This message was deleted.
# citrix-netscaler
s
This message was deleted.
l
Hi Jon, you can tag VLANs on the VPX front if you wish. The consideration is more around the internal traffic flow of the NetScaler. Every interface and IP by default sits on the NetScaler default VLAN. Are any of these VLANs secure VLANs? You may want to take a look at traffic domains and policy based routes to control traffic flow.
👍 1
j
Thanks @Leee Jeffries. depending on "secure" they all should be as they are all internal. Hoping that's what you mean. Apologies if you mean something else, not a strong networking or ADC guy (yet). Thrown as the vmware team bound the 1/1 interface to a specific vlan in vCenter.
l
Aaahhh okay. If the VLANs are all internal networks you can get to form a single subnet then you don't need 4 separate adapters. You can just add routes in for the other networks.
j
Depends on if you want to put your VIPs in every of the 4 VLANs? If it is just for reaching the backend servers I would recommend a simple „One-Arm“ configuration and forward the traffic with normal static routes. Because of lacking features I wouldn’t work with traffic domains and is not needed because no different security zones involved in your case. If you want to work with VLAN tagging on a VPX the portgroup (Example: VMware) needs to be tagged with the ID „4095“ this will give you the possibly to transfer the VLANS directly into the VPX and not as access/untagged network via the Hypervisor.
👍 1
l
What he said ;-)
j
Well, looks like i can use the other arm to beat myself over the head.
😂 2
j
Or use it for a dedicated mgmt interface 👍🏽 But please have a look at PBR otherwise you will get problems with asymmetrical routing. This is one of the most issues I see at customers.
👍 1
j
Will do. there are two nics installed on the vpx. both are assigned to the same vlan, first nic is static assigned to NSIP, the other is not assigned an ip. apart from pbr, is there anything else i need to do to ensure that first nic stays mgmt only?
j
if both nics are in the same VLAN it doesn’t make sense to use them. Default VLAN (1) is always the NSVLAN. Go with one of the following setups ✌🏼 Setup 1: NIC0: Management Network, NIC1: Load Balancer/Gatway VIP Network Create PBR for Mgmt routing Create SNIP in LB Network, Create a VLAN (not tagged) and bind the SNIP to NIC1 Setup 2: NIC0: Load Balancer Network NSIP,SNiP and VIP are in the same network. One default route Use ACL to restrict management access for a jump host or admin network
l
Setup two is your very best option as a beginning. It's much simpler to start to play.
⤴️ 1
j
What Leee said ;-) That’s the best way to get started with ADC. Have fun implementing. If there is an issue feel free to ask. Over and out
j
really glad i asked. Thanks to you both
l
No probs. Same as Julien said. Feel free to followup.