This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
MBR? Do you mean MBF?
j
Duh.. sorry, I meant MBF 😉
j
Can you expand on what you mean with “intermittent failures”? Like the ip address stops responden and it works again after disable/enable ip?
It would be a weird measure though
k
I'd say that without MBF it should either work or then not. There might be some other issues if the problem is on and off... do you have more than one directly connected networks on the NetScaler?
Aka two-arm setup
j
Thanks guys, there's a lot of network infra and routing and we have 2 vips across two DCs that sometimes dont respond... the first ICMP for example responds then goes dark.. the 'hope' is MBF will solve this.
There are a few networks in place.
j
check your ARP table
sounds like an ARP incomplete
make sure the VIP is bound to the correct interface and VLAN in the config
j
The mad thing is.. when it fails... the following 3 ICMP that drop dont make it to the Netscaler...
j
sounds like duplicate ip
(hence the ARP incomplete at some point in the network)
j
It will 100% work work a while then just fail.. when it fails site A can always reach site A, GSLB in play so its only cross site that fails when it goes into this state.. Cisco have looked at the network and cant see anytning wrong, cheers
c
Ask them for the packet trace that led them to suggest MBF. If they can't point to something specific then ask for escalation.
l
I can't see how MBF is going to fix it tbh. MBF helps in places where routing is a bit of a mess or unknown. As Jan said, sounds like an ARP issue. What HyperVisor is the VPX running on? Assuming it's a VPX?
j
Yeah, its a pair of VPX's on vSphere
By the by, Im just helping out. Didnt log the initial case but we got this back...
c
If they suspect asymmetric routing then they should be able to confirm that before suggesting a global change. It's plain as day in the packet traces if that's actually happening.
👍 2
l
You could get this dependent on the network configuration on the hypervisor, mac flapping between interfaces you would be able to confirm that, a packet trace would really help when the issue occurs to see what happens to the traffic. I've seen this on XenServer when the network bonds have been misconfigured in relation to the switching hardware.
j
Also just realised one pair of internals is on 12.0 and the other is 13.0! Going to organise an uplift to get them on all on the same version before we go down any more rabbit holes! 🙂
k
that's worth checking... it's likely the OOOOLD version is not supported on your hypervisor platform
👍 1
j
Im sure 12.0 is unsupported by Citrix too, I'll get the team to start there with the upgrade and see what happens.. cheers for the feedback everyone 🙂
👍🏻 1
s
Personally, i'd probably try the shotgun approach and enable MBF and see if it fixes it. If it does, then I know it's a routing/network issue either downstream or not having the correct PBRs set. if this is a cloud netscaler it's best practice to have MBF enabled.
j
Thanks @Steve Noel - its on prem.. aiming to upgrade and enable MBF if the upgrade doesnt help early next week... I'll keep the thread updated, cheers
👍 1
Guys, firmware updated and matching across the board. Issue remains but at least they are in support. Im reading the MBF notes and see that you can enable for a single LB/VIP vs global change, is that right? See here:
The following is making me nervous about the shotgun/global approach, Im not sure if 'shouldn't' means it will break stuff or have an impact on efficiency:
l
In my experience it won't break anything if you enable MBF. Never done it using a net profile.
s
ditto
usually people experience more problems when going the other way, disabling MBF.
j
Cool - thanks lads
Lads, I thought I had already asked this but checking the thread I dont think I did. This deployment has 2 external facing Netsalers (one in each DC) and 4 internal (a pair in each DC). The problem service is only an internal service. If we are enabling MBF, would you reckon its best to enable it on the internals and externals to keep it consistent across the board or just on the internals where the issue is present? cheers
l
Just the internals, my understanding was that's where the service is going down?
j
Yeah, just the internals bud. The problem vip/service is internal only.
l
Yep, just on the internals chap.
🍻 1