Showing posts with label Rick Davis. Show all posts
Showing posts with label Rick Davis. Show all posts

Tuesday, December 22, 2009

NetScaler MPX vs. VPX - The finer differences

By:Rick Davis
The NetScaler VPX virtual appliance has some decisive differences from its MPX hardware counterparts. While the performance differences are well documented, some of the finer points are a bit obscure and not readily discoverable. While none of them are likely to be show stoppers, it’s important to be familiar with the limitations.

Here’s a short table I’ve assembled describing the impact of the hypervisor on the NetScaler virtual appliance as compared to the network stack of the MPX:

MPX

VPX

Native 802.1q VLAN Tagging

Tagging is defined on the hypervisor. XenServer is limited to 7 tagged networks and 16 on VMware.

Native 802.3ad Link Aggregation

802.3ad is not supported by XenServer. Source Level Balancing (SLB) NIC bonding is the closest parallel and offers NIC redundancy with great performance. But not all switches work well with SLB so be sure to test under load, plug both links into a single switch, or skip SLB entirely in favor of native NetScaler device failover.

Device Fail-over

Failover is supported between VPX devices through NetScaler's native redundancy mechanism. So there's no need for XenMotion or VMotion support with the VPX.

Dedicated SSL Chipset

No SSL chipsets are available to the VPX, but none the less, it is capable of 300 3DES and 1000 RC4 sessions. At double the VPN capacity, VPX makes a great upgrade path from Secure Gateway by providing a full SSL-VPN, Smart Access, and improved security.


Licensing Changes in VPX 9.1 Build 100.3:

For VPX appliances only, the 9.1_100.3 license software will check the MAC address of the FIRST INTERFACE listed. In previous builds, the license software checked the MAC address of the NEWEST INTERFACE. For VPX customers who upgrade to 9.1_100.3, this change will invalidate licenses on VMs which had more than one interface. They will need to revisit MyCitrix.com licensing portal to re-host their license. CTX122426 - NetScaler VPX Licensing Guide has been updated with the rehosting instructions.

VPX owners are allowed to relicense their VPX system up to 3 times.


Read more!

Monday, October 26, 2009

Wan Optimization for VDI and ICA

By:Rick Davis


Wan Optimization Controller (WOC) vendors claim the ability to enhance ICA (the Independent Computing Architecture protocol for remote application and desktop delivery) but there’s a sizable gap between what they say they can do and what they actually deliver. Here’s a view into the limitations of their support for optimizing ICA:




ICA
Prioritization


ICA
Compression


ICA
Caching


Blue Coat

Yes

Native Payload

Byte Stream

Cisco

Yes

Native Payload

Byte Stream

Citrix Repeater

Yes

Yes

Yes

Expand

Yes

Native Payload

Byte Stream

Riverbed

Yes

Native Payload

Byte Stream


Quality of Service: All vendors can prioritize ICA based on the Priority bits defined in the ICA Protocol header.


Compression: Not all ICA Compression is equal.


Citrix servers encrypt and compress ICA by default. While all vendors can compress ICA effectively, they typically can’t do it unless the server-side encryption and compression have been disabled so that the payload is in its native form. This creates challenges in mixed environments where some sites have WOC’s but others do not. Sites without a WOC are penalized twice: their traffic will not be secure and then their bandwidth utilization will increase; at the Headquarters too.

Not true for the Citrix Repeater, which dynamically negotiates the secure ICA session, for those clients that have a corresponding repeater with them at the remote site, to selectively disable server-side compression; Reducing the burden on the WAN and servers while providing confidentiality and ensuring that there are no penalties imposed on non-optimized sites.
Caching: Not all caching is equal


Byte Stream caching (a.k.a. Dictionary Compression, Network Sequence Caching, and de-duplication) operates by replacing repetitive WAN data packets with “tokens”. But because this technique is not protocol specific, it is not able to cache the ICA bitmap images being sent across the wan. And when the images have been compressed or encrypted by the server, there is even less opportunity for effective Byte Stream caching.


Here too the Citrix Repeater has the leg up on the competitors because it will recognize and parse the incoming ICA session, making itself known to the client and the server. Next, the Repeater will act as an intermediary for the encryption, enabling it to participate in the ICA conversation and begin caching at the application layer. This maintains the integrity of end-to-end encryption and enables the Repeater to cache the actual ICA bitmap images, print jobs, file transfers, and streamed media being delivered via the ICA Protocol.


Virtual Desktop Initiative:


On November 20th, 2009 Citrix will provide Repeater software version 5.5.1 which enables the ICA optimization for XenDesktop. Customers with Repeater maintenance agreements will be entitled to this software update.




Read more!

Tuesday, September 15, 2009

SMB Paradigm Shift

By: Rick Davis

It used to be that if you wanted the highest level of Web or Citrix XenApp availability you needed to spend at least $30,000; which bought you a pair of highly available Application Delivery appliances for Access Gateway (SSL VPN), Advanced Health Monitoring, self healing load management, Application Firewall, XenApp Broker and Citrix licensing awareness, improved troubleshooting, and maybe multi-link access and global load balancing. It was a steep price point for some and it dramatically separated the SMB market from the enterprise space. A digital divide of sorts: the application delivery divide.

Right now we're seeing the genesis of application delivery controlers (ADCs) for less than $10,000! And I'm not talking about sacrificing functionality to select a third rate ADC service. We're talking about all the traditional "Gartner defined" application delivery controller functionality that the Citrix NetScaler Appliances have been providing are now available in a software form factor which will empower the SMB space like we've never seen. Giving SMBs new access to the four key web and XenApp application delivery benefits: availability, performance, offload and security – all in one highly scalable, flexible and extensible system.

With the cost of entry into the ADC space being reduced by 60%, we should see a significant adoption of ADCs by the SMB market.

Check it out:

NetScaler VPX
Full NetScaler functionality in a simple virtual appliance

XenServer
Enterprise-class Server virtualization. Free.


More information on Netscaler



Read more!

Wednesday, September 2, 2009

XenApp Intra-zone IMA Communication

By:Rick Davis


Question: Does NetScalers XML Broker health monitoring and load balancing protect intra-zone IMA communication?

Protection for Web Interface


When a user launches web applications from a XenApp Web Interface (WI) server, the WI connects to a member server in order to retrieve a list of available applications and to find the least loaded server for the user to use. It uses an XML Broker query for this communication. Getting this information is critical for application launch success and if the member server has a process failure of the XML or IMA service, this communication will fail.
Since the WI can be given a list of member servers to try to reach (and it can move to other servers if no response is received) a member server process failure may result in just a delayed WI response as it tries to communication with another member server. Which could take several seconds or minutes depending on how many servers are afflicted. And in the worst cases, where just the IMA service fails, a null list of information is returned to WI and the application launch process fails completely. This is the dreaded "black hole" which is nasty because it's so hard to diagnose. Users may experience any of 3 different symptoms, most of which make administrators think they're dealing with a permissions issue.

If the “black hole” occurs on the first server (or the only server listed in the WI’s list of Brokers) the application availability will be 0.0%. This problem gets particularly nasty when it occurs on another server and results in intermittent failures which can be almost impossible to diagnose. Or when a process monitor is constantly restarting the IMA service. (out of desperation, administrators who experience this tend to resort to rebooting every server in the zone) These are the reasons we need the NetScaler; which acts as a 3rd party manager (“traffic cop”) of this communication. By using the built-in XenApp monitors, the NetScaler can detect XML and IMA process failures, alert administrators, and automatically direct the WI servers to working member servers.

Protection for the Zone Data Collector

The XenApp server which receives the WI’s request will contact the Zone Data Collector (ZDC). It does this because only the ZDC knows which member servers in the zone has the least resource utilization and can support the next application launch request. This intra-zone communication also needs to be protected, and it is, through heartbeats and scheduled events which occur on the ZDC. If a ZDC does not receive an IMA based update from a member server every 1 minute (tunable) it becomes concerned and sends a ping (IMAPing) to the member server in question. Should the ping fail, the “lost” member server will not be ping’d again for 5 minutes (tunable) and will not be included in the load distribution response sent to the XenApp server that posed the question on behalf of the WI. Likewise, the ZDC’s communication itself is protected though an election process which operates based on the same mechanism as the member server reporting.

Summary

Both the NetScaler and ZDC health monitoring are needed to achieve five nines (99.999%) uptime for XenApp delivery. With these monitors in place, XML and IMA process failures can be detected, alerted on, and automatically healed around within 60 seconds.


References: CTX103034, CTX112525, CTX11103
More Recomended Reading

More information on Netscaler



Read more!

Monday, August 17, 2009

Howto: Put XenServer ISO installer on a Bootable USB Key

By:Rick Davis
With the movement to virtual appliance versions of application delivery technologies, I find myself needing an expedient method for deploying the XenServer hypervisor. Normally I’d turn to the CD install, but I’m seeing fewer servers in the datacenter with CD ROMs. Using a USB key is an easier and more elegant approach.
A few Citrix blogs suggested I needed Ubuntu and a long list of commands to get the XenServer ISO to boot from a USB key. But I’ve found that there’s an easier way and it works from Windows; it’s called UNetbootin.

Here are the steps:
  1. Download XenServer ISO

  2. Download and run UNetbootin, Universal Netboot Installer
  3. Select the appropriate ISO and USB Drive and hit OK.
  4. Make sure your target systems BIOS is set to boot from a legacy USB device and insert the USB key.
  5. Select INSTALL when UNetbootin prompts you for an action:

You can configure the USB key to skip the Boot Menu by making the following changes:

Rename \syslinux.cfg syslinux_cfg.old
Rename \boot\isolinux syslinux
Rename \boot\syslinux\isolinux.cfg syslinux.cfg


Enjoy!

Read more!
Microsoft Virtualization, Citrix, XENServer, Storage, iscsi, Exchange, Virtual Desktops, XENDesktop, APPSense, Netscaler, Virtual Storage, VM, Unified Comminications, Cisco, Server Virtualization, Thin client, Server Based Computing, SBC, Application Delivery controllers, System Center, SCCM, SCVMM, SCOM, VMware, VSphere, Virtual Storage, Cloud Computing, Provisioning Server, Hypervisor, Client Hypervisor.