Configuring IP Addresses on NetScaler Gateway
You can configure IP addresses to log on to the configuration utility and for user connections. NetScaler Gateway is configured with a default IP address of 192.168.100.1 and subnet mask of 255.255.0.0 for management access. The default IP address is used whenever a user-configured value for the system IP (NSIP) address is absent.
- NSIP address. The management IP address for NetScaler Gateway that is used for all management-related access to the appliance. NetScaler Gateway also uses the NSIP address for authentication.
- Default gateway. The router that forwards traffic from outside the secure network to NetScaler Gateway.
- Subnet IP (SNIP) address. The IP address that represents the user device by communicating with a server on a secondary network.
The SNIP address uses ports 1024 through 64000.
How NetScaler Gateway Uses IP Addresses
NetScaler Gateway sources traffic from IP addresses based on the function that is occurring. The following list describes several functions and the way NetScaler Gateway uses IP addresses for each, as a general guideline:
Authentication. The IP address that NetScaler Gateway uses depends on the authentication server type.
- LDAP/RADIUS/TACACS servers. If AAAD directly communicates with the authentication virtual server, then NSIP address is used.
- If a load balancer is used as proxy, then the load balancer uses the SNIP address for authentication. AAAD uses the NSIP address to communicate with the load balancer. The IP address that the NetScaler uses depends on the entity that is communicating with the authentication virtual server.
- SAML/OAUTH/WEBAUTH servers: These servers communicate using the SNIP address.
- File transfers from the home page. NetScaler Gateway uses the SNIP address.
- DNS and WINS queries. NetScaler Gateway uses the SNIP address.
- Network traffic to resources in the secure network. NetScaler Gateway uses the SNIP address or IP pooling, depending on the configuration on NetScaler Gateway.
- ICA proxy setting. NetScaler Gateway uses the SNIP address.