/login.js\")" Safeword_replace_rewrite_action Used the nspepi tool to convert these for me.