This message was deleted.
# citrix-netscaler
s
This message was deleted.
f
I forgot, the compromised instance (with the production ip) must be able to be isolated without undergoing restarts. That's why I was thinking of adding a new vlan ID to the SDX LAG. Add this vlan to the vpx instance of prod and move the VPX to this isolated vlan. disable the 0/1 interface from the console from the production VPX instance to avoid overlapping IPs.
c
Haven't configured SDX yet, but are you going to copy nsconfig folder from a compromised VPX to new SDX?
f
Migration went fine, although failed to isolate the old vpx. We ended up isolating the entire SDX. Copying the nsconfig folder is fine for us, we don't believe there is anything in that folder that will affect the new instance. Also keep in mind that the migration was preemptive and most likely not exploiting the latest cve.