Situation: After an upgrade of our VPX devices to FW 10.1.121.10 intermittent authentication issues appeared for the access gateway users. They would simply fail the LDAP bind, yet all monitors would be green with all services up. Our radius and LDAP authentication point internally to a LB VIP on the Netscaler first before connecting to the individual servers.
Solution: At this stage Citrix support are investigating the issue, they have recognised it as a bug and their workaround solution was to bypass the netscaler load balancer for LDAPS going direct to a specific server, or to downgrade to 10.1.120.13. The downgrade was not a solution for us as we already had issues with the previous version with the VPX network and LACP negotiation.
Once we removed the internal LDAPS load balancer the Netscalers started authenticating immediately.
We then added another policy for a secondary authentication policy and server so we did not introduce a single point of failure.
Situation: We upgraded our Netscaler VPX from 10.0.70.7 to 10.0.76.7 and we were then unable to authenticate to the netscaler console using our LDAP credentials and users were unable to authenticate at the Access Gateway pages.
Solution: During the VPX upgrade the Netscaler truncated the first 2 characters of each line of the Authentication server section (including the password)
Either manually restore the information or copy the authentication lines from a backup of the previous ns.conf
SItuation: Channels (LA/x) in the VPX do not exist nor are they passed through when provisioned from the SDX netscaler device.
Resolution: The channels are created only once, so if they are deleted or the devices are restored to another device then you must remove all channels, add a dummy channel like 1.8, reboot the VPX, then reassign the LA/x channels again for the creation of the LA/x channels inside the VPX.
The netscalers are license by the FLEXnet host ID of the machine.
To get this information from the device
1) SSH, putty or use the console of the netscaler device and login as the nsroot account
2) run the shell
– command: shell
3) Run the FLEXnet host ID command
– command: lmutil lmhostid -ether
4) Output will be something like
root@ns# lmutil lmhostid -ether
lmutil – Copyright (c) 1989-2007 Macrovision Europe Ltd. and/or Macrovision Corporation. All Rights Reserved.
The FLEXnet host ID of this machine is “xxxxxxxxxxxx”
5) Use this when allocating your licensing file from mycitrix.com
The documentation for Access Gateway has not been updated for 5.0.4 of AG.
Access Gateway 5.0.4 VPX Default username and password
previous version were