This message was deleted.
# citrix-netscaler
s
This message was deleted.
l
Seen this before a couple of time yes. Usually related to gratuitous arp on the failover not being processed by your router/firewall. So it will keep routing traffic to that specific IP to the MAC address of the secondary node. This article has some nice info : https://support.citrix.com/article/CTX208384/behavior-of-address-resolution-protocol-arp-and-gratuitous-arp-on-the-netscaler-device
c
Legend So basically run this on both nodes? set network L2Param -garpReply enabled
l
If the behavior is consistently reproduced it's an option to try for sure. Another path can be using a VMAC.
c
Think things could have changed on the network side (firewall, routers, switches etc) as these NetScalers have been working for some time, upgraded with no issues previously
l
Might have just been a fluke on the failback in this case and not related to the network side as well.
c
So you doing this change should be standard on any NS deployment? These ones in particular are in the DMZ, the internal ones don’t seem to be experiencing this issue.
d
Also if you broke HA without setting the secondary to stay secondary, (can't remember if that stays after breaking HA ) then both adcs will be primary and you will have duplicate addresses that will cause a dos by itself. Switches and firewalls may deal with this by shutting the ports down, and a reboot might fix it.
l
Also true yeah, and yes it stays after breaking HA
m
I would agree with Lucas that GARP is the issue.. when you break the HA before shutting down the other NS, both of them claims ownership over the SNIP/VIPs @Carl Behrent the second opinion you wanted 🙂