Deploy a VPX high-availability pair with private IP address on Google Cloud Platform

You can deploy a VPX high-availability pair on GCP using private IP address. The client IP (VIP) and Server IP (SNIP) must be configured as alias IP addresses on the primary node. Upon failover, both Client IP address and Server IP address are moved to the secondary node, for the traffic to resume.

Note:

Disable the Independent Network Configuration (INC) mode to configure a high-availability pair using private IP addresses.

For more information on HA, see High Availability.

Before you start

  • Read the Limitation, Hardware requirements, Points to note mentioned in Deploy a Citrix ADC VPX instance on Google Cloud Platform. This information applies to HA deployments also.
  • Enable Cloud Resource Manager API for your GCP project.

  • Ensure your GCP service account has the following IAM permissions:

     REQUIRED_INSTANCE_IAM_PERMS = [
    
     "compute.instances.get",
    
     "compute.instances.list",
    
     "compute.instances.updateNetworkInterface",
    
     "compute.zones.list",
     ]
    
  • To use the external IP addresses, ensure your GCP service account has the following IAM permissions:

     REQUIRED_INSTANCE_IAM_PERMS = [
    
     "compute.addresses.use"
    
     "compute.instances.addAccessConfig",
    
     "compute.instances.deleteAccessConfig",
    
     "compute.instances.get",
    
     "compute.instances.list",
    
     “compute.instances.updateNetworkInterface"
    
     "compute.networks.useExternalIp",
    
     "compute.subnetworks.useExternalIp",
    
     "compute.zones.list",
    
     ]
    

How to deploy a VPX HA pair on Google Cloud Platform

Here’s a summary of the HA deployment steps:

  1. Create three VPC networks in the same region. For example, Asia-east.
  2. Create two VPX instances (primary and secondary nodes) on the same region. They can be in the same zone or different zones. For example Asia east-1a and Asia east-Ib.
  3. Configure HA settings on both instances by using the Citrix ADC GUI or ADC CLI commands.

Note:

Stayprimary and Staysecondary settings are not supported for high availability deployment on Google Cloud Platform.

Step 1. Create three VPC networks

Create three VPC networks for associating with management NIC, client NIC, and server NIC.

To create a VPC network, perform these steps:

  1. Log on the Google console > Networking > VPC network > Create VPC Network.
  2. Complete the required fields, and click Create.

For more information, see the Create VPC Networks section in Deploy a Citrix ADC VPX instance on Google Cloud Platform.

Step 2. Create two VPX instances

Create two VPX instances by following the steps given in Scenario: deploy a multi-NIC, multi-IP standalone VPX instance.

Important:

Assign a client alias IP address and server alias IP address to the primary node. Do not use the internal IP address of the VPX instance to configure the VIP or SNIP.

To create a client alias IP address, perform these steps:

  1. Navigate to the VM instance and click Edit.

  2. In the Network Interface window, edit the client interface.

  3. In the Alias IP range field, enter the client alias IP address.

Client alias IP address

To create a server alias IP address, perform these steps:

  1. Navigate to the VM instance and click Edit.

  2. In the Network Interface window, edit the server interface.

  3. In the Alias IP range field, enter the server alias IP address.

After the failover, when the old primary becomes the new secondary, the alias IP addresses move from the old primary and are attached to the new primary.

After you have configured the VPX instances, you can configure the required IP addresses. For more information, see Configuring Citrix ADC-owned IP addresses.

Step 3. Configure high availability

After you’ve created the instances on Google Cloud Platform, you can configure HA by using the Citrix ADC GUI or CLI.

Configure high availability by using the GUI

Step 1. Set up high availability in INC Disabled mode on both the instances.

  1. Log on to the primary node with user name nsroot and instance ID as password.
  2. Navigate to Configuration > System > High Availability > Nodes, and click Add.
  3. In the Remote Node IP address field, enter the private IP address of the management NIC of the secondary node.
  4. Clear the Turn on INC (Independent Network Configuration) mode on self node check box.
  5. Under Remote System Login Credential, enter the user name and password for the secondary node.
  6. Click Create.
  7. Repeat the steps in the secondary node.

Step 2. On the primary node, add client alias IP address and server alias IP address.

  1. Navigate to System > Network > IPs > IPv4s, and click Add.
  2. To create a client alias IP (VIP) address:
    1. Enter the Alias IP address and netmask configured for the client subnet in the VM instance.
    2. In the IP Type field, select Virtual IP from the drop-down menu.
    3. Click Create.
  3. To create a server alias IP (SNIP) address:
    1. Enter the Alias IP address and netmask configured for the server subnet in the VM instance.
    2. In the IP Type field, select Subnet IP from the drop-down menu.
    3. Click Create.

Step 3. Add a virtual server in the primary instance.

  1. Navigate to Configuration > Traffic Management > Load Balancing > Virtual Servers > Add.

Save the configuration. Now, the secondary node has the same log-on credentials as the primary node. After a forced failover, the secondary becomes the new primary. The client alias IP (VIP) and the server alias IP (SNIP) from the old primary moves to the new primary.

Configure high availability by using the CLI

Step 1. Set up high availability in INC Disabled mode in both the instances by using the Citrix ADC CLI.

On the primary node, type the following command.

add ha node 1 <sec_ip> -inc DISABLED in primary

On the secondary node, type the following command.


add ha node 1 <prim_ip> -inc DISABLED in secondary

The sec_ip refers to the private IP address of the management NIC of the secondary node.

The prim_ip refers to the private IP address of the management NIC of the primary node.

Step 2. Add VIP and SNIP on the primary node.

Type the following commands on primary node:

add ns ip <primary_client_alias_ip> <subnet> -type VIP

Note:

Enter the Alias IP address and netmask configured for the client subnet in the VM instance.

add ns ip <primary_server_alias_ip> <subnet> -type SNIP

Note:

Enter the Alias IP address and netmask configured for the server subnet in the VM instance.

Step 3. Add a virtual server on the primary node.

Type the following command:

add <server_type> vserver <vserver_name> <protocol> <primary_client_alias_ip> <port>

Step 4. Add a SNIP on the secondary node.

Type the following command on the secondary node:

add ns ip <primary_server_alias_ip> <subnet> -type SNIP

Note:

To save your configuration, type the command save config. Otherwise, the configurations are lost after you restart the instances.

Deploy a VPX high-availability pair with private IP address on Google Cloud Platform