This message was deleted.
# citrix-netscaler
s
This message was deleted.
c
Managed to sort it luckily had a backup on the Avamar IDPA so i restored the VPX from backup and deleted the old license files and installed the new ADC 200 advanced license file and rebooted. I then re did the 13.1-45.63 firmware update and its all good now
l
It all went quite well then! Damn. Do me a favour John, could you DM me your process for the upgrade in detail so I can feed this back to Citrix? Also, do you still have a broken copy of the VPX that I can steal so I may forward it all on to Citrix?
c
Sure Leee will DM you
s
that license fiasco makes me so furious every time. Do switches or other licensed hardware perform the same when there are Licensing issues? The config just gets blown away...
c
yeah it seems because of the license issue it then messed up the config i was missing loads of config
s
this has been going on for as long as i can remember, at least 11.x.
m
the license issue appears only on VPX, never seen it on MPX or SDX before (no matter if it is pooled licensing or not). It happen if you have an old license file (sometimes I can guess from the date in the file, when it is in the past or not a real date it it likely that it happens) and upgrade to something greater than 13.1 33.47 (I think that was the first version I have seen this issue on). Sure if you loose the lic you may loose a lot of your configuration, but why the ssl certificates? They are included in Freemium as well, the ssl feature I mean
c
I had nothing listed in SSL certificates - Server certicates it was empty apart from the self signed NS cert. The certs were present in nsconfig/SSL folder just all the cert keys in the config was missing. I was also missing loads of AAA config (advanced Auth policy bound to AAA vserver and my login schema wasn't bound) these were all present prior to the upgrade and config was saved so the upgrade deff wiped some of my config
s
this is on par with what i've seen historically.
s
I have had issues where the appliance thinks it is unlicensed and parts of the config disappear, including certs. Usually just reverting to an older ns.conf after fixing the licensing brings it all back. I now always back up & export the conf file before any major changes..
💯 1
d
With recent 13.1 builds, if you've always upgraded along the way from earlier builds it seems older license files become unrecognised after the 13.1 upgrades, regardless of SA dates etc. So as part of our standard process now we install an updated license file prior to upgrade and it seems to prevent the issues that John has here
j
There was a support article about this I think klaar year, or at least a warning message. You had to re-issue the license file so the issue date was beyond 2022-06 or something. If you did that, all should’ve gone as it should.
l
@Jan Tytgat I don't suppose you can dig out that article?
t
According to Citrix website (https://support.citrix.com/article/CTX111618/citrix-product-customer-success-services-eligibility-dates), NetScaler 13.1 VPX Customer Success Services Eligibility Date is 2021.0823 (23-Aug-2021). If the SA date in your license file is before this, the license will not be valid post 13.1.x upgrade. From what you stated John, it looks like your original license had an SA date of 2021.0403 (3-Apr-2021), hence the issues.
Also, Citrix recommends upgrading from 12.1 to 13.0 first, then 13.0 to 13.1. Quite a good article in the NetScaler docs that explains all the pre-checks here: https://docs.netscaler.com/en-us/citrix-adc/current-release/upgrade-downgrade-citrix-adc-appliance/upgrade-downgrade-before-you-begin.html
k
had the similar thing and saved by the automatic conf backups under /nsconfig ... there are files like ns.conf.1 etc... and some with the old firmware in the name
c
yeah seen them files and i also had a full backup prior so i was going to re add the missing config entries either manually via cli or via batch import but Restoring the VPX VM via Avamar IDPA and then fixing the license issue first and then doing the firmware update from 12.1 > 13.1 worked perfectly and didn't take me too long and i had no missing config
l
All great info, but... It should not allow you to upgrade in this scenario. Thanks everyone here for making it 100% crystal clear.
🍑 1
j
Can’t agree more, can’t understand why they pulled the initial article even if there is another one like @Tom Cherrill shared…
c
Worth mentioning that HA would have prevented impact to the environment, but I understand that's not always possible in the real world. Whenever you get bit by the licensing design issue the quickest way to recover is uploading a new license file and then rebooting WITHOUT saving the running config. Then on the next reboot it'll read the same config but (hopefully) not barf due to licensing.
c
This was a UAT vpx instance hence no HA but I agree with you 👍 Does anyone know if the licensing issue impacts MPXs ? Or is just VPXs?
c
That licensing scenario affects all Netscalers
c
ok cool i will fix the licensing issue prior to upgrading the prod MPX's then
c
if I recall correctly ADM service might do some license checking to try and help the issue if you use that to do upgrades but regardless I definitely suggest checking licenses as part of upgrade prep.
c
I have allocated and downloaded the licenses for my MPX 8200 with the updated SA/CSS date so will install prior to the firmware update to 13.1. Can i just install the new license file on the secondary and reboot and then do same on primary and reboot (HA failover will occur) and then fail back ? or will i have to break HA and install on each and reboot and reconfigure HA ?
j
Reboot is fine
Make sure the old license is gone before rebootin
👍 1