Release Notes for Build 52.15 of NetScaler MAS 11.1 Release

Updated: March 17, 2017 | Release notes version: 1.0
This release notes document describes the enhancements and changes, lists the issues that are fixed, and specifies the issues that exist, for the NetScaler MAS release 11.1 Build 52.15. See Release history.
Notes:
Additional Fixes Available in 52.15 compared to 52.13
Version 1.0
What's New?
The enhancements and changes that are available in Build 52.15.
StyleBooks
  • New StyleBooks to deploy Microsoft Exchange and Skype for Business Applications in Enterprise Networks
    NetScaler MAS now provides StyleBooks with which you can deploy the NetScaler configuration of Skype for Business and Microsoft Exchange 2016. These StyleBooks are part of the StyleBook catalog available in the NetScaler MAS user interface.
    [# 638613, 665509]
Fixed Issues
The issues that are addressed in Build 52.15.
Analytics
  • When afdecoder process crashes, NetScaler MAS analytics does not display any reports.
    [# 669966]
  • When Web Insight exports PDF reports for Response, Requests, and Domains, incorrect information is exported.
    [# 670939]
  • The export feature does not work for all the screens in Security Insight under Analytics.
    [# 667544]
  • For NetScaler Insight Center in scale-out deployment, after running for few days, NetScaler Insight Center stops injecting AppFlow traffic into database.
    [# 658971, 646821]
  • In NetScaler Insight center, inventory login to Netscaler instance fails for non-nsroot users.
    [# 670490]
  • When afanalytics process crashes, NetScaler MAS analytics only displays reports for upto an hour.
    [# 667405]
  • NetScaler Insight Center reports might present inconsistent data, depending on the start time and end time inputs for a selected report duration.
    [# 640444]
  • If a failover happens on a NetScaler HA Pair, NetScaler MAS stops collecting the AppFlow data from the secondary NetScaler instance.
    [# 668760]
  • In Security Insight, exported reports don't show the selected duration when exported in pdf, jpeg, or png format.
    [# 670341]
High Availability
  • The NetScaler MAS upgrade process might fail if permissions in the database directory are incorrect.
    [# 676977]
  • When NetScaler instances in a high availability setup are added to NetScaler MAS, NetScaler MAS displays duplicate certificates for these instances, because certificate polling is performed on both the primary and secondary NetScaler instances.
    [# 668709, 657647, 657853]
  • The default community string 'public' is used in the newly added trap destination in the devices when a NetScaler MAS node managing those instances fails over in a NetScaler MAS HA setup even though the SNMP community string in the device profile of those devices is not 'public'.
    [# 675486]
  • In a NetScaler MAS high availability setup, when you make changes to the system settings on one node (System > System Administration > System Settings ), you must confirm the changed system settings on the secondary node by clicking OK, even if the GUI shows that the system settings have been applied.
    [# 669460]
  • In a NetScaler MAS high availability setup, the Analytics configuration does not work.
    [# 642270, 644542]
  • In a NetScaler MAS high availability setup, instance backup files might not get cleared. Such files can accumulate, along with NetScaler MAS backup files. This issue occurs if failure of an SSH channel that does not use a password causes a FileSync failure between the nodes of the HA setup.
    [# 672743]
  • Scheduled and manual backups of NetScaler SDX instances are unsuccessful when they are initiated on NetScaler MAS in high availability mode.
    [# 664945]
  • After prolonged use of NetScaler MAS, you are intermittently unable to change the configuration of one of the nodes of the NetScaler MAS high availability (HA) pair.
    [# 670818]
  • Unwanted logs related to a pgxl user might appear in the service logs file (mps_service.log) and the /var/log/messages file.
    [# 672727]
Infrastructure
  • Event reports might not be accurately displayed if you log on to NetScaler MAS with other than the default credentials (nsroot and nsroot).
    [# 667581]
  • Entity polling in NetScaler MAS stops because of database issues.
    [# 666954]
  • Database logs are not purged periodically since the system disk gets full.
    [# 664320]
  • Any NetScaler MAS user can access a NetScaler VPX instance with full administrator privileges by clicking on the instance's IP address, because of the NetScaler profile attached to the instance.
    [# 675787]
  • NetScaler MAS responds slowly or fails to respond to input from the GUI when the NetScaler MAS server's database contains a large number of events.
    [# 670789]
  • In a NetScaler instance's GUI, the dashboard labels the server-health data as "LB virtual servers Health," and the presentation of the data is confusing. With this fix, the label is changed to "LB Virtual Server Health," and the health distribution is shown as 0%, 25 to 50%, 50 to 75%, 50 to 75% and More than 75%).
    [# 670822, 669805]
  • The NetScaler MAS dashboard displays graphs of the top five system-selected licensed virtual servers instead of the top five user-selected licensed virtual servers.
    [# 670885]
  • NetScaler MAS displays a blank screen when you click the Infrastructure tab.
    [# 676504]
  • You cannot search for admin partitions by name on NetScaler VPX instances. You must search by IP address. With this fix, you can use the Host Name filter to search for admin partitions.
    [# 670570]
  • When a failover occurs for a NetScaler instance in a high availability setup, the NetScaler MAS GUI does not show which entities were enabled and which were disabled before the failover.
    [# 664067]
  • When you search for a virtual server (Applications > Load Balancing > Virtual Servers) by using your NetScaler MAS server's IP address, the Search button is not visible after the first time you use it. To be able to see the Search button repeatedly, you have to access NetScaler MAS through its DNS alias.
    [# 665622]
  • Event messages are not sorted accurately by date when you click the Date tab on the Events Messages page.
    [# 670593, 673703]
  • In a NetScaler MAS high availability setup, certificates are not displayed accurately when certificate polling is enabled.
    [# 666955]
  • NetScaler MAS crashes multiple times after a fresh install or if the NetScaler MAS server is upgraded.
    [# 668556, 668621, 671047]
  • During each polling cycle, the identities of virtual IP addresses and services change. As a result, users are unable to use NITRO APIs to perform operations on NetScaler MAS.
    [# 667409]
  • API calls for servicegroup bindings on NetScaler MAS do not apply Role Based Access (RBA) accurately for service group members.
    [# 667783]
  • The NetScaler MAS API exposes user information and allows users to access NetScaler instances that are not assigned to their groups. For example, if user1 of group1 provides the IP address of a NetScaler instance that belongs to user2 of group2, user1 of group1 is able to see the running configuration of that instance.
    [# 670963]
  • The NetScaler MAS GUI does not display entities (virtual servers or service groups) for which a comment contains a new-line character (\n).
    [# 674383, 674607]
  • On the Licensing page of NetScaler MAS, host identities for a few NetScaler instances are displayed as "Unknown."
    [# 669472]
  • When you click the Learn More button while searching for an instance on the Infrastructure tab of NetScaler MAS, a "Page not found" error message appears. This typically occurs after you upgrade your NetScaler MAS version to 11.1 build 49.16.
    [# 664965]
  • During discovery, the NetScaler MAS GUI does not show all the partitions hosted on NetScaler VPX instances that are running on a NetScaler SDX appliance. This causes the value shown for the number of partitions to fluctuate.
    [# 678382, 678633]
  • If a NetScaler device discovered by using NAT IP address becomes unreachable, subsequent discovery uses NSIP addresses instead of NAT IP addresses.
    [# 674466]
  • When the schedule for an event rule is deleted, NetScaler MAS stops sending email notifications.
    [# 672180]
  • If you specify the SFTP protocol when you attempt to use a backup file to transfer a configuration from one NetScaler MAS server to another, the process fails.
    [# 677285, 678116]
  • Database connection issues prevent NetScaler MAS reports from showing any data.
    [# 658589, 667592]
  • The ns_servicegroupmember_binding resource is missing from the enable and disable functions in the NetScaler MAS server's SDKs.
    [# 670876]
  • Externally authenticated users with admin privileges are unable to see all generated events and services on NetScaler MAS.
    [# 672715]
  • Export to PDF/JPEG/PNG/CSV does not work for external authentication of an LDAP or RADIUS) user.
    [# 671379]
  • The Events page takes a long time to load when NetScaler MAS receives a large number of SNMP traps.
    [# 671417]
Licensing
  • NetScaler MAS randomly selects the virtual servers to monitor on the basis of your license. For example, if you have a license for 130 virtual servers, NetScaler MAS randomly selects 130 virtual servers to monitor. If you want to monitor a smaller number of virtual servers, you can deselect the virtual servers you do not want to monitor. These virtual servers become unlicensed, freeing up that number of licenses. However, the next time that NetScaler MAS polls, the unlicensed virtual servers are randomly added for monitoring, which uses up the available licenses.
    [# 658385, 671869]
Orchestration
  • NetScaler MAS supports the editing of stack for StyleBook resources performed on OpenStack.
    [# 666952]
StyleBooks
  • In the "Sample Application StyleBook using CS, LB and SSL features" (sample-cs-app) StyleBook, the name of the application is hard coded. Therefore, you can create only one application configuration (config pack) from this StyleBook on the same target device. If you try to create a second configuration from this StyleBook, an error message states that the resource already exists.
    [# 665099]
System
  • NetScaler MAS restarts as soon as you apply the required Cipher group and click "OK," instead of waiting until you click "Done." In addition to waiting, NetScaler MAS should display a confirmation pop-up message, but it does not.
    [# 660805]
  • Even if the email notification option is disabled when system-related functions are configured, the NetScaler MAS server sends emails.
    [# 665567]
  • Ability to Create New Group with Admin Level Privileges
    NetScaler MAS allows you to create a new group of externally authenticated users who have admin (nsroot) privileges and can therefore perform all system level operations in NetScaler MAS.
    Navigate to System > User Administration > Groups. Under Groups, add a new group and assign permissions to the group. To enable admin privileges for all users in this group, select the Admin role checkbox.
    You can also authorize the group to configure session timeouts, assign other users to the group, and grant access to specific or all instances managed by NetScaler MAS.
    Note: To view and assign admin level privileges to a new group, you must be signed in with your administrator credentials.
    [# 665978, 673497, 673406]
  • After migrating from NetScaler Insight Center to NetScaler MAS, you cannot log on to NetScaler MAS by using the administrator credentials.
    [# 665410]
  • Only the following categories are applicable to NetScaler MAS for system notification settings:
    - HealthMonitoring
    - InvalidPolicy
    - PasswordRecovery
    - PolicyFailed
    - StatusPoll
    - SubSystemState
    - SystemReboot
    - SystemState
    - UserLogin
    - UserLogout
    - VIPLicenses
    The rest of the Event categories are not available in a NetScaler MAS deployment.
    [# 668859]
Known Issues
The issues that exist in Build 52.15.
Analytics
  • In Security Insight, Safety Index filters display incorrect output.
    [# 640160]
  • The NetScaler MAS GUI does not display the threshold name when you click Breach Count in Security Insight.
    [# 671407]
  • A read-only user cannot export reports from NetSclaer MAS. Read-write permission is required for exporting reports in PDF, JPEG, or PNG format.
    [# 653878]
  • The time interval for which data is displayed on the dashboard might not match the selected time interval. If no data is available for part of the selected time interval, NetScaler MAS shows data from the date on which it started receiving the AppFlow data.
    [# 601474]
  • If client side measurement is enabled, Web Insight data collection might fail, in which case the corresponding reports are not displayed.
    [# 659569]
  • In Security insight, the search-option drop-down list for Application Summary does not include all the filters.
    [# 630031]
  • In Security Insight, on the Application Summary page, IP reputation is not displayed in the Violation Category drop-down list.
    [# 643629]
  • In SSL analytics, if the SSL key strength value is not available, it is displayed as 0.
    [# 676686]
High Availability
  • If, while the primary node of a NetScaler MAS high availability pair is down or being restarted, you change the configuration of the secondary node, such as by adding an external authentication server, syslog server, or NTP server, the changes might not sync to primary node after it returns to service.
    [# 671127]
  • After rediscovery, a NetScaler MAS high availability (HA) setup displays the status of a discovered NetScaler instance as Out of Service if the instance has more than 20 admin partitions.
    [# 676010]
  • In a HA to HA restore or a HA to standalone restore, Syslog and AppFlow settings will not be restored . Also, restoring from HA to HA has issues as device ownerships changes, and device migration will not happen correctly after a node failure.
    [# 676887]
  • In a NetScaler MAS high availability setup, when you back up and restore the system, the instance backup settings (System > System Administration > Instance Backup Settings) do not get backed up and restored to the values that were set before the backup.
    [# 661049]
  • After a NetScaler MAS HA pair is upgraded, random virtual servers are added to the group of virtual servers being managed.
    Workaround: Navigate to Infrastructure > Licenses > System Licenses > Modify licensed Virtual Servers, and select the virtual servers that were managed before the upgrade.
    [# 675819]
  • If NetScaler MAS is in high availability mode and the timeout is set to more than 24 hours, an inappropriate error message appears.
    [# 675505]
  • In a NetScaler MAS high availability setup, if a user is connected to NetScaler MAS through the Load balancing VIP address, the session details are not displayed on the NetScaler MAS GUI.
    [# 675971]
Infrastructure
  • If you use a Mac computer to copy commands and paste them into a configuration-job window in a formatted font, the commands are displayed as a single line instead of in the intended format, causing the job to fail.
    [# 676421]
  • When NetScaler MAS triggers a backup on a NetScaler instance, the backup file is not deleted on the NetScaler instance after the file is downloaded to NetScaler MAS.
    [# 676894]
  • The table on the Events Summary page is not sorted correctly.
    [# 665570]
  • If, while creating a Certificate Signing Request (CSR), you choose the "I don't have a key" option and select either DES or DES3 as the PEM Encoding Algorithm, the following error message appears: "Failed to generate CSR"
    [# 676854, 677968]
  • The Upgrade NetScaler maintenance task does not successfully upgrade NetScaler appliances in high availability (HA) configurations.
    [# 648786]
  • When you poll an individual NetScaler instance in NetScaler MAS, all other instances that have been added to NetScaler MAS are also polled.
    [# 676576]
  • After NetScaler MAS is restarted multiple times, no data is generated for the one-week event report.
    [# 676876]
  • By default, NetScaler MAS generates performance reports once every five minutes. When NetScaler MAS is managing a large number of entities, the polling cycle takes a longer time to generate the report that might result in a blank screen or the system might still display earlier data.
    [# 677698]
  • The NetScaler configuration file (ns.conf) gets corrupted if you upload a template (a configured ns.conf file) that is not in UNIX format.
    [# 673451]
  • NetScaler MAS does not display syslog Warning messages for the Application Firewall and Responder modules of all instances managed by NetScaler MAS.
    [# 676719]
  • After a failover occurs on a NetScaler instance in a high availability setup, data is not visible in the NetWork Interfaces table on that instance's dashboard in NetScaler MAS.
    [# 671368]
  • When a NetScaler VPX instance hosted on a NetScaler SDX appliance is restored from a NetScaler MAS backup file, other instances, monitored by NetScaler MAS but owned by other SDX appliances, are also restored.
    [# 669793]
  • When you click the Host Name tab of the Event Messages screen, all events-related information disappears from the screen.
    [# 676068]
  • When you click Repackage Backup and enter a wrong password for a NetScaler SDX backup file on NetScaler MAS, no error message is displayed.
    [# 670546]
  • By default, the duration of a NetScaler MAS logon session is set to 15 minutes. Therefore, the session times out before a task that takes more than 15 minutes, such as adding a large number of instances, can be completed.
    [# 641274]
  • If you copy commands and paste them into a configuration-job window in a formatted font, such as Comic Sans, execution of the commands fails.
    [# 676422]
  • When configuration advice is applied to a NetScaler cluster node, the following error message appears:
    "Cannot read property 'toLowerCase' of undefined"
    [# 670508]
  • When you use SDK on NetScaler MAS to create a configuration job, the following error message appears:
    !! File "build/bdist.linux-x86_64/egg/massrc/com/citrix/mas/nitro/resource/config/mps/config_job.py", line 733, in add
    raise e
    !! AttributeError: 'dict' object has no attribute '__dict__'
    [# 671506]
  • While creating a Certificate Signing Request (CSR) and uploading the key in DER format locally, NetScaler MAS displays the key format as PEM and does not generate a CSR.
    [# 675875]
  • Clicking on the Date tab of Event Reports does not sort the events by date. The data in the reports is still sorted randomly.
    [# 676843]
Licensing
  • A forced failover might cause the licensed virtual servers on a NetScaler instance to become unlicensed.
    [# 676380]
Orchestration
  • During orchestration, if you perform a "Cleanup" operation for requests on which rollback failed, the following error message appears: "Rollback is not allowed for successfully completed requests".
    Workaround: Refresh the page.
    [# 601294]
  • NetScaler MAS does not support shared service packages created to allot multiple instances to tenants for OpenStack Heat integration.
    [# 664070]
  • During orchestration, when a NetScaler instance is unassigned from a service package, the interfaces configured for the instance are lost.
    Workaround: The interfaces should be reconfigured if the same NetScaler instance is to be assigned to another service package.
    [# 620635]
  • If you update the nsroot user password on a NetScaler instance to a value of more than 15 characters, you can use the updated credentials to log on to the instance and add it to NetScaler MAS. However, during orchestration, NetScaler MAS is not able to add the instance to the service package.
    Workaround: Shorten the password to a length of no more than 15 characters.
    [# 675104]
System
  • NetScaler MAS becomes unresponsive when a failure object is deleted.
    [# 675602]
  • The sessions of an externally authorized user do not time out.
    [# 675475]
  • User lockout information is not synchronized between NetScaler MAS servers in high availability mode. Users locked out by one NetScaler MAS server might be allowed to log on by the other NetScaler MAS server.
    [# 675606]
  • You cannot upload SSL certificates with extension .CER in NetScaler MAS.
    [# 671258, 675625]
What's New in Previous NetScaler MAS 11.1 Releases
The enhancements and changes that were available in NetScaler MAS 11.1 releases prior to Build 52.15. The build number provided below the issue description indicates the build in which this enhancement or change was provided.
Analytics
  • Comparing Graphs in NetScaler MAS Analytics
    You can now combine any two graphs in NetScaler MAS Analytics (Insight) to view and compare the selected parameters.
    [From Build 49.16] [# 617967, 593755]
  • Support to Integrate NetScaler MAS with Citrix Director
    NetScaler MAS is now integrated with Citrix Director. This enables Director to display HDX Insight reports from NetScaler MAS in the Network and the User details page and provides has user, applications, desktops, instances and license specific information. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-drector.html.
    [From Build 49.16] [# 647135]
  • Support to Migrate NetScaler Insight Center to NetScaler MAS
    You can now migrate your NetScaler Insight Center deployment to NetScaler MAS without losing the existing configuration, settings, or data in NetScaler Insight Center. With NetScaler MAS you can not only view the various analytics data generated by the NetScaler instances associated to an application, but you can also manage, monitor, and troubleshoot the entire global application delivery infrastructure from a single, unified console. Note that you can only migrate a standalone NetScaler Insight Center deployment to a standalone NetScaler MAS deployment. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/migrating-netscaler-insight-center-to-mas.html
    [From Build 49.16] [# 632967, 649903]
  • X-Forwarded-For HTTP Header Support for Security Insight Reports
    The X-Forwarded-For HTTP header field is a common method for identifying the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer. NetScaler MAS uses X-Forwarded-For HTTP header to obtain the following details:
    - The address of the client which connected to the proxy.
    - The content of the host header the client sent to the proxy.
    Currently X-Forwarded-For support is available only for Web Insight and Security Insight.
    Note: You can only enable or disable the X-Forwarded-For feature using the NetScaler appliance's CLI.
    To enable this feature, at the command prompt, type: "set appflow param httpXForwardedFor ENABLED".
    [From Build 49.16] [# 636390]
  • Ability to Export Reports in Security Insight
    From NetScaler MAS, you can now save the Security Insight reports with all the details shown in the GUI in PDF, JPEG, PNG, or CSV format on your local computer. You can also schedule the export of the reports to specified email addresses at various intervals. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [From Build 51.26] [# 636398]
  • Ability to Set Thresholds and Monitor Breaches in Security Insight
    You can now set thresholds for the safety-index and threat-index and monitor breaches of the thresholds.
    To set a threshold
    1. Navigate to System > Analytics Settings > Thresholds, and select Add.
    2. Select the traffic type as Security in the Traffic Type field, and enter required information in the other appropriate fields, such as Name, Duration, and Entity.
    3. In the Rule section, use the Metric, Comparator, and Value fields to set a threshold.
    For example, "Threat Index" ">" "5"
    4. Click Create.
    To view the threshold breaches, navigate to Analytics > Security Insight > Devices, and
    select the NetScaler instance. On the screen that appears, in the Application section, the Threshold Breach column shows the number of threshold breaches that occurred for each virtual server. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [From Build 51.26] [# 636397]
  • Ability to Search for Virtual Servers while Configuring Insight
    If you have a large number of virtual servers configured on a NetScaler instance, while enabling or disabling insight it might be difficult to locate a specific virtual server. You can now search for a virtual server in the application list of a NetScaler instance in NetScaler MAS.
    To search for a virtual server
    1. Navigate to Infrastructure > Instances, and select the NetScaler instance you want to enable AppFlow.
    2. From the Action drop-down, select Enable/Disable AppFlow.
    3. In the Application List section, select the type of Virtual server.
    4. Click Search, and specify the name of the virtual server. Click Refine Search.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/analytics-how-to-articles/how-to-enable-analytics-on-instances.html
    [From Build 51.26] [# 651885]
  • View Authorization Policy Failures in Gateway Insight
    You can now view authorization errors that occurred after the authentication process. The authorization process determines whether the user has the authority to access certain features, or make changes in the application. For example, if users are restricted to using only few modules of the application, accessing other modules results in authorization errors. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [From Build 51.26] [# 578024]
  • Ability to Display HA Failover Time Information in NetScaler MAS Analytics
    When NetScaler HA failover happens and a reconnect occurs by using session reliability, NetScaler MAS displays the count of the HA failover per ICA session. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/HDX-Insight.html
    [From Build 51.26] [# 644975]
  • Ability to View Graphs on Attacks on the Security Insight Dashboard
    On the security insight dashboard, you can now view graphs depicting total attacks on an instance.
    To view these graphs
    1. Navigate to Analytics > Security Insight > Devices, and select the NetScaler instance.
    2. In the Application section, click the arrow button next to the Total Attacks summary bar.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [From Build 51.26] [# 636392]
  • Ability to View Additional User Metrics in HDX Insight
    HDX Insight now displays additional user metrics, such as WAN jitter and Server Side Retransmits. To view these metrics, navigate to Analytics > HDX Insight > Users, and select a user name. The user metrics appear in the table next to the graph. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/HDX-Insight.html
    [From Build 51.26] [# 659103]
  • TCP Insight
    The TCP Insight feature of the NetScaler Management and Analytics System (NetScaler MAS) provides an easy and scalable solution for monitoring the metrics of the optimization techniques and congestion control strategies (algorithms) used in NetScaler ADCs to avoid network congestion in data transmission.
    By observing the key Transport Layer metrics, such as Data Volume, Throughput, and Speed, you can measure the traffic volume served by the ADC and evaluate the effectiveness of the TCP optimization. In the display, the metrics are broken down by stream Direction (from client to NetScaler and NetScaler to origin server), TCP Port, and Virtual LAN. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/tcp-insight.html
    [From Build 51.26] [# 654077]
  • Ability to view the details of failed EPA expressions in Gateway Insight
    The details of failed EPA expressions now appear in a table under the dashboard graph when you navigate to Analytics > Gateway Insight. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [From Build 51.26] [# 606882]
  • Export Reports in Gateway Insight
    From NetScaler MAS, you can now save the Gateway Insight reports with all the details shown in the GUI in PDF, JPEG, PNG, or CSV format on your local computer. You can also schedule the export of the reports to specified email addresses at various intervals. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [From Build 51.26] [# 631820]
  • SSL Insight
    SSL Insight provides integrated, real-time monitoring of secure web transactions (HTTPS) for all the secure web applications being served by the NetScaler ADC. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/ssl-insight.html
    [From Build 51.26] [# 660016]
  • View start and end time of a terminated user sessions in Gateway Insight
    The start time and end time of a terminated user sessions in Gateway Insight are now shown in a session-details graph at Analytics > Gateway Insight > Users. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [From Build 51.26] [# 649009]
AppFlow
  • If a NetScaler high-availability failover occurs when ICA AppFlow is enabled, the session reliability feature will now restore the session. This capability is currently disabled by default and configurable via CLI. The CLI command to enable/disable the feature is
    set ica parameter EnableSRonHAFailover YES/NO
    [From Build 49.16] [# 456218, 438710, 547601, 620411]
Application Management
  • Using Regular Expressions to Configure Load Balancing Virtual Servers in NetScaler MAS
    When defining an application from Applications > Dashboard > Applications > New Application, you can now use regular expressions to select multiple virtual servers. For example, the owa|lync expression selects all virtual servers that contain "owa" or "lync" in their names.
    [From Build 49.16] [# 657447]
  • Editing the name of the application
    When you create an application (Applications > Dashboard > Applications), earlier there was no option to edit the name of the application. With this fix, you can edit the name of the application at any later time.
    [From Build 49.16] [# 644896]
  • Configuring Load Balancing Virtual Servers From the Application Dashboard
    You can configure load balancing virtual servers and bind or unbind services and service groups from the Application Dashboard screen of the NetScaler MAS. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/load-balancing-support-through-application-dashboard.html.
    [From Build 49.16] [# 653169]
  • NetScaler MAS Application Dashboard Enhancements
    The following enhancements have been made to the Application Dashboard:
    1. Each application now displays the number of bound services, service groups, and servers.
    2. You can now click on the one-line displays in each application to enable or disable the bound services, service groups, and servers.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [From Build 51.26] [# 658524]
  • Ability to Display all Services and Service Groups for Each Application Group
    On the Application Dashboard page, for each application, NetScaler MAS now displays all the services and service groups associated with the NetScaler instances that belong to that application. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [From Build 51.26] [# 657552]
  • Ability to Select NetScaler Gateway Virtual Server during Application Definition
    You can now select the NetScaler Gateway virtual server while defining an application. NetScaler MAS supports the following types of virtual servers:
    - Load balancing virtual servers
    - Content switching virtual servers
    - GSLB virtual servers
    - NetScaler Gateway virtual servers
    - Cache redirection virtual servers
    - Authentication virtual servers
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [From Build 51.26] [# 654175]
  • Ability to View Bound Entities when Multiple Objects are Selected in NetScaler MAS
    NetScaler MAS now provides the option to select multiple virtual servers, services, or service groups. You can see bound services and service groups, virtual servers, or services for all multiple objects that you have selected. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [From Build 51.26] [# 658287]
Infrastructure
  • Reusing Completed Configuration Jobs on NetScaler MAS
    You can now modify the commands, parameters, configuration settings, and instances in a completed or a scheduled job and execute the job again. This is useful when you want to execute the same set of commands on a different instance or when the job encounters an error and stops further execution. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-jobs-replicate-configuration.html.
    [From Build 49.16] [# 637401]
  • Wildcard Character Support for Failure Objects
    You can now use the wildcard character search for failure objects to apply to a rule. You can use * as a wildcard character in the Add field above the Failure Objects parameter in the Create Rule page, to search for similar failure objects that can be applied to the rule. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-set-multiple-event-rules-notifications-mas.html.
    [From Build 49.16] [# 653144]
  • Unrecognized Failovers in NetScaler MAS
    Earlier when failover occurred on NetScaler instances in a high availability mode, NetScaler MAS was unable to detect the state change until the next polling by the system. Now, when failover occurs on NetScaler instances in a high availability mode, NetScaler MAS updates the primary or secondary node's state based on SNMP traps received by NetScaler MAS when the instance state changes.
    [From Build 49.16] [# 657297]
  • Email Notification Support to Send Configuration Audit Notifications for Saved v/s Running Config Differences
    You can now configure NetScaler MAS to send email notifications every time the saved configuration is different from the running configuration on managed NetScaler instances. A configuration might get changed when you manually poll your instances, or if you have scheduled a configuration to be run at a particular polling interval. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/nmas-audit-configuration-instance.html
    [From Build 49.16] [# 653168]
  • Support to View Host Names with IP Addresses of NetScaler Instances
    You can now view the host name along with the IP address of your NetScaler instance across all tables and graphs in NetScaler MAS. Previously, only the IP address was displayed, making it difficult to keep track of thousands of instances. By assigning host names, you can now identify instances more easily.
    [From Build 49.16] [# 649667]
  • View Instance User Information in Execution Logs
    Execution logs are generated when you create and execute a job that contains the NetScaler user (Instance User) whose credentials were used to perform the action. Previously, only the MAS user’s name was displayed in the execution log. In some cases, both the MAS user and the NetScaler user had the same system credentials, nsroot/ nsroot. In this situation, should your NetScaler profile be changed, you can rediscover the instance with its new user credentials and execute the job again. You can then see the new instance user credentials in the execution summary.
    To view execution logs with system and instance name, navigate to Infrastructure > Configuration Jobs. Select a job and click Details. Click Execution Summary to see the status of the instance on that executed the job and the instance user's name. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-job.html
    [From Build 49.16] [# 653167]
  • Support to Send Email Notifications when Jobs are Executed
    Email notifications can now be sent every time a job is executed or scheduled. The notifications provide information such as the success or failure of the job, and include relevant details. If you have created a job in NetScaler MAS to perform specific configuration changes on a NetScaler appliance, and you want to know if the scheduled task has succeeded or failed, you previously had to log back on to NetScaler MAS and check the execution logs. You can now direct NetScaler MAS to send an email reporting on the success or failure of the task. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-job.html
    [From Build 49.16] [# 652828]
  • Ability to View Events Summary
    You can now view and monitor the events and traps received on your NetScaler MAS server. The Events Summary page displays the following information in a tabular format:
    - Summary of all the events received by NetScaler MAS. The events are listed by category, and the different severities are displayed in separate columns: Critical, Major, Minor, Warning, Clear, and Information.
    - Number of events received for each category. Clicking on the event displays the Events page, on which filters such as the Category and Severity are preselected, and which displays more information about the event, such as the NetScaler instance, host name, date when the event was received, category, and the message notification received.For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-view-events-summary-in-mas.html
    [From Build 51.26] [# 653877]
  • Ability to Monitor SSL Protocols Enabled with Enterprise Policy on the NetScaler MAS SSL Dashboard
    The NetScaler MAS SSL Dashboard now shows the distribution of SSL protocols that are running on your virtual servers. As an administrator, you can specify the protocols that you want to monitor through the SSL policy. The protocols supported are SSLv2, SSLv3, TLS1.0, TLS1.1, and TLS1.2. The SSL protocols used on virtual servers appear in a bar chart format. Clicking on a specific protocol displays a list of virtual servers using that protocol.
    A donut chart appears after Diffie-Hellman (DH) or Ephermeral RSA keys are enabled or disabled on the SSL dashboard. These keys enable secure communication with export clients even if the server certificate does not support export clients, as in the case of a 1024-bit certificate. Clicking on the appropriate chart displays a list of the virtual servers on which DH or Ephemeral RSA keys are enabled.
    [From Build 51.26] [# 653408]
  • Ability to Preview a New Job Before Execution
    You can now evaluate and verify the commands to be run on each instance or instance group before you run a job. Previously, the information you would need was available only in the execution logs, which are not available until the job is executed. NetScaler MAS now has a Job Preview feature, which is available when you configure a job.
    [From Build 51.26] [# 654179]
  • Ability to Define Global, Group, or Instance Level Variables
    You can now make edits to the global, group, and instance level variable values in the Input Key File while creating a job. Global variables are variable values that will be applied across all instances and instance groups in the event that those values are not provided. Group and instance level variable values are applied to all instances that are defined as variables in the job. In the file that is downloaded, you can provide variable values at instance level, instance group level, and global level. After downloading input key file, you can upload it to the NetScaler MAS server, and then execute the job with your customized variable values.
    [From Build 51.26] [# 654178]
  • Ability to Create Configuration Jobs with Corrective Commands
    You can create audit templates with specific configurations that you want running on certain instances. NetScaler MAS compares these instances with the audit template and reports any mismatch in configuration. You can now correct the configuration commands being run on your NetScaler instance if there is a change in the configuration, to ensure optimal performance of your network. Using NetScaler MAS’s corrective commands feature, you can create an audit template with the modified and corrected configuration commands on specific NetScaler instances.
    When there is a difference between an instance's running and saved configurations, a Diff Exists status message appears on the Audit Report page. Clicking the Diff Exits link takes you to Configuration Diff page, where you can view the corrective command and create a job to run on that specific instance. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-jobs-from-corrective-commands-mas.html
    [From Build 51.26] [# 654180]
  • Ability to Replicate Configuration Command from One NetScaler Instance to Another
    You can now replicate a NetScaler instance’s configuration on other instances. When you configure a job in NetScaler MAS, select an instance as the Configuration Source and choose the selected instance’s running or saved configuration. For example, when you select Running Configuration and click Extract, NetScaler MAS sends a request to the selected NetScaler instance to locate the running configuration, and displays it as a template. You can drag and drop the template into the Commands field in the right-hand pane. You can modify commands, parameters, and the instances. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-replicate-configuration-commands-from-one-netscaler-to-another-mas.html
    [From Build 51.26] [# 654075]
  • Ability to Select Specific Event Severity on Infrastructure Dashboard
    On the Infrastructure Dashboard, you can now mask severity levels to more clearly display an event that you are interested in. To mask the levels that you don't want to appear on the severity graph, click them.
    For example, events of Critical severity level might occur rarely. However, when these critical events do occur on your network, you might want to further investigate them to troubleshoot and monitor where and when the event occurred. If you select all severity levels except Critical, the events severity graph shows only the critical events. You can then click the graph to go to a page that shows all the details of when a critical event occurred during the duration that you’ve selected, including the instance source, the date, category, and message notification sent when the critical event occurred. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-display-event-severities-and-skews-of-SNM-traps-infrastructure-dashboard-mas.html.
    [From Build 51.26] [# 654059]
  • Ability to Represent Skews of SNMP Traps on Infrastructure Dashboard
    On the Infrastructure dashboard, you can now mask irrelevant values so that you can more easily view and monitor information such as health, up time, models, and version of NetScaler instances in minute detail.
    For example, when you view the health of a NetScaler VPX instance on the Infrastructure dashboard, you can mask all the times during which the instance was up and running, and view only the times the instance was 'out of service.' For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-display-event-severities-and-skews-of-SNM-traps-infrastructure-dashboard-mas.html
    [From Build 51.26] [# 654060]
  • Support for Monitoring HAProxy Instances
    You can now use NetScaler MAS to monitor HAProxy instances in your deployment. To do so, navigate to Infrastructure > Instances > HAProxy.
    You can also navigate to Applications > Dashboard > HAProxy to view the servers, frontend, and backend configured on the HAProxy instances.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/monitoring-haproxy-instances.html.
    [From Build 51.26] [# 638608]
  • Ability to Support '$' Symbol as a Variable while Performing the Copy-Paste Operation on the Create Job Commands Pane
    A value enclosed in dollar sign ($) symbols is automatically assumed to be a variable when it is copied to the Commands field while configuring a job. Previously, administrators had to select the value they wanted to convert to a variable, and then click "Convert to Variable." This is particularly useful when you are copying large sets of configuration commands with multiple variables.
    Note: You still have to define the variable.
    [From Build 51.26] [# 654177]
  • Ability to Select a Previously Saved Configuration Template to Create an Audit Template
    In audit templates, you can now use configuration commands that were previously saved in configuration templates. While creating an audit template, you can drag and drop previously saved configuration templates into the Commands field, and edit the template to suit your requirements. You can also select specific instances on which to run these newly selected audit commands. NetScaler MAS compares these instances with the audit template and reports any mismatch. This helps you identify errors and rectify them in a timely manner.
    You can create configuration templates while creating a new job and saving a set of configuration commands as a template. When you save these templates on the Create Jobs page, they are automatically displayed on the Create Template page. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-use-configuration-templates-to-create-audit-templates-on-mas.html.
    [From Build 51.26] [# 487693]
Licensing
  • Expiry Check Support for Virtual Server Licenses
    You can now view the status and set alerts for the virtual server licenses expiry in NetScaler MAS. This helps you plan your license upgrades on time. You can set the expiry notifications to be received through email or through SMS. To view the status of the licenses, navigate to Infrastructure > Licenses > System Licenses. Then, in the License Expiry Information section, you can find the details of the licenses that are going to expire. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649426, 660051]
  • Port Configuration Support for License Server Client
    If your network firewall does not allow the using of ports above 10000 for communication between license server (port 27000) and NetScaler instances, you can use vendor daemon port (7279) for communication. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649424]
  • Management and Monitoring Support for Virtual Servers through NetScaler MAS
    You can now select the virtual servers to manage and monitor through MAS. To manage licensed virtual servers, navigate to Infrastructure > Licenses > System Licenses, and select Modify Licensed Virtual Servers to license/un-license the virtual servers. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649425, 649591]
Orchestration
  • Support for OpenStack Mitaka Features in NetScaler MAS
    NetScaler MAS now supports integration with OpenStack Mitaka, giving OpenStack users access to NetScaler capabilities from OpenStack.
    [From Build 51.26] [# 605594]
  • NetScaler MAS Orchestration User Interface Enhancements
    New organization of the Orchestration tab in NetScaler MAS shows the third-party services with which the NetScaler MAS integrates under three headings:
    - OpenStack and Accelerite cloud platforms are under "Cloud Orchestration."
    - Cisco ACI support and VMware NSX manager are under "SDN Orchestration."
    - Under "Container Orchestration," you can deploy your containerized applications and micro services with Mesos cluster management software.
    [From Build 51.26] [# 653565]
  • Exposing advanced NetScaler Features through OpenStack Heat using NetScaler MAS
    In addition to being able to integrate OpenStack Neutron LBaaS, OpenStack users can now configure more advanced features of NetScaler through OpenStack Heat, by using StyleBooks provided in NetScaler MAS. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-openstack-platform/integrating_netscaler_mas_with_openstack_heat_services.html.
    [From Build 51.26] [# 640110]
  • Support for OpenStack L7 Switching Support in NetScaler MAS
    NetScaler MAS can now orchestrate the OpenStack Neutron Layer 7 (L7) switching functionalities by deploying them on NetScaler instances. When the L7 configurations are created in OpenStack with a NetScaler instance as the provider, NetScaler MAS allots a NetScaler instance, and deploys content switching and responder configurations corresponding to the L7 configurations. The NetScaler instances can then distribute and load balance user requests on the basis of application-layer characteristics of the requests. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-openstack-platform/configuring-layer7-content-switching-mas.html.
    [From Build 51.26] [# 657952]
  • Support for OpenStack Newton Features in NetScaler MAS
    NetScaler MAS now supports integration with OpenStack Newton. This enhancement enables integration with OpenStack Newton and gives OpenStack users access to NetScaler services from OpenStack.
    [From Build 51.26] [# 646611]
StyleBooks
  • Configure Alerts and Collect Analytics Data on a Virtual Server Defined by Using a StyleBook
    You can now use the operations construct in StyleBooks to configure NetScaler MAS analytics alarms on any virtual server created through the StyleBook. The attributes in this construct are used to set thresholds to generate alarms and send notifications on the virtual server. For example, you can configure an alert to send notification if the total requests handled by a load balancing virtual server is greater than 25 and for a period defined by the user. For more information, see: http://docs.citrix.com/en-us/netscaler-mas/11-1/stylebooks/how-to-enable-analytics-on-virtual-server-defined-in-stylebooks.html
    [From Build 49.16] [# 627838]
  • StyleBooks for NITRO Entities Available on NetScaler MAS
    Built-in StyleBooks corresponding to all NITRO entities for releases 10.5, 11.0, and 11.1 are now available on NetScaler MAS. You cannot access these StyleBooks from the NetScaler MAS GUI. To access these built-in StyleBooks, you have to use StyleBooks API requests.
    For example, to get the definition of a built-in StyleBook for lbvserver resource of NetScaler NITRO API, you have to use the following GET request:
    [GET] http://<mas_ip>/stylebook/nitro/v1/config/stylebooks/netscaler.nitro.config/<netscaler_release>/lbvserver
    To create a load balancing virtual server on the target instance with the specified attribute values, you have to use the following POST request:
    [POST] http://<mas_ip>/stylebook/nitro/v1/config/stylebooks/netscaler.nitro.config/<netscaler_release>/lbvserver
    payload:
    {
    "configpack": {
    "parameters": {
    "name": "test-lb",
    "servicetype": "HTTP",
    "ipv46": "101.102.11.10",
    "port": 80
    },
    "target_devices": {
    "<device IP>": {
    "id": "<device_id>"
    }
    }
    }
    }
    For more information on how to use APIs to create configurations from StyleBooks, see: http://docs.citrix.com/en-us/netscaler-mas/11-1/stylebooks/how-to-use-api-to-create-configuration-from-stylebooks.html
    [From Build 49.16] [# 644498]
  • Support for File Uploads From StyleBooks by Using NetScaler MAS GUI
    To upload certificate file and certificate key file, two new types of parameters are now available, "certfile" and "keyfile". For these two parameter types, you can now upload the files directly from your local system when you are creating a StyleBook configuration using the NetScaler MAS GUI. The uploaded certificate file is stored in the directory /var/mps/tenants/<tenant_path>/ns_ssl_certs and the certificate key file is stored in /var/mps/tenants/<tenant_path>/ns_ssl_keys in NetScaler MAS. These uploaded certificates become part of the certificates managed by NetScaler MAS.
    For uploading any other type of file, you can use the parameter type "file". In this case, you have to first manually upload the file to /var/mps/tenants/<tenant_path>/ on NetScaler MAS, before you can use that file in a StyleBook configuration.
    When creating configurations from StyleBooks, you must provide only the name of the file you want to upload if you are using the API for any of the three parameters types or if the parameter type is "file" (from NetScaler MAS GUI or API). You must not provide the complete path of the files. The files are expected to be already available in the respective folders.
    [From Build 49.16] [# 645248]
  • Support for Nitro non-CRUD Operations in StyleBooks
    NetScaler MAS StyleBooks now supports Nitro non-CRUD operations such as "enable feature" and "enable mode." Add the "meta-properties" attribute in the Components section in the StyleBooks to enable the support.
    [From Build 51.26] [# 656493]
  • Deploying StyleBook Configuration on Multiple NetScaler Instances
    You can now deploy a single StyleBooks configuration on multiple NetScaler instances.
    [From Build 51.26] [# 662221]
System
  • Compressing Core Files to Save Disk Space
    The NetScaler MAS server now compresses the backup files that are generated during the "backup and restore" process. This ensures that the backup files now occupy minimum storage within the server.
    [From Build 49.16] [# 654672]
  • Ability to Backup and Restore NetScaler MAS
    You can now configure a backup NetScaler MAS server that continuously archives your primary NetScaler MAS server's data to ensure minimum loss of data in the event that your system becomes unstable. Transaction logs are continuously synced from your primary server to the backup NetScaler MAS server. The entire database on the primary NetScaler MAS server is archived and transferred remotely to the backup server during a scheduled time. By default, it is done once every 15 days.
    This method of transferring your entire NetScaler MAS server’s database to a backup NetScaler MAS server is called “base backup.” For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/mas-system-how-to-articles/how-to-backup-and-restore-configuration-on-mas.html.
    [From Build 51.26] [# 632373]
Fixed Issues in Previous NetScaler MAS 11.1 Releases
The issues that were addressed in NetScaler MAS 11.1 releases prior to Build 52.15. The build number provided below the issue description indicates the build in which this issue was addressed.
Analytics
  • When you upgrade the NetScaler appliance from 11.0 release to a newer release (11.1 or higher), Security Insight is set to disabled.
    [From Build 49.16] [# 653626]
  • In a NetScaler MAS high availability setup, the Analytics configuration does not work.
    [From Build 49.16] [# 642270, 644542]
  • NetScaler Insight Center displays the VPN virtual server IP address in the Server IP Address field rather than the XenApp or XenDesktop server IP address.
    [From Build 49.16] [# 635525]
  • NetScaler MAS Analytics displays the HA failover count per ICA session whenever HA failover happens, and a reconnect occurs using session reliability.
    [From Build 49.16] [# 644975]
  • The value of the X-Forwarded-For HTTP header field is not displayed as client IP address in Security Insight violation logs.
    [From Build 50.10] [# 645284, 636390]
  • NetScaler MAS Analytics displays the NetScaler HA failover count per ICA session whenever HA failover happens, and a reconnect occurs using session reliability.
    [From Build 50.10] [# 644975]
  • When you upgrade the NetScaler appliance from 11.0 release to a newer release (11.1 or higher), Security Insight is disabled.
    [From Build 50.10] [# 653626]
  • If URL reporting is enabled, analytics subsystem might fail, and reports might not be displayed.
    [From Build 50.10] [# 649947]
  • When you use LDAP for external authentication, you might receive a "Error: Resource does not exist" error message when you click the Configuration tab.
    [From Build 50.10] [# 658344]
  • Geo location does not resolve from Maxmind GeoCity.dat database file.
    [From Build 50.10] [# 656017]
  • If you add CloudBridge appliances in NetScaler MAS, Web Insight reports might not be displayed.
    [From Build 50.10] [# 659008]
  • For a NetScaler appliance in multicore setup, reports from all cores were not getting generated except "0" core.
    [From Build 50.10] [# 656225]
  • When you use LDAP for external authentication, you might receive a "Error: Resource does not exist" error message when you click the Configuration tab.
    [From Build 51.26] [# 658344]
  • If URL reporting is enabled, analytics subsystem might fail, and reports might not be displayed.
    [From Build 51.26] [# 649947, 667326]
  • HDX insight in NetScaler MAS might display zero for ICA_RTT average.
    [From Build 51.26] [# 660173]
  • There is no option to select the gateway device in a multi-hop deployment for NetScaler MAS. This does not allow us to bifurcate and report client and server side latency correctly.
    [From Build 51.26] [# 658855]
  • When Appflow is enabled for a new VPN virtual server through NetScaler MAS Analytics, the NetScaler MAS Analytics stops reporting ICA session data for some sessions.
    [From Build 51.26] [# 644748, 643704]
AppFlow
  • If HDX insight is enabled on a NetScaler appliances in high availability mode, and if the nodes are set to STAY PRIMARY or STAY SECONDARY, session reliability fails when a failover happens.
    [From Build 49.16] [# 653438]
  • If Appflow for ICA is enabled on a NetScaler appliance, the appliance might become unresponsive under certain circumstances during ICA capability negotiation in ICA PROXY mode.
    [From Build 49.16] [# 653385, 655823]
  • When AppFlow for ICA is enabled on a NetScaler appliance in a multi core environment, the Netscaler appliance might become unresponsive.
    [From Build 49.16] [# 647713]
  • If the NetScaler appliance sends AppFlow data with application firewall records to NetScaler MAS, the appliance might fail. This might occur if the built-in NOPOLICY policy, which does not have any specified action, is configured as a global policy.
    [From Build 50.10] [# 656771]
  • Automatic client reconnection (ACR) for Linux VDA clients fails if the NetScaler appliance is in the path and ICA AppFlow is enabled for the appliance.
    [From Build 50.10] [# 648254]
Application Management
  • The Bound Service Group option was earlier displayed in both the Services and Virtual Servers pages in the NetScaler MAS GUI. Because there is no mapping from services to service groups, the redundant Bound Service Group option is removed from the Services page. You can now view bound service groups from the Virtual Servers page. Select multiple virtual servers to view all service groups bound to the virtual servers.
    [From Build 51.26] [# 662245]
Infrastructure
  • If the frequency of a job is scheduled as "once" for a specific time and date, the job is executed immediately instead of getting executed at the scheduled time.
    [From Build 49.16] [# 654763]
  • If the frequency of a job is scheduled as "once" for a specific time and date, the job is executed immediately instead of getting executed at the scheduled time.
    [From Build 50.10] [# 654763]
  • The SSL Certificates page of NetScaler MAS does not show the host names associated with the certificates. With this fix, you can see the Host Name associated with a certificate as a column in the SSL certificates page.
    [From Build 51.26] [# 665130]
  • You can now view the serial number of a managed NetScaler SDX instance. To view the serial number, navigate to the Infrastructure > Instances > NetScaler SDX.
    [From Build 51.26] [# 662180]
  • When creating configuration jobs in NetScaler MAS, you cannot copy and paste commands in the Commands editor. For example, if you type a command in the editor, copy the command and try to paste it in the next line, the command does not get pasted.
    [From Build 51.26] [# 663486]
  • Database connection issues prevent NetScaler MAS reports from showing any data.
    [From Build 51.26] [# 658589, 667592]
  • In NetScaler MAS, the nssdx.py class is missing from the NITRO API SDK for Python.
    [From Build 51.26] [# 662355]
  • The ns_servicegroupmember_binding resource is missing from the enable and disable functions in the NetScaler MAS server's SDKs.
    [From Build 51.26] [# 670876]
  • Event messages are not sorted accurately by date when you click on the Date tab in the Events Messages page.
    [From Build 51.26] [# 670593]
  • When you click the Learn More button while searching for an instance on the Infrastructure tab of NetScaler MAS, a “Page not found” error message appears. This typically occurs after you upgrade your NetScaler MAS version to 11.1 build 49.16.
    [From Build 51.26] [# 664965]
  • You cannot search for admin partitions by name on NetScaler VPX instances. You must search by IP address. With this fix, you can use the Host Name filter to search for admin partitions.
    [From Build 51.26] [# 670570]
  • When the same NetScaler instances are discovered by a standalone NetScaler MAS deployment and a NetScaler MAS high availability (HA) deployment, the HA deployment shows a larger number of virtual servers and services.
    [From Build 51.26] [# 670072]
  • When you search for a virtual server (Applications > Load Balancing > Virtual Servers) by using your NetScaler MAS server’s IP address, the Search button is not visible after the first time you use it. To be able to see the Search button repeatedly, you have to access NetScaler MAS through its DNS alias.
    [From Build 51.26] [# 665622]
  • On the Licensing page of NetScaler MAS, host identities for a few NetScaler instances is displayed as "Unknown."
    [From Build 51.26] [# 669472]
  • In a NetScaler MAS high availability setup, certificates are not displayed accurately when certificate polling is enabled.
    [From Build 51.26] [# 666955]
  • NetScaler MAS crashes multiple times after a fresh install or if the NetScaler MAS server is upgraded.
    [From Build 51.26] [# 668556, 668621, 671047]
  • Event reports might not be visible to if you log on to NetScaler MAS with other than the default credentials (nsroot and nsroot).
    [From Build 51.26] [# 665445, 665554]
  • API calls for servicegroup bindings on NetScaler MAS do not apply Role Based Access (RBA) accurately for service group members.
    [From Build 51.26] [# 667783]
  • Event reports might not be accurately displayed if you log on to NetScaler MAS with other than the default credentials (nsroot and nsroot).
    [From Build 51.26] [# 667581]
  • During each polling cycle, the identities of virtual IP addresses and services change. As a result, users are unable to use NITRO APIs to perform operations on NetScaler MAS.
    [From Build 51.26] [# 667409]
  • When NetScaler instances in a high availability setup are added to NetScaler MAS, duplicate certificates are displayed for these instances in NetScaler MAS because certificate polling is performed on both the primary and secondary NetScaler instances.
    [From Build 51.26] [# 668709, 657647]
  • Scheduled and manual backups of NetScaler SDX instances are unsuccessful when they are initiated on NetScaler MAS in high availability mode.
    [From Build 51.26] [# 664945]
  • Entity polling in NetScaler MAS stops because of database issues.
    [From Build 51.26] [# 666954]
  • When a failover occurs for a NetScaler instance in a high availability setup, entities that were enabled or disabled are not displayed on the NetScaler MAS GUI.
    [From Build 51.26] [# 664067]
NS-MAS
  • When the MAS receives a request from an OpenStack tenant, the name of the tenant does not appear in the Tenant Name field in on the Orchestration Request tab.
    [From Build 48.10] [# 637841]
  • The Desktop Director is not integrated with the NetScaler MAS.
    [From Build 48.10] [# 647135]
  • The Tasks page under the Request tab keeps refreshing even after the tasks are complete.
    [From Build 48.10] [# 647517]
  • Events and syslog data are not sorted by date in the NetScaler MAS GUI.
    [From Build 48.10] [# 647576]
  • NetScaler MAS NITRO API documentation references "NetScaler SDX" instead of "NetScaler MAS".
    [From Build 48.10] [# 647686]
  • Enabling or disabling an entity from the Application Dashboard by using the State On-Off button does not create audit logs.
    [From Build 48.10] [# 646015]
  • For a service pack with an auto-provisioned device, NetScaler MAS does not support an HA pair for NOVA.
    [From Build 48.10] [# 648298]
  • After selecting one of the Cloud Platforms and submitting the form with the required settings under Orchestration, you is redirected to the Cloud Platform Selection page instead of Setting page.
    [From Build 48.10] [# 648355, 648561]
  • During instance interface configuration for Orchestration, the user can disable/enable the interface or assign the VLAN range. After user updates the setting, the GUI does not display the updated settings, until the page is refreshed.
    [From Build 48.10] [# 648363]
  • On the Application dashboard, for all virtual servers, the Search criterion generates a wrong count even if the data displayed in the GUI is accurate.
    [From Build 48.10] [# 648441]
  • When a tenant assigned to a service package with an isolation policy partition is unable to create a VIP on a shared network, rollback fails and the NetScaler MAS displays the following error message: "Nitro timed out: Invalid Argument [tagged]." Although the rollback fails, configurations are successfully configured on the NetScaler instance type.
    [From Build 48.10] [# 648514]
  • For a service pack with an auto-provisioned instance, NetScaler MAS does not support an HA pair for SDX.
    [From Build 48.10] [# 648566]
  • In the NetScaler MAS Infrastructure dashboard, NetScaler SD-WAN is not split into two instance types: SD-WAN WO and SD-WAN-EE. The SD-WAN displays include both SD-WAN WO and SD-WAN-EE instances.
    [From Build 48.10] [# 648690]
  • In NetScaler MAS, virtual servers and services takes a long time (~30 minutes) to be discovered on a HA setup.
    [From Build 48.10] [# 647904]
  • Using the NetScaler MAS GUI, you might not be able to delete partitioned instances that have gone out of service.
    [From Build 48.10] [# 644750]
  • When an HA pair is created with different NetScaler MAS versions, an erroneous "Invalid Password" message is displayed.
    [From Build 49.16] [# 647168]
Orchestration
  • In Orchestration, the Tasks page under the Request tab keeps refreshing even after the tasks are complete.
    [From Build 49.16] [# 647517]
  • During OpenStack orchestration, when you auto-provision a NetScaler VPX instance on NetScaler SDX in the NetScaler 11.1 release 48.10 build, an error is noticed during creation of the virtual IP address.
    [From Build 49.16] [# 655535]
  • In OpenStack integration, for an auto-provisioned NetScaler instance in NOVA, NetScaler MAS does not support a service package that specifies a partitioned isolation policy. Service package creation might succeed, but an error occurs when you configure the first load balancer.
    [From Build 49.16] [# 654374]
  • After selecting one of the cloud platforms and submitting the form with the required settings under Orchestration, you are redirected to the Cloud Platform Selection page instead of the Deployment Settings page. With this fix, when you now select one of the cloud platforms and submit the form, you are redirected to the Deployment Settings page.
    [From Build 49.16] [# 648355, 648561]
  • For NSX Integration, a VLAN is allotted for every VXLAN during service insertion. The VLANs do not get de-allotted when service insertion is disabled/deleted. Because of this VLANs might get exhausted.
    [From Build 49.16] [# 648726]
  • In OpenStack integration, the installation files and scripts in the NetScaler driver bundle, and the configurations in the neutron.conf file now display NetScaler MAS options.
    [From Build 51.26] [# 653696]
  • If a network gets disconnected while you are autoprovisioning NetScaler instances on NOVA, you should not perform other operations on the NetScaler instances. Doing so could result in the instance becoming unstable. In that case, you might have to ask Citrix technical support to reconfigure the instance.
    [From Build 51.26] [# 590687]
  • For NSX Integration, a VLAN is allotted for every VXLAN during service insertion. The VLANs do not get de-allotted when service insertion is disabled/deleted. Because of this VLANs might get exhausted.
    [From Build 51.26] [# 648726]
StyleBooks
  • In the "Sample Application StyleBook using CS, LB and SSL features" (sample-cs-app) StyleBook, the name of the application is hard coded. Therefore, using this StyleBook you can create only one application configuration (config pack) from this StyleBook on the same target device. If you try to create a second configuration from this StyleBook, an error message is displayed mentioning that the resource already exists.
    [From Build 51.26] [# 665099]
System
  • In NetScaler MAS, when you configure instance backup settings (System > Instance Backup Settings), the backup files are generated randomly and not at the set time interval. Also, the older backup files are not being deleted in the order that they were created.
    [From Build 49.16] [# 661153]
  • Earlier, when trying to remove or edit a threshold, the following error message appeared even for an nsroot user: "Not authorized to perform this operation." Now, you can remove or edit previously created thresholds on NetScaler MAS.
    [From Build 49.16] [# 654615]
  • Earlier, when trying to remove or edit a threshold, the following error message appeared even for an nsroot user: "Not authorized to perform this operation." Now, you can remove or edit previously created thresholds on NetScaler MAS.
    [From Build 50.10] [# 654615]
  • When multiple NetScaler MAS servers access a NetScaler instance at the same time to back up the instance, backup files might get overwritten. To prevent this, a random string is now appended to the backup files.
    [From Build 50.10] [# 658479]
  • Even if the email notification option is disabled when system-related functions are configured, the NetScaler MAS server sends emails.
    [From Build 51.26] [# 665567]
  • When multiple NetScaler MAS servers access a NetScaler instance at the same time to back up the instance, backup files might get overwritten. To prevent this, a random string is now appended to the backup files.
    [From Build 51.26] [# 658479]
  • File sync issues between NetScaler MAS nodes can occur if bad permissions on a private key file disrupt the Secure Shell (SSH) channel between the nodes of a high availability pair.
    [From Build 51.26] [# 664887]
Release history
For details of a specific release, see the corresponding release notes.

1999-2016 Citrix Systems, Inc. All rights reserved. | Terms of use.
Useful links

On this page

Additional Issues in Versions (6)
What's New? (1)
Fixed Issues (55)
Known Issues (44)
What's New in Previous 11.1 Builds (57)
Fixed Issues in Previous 11.1 Builds (79)