This document describes the changes, fixed issues, and known issues provided in the maintenance releases of the Citrix NetScaler, Citrix NetScaler SDX, and Citrix Access Gateway software.
Release version: Citrix NetScaler, version 9.3 build 65.8
Replaces build: None
Release date: December 2013
Release notes version: 1.0
Language supported: English (US)
Issue ID 0422639: On a NetScaler appliance with the application firewall enabled, web forms submitted with URL-encoded double-byte character (Chinese, Japanese, or Korean) inputs might generate a Form Field consistency check violation. The reason is that the application firewall counts bytes instead of characters when validating web form input, causing some double-byte input to exceed the form field maxlength attribute.
Issue IDs 0391317 and 0423289: On a NetScaler appliance with both the application firewall and integrated caching enabled, a memory leak might occur. To work around this issue, disable integrated caching.
Issue IDs 0422919 and 0423289: On a NetScaler appliance with the application firewall enabled and configured, if a protected web site contains a multipart web form, a memory leak causes a small amount of memory to be consumed and not released each time the application firewall processes the web form. Repeated processing of requests and responses can gradually consume available memory.
Issue ID 0427717: On a NetScaler appliance with the application firewall enabled and configured, if memory utilization is high any URL redirect might fail, causing the appliance to crash. To work around this issue, reduce memory utilization by reducing session timeouts and disabling memory-intensive filtering rules.
Issue ID 0427857: The application firewall currently miscalculates memory limits on 12 GB 2 vCPU NetScaler appliances. For example, when the appliance has 2 GB memory available, the application firewall shows only 600 M of available memory.
Issue ID 0431456: On a NetScaler appliance with the application firewall enabled, occasionally an embedded image URL is blocked, leading to the web page with that image URL rendering a broken image in the user's browser.
Issue ID 0379234: The show ns runningConfig command displays the current time instead of the time at which the configuration was last modified.
Issue ID 0426594: The NetScaler configuration utility is not compatible with JRE version 7.45.
Issue ID 0426904: When you navigate to
and click on a server to view the server details, the time zone displayed will be different from the time zone selected when you created the server.Issue ID 0419409: When you navigate to SSL Settings under the SSL Parameter tab on the Create Virtual Server dialogue box, the Enable Cipher Redirect check box is enabled by default.
and clickIssue ID 0394856: If a content switching virtual server with a large number of existing connections is removed, flushing all the PCBs takes time. If any traffic destined for the virtual server is received during this time, the appliance fails.
Issue ID 0417800: The NetScaler appliance might fail if after forwarding a client request to the server and while sending the response from the server to the client, the client connection is closed.
Issue ID 0408374: If a configuration has a large number of GSLB services and the add location file command is used to add the location database, some of the services might not be assigned a location from the database.
Issue ID 0368151: In a high availability configuration, when you save the running configuration or synchronize file by using the NetScaler command line or configuration utility, synchronization of running configuration is automatically triggered.
Issue ID 0437809: In an High Availability configuration, synchronization and propagation auto disabled on the nodes after the secondary node is upgraded from 9.3_64.4_nc to 9.3_65.5_nc
Issue ID 0390037: After authentication, if AAA generates the URL redirect, it rewrites the query portions of certain URLs into base 8 ASCII string equivalents instead of transmitting the original strings.
Issue ID 0257491: If the first few characters of the name of a load balancing virtual server (for example VSVR1) are the same as the name of another load balancing virtual server (for example VSVR) and persistence is configured on the virtual server with the shorter name (VSVR), the name of the virtual server in the output of the show persistentsessions command on virtual server VSVR might incorrectly appear as VSVR1.
Issue ID 0429549: If rule-based persistence is configured on a virtual server, the sessions are not cleared after the stipulated timeout period. Also, running the clear ns persistencesessions command does not release the resources consumed by these sessions. As a result the appliance reaches its session limit and no new sessions can be formed.
Issue ID 0260803: In an HA configuration, ping to NSIP of the secondary node fails because of the frequent clearing of configuations triggered by synchronization of configurations to secondary. This synchronization in turn was triggered by repeated saving of configurations in the primary.
Issue ID 0423856: For a load balancing configuration in which an IPv6 virtual server is used to load balance IPv6 servers, if the NetScaler appliance processes client's final ACK of the TCP handshake and the first data packets in the same IO cycle, the appliance may not forward the data packets to the server causing the connection to fail.
Issue ID 0311561: The MPX 22040/22060/22080/22100/22120 platform now supports NetScaler release 9.3 build 65.x.
Issue ID 0427155: NetScaler MPX appliances now support Cisco QSPF+ cables (part number L45593-D178-C30).
Issue ID 0421791: The MPX 8800 appliance now delivers a throughput of 10 Gbps.
Issue ID 0428562: NetScaler does not display the correct daylight savings time for Israel.
Issue ID 0430148: Error messages that are thrown while binding policies are displayed as hexadecimal code instead of the corresponding warning message.
Issue ID 0382647: The stat system -detail command does not display the number of CPUs.
Issue ID 0365828: Before reusing a server connection in the reuse pool, the NetScaler appliance checks the connection's idletimeout and reusepool values, and closes the connection if either value is exceeded. The appliance also checks the reuse pool for idle connections, and closes them, more frequently than specified by the zombie timer interval.
Issue ID 0396373: The SNMP daemon (SNMPD) displays memory-usage values incorrectly if you use the packet-engine formula instead of the SNMPD formula to generate the values.
Issue ID 0378974: On a NetScaler appliance that has AAA-TM enabled and single sign-on (SSO) configured, attempts to upload large files in HTTP POST requests might cause high memory allocation errors.
add tm trafficaction disablesso -sso off add tm trafficpolicy disablesso "http.req.method.eq(POST)" disablesso bind tm global trafficpolicy
Issue ID 0259458: Attempts to upload a 30 MB or larger file might fail when Cross-Site Scripting (XSS) and SQL Injection checks are enabled.
Issue ID 0284677: The online help for the application firewall wizard points to placeholders. If you need help with the wizard, consult the following URL:
Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
Issue ID 0316200: After upgrading to NetScaler 9.3, build 58.x, the built-in AppFW profiles are not visible in the NetScaler configuration utility or listed in the ns.conf file.
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add sys cmdPolicy policy1 ALLOW ((show)\s+ns\s+version|(show)\s+ns\s+hardware) bind sys user user1 policy1 1
Workaround: Change the GSLB method and restart the appliance.
Issue ID 0262505: When viewing the built-in or custom reports in the Reporting tab on a NetScaler VPX instance running on the NetScaler SDX 17550/19550/20550/21550 platform, the following message appears: NO DATA TO CHART.
Issue ID 0265006: Tx flow control on the interfaces of a NetScaler VPX instance can cause packets to be dropped instead of transmitted.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Issue ID 0318639: If you log on to a NetScaler SDX appliance by using Internet Explorer version 8.0.6001.18702, and try to upgrade the Management Service or a NetScaler VPX instance without providing a documentation file, the following error message appears: “Invalid documentation filename format”.
Workaround: Reduce the memory allocated for caching.
Issue ID 94487/0258286: On the Microsoft Hyper-V platform, if there are fragmentation issues on dynamic virtual disks, the NetScaler VPX appliance sends HTTP 5xx responses to requests.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
Issue ID 90018/0249389 (nCore): When you upgrade any MPX appliance, except MPX 15000/17000, restart the appliance, and then apply the default configuration, the 1G interfaces are reset.
This change affects the following platforms:
Issue ID 74279/0236509: The cipher TLS1-EXP1024-DES-CBC-SHA is not supported by the NetScaler appliance.
Issue ID 81850/0242774 (nCore): You cannot import an external, encrypted FIPS key directly to an MPX 9700/10500/12500/15500 10G FIPS appliance.
Issue ID 84099/0244639 (nCore): The NetScaler appliance might fail if traffic reaches a load balancing virtual server that uses the token method for load balancing and has connection failover enabled.
Issue ID 84282/0244774: A global setting of less than 1220 for the maximum segment size (MSS) for TCP connections causes an excessive delay in saving the configuration.
Workaround: The global setting for MSS must be set to a value greater than 1212.
Issue ID 0412329: When the URL Transformation feature is enabled on a NetScaler appliance, Apple iOS-based mobile devices are unable to play MP4 video files.
Release version: Citrix NetScaler, version 9.3 build 64.4
Replaces build: None
Release date: September 2013
Release notes version: 1.0
Language supported: English (US)
Issue ID 0333655: When the application firewall parses multipart POST requests to identify boundary text, instead of attempting to match the string ; boundary=, it instead searches for the string boundary within the Content-type HTTP header. The relevant RFCs permit white space between the semicolon (;) and boundary, between boundary and the equals sign, and between the equals sign and the beginning of the boundary text value, so searching for an exact string that includes the semicolon or equals sign fails when unexpected white space is present. This change ensures that the application firewall correctly identifies boundary text.
Issue ID 0403027: The application firewall includes an extraneous line break in the hidden field that it adds to forms as part of the form field consistency check. This line break is not javascript-compliant and can cause issues with javascript-enhanced forms.
Issue ID 0376437: To improve performance, when processing buffer overflow signatures the application firewall now evaluates PCRE regular expressions only when the minLength parameter is set.
Issue ID 0382182: The issue occurs when the output of a CLI command is piped to another command more than once. This is due to the NetScaler appliance treating the second (and later) pipes as arguments to the first piped command, instead of treating them as separate commands.
Issue ID 0361970: When a NetScaler session expires, a session expiry message appears in the graphical user interface, and the user has to manually enter the IP address or the domain name of the NetScaler appliance in the address bar to log back on.
Issue ID 0357841: In an high availability configuration, for a connection to an FTP virtual server with stateful connection failover option enabled, if the FTP control connection is closed before the passive mode FTP data connection is opened, the secondary node may become unresponsive.
Issue ID 0380302: In a high availability configuration, as a result of an internal connection timeout event, the command sync ha files might fail and display the following warning message when you run the command from the primary node:
Warning: Command failed on secondary node, but succeeded on primary node. Configuration will be synchronized to ensure secondary and primary have same configuration.
Issue ID 0407376: In an High Availability configuration, when you run the command force ha sync on the primary node, the client timeout parameter setting for DNS and UDP services is reset to 120 secs on the secondary node.
Issue ID 0312844 (nCore and nCore VPX): The NetScaler appliance might fail when it is rate limiting DNS or SIP traffic associated with a sessionless load balancing virtual server.
Issue ID 0349420: If the length of the Send String is greater than 430 characters for an HTTP-ECV load balancing monitor, the string is truncated if the set lb monitor command is issued. If the send string is less than or equal to 430 chars, it is not truncated.
Issue ID 0390545: In an interactive voice response (IVR) setup, the option selected by a user is not communicated to the backend server because the RTSP packet is corrupted. As a result, the user is repeatedly asked to select an option from the same list.
Issue ID 0391273: When you add a new server to an existing service group, the services in the group might be designated as DOWN even though monitoring probes succeed. To enable the services, unset the virtual server spillover method. They are then correctly designated as UP.
Issue ID 0409028: If you unbind a load balancing (LB) monitor from its service, all the connections to the configured destination IP address (destip) and port (destport) of the LB monitor are closed. In a typical L3 Direct Server Return (DSR) deployment mode, the destip and destport of the LB monitor are actually the IP address and port of the virtual server. Therefore, in a typical L3 DSR deployment, if you unbind an LB monitor from its service, all the existing connections to the virtual server are closed. As a result, performance temporarily decreases. The same behavior occurs if you delete a service.
Issue ID 0409055: If you run a custom health monitoring script that does not require an argument, the NetScaler appliance sends an incorrect timeout to the script. As a result, the script continues to run for longer than expected. After some time, the maximum limit for the number of scripts allowed on the appliance is reached and new scripts cannot be run.
Issue ID 0391105: A NetScaler appliance that has AAA-TM configured for authentication with a RADIUS Server might intermittently generate HTTP/1.1 Internal Server Error 6 error messages.
Issue ID 0400164: You cannot change the default SSL certificate that is used for secure access to the Management Service.
Issue ID 0405115: SSL certificate installation on a NetScaler instance from the SDX Management Service fails during validation if the SSL certificate does not have an associated key file.
Issue ID 0404861: If the NetScaler appliance has redundant L2 connectivity with a switch, the NetScaler appliance may mark its link-local IPv6 addresses as duplicate during the DAD (Duplicate address detection) process.
Issue ID 0405190: When IP fragments are received on a load balancing virtual server with client timeout parameter set to zero, the NetScaler appliance might dump core and then restart.
Issue ID 0378685: The NetScaler appliance fails to respond when HTTP callouts are configured with IP address and port instead of a virtual server and if a virtual server based expression (in particular, when NetScaler evaluates the expression, even if the request comes from the callout) is configured on the appliance.
Issue ID 0391238: If an HTTP callout is configured with a virtual server that has a widcard port, the NetScaler appliance fails to respond the first time the callout is triggered.
Issue ID 0401455: Modifying the content with more than one callout results in incorrect computation of the content length. This issue is not observed if all the callouts use GET requests.
Issue ID 0360751: The month displayed on the CLI prompt on issuing the set prompt %d command is incorrect.
Issue ID 0369909: If you use a SNIP address for which management access is enabled as the IP address of an HTTP or HTTPS service, and the service is deleted, the NetScaler appliance fails if HTTP or HTTPS traffic is sent to that SNIP address.
Issue ID 0391632: Stat-command output specified with the -fullValues parameter is aligned incorrectly.
Issue ID 0391754: On a NetScaler MPX system, the SNMP count for the system’s hardware memory and the show system memory display are incorrect. The amount of memory shown is larger than the actual amount.
Issue ID 0394724: The SNMP module allocates memory for all OIDs in an SNMP request and queues them for further processing. With a large number of SNMP requests (each request with possibly hundreds of OIDs), the result can be a memory shortage that in turn leads to memory allocation failures.
Issue ID 0415623: If you specify an invalid IPv4 address in a command that can accept either IPv4 or IPv6 address, the NetScaler shell exits automatically due to memory corruption.
Issue ID 0378974: On a NetScaler appliance that has AAA-TM enabled and single sign-on (SSO) configured, attempts to upload large files in HTTP POST requests might cause high memory allocation errors.
add tm trafficaction disablesso -sso off add tm trafficpolicy disablesso "http.req.method.eq(POST)" disablesso bind tm global trafficpolicy
Issue ID 0264933: The NetScaler appliance does not display the correct default values for the icmpType and icmpCode parameters of an extended ACL or ACL6.
Issue ID 0259458: Attempts to upload a 30 MB or larger file might fail when Cross-Site Scripting (XSS) and SQL Injection checks are enabled.
Issue ID 0284677: The online help for the application firewall wizard points to placeholders. If you need help with the wizard, consult the following URL:
Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
Issue ID 0316200: After upgrading to NetScaler 9.3, build 58x, the built-in AppFW profiles are not visible in the NetScaler configuration utility or listed in the ns.conf file.
Issue ID 0318595: On a Sharepoint 2010 server that is protected by the application firewall, drop-down menus that are used to access documents do not open. When the user attempts to open a menu, a JavaScript progress indicator appears on the right side of the page, but no menu is displayed. For more information, see http://support.citrix.com/article/CTX132945.
Issue ID 0363687: Modifying the configured actions for rules in signature objects that are bound to profiles might cause failover and result in loss of configuration due to failure in command propagation to the secondary node.
Issue ID 91850/0250982 (nCore and nCore VPX): The NetScaler appliance drops TCP packets when the server has to send, across the cloud bridge, a full-size packet in which the DF bit is unset. The cause is a bad checksum.
Issue ID 82908/0243626 (nCore): In certain rare cases, if the NetScaler MPX appliance is subject to conditions of heavy SSL-related traffic, CLI commands fail and report a configuration inconsistency error.
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Issue ID 0346576: The NetScaler graphical user interface (GUI) becomes unresponsive when you try to access the Dashboard tab. The reason might be because the user that is trying to access the GUI does not have permission to execute the show ns version and show ns hardware commands.
add sys cmdPolicy policy1 ALLOW ((show)\s+ns\s+version|(show)\s+ns\s+hardware) bind sys user user1 policy1 1
Issue ID 93203/0257123 (nCore): A DNS policy that is bound to a GSLB service is not evaluated if the GSLB method is set to dynamic round trip time (RTT).
Workaround: Change the GSLB method and restart the appliance.
Issue ID 82872/0243593: The setting for maximum requests per connection might be exceeded during a transaction with the physical server.
Issue ID 88593/0248222 (nCore): After failover, the maxclient setting on a service is not honored.
Issue ID 0262505: When viewing the built-in or custom reports in the Reporting tab on a NetScaler VPX instance running on the NetScaler SDX 17550/19550/20550/21550 platform, the following message appears: NO DATA TO CHART.
Issue ID 0265006: Tx flow control on the interfaces of a NetScaler VPX instance can cause packets to be dropped instead of transmitted.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Issue ID 0318639: If you log on to a NetScaler SDX appliance by using Internet Explorer version 8.0.6001.18702, and try to upgrade the Management Service or a NetScaler VPX instance without providing a documentation file, the following error message appears: “Invalid documentation filename format”.
Issue ID 88057/0247795: If you allocate more than 200MB for caching on a VPX virtual appliance with 2GB RAM, or allocate more than 800MB on a virtual appliance with 4GB RAM, memory-intensive features (such as compression and GSLB) stop working.
Workaround: Reduce the memory allocated for caching.
Issue ID 94487/0258286: On the Microsoft Hyper-V platform, if there are fragmentation issues on dynamic virtual disks, the NetScaler VPX appliance sends HTTP 5xx responses to requests.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
Issue ID 0271154: The man pages for the commands add ns ip, set ns ip, add ns ip6, and set ns ip6 display an incorrect default value for the ospfArea parameter.
Issue ID 90018/0249389 (nCore): When you upgrade any MPX appliance, except MPX 15000/17000, restart the appliance, and then apply the default configuration, the 1G interfaces are reset.
Issue ID 0262488 (nCore): On the MPX and SDX 11500/13500/14500/16500/18500/20500 and MPX and SDX 17550/19550/20550/21550 appliances, the network cable does not lock properly into the port and is easy to pull out.
Issue ID 87419/0247297 (nCore): When you start the remote console from the LOM configuration utility on a NetScaler MPX 11500/13500/14500/16500/18500/20500 or MPX 17550/19550/20550/21550 appliance, remote keyboard redirection does not work.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance.
ipmi0: KCS error: 01
ipmi0: KCS: Reply address mismatch
Issue ID 0381000: On some NetScaler appliances, the following four sensor readings are no longer available. The stat system -detail command displays a value of 0.
Intel CPU Vtt Power (Volts)
Voltage Sensor2 (Volts)
Temperature 0 (Celsius)
Temperature 1 (Celsius)
This change affects the following platforms:
MPX 11500/13500/14500/16500/18500/20500
MPX 17550/19550/20550/21550
MPX 8200/8400/8600
MPX 5550/5650/5750
Issue ID 0438508: Release 9.3 build 65.8 is not supported on the NetScaler 7000 platform.
Issue ID 85025/0245335 (nCore and nCore VPX):Reporting charts do not support plotting of counters per packet engine.
Issue ID 74279/0236509: The cipher TLS1-EXP1024-DES-CBC-SHA is not supported by the NetScaler appliance.
Issue ID 80830/0241961 (nCore): If you attempt to delete an SSL certificate-key pair that is referenced by a certificate revocation list (CRL), the following, incorrect message appears: "ERROR: Configuration possibly inconsistent. Please check with the 'show configstatus' command or reboot." However, the correct message, "ERROR: Certificate is referenced by a CRL, OCSP responder, virtual server, service, or another certificate," appears upon subsequent attempts to delete the certificate-key pair.
Issue ID 81850/0242774 (nCore): You cannot import an external, encrypted FIPS key directly to an MPX 9700/10500/12500/15500 10G FIPS appliance.
Issue ID 84099/0244639 (nCore): The NetScaler appliance might fail if traffic reaches a load balancing virtual server that uses the token method for load balancing and has connection failover enabled.
Issue ID 84282/0244774: A global setting of less than 1220 for the maximum segment size (MSS) for TCP connections causes an excessive delay in saving the configuration.
Workaround: The global setting for MSS must be set to a value greater than 1212.
Issue ID 84320/0244792 (nCore and nCore VPX): The NetScaler appliance might fail if a failover occurs while high availability (HA) synchronization is in progress.
Issue ID 0382647: The stat system -detail command does not display the number of CPUs.
Issue ID 0412329: When the URL Transformation feature is enabled on a NetScaler appliance, Apple iOS-based mobile devices are unable to play MP4 video files.
Issue ID 81650/0242628: The application firewall import feature validates XML schemas when importing them, but it might not validate certain XHTML files if they are imported as XML schemas. An invalid XHTML file appears in the list of imported XML schemas, but it is rejected if the user attempts to configure the XML Message Validation check to use the invalid file as the XML schema for validation.
Issue ID 80170/0241429: The syntax of the unset servicegroup command has been changed to allow unsetting the parameters of the service group members. This can cause XML API incompatibility with respect to the unset servicegroup command.
Issue ID 0242149: The rmlbvserver API throws an error if the name of the load balancing virtual server includes a space character.
Issue ID 82501/0243262: The data type of the maxforwards argument of the setlbmonitor API is updated from int to unsignedint. This can cause incompatibility of the API.
Issue ID 86524/0246517: The data type of the type parameter of the bindcmpglobal_policyEx and unbindcmpglobal_policyEx APIs is changed from rwglobalbindpointEnum to piglobalbindpointEnum. This can cause incompatibility in the API.
Release version: Citrix NetScaler, version 9.3 build 63.4
Replaces build: None
Release date: July 2013
Release notes version: 2.0
Language supported: English (US)
Value entered is out of range.
" Domain name cannot be resolved".
The following SFP+ and SFP transceivers, and direct access cables, are supported:
API has been removed from XML-API.
add tm trafficaction disablesso -sso off add tm trafficpolicy disablesso "http.req.method.eq(POST)" disablesso bind tm global trafficpolicy
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add sys cmdPolicy policy1 ALLOW ((show)\s+ns\s+version|(show)\s+ns\s+hardware) bind sys user user1 policy1 1
Workaround: Change the GSLB method and restart the appliance.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Reduce the memory allocated for caching.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
Workaround: The global setting for MSS must be configured to greater than 1212.
Release version: Citrix NetScaler, version 9.3 build 62.4
Replaces build: None
Release date: April 2013
Release notes version: 2.0
Language supported: English (US)
add tm trafficaction disablesso -sso off add tm trafficpolicy disablesso "http.req.method.eq(POST)" disablesso bind tm global trafficpolicy
Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add sys cmdPolicy policy1 ALLOW ((show)\s+ns\s+version|(show)\s+ns\s+hardware) bind sys user user1 policy1 1
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Use a different browser.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: The global setting for MSS must be configured to greater than 1200.
Release version: Citrix NetScaler, version 9.3 build 61.5
Replaces build: None
Release date: February 2013
Release notes version: 1.0
Language supported: English (US)
Instead of text indicating that the most recent probe timed out, the content of the Last response field is Internal error: resource unavailable to send probe.
To create a new administrator profile, log on to the Management Service and, on the Configuration tab, navigate to NetScaler > Admin Profiles. In the details pane, click Add. In the Create NetScaler Admin Profile dialog box, type the new profile name and password. Then navigate to NetScaler > Instances and select the instance to which you want to bind the new profile. Click Modify to open the Modify NetScaler wizard and, from the Admin Profile list, select the new profile. You do not need to restart the instance for this change to take effect.
You can also lose connectivity to XenServer by changing the password on XenServer instead of from the Management Service. To restore connectivity, you can now change the password for XenServer from the Management Service.
To change the password, log on to the Management Service and, on the Configuration tab, navigate to System > Users. Select the nsroot user, and then click Modify. In the Modify System User dialog box, type the same password that you specified when you were logged directly on to XenServer.
Alternatively, a description of the Wizard can be found in the PDF-based documentation, in the Configuration chapter.
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add sys cmdPolicy policy1 ALLOW ((show)\s+ns\s+version|(show)\s+ns\s+hardware) bind sys user user1 policy1 1
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Use a different browser.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: The global setting for MSS must be configured to greater than 1200.
sysctl netscaler.ticks_on_cpu1=1To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type:
sysctl netscaler.ticks_on_cpu1=0To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Release version: Citrix® NetScaler®, version 9.3 build 60.3
Replaces build: None
Release date: December 2012
Release notes version: 4.0
Language supported: English (US)
In addition, if you configure double-source authentication that requires authentication with LDAP plus RSA authentication, you need to also add the following as REG_SZ:
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Delete the time zone from the configuration (ns.conf), upgrade to the target build or release, and then reconfigure the time zone.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: After the appliance restarts, rebind the certificate to the service group, or use services instead of a service group.
sysctl netscaler.ticks_on_cpu1=1To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type:
sysctl netscaler.ticks_on_cpu1=0To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Release version: Citrix® NetScaler®, version 9.3 build 59.5
Replaces build: None
Release date: October 2012
Release notes version: 4.0
Language supported: English (US)
In addition, if you configure double-source authentication that requires authentication with LDAP plus RSA authentication, you need to also add the following as REG_SZ:
Workaround: Check for configuration inconsistency by using the 'show configstatus' command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Delete the time zone from the configuration (ns.conf), upgrade to the target build or release, and then reconfigure the time zone.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Reduce the memory allocated for caching.
Issue ID 94487/0258286: On the Microsoft Hyper-V platform, if there are fragmentation issues on dynamic virtual disks, the NetScaler VPX appliance sends HTTP 5xx responses to requests.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch.
Workaround: After the appliance restarts, rebind the certificate to the service group, or use services instead of a service group.
Workaround: Initiate steering to CPU1. At the shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Release version: Citrix® NetScaler®, version 9.3 build 58.5
Replaces build: None
Release date: August 2012
Release notes version: 5.0
Language supported: English (US)
show tm sessionaction <profileName>
You can fix the persistency settings for any AAA-TM profile that is affected by this issue by typing the following command at the NetScaler command line:
set tm sessionAction <profileName> -persistentCookie ENABLED -persistentCookieValidity <positive_integer>
For <positive_integer>, substitute the number of minutes that the persistency cookie is to remain valid. Then, use the 'show tm sessionaction' command to verify your changes.
When a failover occurs, the failover of some services might be delayed by a few seconds while monitors learn the actual states of those services. Until the monitors learn and correct the states, new connections to those services might be rejected. Consequently, you might also observe a brief period of outage following a failover.
In addition, if you configure double-source authentication that requires authentication with LDAP plus RSA authentication, you need to also add the following as REG_SZ:
Workaround: Check for configuration inconsistency by using the 'show configstatus' command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Delete the time zone from the configuration (ns.conf), upgrade to the target build or release, and then reconfigure the time zone.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: In the browser, refresh or minimize the page to release the memory.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
sysctl netscaler.ns_vpx_halt_method=2
sysctl netscaler.ns_vpx_halt_method=2
ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type: openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Initiate steering to CPU1. At the shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Workaround: Replace the 'any' type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The 'any' type is rarely used.)
Release version: Citrix® NetScaler®, version 9.3 build 57.5
Replaces build: None
Release date: June 2012
Release notes version: 4.0
Language supported: English (US)
For example, the second command provided below might not succeed if there exists some request for which the evaluation of rule in cs_example is in progress.
-> add cs policy cs_example -rule 'HTTP.REQ.BODY(1000).CONTAINS("MyLengthIs12")
-> add cs policy cs_example_break -rule 'HTTP.REQ.BODY(1000).CONTAINS("MyLengthIsBIG15")
show tm sessionaction <profileName>
You can fix the persistency settings for any AAA-TM profile that is affected by this issue by typing the following command at the NetScaler command line:
set tm sessionAction <profileName> -persistentCookie ENABLED -persistentCookieValidity <positive_integer>
For <positive_integer>, substitute the number of minutes that the persistency cookie is to remain valid. Then, use the "show tm sessionaction" command to verify your changes.
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Delete the time zone from the configuration (ns.conf), upgrade to the target build or release, and then reconfigure the time zone.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: In the browser, refresh or minimize the page to release the memory.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
"ps -ax | grep svm_migration"If you see some processes running, then migration is in progress and you must not restart the Management Service.
Workaround: First, upgrade the Management Service from build 48.6 to build 55.6, and then upgrade it from build 55.6 to build 56.5 or 57.5.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type: openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Initiate steering to CPU1. At the shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Release version: Citrix® NetScaler® release 9.3 build 56.5
Replaces build: None
Release date: May 2012
Release notes version: 2.0
Language supported: English (US)
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Delete the time zone from the configuration (ns.conf), upgrade to the target build or release, and then reconfigure the time zone.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: In the browser, refresh or minimize the page to release the memory.
"ps -ax | grep svm_migration"If you see some processes running, then migration is in progress and you must not restart the Management Service.
Workaround: First, upgrade the Management Service from build 48.6 to build 55.6, and then upgrade it from build 55.6 to build 56.5 or 57.5.
Workaround: Reduce the memory allocated for caching.
Workaround: Defragment the disk. For consistent virtual hard disk (VHD) performance, change a dynamic disk to a static disk.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch.
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type: openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Initiate steering to CPU1. At the shell prompt, type: sysctl netscaler.ticks_on_cpu1=1 To change the interrupt steering option back to CPU0 (the default), at the shell prompt, type: sysctl netscaler.ticks_on_cpu1=0 To make the workaround persistent, add the first command to the initialization script /nsconfig/rc.netscaler or its equivalent.
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Release version: Citrix® NetScaler® release 9.3 build 55.6
Replaces build: None
Release date: February 2012
Release notes version: 2.0
Language supported: English (US)
Workaround: Check for configuration inconsistency by using the show configstatus command and reconfigure the appliance under low traffic conditions or during a maintenance period. If that does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: Run Internet Explorer version 9.0 in compatibility mode.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: To correct the parameter values, log on to the NetScaler instance through the Xen Console. You also need to correct the values for this instance in the XenStore. After correcting the values in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance, by clicking Rediscovery in the NetScaler Instance pane.
Workaround: In the browser, refresh or minimize the page to release the memory.
Workaround: Reduce the memory allocated for caching.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance--ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch.
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type: openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Release version: Citrix® NetScaler® release 9.3 build 54.4
Replaces build: None
Release date: December 2011
Release notes version: 1.0
Language supported: English (US)
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If this does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: Run Internet Explorer version 9.0 in compatibility mode.
Workaround: To correct the parameter values, log on to the NetScaler instance through the Xen Console. You also need to correct the values for this instance in the XenStore. After correcting the values in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance, by clicking Rediscovery in the NetScaler Instance pane.
Workaround:In the browser, refresh or minimize the page to release the memory.
Workaround: Assign a 0/x interface to the VPX instance.
workaround: Assign a 0/x interface to the VPX instance.
Workaround: Reduce the memory allocated for caching.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Release version: Citrix® NetScaler® release 9.3 build 53.6
Replaces build: None
Release date: November 2011
Release notes version: 2.0
Language supported: English (US)
Before: unset dns mxRec <domain> -TTL
After: unset dns mxRec <domain> -mx <string> -TTL
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If this does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: Run Internet Explorer version 9.0 in compatibility mode.
Workaround: To correct the parameter values, log on to the NetScaler instance through the Xen Console. You also need to correct the values for this instance in the XenStore. After correcting the values in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance, by clicking Rediscovery in the NetScaler Instance pane.
Workaround: In the browser, refresh or minimize the page to release the memory.
Workaround: Turn off the Tx flow control globally on the interfaces from the management Service VM user interface. On the Configuration tab, in the navigation pane, click System, and then click Interfaces.
Workaround: First, add an interface to the NetScaler VPX instance. After the instance restarts, remove the interfaces that are not required.
Workaround: Reduce the memory allocated for caching.
Workaround: Reset the LOM firmware. The following error messages might appear on the console during LOM reset, because the LOM module does not respond to the appliance. ipmi0: KCS error: 01 ipmi0: KCS: Reply address mismatch
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type:
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Do the following:
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Workaround: Convert XML schema or WSDL files to ASCII before importing them.
Release version: Citrix® NetScaler® release 9.3 build 52.3
Replaces build: None
Release date: October 2011
Release notes version: 2.0
Language supported: English (US)
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If this does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
Workaround: Run Internet Explorer version 9.0 in compatibility mode.
Workaround: To correct the parameter values, log on to the NetScaler instance through the Xen Console. You also need to correct the values for this instance in the XenStore. After correcting the values in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance, by clicking Rediscovery in the NetScaler Instance pane.
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type: openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Workaround: Convert XML schema or WSDL files to ASCII before importing them.
Release version: Citrix® NetScaler® release 9.3 build 51.5
Replaces build: None
Release date: August 2011
Release notes version: 1.0
Language supported: English (US)
Accept-Encoding: gzip;q=1.0
1. Disable split tunneling
2. Configure Access Gateway so user connections do not receive an intranet IP address.
3. Configure the wireless device to use an Ethernet connection instead of a mobile broadband connection. For example:
1. Create a clientless access Outlook Web Access Profile and enable persistent cookies.
2. Bind the Outlook Web Outlook regular expression to this profile.
3. Bind the profile so that is assumes the highest priority.
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If this does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
For example:
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa
-password bbb -domain ccc
In some situations, (where multiple persons use same user-login credentials) session cookie persistence may not be helpful and IP-based persistence methods will be necessary. In some other situations, load balancing of the RDP services without persistence may be necessary. That is, each new connection to an RDP virtual server needs to be load balanced irrespective of a user's disconnected session existing on a terminal server.
Workaround: To rectify the parameter values, log on to the NetScaler instance through the Xen Console. You also need to rectify the values for this instance in the XenStore.
After correcting in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance by clicking Rediscovery in the NetScaler Instance pane.
Workaround: Reset the LOM firmware. Note that the appliance may become unresponsive for approximately 60 seconds when you reset the LOM firmware.
Warning: You should reset the LOM firmware only when one of the following conditions apply:
This message is not the intended message. However, on the subsequent attempt to delete the certificate key-pair object, the correct message, "ERROR: Certificate is referenced by a CRL, OCSP responder, virtual server, service, or another certificate," is displayed.
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type:
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Workaround: Convert XML schema or WSDL files to ASCII before importing them.
Release version: Citrix® NetScaler® release 9.3 build 50.3
Replaces build: None
Release date: July 2011
Release notes version: 1.0
Language supported: English (US)
add ip 1.1.1.1 255.255.255.0 [configured as SNIP]
add service adns 1.1.1.1 adnS 53 [configuring the same IP as ADNS]
set server 1.1.1.1 -ipaddress 1.1.1.2 [changing the adns server IP to new IP]
rm ip 1.1.1.1 [Removing old IP returns error]
set lb parameter -consolidatedLConn ( YES | NO )
By default, the option is set to 'Yes'. If and only if there is uneven least connection load balancing in low-traffic scenarios, you can set the "consolidatedLConn" to 'No' to make the load balancing even.
Model Maximum throughput (in Gbps)
11500 8
13500 12
14500 18
16500 24
18500 36
Workaround: Check for configuration inconsistency by using the "show configstatus" command and reconfigure the appliance under low traffic conditions or during a maintenance period. If this does not resolve the issue, restart the appliance.
Workaround: Search for the virtual server names with the expressions "*" or "app" by using the search utility.
For example:
add monitor wi CITRIX-WI-EXTENDED -sitepath "/Citrix/DesktopWeb" -username aaa -password bbb -domain ccc
Workaround: To rectify the parameter values, log on to the NetScaler instance through the Xen Console. You also need to rectify the values for this instance in the XenStore. After correcting in the both the places, rediscover the NetScaler instances from the Management Service VM user interface without selecting any specific instance by clicking Rediscovery in the NetScaler Instance pane.
Workaround: First, decrypt the key, and then import it. To decrypt the key, at the shell prompt, type:
openssl rsa -in <EncryptedKey.key> > DecryptedKey.out
Workaround: Replace the "any" type definitions in the XML schemas with definitions of the actual elements that occur in the XML message. (The "any" type is rarely used.)
Workaround: Convert XML schema or WSDL files to ASCII before importing them.