This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
you should not see that error, have you configured both of the nodes separately for licensing and allocated licenses?
j
Hi Kari, Yes I have configured them both. if I look at the licensing tab on the secondairy node, its greyed out also.
c
If your licensing configuration is totally grayed out on the secondary VPX then honestly you might have bigger problems. I'd break HA and start again with a totally fresh VPX - setup the date/time, NSIP configuration and licensing first then join it to HA.
You can revoke the assigned licenses from the problematic box from either the VPX or ADM itself.
m
maybe a stupid question but could it be that the secondary is unable to reach the license server? If this is a HA Pair not in the "independent Network Configuration Mode" I guess this could happen.
j
Hi Marion, that was I was thinking of, but I am not sure. Because working with this license type is new for me also.
m
Same for me, but I think it need to reboot (warm at least) do query the license server again. But I am not totally sure.
j
No unfortunately thats not working. Even if I switch nodes, the other node will be secondairy with the same behavior
k
Firewall passes traffic only using snip, but not with nsip?
Although it should always use the NSIP
Not sure how it behaves if you have snip in mgmt network
j
Basically licensing traffic will always go over the NSIP. I have no snip configured for this management VLAN.
I must make a correction. The licensing module on the secondairy node is visible though. But there I will see that the license server is not reachable. So is it true that because the secondairy node is not using his snip for the licensing traffic because the snip is active on the primaire node? And should that be the reason why the sec node is running in Grace?
"27000 and 7279 TCP License ports for communication between Citrix ADM license server and ADC instance. These ports are also used for ADC pooled licenses."
vCPU lics are considered as pooled afaik
m
maybe a ns trace? then we should know at least if the connection to the license server is successful and with the ssl master keys we might get a hint if it is successful what else could be wrong
j
The connection is fine, if I switch from one to another then the behavior switched to the other node.
k
my guess is that the licensing traffic flows for some reason via snip
you can go to shell (ssh to cli and run the shell -command) and then see what the nstrace shows for the licensing ports:
nstcpdump.sh port 27000 or port 7279
just put that one running and toy around with the license thingy in GUI and you should see some traffic
👍 1
j
The licensing traffic should be travel over the SNIP for that specific VLAN? I have configured the VLANs like they are following the path through the proper NIC and SNIP
k
you might need a policy-based route for the licensing traffic that would enforce the traffic to flow via the management IP
because snip is active only on the active node
j
Good one, let me try that one
That did the trick @Kari Ruissalo (WyW)! Many thanks to all of you! Enjoy your weekend!
👍 1