This document describes the changes, fixed issues, and known issues provided in the maintenance releases of the Citrix® NetScaler®, Citrix® NetScaler® SDX, and Citrix® Access Gateway® software.
Release version: Citrix® NetScaler®, version 9.3 build 59.5
Replaces build: None
Release date: October 2012
Release notes version: 2.0
Language supported: English (US)
Note: Unless stated otherwise, an issue applies to all build types (Classic, nCore, and nCore VPX) of Citrix NetScaler and Citrix Access Gateway.
Changes
Nitro API
- Issue ID 89377/0248847: You can now specify the attributes that you want to view, by specifying the required attributes in the URL. For example, you can view the name and service type for all load balancing virtual servers by using the URL <nsip_address>/nitro/v1/config/lbvserver?attrs=name,servicetype.
SSL
- Issue ID 74374/0236585: You can now load a certificate bundle containing one server certificate, up to nine intermediate certificates, and optionally, a server key. Separate steps for loading and linking the certificates are no longer required.
Bug Fixes
AAA Application Traffic
- Issue ID 0319434: If 401 basic authentication is enabled on a load balancing virtual server, and authentication fails either due to invalid credentials or a Kerberos authentication failure, the NetScaler packet engine might crash.
- Issue ID 0341787/ 344661: AAA-TM does not remove authorization headers from requests, so even
if single sign-on (SSO) is configured, the user cannot use it to
sign on to protected applications.
Access Gateway
- Issue ID 289686: If users connect with the Access Gateway Plug-in for Mac and then log off from the Web Interface, if users log on again within five minutes, the connection fails. This only occurs if you enable ICA proxy in Access Gateway.
- Issue ID 0326413: If you configure a pre-authentication policy by using the
command-line interface, and you use an exceedingly large number of
characters (900, for example) in the name, when you view the policy
in the configuration utility, the policy fails to open and Java
exception error occurs. The policy works, however.
- Issue ID 0329603: When you configure Access Gateway to use a proxy server for network
resources and to assign an intranet IP address to a user session,
Access Gateway fails.
- Issue ID 0329917: If you configure address pools, when users log on with the Access
Gateway Plug-in and the connection routes through a virtual IP
address, if you configure a load balancing virtual server or a
content switching virtual server on NetScaler, occasionally, Access
Gateway fails.
- Issue ID 0330636: When users log on with the Access Gateway Plug-in on an nCore Access Gateway appliance, occasionally when server-initiated connections occur, depending on the core through which the traffic is passed, the user device may fail.
- Issue ID 0331288: When split tunneling is OFF, when users try to connect with an
Access Gateway Plug-in, occasionally host routes added by the
plug-in may block communication between the Internet IP address and
the Domain Name Server. Users may experience network connectivity
issues, such as the inability to access file shares on the network.
- Issue ID 0332483:
If you have a VLAN configuration on the NetScaler appliance, when
users log on with the Access Gateway Plug-in, occasionally
service-initiated connections to the user device fail.
- Issue ID 0337609: When you integrate Access Gateway with a SharePoint site, after
users log on successfully, when they open a Microsoft Office
document, the session ends and the logon page appears.
- Issue ID 0336091:
When users log on with the Access Gateway Plug-in and they
successfully establish a connection, and then users start a Remote
Desktop Protocol (RDP) connection, the Access Gateway Plug-in
resets the connection multiple times before users receive a stable
connection to the RDP server.
- Issue ID 0336576: If you configure an endpoint analysis scan with a client security expression for any scan type, such as requiring Notepad to be running on the user device, endpoint analysis does not work as expected.
- Issue ID 0336499: When users log on to Access Gateway by using Citrix Receiver and then log off by using the Receiver icon in the taskbar, the computer loses network access. To restore network access, users must either disable and then enable their network interface or restart their computer. To avoid the issue, users can log off from the Access Interface home page.
- Issue ID 0338220: If you configure client certificate-based expressions for preauthentication or post-authentication scans, when users try log on to Access Gateway, occasionally, the scan fails. To avoid the issue, you can use the classic or MPX 5500 platforms.
- Issue ID 0340122: After users upgrade to Access Gateway 10, build 70.7, if you have a high availability configuration that includes an FTP server, when users log on with the Access Gateway Plug-in and initiate an FTP session, occasionally Access Gateway fails on both primary and secondary appliances while the FTP connection is active.
Application Firewall
- Issue ID 0257168: The application firewall might trigger a false positive for a field consistency violation if submitted form data contains unnamed field(s), because some browsers do not send unnamed field(s) back to the server.
- Issue ID 0306242/0248379: In rare cases, the internal data maintained by the application firewall might change incorrectly, causing the NetScaler appliance to restart.
- Issue ID 0329401: On a NetScaler appliance that has the Application Firewall enabled and both cookie transformation and encryption on, secure memory usage increases slowly and continuously until the NetScaler appliance starts to drop connections. To work around this issue, you can reboot the NetScaler appliance regularly.
- Issue ID 0330642/0331885: On a NetScaler appliance with both the Application Firewall and Integrated Caching features enabled, the NetScaler appliance might experience occasional resets when its memory fills up. The cause is a small memory leak.
- Issue ID 0331112/0330298 (nCore): In the NetScaler 9.3 58.2.nc build, when applying the HTML or XML SQL Injection check the application firewall does not transform special strings even when Transformation is enabled. This issue was fixed in build 58.4.nc.
- Issue ID 0331872: The NetScaler appliance now supports decoding of overlong UTF-8 characters.
- Issue ID 0333332: When signatures that work on post body are enabled, a large post request may cause an HA failover during Literal pattern match.
- Issue ID 0335102: On a NetScaler appliance that has the Application Firewall enabled, adding a large number of signatures objects can cause high CPU loads.
Configuration utility
- Issue ID 93754/0257608: When you view the configuration difference between files, the corrective commands generated for bind or unbind commands of load balancing and content switching virtual servers might not be accurate in some cases.
- Issue ID 0305248: In the Reporting tool, when users try to generate a 'system entities statistics' report for load balancing virtual servers, the load balancing virtual servers configured on the appliance might be displayed as being inactive. Users cannot choose the virtual server to view the statistics
- Issue ID 0310203: In the Reporting tool, when users try to generate a custom report for load balancing virtual servers, the virtual servers might be displayed as being inactive. Users cannot choose the virtual server to view the statistics.
- Issue ID 0327492: If a user attempts to access the Web Interface through the load balancing virtual server, the attempt fails if "enable access via mobile receivers" is enabled at global level and also on the individual load balancing virtual server, because the rewrite policies are also bound at both global level and vserver level
- Issue ID 0328747: In the Reporting tool, when users try to generate a 'system entities statistics' report for GSLB domains, the GSLB domain names configured on the appliance might not be displayed in the entities list.
- Issue ID 0329547 (nCore): In some cases, the value to which you set the prefetchPeriodMilliSec parameter for a cache content group might not be saved in the nsconfig file.
- Issue ID 0333814: When users configure a port on the audit server, the configuration utility displays the port number as a negative integer if the port number is greater than 32767.
- Issue ID 0339085: When you navigate to Network>Routes>Basic to view the basic route details, the 'Gateway/Owned IP/Name' column in the table does not display the name of the load balancing virtual server for LLB routes.
Cloud Bridge
- Issue ID 0313629 (nCore and nCore VPX): When the NetScaler system time is modified, either due to Network Time Protocol Daemon (NTPD) or other external factors to a time earlier than the boot time, the iked process might start consuming 100% of CPU resources.
DataStream
- Issue ID 0323442 (nCore and nCore VPX): The DataStream feature does not support dynamic stored procedures. Consequently, dynamic stored procedures fail if they use the sp_prepexec and sp_prepare stored procedures.
Domain Name System
- Issue ID 0318199: If core memory is not available when the NetScaler appliance is processing an RRSIG record received in a response, the appliance fails.
Global Server Load Balancing
- Issue ID 0299642: If static proximity is configured as the primary GSLB method, and it returns multiple GSLB services, the NetScaler appliance implements round robin load balancing on those services, regardless of which GSLB method is configured as the backup method. Additionally, the appliance does not consider any weights that might be configured for those GSLB services.
- Issue ID 0308555 (nCore, nCore VPX): In certain scenarios, if the primary and backup GSLB methods are static proximity and dynamic RTT, respectively, requests for domain name resolution are not processed correctly. As a result, the appliance can fail.
- Issue ID 0326364/0315417 (nCore and nCore VPX): Even though a GSLB virtual server is configured with the static proximity method, and some requests match a DNS policy whose action uses a DNS view to restrict matching requests to only a subset of the bound services, the NetScaler appliance uses the round robin method to load balance requests across all of the GSLB services that are bound to the GSLB virtual server. The issue can occur if the locations that correspond to the source IP addresses in the DNS requests are not found in the location database.
Load Balancing
- Issue ID 0309954: A GSLB virtual server becomes unavailable if you use the same IP address as the public IP address for both a local and a remote GSLB service, bind monitors to the services, and then bind the services to the virtual server.
- Issue ID 0312844 (nCore, nCore VPX): The NetScaler appliance might fail when it is rate limiting DNS or SIP traffic associated with a sessionless load balancing virtual server.
- Issue ID 0331329/0341782 (nCore): If you rename a domain name server on which a
service group is configured, and later perform an SNMP walk on the service group member full name, the NetScaler appliance fails.
- Issue ID 0338196 (nCore, nCore VPX): The NetScaler appliance might fail during active-mode FTP transactions.
NetScaler SDX Appliance
- Issue ID 88515/0248159: Client authentication is enabled by default in the Management Service VM. Consequently, HTTPS connections fail when you access the Management Service VM user interface from the Apple Safari browser.
- Issue ID 0331900: If you try to upload a file larger than 300 MB to the NetScaler SDX appliance, the upload fails.
- Issue ID 0332313 100 percent CPU usage is observed when the Management Service takes daily backup.
- Issue ID 0334340: If you upgrade the Management Service on which a NetScaler instance with a description of greater than 32 characters is provisioned, the instance is not migrated, and therefore, complete data related to the instance is not available in the database. Later, if you delete this instance and provision a new instance with the same IP address, the operation fails.
Networking
- Issue ID 0322026: In an L2 DSR configuration, packets arriving on the loop back interface are dropped even when the traffic rate on the interface is low.
- Issue ID 0334312: During a warm restart of the NetScaler appliance, a daemon might fail to start. After not receiving heartbeats from the daemon, the Pitboss process restarts the appliance.
- Issue ID 0336136: If a NetScaler appliance acting as a DHCP relay agent receives DHCP Discover traffic that is not from a Layer 3 VLAN, the appliance might disconnect from the default gateway and remain disconnected for some time.
Platform
- Issue ID 0269952 (nCore): In rare cases, after you start a NetScaler appliance, the appliance might fail or the console might not respond because of a deadlock in the 10G ixgbe or e1k driver.
- Issue ID 0321989: NetScaler release 9.3 build 59.x is supported on the new MPX 5550/5650 platforms.
Policies
- Issue ID 0291975: The SYS.VSERVER("<vserver_name>").THROUGHPUT expression returns an incorrect throughput value.
- Issue ID 0336384: When creating an advanced expression, ClientSecurityMessage is unexpectedly added when you save the configurations. Therefore, when the appliance is rebooted, these advanced expressions are not executed and are lost.
Responder
- Issue ID 0324200 (nCore): On a NetScaler appliance with the responder feature configured to redirect requests from authenticated members of a particular group to a custom web page, the redirections sometimes fail. The reason is that, when the responder feature is invoked before the AAA session is completely established (as is the case when a user selects a choice after initial logon), the user’s AAA session is not transferred from one core to the other. Responder therefore fails to identify the user as a member of the targeted group.
- Issue ID 0330133: On a NetScaler appliance with the responder feature enabled and a respondWith response configured, if a user sends a request with a large Content-Length header, the NetScaler appliance might appear to hang. The cause of the apparent hang is that the NetScaler appliance expects a request of the specified Content-Length, and waits for the rest of the request before responding to it.
Rewrite
- Issue ID 0301481: On a NetScaler appliance that has a response-side rewrite policy configured and bound to a load balancing virtual server, a request sent to the virtual server might trigger a sequence of events that causes the NetScaler appliance to fail.
SSL
- Issue ID 0236585: You can now load a certificate bundle containing one server certificate, up to nine intermediate certificates, and optionally, a server key. Separate steps for loading and linking the certificates are no longer required.
- Issue ID 0302532: The NetScaler appliance fails if all of the following conditions are met:
- A certificate revocation list (CRL) is present and linked with a CA certificate, and the CA certificate is continuously updated.
- The CRL is uploaded by using HTTP, and auto refresh is enabled on the CRL.
- Client authentication is enabled. Therefore, the client is verified for every GET request.
- Issue ID 0318672: In rare cases, a warm restart can cause the NetScaler appliance to fail or perform a core dump.
System
- Issue ID 0250872 (nCore): In extremely rare circumstances, if the NetScaler management CPU becomes unresponsive due to internal causes, the NetScaler packet engines might also become unresponsive after waiting for replies from the management CPU. In that event, the NetScaler appliance can become unresponsive or fail.
- Issue ID 0277102: When you execute the show events command, the NetScaler appliance might fail if the number of events to be displayed is more than 2^31.
- Issue ID 0325718 (nCore): The amount of memory allocated to a packet engine can be retrieved by using show ns stat command (value of InUseMemory) or by SNMP polling (value of resMemUsage). There was a mismatch in InUseMemory and resMemUsage value for the same packet engine due to difference method used to calculate the allocated memory. This mismatch problem is now resolved and both the methods return the correct value.
- Issue ID 0332251: You can now configure LACP from within a NetScaler VPX instance hosted on a NetScaler SDX appliance. Make sure that the interfaces that are part of the channel are not shared with other instances, and a dedicated channel is configured for an instance.
- Issue ID 0333385: A hash collision might put the NetScaler aggregator into a recursive loop, causing the aggregator to fail. The NetScaler appliance might also fail, because of the aggregator failure.
Web Interface
- Issue ID 0306731: If the Rewrite feature is not enabled, the Enable access through receiver client option for a Web Interface(WI) site does not work. This is because the functionality of the option depends on some rewrite policies on the appliance.
Known Issues and Workarounds
ACL
- Issue ID 0264933: The NetScaler appliance does not display the correct default values for the icmpType and icmpCode parameters of an extended ACL or ACL6.
Access Gateway
- Issue ID 80175/0241433
and 82022/242906
:
If you enable split tunneling, split DNS, and assign an intranet IP address on Access Gateway, when users log on with the Access Gateway Plug-in using a mobile broadband wireless device that uses the Sierra driver (for example, Telstra Compass or AT&T USBConnect) on a Windows 7 computer, Domain Name Service (DNS) resolution fails and the home page fails to open. You can use one of the following options to resolve the issue:
- Disable split tunneling.
- Configure Access Gateway so user connections do not receive an intranet IP address.
- Configure the wireless device to use an Ethernet connection instead of a mobile broadband connection. For example:
- Disable the setting 'Windows 7 Mobile Broadband' in the Telstra Connection Manager 'Options' dialog box.
- Install Sierra Wireless Watcher (6.0.2849) if users connect with an AT&T USBConnect 881 network card. This installs an Ethernet adapter instead of the mobile broadband adapter.
- Contact the manufacturer for other devices.
- Issue ID 0242252:
In the Access Gateway configuration utility, you can bind a server running the STA with the same IP address or fully qualified domain name (FQDN) two times.
- Issue ID 81494/0242522:
If users access a Distributed File Share on a computer running Windows Server 2008 64-bit, a blank folder appears in the directory path.
- Issue ID 0251596: After you configure Access Gateway to provide user connections through Citrix Receiver, when users right-click the Receiver icon in the notification area, the 'Log on' option does not appear. Users must connect by using the Web browser or they must right-click the Receiver icon and then, depending on the version of Receiver they are using, click 'About' or 'Preferences' from the Receiver menu and 'Plug-in Status' or 'Advanced' from the Receiver panel. You can also enable the log on option to appear when users right-click the Receiver icon by adding the following settings in the registry:
- Add the Receiver key (if the key does not already exist) under the following registry locations:
- HKEY_CURRENT_USER\Software\Citrix\
- HKEY_LOCAL_MACHINE\Software\Citrix\
- Add the Inventory key in the following registry locations:
- HKEY_CURRENT_USER\Software\Citrix\Receiver
- HKEY_CURRENT_USER\Software\Citrix\Receiver
- In the
'Inventory
key', configure the following
'REG_SZ'
values:
- Issue ID 0289001: If you configure multiple post-authentication expressions with cascading priorities, Access Gateway might fail and then restart.
- Issue ID 91832/0250964: If users log on with the Access Gateway Plug-in and then put the
user device into hibernation, when the device resumes from a
different network, the Access Gateway Plug-in reconnects. When
users log off, however, the default route might be deleted. Users
can restart their device to obtain the network route.
- Issue ID 89439/0248898:
If users connect with the Access Gateway Plug-in and a T-Mobil 3G
device and if you enable split tunneling and assign an intranet IP
address to users on Access Gateway, users cannot connect to either
the intranet or to external resources. To allow users to connect to
both internal and external resources, disable split tunneling.
- Issue ID 89791/249202:
If users log on with a Windows-based computer that is not part of a domain, by using a 3G network adapter and the Access Gateway Plug-in for Windows, requests that use the host name fail. In this instance, use the fully qualified domain name (FQDN) instead of the host name.
- Issue ID 90675/249937: If users log on with the Access Gateway Plug-in for Windows and then access a CIFS share by using the Run dialog box, when users navigate to a folder in the share and attempt to copy a file to another file share, users receive an error message and the attempt fails.
- Issue ID 84787/0245136: When you issue the command "sh vpn vserver" on Access Gateway, the
number of current ICA connections does not appear when Access
Gateway is in Basic mode.
- Issue ID 84986/0245297: If users log on with clientless access and attempt to open an external Web site (such as http://www.google.com) from the Email tab in the Access Interface, users might receive the Access Gateway logon page instead of the external Web site.
- Issue ID 88268/0247968: If users attempt to open a large Microsoft Word file from a Distributed File Share (DFS) hosted on Windows Server 2008 64-bit, Access Gateway fails.
- Issue ID 83492/0244134: When users log on by using clientless access, a JavaScript error might appear when the logon page opens.
- Issue ID 83819/0244412: If you configure a load balancing virtual server and the destination port is 21, when users log on with the Access Gateway Plug-in, logon is successful but data connections do not go through. When you configure a load balancing virtual server, do not use port 21.
- Issue ID 84894/0245227:
When users log off from the Access Gateway Plug-in and then clear the cache in Internet Explorer and Firefox, users might receive an error message that says "Error. Not a privileged user." Access Gateway records an HTTP/1.1 403 Access Forbidden error message in the logs.
- Issue ID 84915/0245243:
If users attempt to open and edit a Microsoft Office file from Outlook Web Access, users might receive an error and the file takes a long time to open. To allow users to edit files from Outlook Web Access, do the following:
- Create a clientless access Outlook Web Access Profile and enable persistent cookies.
- Bind the Outlook Web Outlook regular expression to this profile.
- Bind the profile so that is assumes the highest priority.
- Issue ID 85861/0245969: If you enable ICA Proxy on Access Gateway, when users log on and attempt to open a virtual application, the connection to the Web Interface through Access Gateway times out and closes.
- Issue ID 86122/0246165:
If you disable transparent interception and set the force time-out setting, when users log on with the Access Gateway Plug-in for Java, when the time-out period expires, a session time-out message appears on the user device, however the session is not closed on Access Gateway.
- Issue ID 86123/0246166:
If users log on with clientless access in the Firefox Web browser, when users click a link for a virtual application, the tab closes and the application does not start. If users right-click the virtual application and attempt to open it in a new window, the Web Interface appears and users receive the warning "Published resource shortcuts are currently disabled." Users can open the virtual application in Internet Explorer.
- Issue ID 86323/0246328: If you configure single sign-on with Windows and configure the user name with special characters, when users log on to Windows 7 Professional, single sign-on fails. Users receive the error message "Invalid username or password. Please try again." This issue does not occur if users log on to Windows XP.
- Issue ID 86470/0246469 and 86787/246736: When users log on with the Access Gateway Plug-in for Windows by using Internet Explorer 9, a delay may occur in establishing the connection. The Access Interface, or a custom home page, might take a long time to appear when users log on by using Internet Explorer 9.
- Issue ID 86471/0246473: When users log on with the Access Gateway Plug-in by using a Web browser, users might see a delay during logon.
- Issue ID 86722/0246679: When users log on with clientless access using Internet Explorer 9 and connect to SharePoint 2007, some images might not appear correctly.
- Issue ID 0301790: If you add sites from Citrix Presentation Server 4.5 and XenApp 6.5 to the same Web Interface site, when users log on with Internet Explorer 9 and then log off from the Web Interface, the session does not close completely. An error message appears stating that some resources are still active.
- Issue ID 0311708:
If you configure LDAP and RADIUS authentication using RADIUS shared secrets, the configuration may remain stable for several weeks, but eventually, the RADIUS authentication may fail even if users enter the PIN correctly. When users log on, instead of offering a challenge in which the user must enter the shared secret, a message appears stating that authentication fails. As a workaround, you can change the IP address of the DNS server to redirect users to another site, while you restart the appliance, or you can enable users to log on through a virtual server that requires LDAP authentication only.
- Issue ID 0329621: If you configure an endpoint policy and bind the policy to a
virtual server, the preauthentication policy is not working as
expected. Users with devices that meet the requirements may not be
able to log on to Access Gateway.
- Issue ID 0332348: When you configure a post-authentication policy to check for a registry key or value on a user device, the scan fails each time the scan is run even if the user device meets the requirements of the policy.
- Issue ID 0332373: In a high availability configuration, if failover occurs, the
session is removed from the appliance that becomes secondary. If
failover occurs again, the session is closed
Application Firewall
- Issue ID 0259458: Attempts to upload a 30 MB or larger file might fail when Cross-Site Scripting (XSS) and SQL Injection checks are enabled.
- Issue ID 0318595: On a Sharepoint 2010 server that is protected by the application firewall, drop-down menus that are used to access documents do not open. When the user attempts to open a menu, a JavaScript progress indicator is displayed on the right side of the page, but no menu is displayed.
- Issue ID 0284677: The online help for the application firewall wizard points to placeholders. If you need help with the wizard, consult the following URL, http://support.citrix.com/proddocs/topic/netscaler-application-firewall-93/appfw-config-wizard-tsk.html Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
- Issue ID 0316200: After upgrading to NetScaler 9.3, build 58x, the built-in AppFW profiles are not visible in the NetScaler configuration utility or listed in the ns.conf file.
CloudBridge
- Issue ID 91850/0250982 (nCore and nCore VPX): The NetScaler appliance drops TCP packets when the server has to send, across the cloud bridge, a full-size packet in which the DF bit is unset. The cause is a bad checksum.
Configuration Utility
- Issue ID 92269/0251344: If you upgrade from an earlier build to a later build within release 9.2 or release 9.3, or upgrade from release 9.2 to release 9.3, or upgrade from an earlier release to release 10, the time zone settings might be lost on upgrade.
DataStream
- Issue ID 0287492: Some international characters resemble one or more ASCII alphabetic characters. If a client request contains such international characters, when forwarding the request to a database server, the NetScaler appliance replaces the international characters with the ASCII alphabetic characters that they resemble.
Domain Name System
- Issue ID 93203/0257123 (nCore): A DNS policy that is bound to a GSLB service is not evaluated if the GSLB method is set to dynamic round trip time (RTT).
Integrated Caching
- Issue ID 81159/0242246: When the NetScaler appliance receives a single byte-range request, if the starting position of the range is beyond 9 megabytes, the appliance sends the client a full response with a status code of 200 OK instead of a partial response.
Load Balancing
- Issue ID 86096/0246139: While configuring the WI-EXTENDED monitor, the user will have to provide the value of sitepath in such a way that it does not end with a '/' . For example: add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
- Issue ID 88593/0248222 (nCore): After failover, the 'maxclient' setting on a service is not honored.
- Issue ID 82872/0243593: The setting for maximum requests per connection might be violated during a transaction with the physical server.
- Issue ID 82929/0243645: When using a TCP monitor for a MYSQL service, the MySQL server blocks the MIP for making new connections.
NetScaler SDX Appliance
- Issue ID 88515/0248159: Client authentication is enabled by default in the Management Service VM. Consequently, HTTPS connections fail when you access the Management Service VM user interface from the Apple Safari browser.
- Issue ID 0262505: When viewing the built-in or custom reports in the Reporting tab on a NetScaler VPX instance running on the NetScaler SDX 17550/19550/20550/21550 platform, the following message appears “NO DATA TO CHART”.
- Issue ID 0265006: Tx flow control on the interfaces of a NetScaler VPX instance can cause packets to be dropped instead of transmitted.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
NetScaler VPX Appliance
- Issue ID 88057/0247795: If you allocate more than 200MB for caching on a VPX (virtual) appliance with 2GB RAM or allocate more than 800MB on a VPX appliance with 4GB RAM, memory-intensive features (such as compression and GSLB) stop working.
Workaround: Reduce the memory allocated for caching.
Issue ID 94487/0258286: On the Microsoft
Hyper-V platform, if there are fragmentation issues on dynamic
virtual disks, the NetScaler VPX appliance sends HTTP 5xx responses
to requests.
Workaround: Defragment the disk. For consistent
virtual hard disk (VHD) performance, change a dynamic disk to a
static disk.
Networking
- Issue ID 0271154: The man pages for the commands 'add ns ip','set ns ip','add ns ip6', and 'set ns ip6' displays an incorrect default value for the 'ospfArea' parameter.
- Issue ID 0319744: When an NS CLI login session times out, typing exit at the NS CLI prompt does not disconnect the session.
Reporting
- Issue ID 85025/0245335 (nCore and nCore VPX): Reporting charts do not support plotting of counters per packet engine.
System
- Issue ID 84099/0244639 (nCore): The NetScaler appliance might fail if traffic reaches a load balancing virtual server that uses the token method for load balancing and has connection failover enabled.
- Issue ID 84282/0244774: A global setting of less than 1220 for the maximum segment size (MSS) to use for TCP connections causes an excessive delay in saving the configuration.
- Issue ID 84320/0244792 (nCore and nCore VPX): The NetScaler appliance might fail if a failover happens while high availability (HA) synchronization is in progress.
- Issue ID 94133/0257961: If a server (load balancing virtual server or content switching vserver) is configured with the same IP address, port, and protocol as the server configured in the audit syslog or nslog action, the configured virtual server will be deleted on upgrading from 9.3_49 or a prior build to a build later than 9.3_49. Workaround: Do the following:
- Remove the audit policy and action.
- Add the deleted virtual server.
- Add the audit policy and action.
- Save the configuration.
- Issue ID 0263852 (nCore): If you configure link aggregation on the 10G interfaces by using the link aggregation control protocol (LACP), the LA interface might flap (go down and come back up).
Workaround: Initiate steering to CPU1. At the shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
- Issue ID 0306660 (nCore): You can now use the set ns tcpparam connFlushIfNoMem <connFlushIfNoMem> command on a NetScaler appliance to close existing connections if memory is not available for a new connection. When using this command, you must specify the type of connection to be closed. By default, this feature is disabled on the appliance.
XML
- Issue ID 81650/0242628: The application firewall import feature validates XML schemas when importing them, but it might not validate certain XHTML files if they are imported as XML schemas. An invalid XHTML file appears in the list of imported XML schemas, but it is rejected if the user attempts to configure the XML Message Validation check to use the invalid file as the XML schema for validation.
XML API
- Issue ID 80170/0241429: The syntax of the 'unset servicegroup' command has been changed to allow unsetting the parameters of the service group members. This can cause XML API incompatibility with respect to the 'unset servicegroup' command.
Release version: Citrix® NetScaler®, version 9.3 build 58.5
Replaces build: None
Release date: August 2012
Release notes version: 2.0
Language supported: English (US)
Note: Unless stated otherwise, an issue applies to all build types (Classic, nCore, and nCore VPX) of Citrix NetScaler and Citrix Access Gateway.
Changes and Fixes
AAA Application Traffic
- Issue ID 0307258: When you create a AAA-TM profile by using the configuration utility, it sets persistency for the profile to zero (0), instead of deriving the persistency values from the global persistency settings. You can verify this issue by typing the following command at the NetScaler command line:
show tm sessionaction <profileName>
You can fix the persistency settings for any AAA-TM profile that is affected by this issue by typing the following command at the NetScaler command line:
set tm sessionAction <profileName> -persistentCookie ENABLED -persistentCookieValidity <positive_integer>
For <positive_integer>, substitute the number of minutes that the persistency cookie is to remain valid. Then, use the 'show tm sessionaction' command to verify your changes.
- Issue ID 0313931: On a NetScaler appliance that has AAA-TM enabled, if a user takes more than four minutes to finish authenticating and the AAA session expires, the user is unable to authenticate. When the user clicks the 'click here' link to return to the logon page, instead of being redirected to the logon page, the user is redirected to the 'Expired Session' page repeatedly.
- Issue ID 0314561: On a NetScaler appliance with AAA-TM enabled and single sign-on (SSO) configured, if a user who uses the Google Chrome browser takes more than four minutes to authenticate and the session expires, the browser displays a blank page instead of the Session Expired page.
- Issue ID 0322445: On a NetScaler appliance that has AAA-TM enabled and a load balancing virtual server configured to support 401 basic authentication, if a user sends a GET request that does not contain a Host header, the NetScaler appliance crashes.
Access Gateway
- Issue ID 0308733: If you configure Access Gateway with additional appliances in which global server load balancing (GSLB) is enabled, when users log on with the Access Gateway Plug-in, occasionally the connection times out, a time-out error appears, such as 'Your Citrix Access Gateway session timed-out and you are not connected,' and the session disconnects.
- Issue ID 0319607: If an authentication server and Access Gateway reside in the same domain, the appliance may fail.
- Issue ID 0319901: If you enable Integrated Caching and Web Interface on Netscaler on an Access Gateway appliance, and then change the URL for the Web Interface, Access Gateway might fail.
- Issue ID 0320210: When users connect with the Access Gateway Plug-in on a computer running Windows XP, the Group Policy Object is not applied.
- Issue ID 0320493: If your authentication policies include the rules REQ.SSL.CLIENT.CERT.EXISTS and REQ.SSL.CLIENT.CERT.NOTEXISTS, and users log on with a smart card, the following might occur:
- If smart card authentication fails, users are redirected to the Web Interface and prompted again for the smart card credentials.
- If users do not enter smart card credentials, they are redirected to the Web Interface and prompted for their user name and password in order to authenticate with RADIUS.
AppExpert
- Issue ID 0323436: The NetScaler configuration utility can display a maximum of 4500 bound patterns of a pattern set.
Application Firewall
- Issue ID 0299876: You can now specify a type of either LITERAL or PCRE for any SQL keywords or special strings that you add to a signatures rule. You can use PCRE regular expressions in any keywords or special strings that are assigned a type of PCRE. Built-in and existing user-created SQL keywords and special strings are assigned the LITERAL type, but you can change the type assigned to any user-created keywords or special strings.
- Issue ID 0303169: On a NetScaler appliance with the application firewall enabled, if a user sends a request with a large number of query parameters that contain SQL special strings without associated SQL keywords, a spike in CPU usage can result. The CPU spike can cause the application firewall to become unresponsive to subsequent requests, blocking user access to protected web sites and web services.
- Issue ID 0319787: On a NetScaler appliance with the application firewall feature enabled, the comment stripping feature does not correctly parse web pages that have an HTML comment that is terminated with two hyphens, a space, two more hyphens, and a greater-than symbol (-- -->). In other words, you cannot have a string consisting of two hyphens and a space immediately preceding the usual comment termination string (-->). If you do, the comment stripping feature does not detect the final two hyphens and greater-than symbol as a comment terminator. The comment stripping feature therefore strips all content that follows the missed comment terminator.
- Issue ID 0325339: On a NetScaler appliance with the Application Firewall enabled, if a protected web site sets a cookie longer than 735 bytes, the Cross-Site Request Forgery (CSRF) check is violated. If blocking is enabled for the CSRF check, the response is blocked.
- Issue ID 0329539 (nCore): On a NetScaler appliance with the application firewall enabled, occasionally the NetScaler appliance crashes when retrieving a page from a protected web site that sets one or more cookies.
- Issue ID 0331112 (nCore): In the NetScaler 9.3 58.2.nc build, when applying the HTML or XML SQL Injection check the application firewall does not transform special strings even when Transformation is enabled. This issue was fixed in build 58.4.nc.
Configuration Utility
- Issue ID 0308459: In Enable/disable service group member view, the Enable and Disable buttons are inactive when the state of a service group member is one of the following - 'GOING OUT OF SERVICE', 'DOWN WHEN GOING OUT OF SERVICE' or 'GOING OUT OF SERVICE (graceful)'.
- Issue ID 0314769: When the certificate used to sign the JAR files expires, the application's digital signature cannot be verified. An error is displayed when the user tries to access the NetScaler GUI.
- Issue ID 0323197: An HTTP monitor with extended respCode range cannot be configured through the configuration utility. If it is configured through the CLI, an error occurs when it is viewed in the configuration utility.
- Issue ID 0328781: On a NetScaler appliance with the Application Firewall enabled, if an administrator uses the configuration utility to open a specific load balancing virtual server, and then clicks 'Configure Application Firewall', the configuration utility might display the following error message: Error creating view.
Intergrated Caching
- Issue ID 0322506 (nCore): When you upgrade the NetScaler appliance from NetScaler release 9.1 to 9.3, the number of objects being cached is reduced because of architectural changes.
Load Balancing
- Issue ID 0286525 (Classic): NetScaler Classic builds become unresponsive under the following set of conditions:
- A service that is being monitored by the appliance does not receive traffic for 248 days.
- The state of the service is UP at least once after the 248-day period.
- During the termination of a TCP connection used for monitoring the service, when the appliance sends the server a FIN packet, the server either does not respond or responds with an RST packet.
- Issue ID 0314738: If you issue the 'force HA sync -force' command when HA synchronization is disabled on both nodes, the services on the secondary node are marked as DOWN. The services remain in that state until after a failover.
When a failover occurs, the failover of some services might be delayed by a few seconds while monitors learn the actual states of those services. Until the monitors learn and correct the states, new connections to those services might be rejected. Consequently, you might also observe a brief period of outage following a failover.
Monitoring
- Issue ID 0320571: The state of a service is shown as UP even when the service is down. Consequently, the NetScaler appliance continues to forward requests to that service, and clients do not receive responses to their requests.
NetScaler SDX Appliance
- Issue ID 88556/0248194: When provisioning a NetScaler instance, if you have entered invalid NetScaler settings for any of the IP address, Netmask, or Gateway parameters, you cannot modify the values for those parameters.
- Issue ID 0303515: You can now install the NetScaler SDX supplemental packs from the Management Service without manually opening an ssh connection to XenServer. To install this pack, on the configuration tab, in the navigation pane, expand Management Service, and then click XenServer Files. In the details pane, click 'Supplemental Packs'. You can upload the supplemental pack to the SDX appliance and also download it to create a backup on your client.
- Issue ID 0326655: If you upgrade the Management Service from an earlier build to build 56.x or 57.x, restarting the appliance while data migration is in progress might corrupt your data contents.
- Issue ID 0326663: In release 9.3, the upgrade process fails if you attempt to upgrade the Management Service from build 48.6 to build 56.5 or 57.5.
- Issue ID 0326878: The Management Service shows duplicate entries for NetScaler VPX instances because of intermittent database connection failures. This is only a display issue. However, if a VPX instance is configured with an external authentication server for the nsroot (administrator) user, the authentication server might show several authentication failures.
- Issue ID 0327984: You can now apply a hotfix for XenServer from the Management Service. On the Configuration tab, expand Management Service, and then click XenServer Files. In the details pane, click Hotfixes, and then click Upload. After uploading the hotfix to the appliance, click Apply. If an error occurs in the process of applying the hotfix, an error message displays the cause of the problem.
Networking
- Issue ID 0260803: In an HA configuration, ping to NSIP of the secondary node fails because of the frequent clearing of configuations triggered by synchronization of configurations to secondary. This synchronization in turn was triggered by repeated saving of configurations in the primary.
- Issue ID 0312412: The command sh ip ospf <1-65535> database, in the VTYSH command prompt, displays the database for all the OSPF processes instead of just for the process id specified.
- Issue ID 0318668: A virtual server of type ANY drops the IPv6 ECHO reply if the ECHO request didn't pass through the appliance and the related IPv6 to IPv4 mapping is not present in appliance.
- Issue ID 0319744: When an NS CLI login session times out, typing exit at the NS CLI prompt does not disconnect the session.
- Issue ID 0321868: BGP does not advertise default route to the peer, with default-originate flag, if the state of a learnt default route toggles.
- Issue ID 0324432: The NetScaler appliance forwards (L3 mode) certain response packets with IP header checksum value 0xFFFF, which is an invalid value according to RFC 1624. As a result, the router drops these packets.
- Issue ID 0330118: OSPF maximum age link-state advertisements (LSAs) are not removed from the NetScaler appliance because the maximum age walker processes suspended indefinitely.
- Issue IDs 0303966 and 0318380: In an High Availability configuration in the INC mode, GSLB site IP
address is not synchronized with the secondary node.
Policies
- Issue ID 92149/0251246: Binding policies with actions related to HTTP, to TCP bindpoints results in the NetScaler appliance becoming unresponsive at runtime.
SNMP
- Issue ID 0309930: The SNMP OID for 'vsvrCurSslVpnUsers' is getting counter values only from core 0.
System
- Issue ID 0271783: If you configure an RNAT rule and enable the TCP proxy option for RNAT, the NetScaler appliance functions as a proxy for internal clients and maintains separate client-side and server-side connections. In certain scenarios, this behavior might result in a service type mismatch between the client-side and server-side connections, and the appliance might reboot with a core dump.
- Issue IDs 0292272 and 0319417 (Classic): NetScaler resets the client and server-side connections if it receives a response with long headers (more than 16 packets) on a server-side connection after receiving a normal response on the same connection.
- Issue ID 0300116: In an high availability configuration, when AAA keys are not synchronized to the secondary node and the appliance failover happens, the new primary node becomes unresponsive. This happens when NSC_TASS and NSC_TMAS cookies have same values and improper session lookup happens.
- Issue ID 0302004: For load balancing virtual servers that have SOURCEIP persistence configured, client IP header insertion might fail for HTTP CONNECT requests sent to that virtual server.
- Issue ID 0306237: If the number of dynamic services running on the NetScaler appliance exceeds 64k, any service created could not be accessed even after when the number of services is less than 64k.
- Issue ID 0306660 (nCore): You can now use the set ns tcpparam connFlushIfNoMem <connFlushIfNoMem> command on a NetScaler appliance to close existing connections if memory is not available for a new connection. When using this command, you must specify the type of connection to be closed. By default, this feature is disabled on the appliance.
- Issue ID 0328271: Output of the mem stats or stat system -detail command is not same as the output displayed by the conmsg mem stats command.
- Issue ID 0330336 (nCore): IPv6 addresses might occasionally be captured in the audit log, even though IPv6 addresses are not configured.
Web Interface
- Issue ID 0322207: In a high availability setup, delays in Apache Tomcat start-up might prevent the propagation of web interface configurations to the secondary appliance. As a result, the web interface configurations are not available when the secondary appliance becomes primary and the 'Web Interface not installed' error is displayed.
XML
- Issue ID 0304314: SOAP requests that do not conform to a WSDL are not handled properly by the XML validation module, which can cause the NetScaler appliance to hang or crash.
Known Issues and Workarounds
Access Gateway
- Issue IDs 80175/0241433 and 82022/0242906: If you enable split tunneling, split DNS, and assign an intranet IP address on Access Gateway, when users log on with the Access Gateway Plug-in using a mobile broadband wireless device that uses the Sierra driver (for example, Telstra Compass or AT&T USBConnect) on a Windows 7 computer, Domain Name Service (DNS) resolution fails and the home page fails to open. You can use one of the following options to resolve the issue:
- Disable split tunneling
- Configure Access Gateway so user connections do not receive an intranet IP address.
- Configure the wireless device to use an Ethernet connection instead of a mobile broadband connection. For example:
- Disable the setting 'Windows 7 Mobile Broadband' in the Telstra Connection Manager 'Options' dialog box.
- Install Sierra Wireless Watcher (6.0.2849) if users connect with an AT&T USBConnect 881 network card. This installs an Ethernet adapter instead of the mobile broadband adapter.
- Contact the manufacturer for other devices.
- Issue ID 81494/0242522: If users access a Distributed File Share on a computer running Windows Server 2008 64-bit, a blank folder appears in the directory path.
- Issue ID 83492/0244134: When users log on by using clientless access, a JavaScript error might appear when the logon page opens.
- Issue ID 83819/0244412: If you configure a load balancing virtual server and the destination port is 21, when users log on with the Access Gateway Plug-in, logon is successful but data connections do not go through. When you configure a load balancing virtual server, do not use port 21.
- Issue ID 84787/0245136: When you issue the command 'sh vpn vserver' on Access Gateway, the number of current ICA connections does not appear when Access Gateway is in Basic mode.
- Issue ID 84894/0245227: When users log off from the Access Gateway Plug-in and then clear the cache in Internet Explorer and Firefox, users might receive an error message that says 'Error. Not a privileged user.' Access Gateway records an HTTP/1.1 403 Access Forbidden error message in the logs.
- Issue ID 84915/0245243: If users attempt to open and edit a Microsoft Office file from Outlook Web Access, users might receive an error and the file takes a long time to open. To allow users to edit files from Outlook Web Access, do the following:
- Create a clientless access Outlook Web Access Profile and enable persistent cookies.
- Bind the Outlook Web Outlook regular expression to this profile.
- Bind the profile so that is assumes the highest priority.
- Issue ID 84986/0245297: If users log on with clientless access and attempt to open an external Web site (such as http://www.google.com) from the Email tab in the Access Interface, users might receive the Access Gateway logon page instead of the external Web site.
- Issue ID 85861/0245969: If you enable ICA Proxy on Access Gateway, when users log on and attempt to open a virtual application, the connection to the Web Interface through Access Gateway times out and closes.
- Issue ID 86122/0246165: If you disable transparent interception and set the force time-out setting, when users log on with the Access Gateway Plug-in for Java, when the time-out period expires, a session time-out message appears on the user device, however the session is not terminated on Access Gateway.
- Issue ID 86123/0246166: If users log on with clientless access in the Firefox Web browser, when users click a link for a virtual application, the tab closes and the application does not start. If users right-click the virtual application and attempt to open it in a new window, the Web Interface appears and users receive the warning 'Published resource shortcuts are currently disabled.' Users can open the virtual application in Internet Explorer.
- Issue ID 86323/0246328: If you configure single sign-on with Windows and configure the user name with special characters, when users log on to Windows 7 Professional, single sign-on fails. Users receive the error message 'Invalid username or password. Please try again.' This issue does not occur if users log on to Windows XP.
- Issue ID 86470/0246469 and 86787/0246736: When users log on with the Access Gateway Plug-in for Windows by using Internet Explorer 9, a delay may occur in establishing the connection. The Access Interface, or a custom home page, might take a long time to appear when users log on by using Internet Explorer 9.
- Issue ID 86471/0246473: When users log on with the Access Gateway Plug-in by using a Web browser, users might see a delay during logon.
- Issue ID 86722/0246679: When users log on with clientless access using Internet Explorer 9 and connect to SharePoint 2007, some images might not appear correctly.
- Issue ID 88268/0247968: If users attempt to open a large Microsoft Word file from a Distributed File Share (DFS) hosted on Windows Server 2008 64-bit, Access Gateway fails.
- Issue ID 89439/0248898: If users connect with the Access Gateway Plug-in and a T-Mobil 3G device and if you enable split tunneling and assign an intranet IP address to users on Access Gateway, users cannot connect to either the intranet or to external resources. To allow users to connect to both internal and external resources, disable split tunneling.
- Issue ID 89791/0249202: If users log on with a Windows-based computer that is not part of a domain, by using a 3G network adapter and the Access Gateway Plug-in for Windows, requests that use the host name fail. In this instance, use the fully qualified domain name (FQDN) instead of the host name.
- Issue ID 90675/0249937: If users log on with the Access Gateway Plug-in for Windows and then access a CIFS share by using the Run dialog box, when users navigate to a folder in the share and attempt to copy a file to another file share, users receive an error message and the attempt fails.
- Issue ID 91832/0250964: If users log on with the Access Gateway Plug-in and then put the user device into hibernation, when the device resumes from a different network, the Access Gateway Plug-in reconnects. When users log off, however, the default route might be deleted. Users can restart their device to obtain the network route.
- Issue ID 92543/0251596: After you configure Access Gateway to provide user connections through Citrix Receiver, when users right-click the Receiver icon in the notification area, the 'Log on' option does not appear. Users must connect by using the Web browser or they must right-click the Receiver icon and then, depending on the version of Receiver they are using, click 'About' or 'Preferences' from the Receiver menu and 'Plug-in Status' or 'Advanced' from the Receiver panel. You can also enable the log on option to appear when users right-click the Receiver icon by adding the following settings in the registry:
- Add the Receiver key (if the key does not already exist) under the following registry locations:
- HKEY_CURRENT_USER\Software\Citrix\
- HKEY_LOCAL_MACHINE\Software\Citrix\
- Add the Inventory key in the following registry locations:
- HKEY_CURRENT_USER\Software\Citrix\Receiver
- HKEY_CURRENT_USER\Software\Citrix\Receiver
- In the
'Inventory
key', configure the following
'REG_SZ'
values:
- Issue ID 0289001: If you configure multiple post-authentication expressions with cascading priorities, Access Gateway might fail and then restart.
- Issue ID 0301790: If you add sites from Citrix Presentation Server 4.5 and XenApp 6.5 to the same Web Interface site, when users log on with Internet Explorer 9 and then log off from the Web Interface, the session does not close completely. An error message appears stating that some resources are still active.
ACL
- Issue ID 0264933: The NetScaler appliance does not display the correct default values for the icmpType and icmpCode parameters of an extended ACL or ACL6.
AppExpert
- Issue ID 0270708: The process of configuring the application firewall for an application unit (appunit) is different than for other features, such as responder and rewrite. Instead of the Policy Manager, the Application Firewall wizard is invoked. The wizard prompts the user to configure the security check settings directly. It then creates a profile and policy from that information, and binds the policy to the appunit in the background, without displaying either the policy or the profile to the user. NOTE: You cannot associate multiple policies with an application unit by using the wizard. To do so, use the policy manager. A link is located on the main Application Firewall pane.
Application Firewall
- Issue ID 0259458: Attempts to upload a 30 MB or larger file may fail when Cross-Site Scripting (XSS) and SQL Injection checks are enabled.
- Issue ID 0284677: The online help for the application firewall wizard points to placeholders. If you need help with the wizard, consult the following URL: http://support.citrix.com/proddocs/topic/netscaler-application-firewall-93/appfw-config-wizard-tsk.html Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
- Issue ID 0316200: After upgrading to NetScaler 9.3, build 58x, the built-in AppFW profiles are not visible in the NetScaler configuration utility or listed in the ns.conf file.
- Issue ID 0318595: On a Sharepoint 2010 server that is protected by the application firewall, drop-down menus that are used to access documents do not open. When the user attempts to open a menu, a JavaScript progress indicator is displayed on the right side of the page, but no menu is displayed.
CloudBridge
- Issue ID 91850/0250982 (nCore and nCore VPX): The NetScaler appliance drops TCP packets when the server has to send, across the cloud bridge, a full-size packet in which the DF bit is unset. The cause is a bad checksum.
Configuration Utility
- Issue ID 92269/0251344: If you upgrade from an earlier build to a later build within release 9.2 or release 9.3, or upgrade from release 9.2 to release 9.3, or upgrade from an earlier release to release 10, the time zone settings may be lost on upgrade.
DataStream
- Issue ID 83862/0244449 (nCore and nCore VPX): In this release, the DataStream feature does not support IPv6 addresses.
- Issue ID 0287492: Some international characters resemble one or more ASCII alphabetic characters. If a client request contains such international characters, when forwarding the request to a database server, the NetScaler appliance replaces the international characters with the ASCII alphabetic characters that they resemble.
Domain Name System
- Issue ID 93203/0257123 (nCore): A DNS policy that is bound to a GSLB service is not evaluated if the GSLB method is set to dynamic round trip time (RTT).
Integrated Caching
- Issue ID 81159/0242246: When the NetScaler appliance receives a single byte-range request, if the starting position of the range is beyond 9 megabytes, the appliance sends the client a full response with a status code of 200 OK instead of a partial response.
Load Balancing
- Issue ID 82872/0243593: The setting for maximum requests per connection may be violated during a transaction with the physical server.
- Issue ID 82929/0243645: When using a TCP monitor for a MYSQL service, the MySQL server blocks the MIP for making new connections.
- Issue ID 82996/0243703: MYSQL monitors show the service state as UP even when no subnet IP (SNIP) address or mapped IP (MIP) address is configured. This is expected behavior, because MYSQL monitors use the NetScaler IP (NSIP) address to send their probes.
- Issue ID 86096/0246139: While configuring the WI-EXTENDED monitor, the user will have to provide the value of sitepath in such a way that it does not end with a '/' . For example: add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
- Issue ID 87407/0247289 (nCore and nCore VPX): For an RDP virtual server, the NetScaler appliance automatically maintains persistence through session cookies by using Session Directory, so you need not explicitly configure persistence. Currently, IP address based persistence is not supported, and you cannot disable the implicit session-cookie based persistence.
- Issue ID 88593/0248222 (nCore): After failover, the 'maxclient' setting on a service is not honored.
- Issue ID 90271/0249597: Application scripts that parse the servicegroup member name, and use the underscore delimiter (_) to identify fields to be extracted, fail, because the delimiter is now a question mark (?). In NetScaler releases earlier than 9.3, the format is <service group name>_<IP address>_<port>. The new format is <servicegroup name>?<IP address | server name>?<port>.
- Issue ID 0309954: The NetScaler appliance fails in the following scenario:
- You create a remote GSLB service whose public IP address is the same as the public IP address of a local GSLB service.
- You bind monitors to the GSLB services, and then bind the GSLB services to a GSLB virtual server.
NetScaler SDX Appliance
- Issue ID 88515/0248159: Client authentication is enabled by default in the Management Service VM. Consequently, HTTPS connections fail when you access the Management Service VM user interface from the Apple Safari browser.
- Issue ID 91605/0250759: If the dashboard page on the management service virtual machine is open for more than 4 days, the browser (Internet Explorer 8.0) might report high memory usage.
Workaround: In the browser, refresh or minimize the page to release the memory.
- Issue ID 0262505: When viewing the built-in or custom reports in the Reporting tab on a NetScaler VPX instance running on the NetScaler SDX 17550/19550/20550/21550 platform, the following message appears: “NO DATA TO CHART”.
- Issue ID 0265006: Tx flow control on the interfaces of a NetScaler VPX instance can cause packets to be dropped instead of transmitted.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
NetScaler SDX Appliance and NetScaler VPX Appliance
- Issue IDs 0274497 and 0274498: Layer 2 (L2) mode, link aggregation control protocol (LACP), and virtual MAC addresses (VMACs) are not supported on the NetScaler SDX appliance or the NetScaler VPX virtual appliance.
NetScaler VPX Appliance
- Issue ID 88057/0247795: If you allocate more than 200MB for caching on a VPX (virtual) appliance with 2GB RAM or allocate more than 800MB on a VPX appliance with 4GB RAM, memory-intensive features (such as compression and GSLB) stop working.
Workaround: Reduce the memory allocated for caching.
- Issue ID 94487/0258286: On the Microsoft
Hyper-V platform, if there are fragmentation issues on dynamic
virtual disks, the NetScaler VPX appliance sends HTTP 5xx responses
to requests.
Workaround: Defragment the disk. For consistent
virtual hard disk (VHD) performance, change a dynamic disk to a
static disk.
Networking
- Issue ID 0271154: The man pages for the commands 'add ns ip','set ns ip','add ns ip6', and 'set ns ip6' displays an incorrect default value for the 'ospfArea' parameter.
Platform
- Issue ID 87419/0247297 (nCore): When you start the remote console from the LOM configuration utility on a NetScaler MPX 11500/13500/14500/16500/18500/20500 or MPX 17550/19550/20550/21550 appliance, remote keyboard redirection does not work.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance.
ipmi0: KCS error: 01
ipmi0: KCS: Reply address mismatch
- Issue ID 90018/0249389 (nCore): When you upgrade any MPX appliance, except MPX 15000/17000, restart the appliance, and then apply the default configuration, the 1G interfaces are reset.
- Issue ID 0262488 (nCore): On the MPX and SDX 11500/13500/14500/16500/18500/20500 and MPX and SDX 17550/19550/20550/21550 appliances, the network cable does not lock properly into the port and is easy to pull out.
Policies
- Issue ID 0291975: The SYS.VSERVER('<vserver_name>').THROUGHPUT expression returns an incorrect throughput value.
Reporting
- Issue ID 85025/0245335 (nCore and nCore VPX): Reporting charts do not support plotting of counters per packet engine.
SSL
- Issue ID 74279/0236509: The cipher TLS1-EXP1024-DES-CBC-SHA is not supported by the NetScaler appliance.
- Issue ID 80830/0241961 (nCore): If you attempt to delete an SSL certificate-key pair that is referenced by a certificate revocation list (CRL), the following, incorrect message appears: “ERROR: Configuration possibly inconsistent. Please check with the 'show configstatus' command or reboot.” However, the correct message--“ERROR: Certificate is referenced by a CRL, OCSP responder, virtual server, service, or another certificate”-- appears upon subsequent attempts to delete the certificate-key pair.
- Issue ID 81850/0242774 (nCore): You cannot
import an external, encrypted FIPS key directly to an MPX
9700/10500/12500/15500 10G FIPS appliance.
Workaround: First, decrypt the key, and then
import it. To decrypt the key, at the shell prompt, type: openssl
rsa -in <EncryptedKey.key> > DecryptedKey.out
- Issue ID 85393/0245605: A DSA certificate signed with the SHA-2 algorithm is not supported in the client authentication process.
System
- Issue ID 84099/0244639 (nCore): The NetScaler appliance may fail if traffic reaches a load balancing virtual server that uses the token method for load balancing and has connection failover enabled.
- Issue ID 84282/0244774: A global setting of less than 1220 for the maximum segment size (MSS) to use for TCP connections causes an excessive delay in saving the configuration.
- Issue ID 84320/0244792 (nCore and nCore VPX): The NetScaler appliance may fail if a failover happens while high availability (HA) synchronization is in progress.
- Issue ID 94133/0257961: If a server (load balancing virtual server or content switching vserver) is configured with the same IP address, port, and protocol as the server configured in the audit syslog or nslog action, the configured virtual server will be deleted on upgrading from 9.3_49 or a prior build to a build later than 9.3_49.
Workaround: Do the following:
- Remove the audit policy and action.
- Add the deleted virtual server.
- Add the audit policy and action.
- Save the configuration.
- Issue ID 0263852 (nCore): If you configure link
aggregation on the 10G interfaces by using the link aggregation
control protocol (LACP), the LA interface might flap (go down and
come back up).
Workaround: Initiate steering to CPU1. At the
shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the
interrupt steering option back to CPU0 (the default), at the shell
prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the
workaround persistent, add the first command to the initialization
script /nsconfig/rc.netscaler or its equivalent.
Web Interface
- Issue ID 89052/0248592 (nCore and nCore VPX): The response from a Web Interface site that is configured in direct mode may have Java errors.
XML API
- Issue ID 80170/0241429: The syntax of the 'unset servicegroup' command has been changed to allow unsetting the parameters of the service group members. This can cause XML API incompatibility with respect to the 'unset servicegroup' command.