This message was deleted.
# citrix-netscaler
s
This message was deleted.
s
Check SSL Negotiation is checked?
j
Hey, where abouts? The traffic flow is content switch>service>LB, cheers
r
I've had a vague memory we had a SSL / CSS caching customer case - self-signed certificates with similar symptoms - maybe worth a long shot (this isn't really my area) https://www.eginnovations.com/blog/troubleshooting-web-application-performance/
👍 1
m
packet capture and see what is going on 🙂 who returns the 404
j
Just found it! As its a sharepoint site... I used the web inspection tool and found failures (503) to the css file in/_layouts ... I must have had that cached from before...
Next issue... when I add /_layout in the content policy it means customer A and browse to Customer Bs URL 😞
I dont know if theres any way around that...
m
include hostname in the policy?
j
Thanks.. the policy is using source IPs... example. if trying to get to /clientname and come from x.x.x.x
m
include the client.ip.src && http.req.url.startswith("/_layout") bla bla
j
But when I add contains /Layout all clients can get to all other sites due to the layout setting...
m
The customers are running on the same server, just different virtual directories? I don't know Sharepoint that well 🙂
j
ahh wait.. I see what you mean.. I have this at the end..
m
yeah that one is way to generic
j
So I could have those && for each client so the layout would only work based on their URL..
m
Yes, so those IPs would only only be sent to the correct LB. But are all the customers running on the same sharepoint server? How are they separated if not by a hostname binding on the webserver
j
Yep all on the same service... seperated by /client1, /client2 so on ...
m
So the start url would always be /client1 or /client2 ?
j
yep.. well uk/client..
The current policy is based on 'CONTAINS'
m
Then you bind the client IP with the starturl also
j
And the the client name
m
So client.ip.src.equals_any("patternset") && http.req.url.startswith("/client1")
Then you would force certain IPs to only use client 1 and they would get http1/1 service unavailable if they didn't match
j
Thats sounds ideal, Mads..
At present its just a load of these...
m
Yeah i would switch over to a patternset/dataset and pair that with the starturl for each client, then you wouldn't really care what they called within that URL, as long as the start url is always the same. Not sure if /_layout would be under /client1/_layout or not, but i think you could improve the content switch policies and making it easier to manage
🍻 1
j
I would recommend looking at https://github.com/corelayer/corelogic for a pretty good L7 router system for content-switching (yeah yeah, another shameless plug for CoreLogic). If you need help, I can always offer some help 🙂
💸 1
🍻 1
❤️ 1
j
It doesnt actually start with 'client1' blah blah but its in the URL so might got something like: client.ip.src.equals_any("Client1_IP_Addresses") && http.req.url.contains("/client1")
m
Is the /client1 always in the same path? then i would use http.req.url.path.get(value) i don't like contains 🙂
j
Got it .. thing is... some clients have multiple sites ... like client1, client1apps, client1cats, client1dogs etc
m
HTTP.REQ.URL.PATH.GET(2).EQUALS_ANY("patset")
something like that then
👍 1