This document describes the enhancements and known issues in the enhancement releases of the Citrix NetScaler software.
Release version: Citrix NetScaler release 10.1.e build 130.1302.e
Replaces build: None
Release date: Mar 2015
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 130.13. The release notes are available in the Build 130.13 section on Citrix eDocs.
The enhancements and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
NetScaler Gateway
CloudBridge Connector
NetScaler Gateway
Users are affected only if:
1. They use Windows full client for establishing the gateway session
AND
2. They have both Automatic Configuration script and Manual configuration for Proxy in their Internet Explorer settings
AND
3. The configured Automatic Proxy script file happens to be unreachable from the user's device (for example the Automatic Proxy script file address is an internal address and not reachable remotely).
- If enable_vpn_dnstruncate_fix nsapimgr flag is set on NetScaler.
- DNS servers on NetScaler are configured to send negative DNS response for external DNS query.
- Split DNS is set to both
NetScaler SDX Appliance
SSL
Sixteen new ciphers are supported with TLS protocol version 1.2 on all MPX platforms, and on SDX platforms if an SSL chip is assigned to the instance when you provision it.
1) Cipher Name: TLS1-ECDHE-RSA-RC4-SHA
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=RC4(128) Mac=SHA1
2) Cipher Name: TLS1-ECDHE-RSA-DES-CBC3-SHA
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=3DES(168) Mac=SHA1
3) Cipher Name: TLS1-ECDHE-RSA-AES128-SHA
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(128) Mac=SHA1
4) Cipher Name: TLS1-ECDHE-RSA-AES256-SHA
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(256) Mac=SHA1
5) Cipher Name: TLS1.2-AES128-GCM-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES-GCM(128) Mac=SHA-256
6) Cipher Name: TLS1.2-AES256-GCM-SHA384
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES-GCM(256) Mac=SHA-384
7) Cipher Name: TLS1.2-DHE-RSA-AES128-GCM-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES-GCM(128) Mac=SHA-256
8) Cipher Name: TLS1.2-DHE-RSA-AES256-GCM-SHA384
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES-GCM(256) Mac=SHA-384
9) Cipher Name: TLS1.2-ECDHE-RSA-AES128-GCM-SHA256
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES-GCM(128) Mac=SHA-256
10) Cipher Name: TLS1.2-ECDHE-RSA-AES256-GCM-SHA384
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES-GCM(256) Mac=SHA-384
11) Cipher Name: TLS1.2-ECDHE-RSA-AES-128-SHA256
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(128) Mac=SHA-256
12) Cipher Name: TLS1.2-ECDHE-RSA-AES-256-SHA384
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(256) Mac=SHA-384
13) Cipher Name: TLS1.2-AES-256-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES(256) Mac=SHA-256
14) Cipher Name: TLS1.2-AES-128-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES(128) Mac=SHA-256
15) Cipher Name: TLS1.2-DHE-RSA-AES-128-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES(128) Mac=SHA-256
16) Cipher Name: TLS1.2-DHE-RSA-AES-256-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES(256) Mac=SHA-256
NetScaler release 10.5 build 53.9 introduces support for the following ciphers:
- Cipher Name: TLS1.2-AES128-GCM-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES-GCM(128) Mac=SHA-256
- Cipher Name: TLS1.2-AES256-GCM-SHA384
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES-GCM(256) Mac=SHA-384
- Cipher Name: TLS1.2-DHE-RSA-AES128-GCM-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES-GCM(128) Mac=SHA-256
- Cipher Name: TLS1.2-DHE-RSA-AES256-GCM-SHA384
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES-GCM(256) Mac=SHA-384
- Cipher Name: TLS1.2-ECDHE-RSA-AES128-GCM-SHA256
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES-GCM(128) Mac=SHA-256
- Cipher Name: TLS1.2-ECDHE-RSA-AES256-GCM-SHA384
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES-GCM(256) Mac=SHA-384
- Cipher Name: TLS1.2-ECDHE-RSA-AES-128-SHA256
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(128) Mac=SHA-256
- Cipher Name: TLS1.2-ECDHE-RSA-AES-256-SHA384
Description: TLSv1.2 Kx=ECC-DHE Au=RSA Enc=AES(256) Mac=SHA-384
- Cipher Name: TLS1.2-AES-256-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES(256) Mac=SHA-256
- Cipher Name: TLS1.2-AES-128-SHA256
Description: TLSv1.2 Kx=RSA Au=RSA Enc=AES(128) Mac=SHA-256
- Cipher Name: TLS1.2-DHE-RSA-AES-128-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES(128) Mac=SHA-256
- Cipher Name: TLS1.2-DHE-RSA-AES-256-SHA256
Description: TLSv1.2 Kx=DH Au=RSA Enc=AES(256) Mac=SHA-256
Release version: Citrix NetScaler release 10.1.e build 129.1105.e
Replaces build: None
Release date: Oct 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 129.11. The release notes are available in the Build 129.11 section on Citrix eDocs.
The enhancements and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
Networking
Release version: Citrix NetScaler release 10.1.e build 127.1007.e
Replaces build: None
Release date: Aug 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 127.10. The release notes are available in the Build 127.10 section on Citrix eDocs.
The enhancements and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
High Availability
The fix ensures that the NetScaler IP (NSIP) address of the local box is always set as the source IP address in a HA setup.
NetScaler Gateway
NetScaler SDX Appliance
Workaround:Configure the DNS configuration through network settings option
Release version: Citrix NetScaler release 10.1.e build 126.1203.e
Replaces build: None
Release date: June 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 126.12. The release notes are available in the Build 126.12 section on Citrix eDocs.
The enhancements and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
Source IP Persistency for RNAT Sessions
The source IP persistency of a RNAT rule enables the NetScaler ADC to use the same NAT IP address for all RNAT sessions initiated from a particular server.
Source IP Persistency for NetProfiles
The source IP persistency of a netprofile associated with a virtual server or service enables the NetScaler ADC to use the same address, specified in the net profile, for all sessions initiated from a particular client.
The LCD has a neon backlight. Normally, the backlight glows steadily. When there is an active alert, it blinks rapidly. When the appliance shuts down, the backlight remains on for one minute and then automatically turns off.
Note: The LCD screen on a NetScaler SDX appliance displays the base model number for that platform. To view the licensed model number of the appliance, log on to the Management Service and check the licensed model number on the top left corner of the screen. For example, if you have purchased an SDX 11515 license, the LCD screen displays SDX 11500, and the Management Service screen displays NetScaler SDX (11515).
On some SDX platforms, the LCD backlight might not work. Therefore, the display might not be clear.
NetScaler ADC sends SNMP trap when port allocation fails on the NetScaler. The following SNMP OID is added: dstip (1.3.6.1.4.1.5951.1.1.0.143)
Release version: Citrix NetScaler release 10.1.e build 124.1311.e
Replaces build: None
Release date: May 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 124.13. The release notes are available in the Build 124.13 section on Citrix eDocs.
The enhancement and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
Release version: Citrix NetScaler release 10.1.e build 124.1308.e
Replaces build: None
Release date: April 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 124.13. The release notes are available in the Build 124.13 section on Citrix eDocs.
The enhancement in this release apply to Citrix NetScaler 10.1.e nCore.
With a RISE based implementation, the NetScaler functionality is available as a centralized resource that can be leveraged across the application infrastructure supported by the Cisco Nexus 7000 series switch. The key functionalities of the RISE architecture include:
RISE provides a plug and play auto-provisioning feature. When you directly connect the NetScaler ADC to the Cisco Nexus 7000 series switch, auto-discovery commences.
The discovery and bootstrap mechanism enables the Cisco Nexus 7000 Series switch to communicate with the NetScaler ADC by exchanging information to set up a RISE channel, which transmits control and data packets.
The NetScaler ADC uses its health monitoring feature to track and support server health by sending health probes to verify server responses.
Automatic Policy Based Routing (APBR) automatically routes the return traffic from the servers to the NetScaler ADC, preserving the client IP addresses. The automatic policy based routes are defined on the Cisco Nexus 7000 series switch. When the return traffic from the server reaches the Cisco Nexus 7000 series switch, the APBR policies defined on the switch route the traffic to the NetScaler ADC, which in turn routes the traffic to the client.
With stateful connection failover enabled, the secondary appliance has information about the connections established before the failover and starts serving those already established connections after the failover.
After HA failover, the client remains connected to the same physical server. The new primary appliance synchronizes the information with the new secondary appliance by using the SSF framework. During the transition period, the client and server may experience a brief disruption and retransmissions.
Release version: Citrix NetScaler release 10.1.e build 123.1100.e
Replaces build: None
Release date: March 2013
Release notes version: 2.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 123.11. The release notes are available in the Build 123.11 section on Citrix eDocs.
The enhancements and known issue in this release apply to Citrix NetScaler 10.1.e nCore™.
ENH ID 0368447: This enhancement allows state information, in the form of variables, to be stored and used on NetScaler appliances . Variables can be of ulong, text, or map types. A map can have ulong and text type elements. And the map key is always text.
add ns variable my_counter –type ulong
add ns variable user_privilege_map -type map(text(15),text(10),10000)
add ns assignment inc_my_counter -var $my_counter -add 1
add ns assignment set_user_privilege -var $user_privilege_map[client.ip.src.typecast_text_t] -set sys.http.callout(get_user_privilege)
add ns assignment clear_user_privilege -var $user_privilege_map[client.ip.src.typecast_text_t] -clear
add cmp policy set_user_privilege_pol -rule $user_privilege_map.valueExists(client.ip.src.typecast_text_t).not -resAction set_user_privilege
For more information, see Variables.
Issue ID 0419226: In the configuration utility, the online help for the content accelerator feature mentions a video that is not available.
Release version: Citrix NetScaler release 10.1.e build 122.1708.e
Replaces build: None
Release date: February 2014
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 122.17. The release notes are available in the Build 122.17 section on Citrix eDocs.
The enhancements and known issues in this release apply to Citrix NetScaler 10.1.e nCore.
ENH ID 0378995: The adaptive threshold functionality in NetScaler Insight Center dynamically sets the threshold value for the maximum number of hits on each URL. If the maximum number of hits on a URL is greater than the threshold value set for the URL, a syslog message is sent to an external syslog server. The threshold value can be set for daily or weekly interval.
For more information, see Managing Threshold.
ENH ID 0357214: Palo Alto Networks VM-Series on Citrix NetScaler SDX enables consolidation of best-in-class security and ADC capabilities on a single platform, for secure, reliable access to applications by businesses, business units, and service-provider customers. The combination of VM-Series on Citrix NetScaler SDX also provides a complete, validated, security and ADC solution for Citrix XenApp and XenDesktop deployments.
You can provision, monitor, manage, and troubleshoot an instance from the Management Service.
For more information, see Palo Alto Networks VM-Series.
Issue ID 0419226: In the configuration utility, the online help for the content accelerator feature mentions a video that is not available.
Release version: Citrix NetScaler release 10.1.e build 121.1013.e
Replaces build: None
Release date: December 2013
Release notes version: 1.0
Language supported: English (US)
This release is based on Citrix NetScaler release 10.1 build 121.10. The release notes are available in the Build 121.10 section on Citrix eDocs.
The enhancements and known issue in this release apply to Citrix NetScaler 10.1.e nCore™.
ENH ID 0399086: With this release, the following authentication and authorization capabilities are supported on NetScaler SDX appliance:
For more information, see Configuring Authentication and Authorization Settings.
ENH ID 0325421: User names and passwords on the NetScaler appliance can now be up to 127 characters in length. Usernames and passwords can consist of upper-case and lower-case letters, digits, and the hyphen and underscore characters.
ENH ID 0400961: The NetScaler provides a feature called Content Accelerator, that can be used in a Citrix ByteMobile T1100 deployment, to store content on a Citrix ByteMobile T2100 appliance. For more information, see Content Accelerator.
Issue ID 0419226: In the configuration utility, the online help for the content accelerator feature mentions a video that is not available.