NetScaler SD-WAN 10.0.2 Release Notes
This release note describes what’s new, known issues, and fixed issues applicable to SD-WAN software release version 10.0.2 for the SD-WAN Standard Edition, WANOP, and Enterprise Edition appliances, and SD-WAN Center.
For information about the previous release versions, see the Citrix SD-WAN documentation.
The SD-WAN release version 10.0.2 introduces the following enhancements:
210-SE LTE configuration and change management process
If you configured a WAN link on a 210-SE appliance with release 9.3 version 5, it is possible to misconfigure the 210-SE appliance with the incorrect hardware. For instance; a 210-SE appliance with no LTE port can still turn on the LTE port in the configuration and push that change to the non-lte 210-SE appliance during the change management process.
To prevent misconfiguring the 210-SE appliance, update the network to release 10.0 version 2, and ensure the following:
Any 210-SE LTE appliances in the network have the “LTE” submodel configured or selected for those sites.
Any 210-SE base (non-LTE) appliances in the network have the “BASE” submodel configured at those sites.
A 210-SE appliance with the “LTE” port enabled in release 9.3 version 5 automatically translates to the 210-SE LTE submodel after migrating to release 10.0 version 2.
210-SE sub model information
In the SD-WAN GUI, when creating a client site for the 210-SE appliance, the GUI displays submodel information; LTE and BASE.
High availability support
The NetScaler SD-WAN release 10.0 version 2 supports configuring High availability on the 210-SE BASE and LTE appliances.
Support to upload modem firmware on multiple sites is added.
MOS score for Applications and Application QoS Rules is added.
Multi-regions in SD-WAN Center
Multi-region network support is added. The enhancements related to multi-region support are as follows:
The Head end SD-WAN Center can only perform upload operation for sites in the “Default Region” and the Collector SD-WAN Center can perform upload operation for the sites in its region.
The Mobile Broadband tab in the Collector SD-WAN Center GUI shows data and summary from LTE sites in the region. Modem operations are performed from this Collector.
The Inventory Manager field in the SD-WAN Center GUI displays the submodel information for the 210-SE platform.
When Centralized licensing is configured for a site with a specific license rate (bandwidth), the site appliance can consume the license rate equal to or greater than the license rate configured for that site.
- Issue ID 709418: If a new site that has a WAN link with public IP address learning enabled is added to the network, after configuration change, it is possible that a WAN path on the network will go DEAD.
- Issue ID 707003: In NetScaler SD-WAN release 9.3 version 3, generation of STS in peak traffic or load can lead to memory issues causing the STS generation process incomplete.
- Issue ID 709309: In NetScaler SD-WAN release 9.3 version 4, packets are dropped when packets are received on an untrusted link with a source MAC address, which is different than the link gateway MAC address.
Application QOS rule index
- Issue ID 707561: In NetScaler SD-WAN release 9.3 version 3, the SD-WAN service restarts unexpectedly, when switching from static virtual paths to dynamic virtual paths due to memory issues because of incorrect application QOS rule index.
- Issue ID 703119: In NetScaler SD-WAN release 9.3 version 2, the SD-WAN service restarts on a 410-SE appliance edition because of high rate of packet bursts. Sometimes, the appliance might go into a hung state.
- Issue ID 709077: In NetScaler SD-WAN release 10.0 version 1, the WAN Link usage report shows multiple Internet Services view instead of one when multiple routing domains are configured.
- Issue ID 709392: In NetScaler SD-WAN release 9.3 version 4, the SD-WAN service restarts when the Internet Service transfers from Primary/Secondary mode to balanced mode with internet access to all routing domains configured in the WAN link access interface.
- Issue ID 709403: In NetScaler SD-WAN release 10.0 version 1, the DHCP server cannot allocate IP address in the configured subnet, if a new site is created and the DHCP server is configured before the Audit Now button is clicked.
- Issue ID 709125: In NetScaler SD-WAN WAN OP release 9.3 version 4, passive FTP connectivity issue is encountered when using the WAN OP plug-in on Windows platform.
STS packet capture
- Issue ID 708889: In NetScaler SD-WAN release 10.0 version 1, on the 4100 or 5100 platform editions, STS packet capture does not contain any data when it is collected for the first time with only 5 seconds on the data interface.
- Issue ID 705654: in NetScaler SD-WAN WANOP release 9.3 version 3, on the SD-WAN 4000 or 5000 platform editions, the WANOP module drops the ESP protocol packets when it is configured with return to Ethernet sender.
Ether IP Protocol
- Issue ID 702652: in NetScaler SD-WAN WANOP release 9.3 version 3, on the SD-WAN 4000 or 5000 platform editions, the WANOP module drops the Ether IP protocol packets when it is configured with return to Ethernet sender.
Change management process
- Issue ID 706577: During the change management staging process on an SD-WAN 1000 appliance, a branch node might remain in the unpacking phase for a long duration.
- Issue ID 709212: A “Backup file parsing failed” error is encountered when an SD-WAN WAN OP appliance configuration running with release 10.0.x is restored after a backup.
- Issue ID 709079: In NetScaler SD-WAN release 10.0 version 1, the SD-WAN Center application notification configuration settings such as, Virtual Path, Dynamic Virtual Path, Appliance, License, and Events are not applied to the SD-WAN appliances in the network.
- Issue ID 710635: In NetScaler SD-WAN release 10.0 version 1, packets matching the same header (source/destination IP/port) processed simultaneously through the firewall can cause the system to restart, if WAN-to-WAN forwarding is disabled and an external router is used to forward branch-to-branch traffic.
- Issue ID 709572: In NetScaler SD-WAN release 10.0 version 1, you do not have to change the access interface IP address when cloning a site, if it is a private Virtual IP address, and public IP address is configured for that WAN link.
- Issue ID 710493: In NetScaler SD-WAN release 10.0 version 1, when WAN gateway is unavailable and becomes available in a fraction of second, the routes are not relearned. Restart the SD-WAN service at the Branch to relearn routes.
- Issue ID 710960: When configuring OSPF, the OSPF areas configuration in the SD-WAN GUI does not show the routing domain drop-down option. Therefore, areas for multiple routing domains cannot be created. The BGP configuration works fine showing the routing domains by listing the VNIs to choose for enabling the dynamic routing participating interface.
- Issue ID 709163: In NetScaler SD-WAN, release versions 10.0.0 and 10.0.1, the TCP connections are not established, if WANOP redirection is enabled in the multi routing domain environment on an Enterprise Edition appliance, which has SD-WAN release 9.1 version 2 factory shipped base image.
SD-WAN WANOP 4000/4100/5000/5100 appliances
- Issue ID 681372, 0709820: NetScaler SD-WAN appliance becomes unresponsive when sending traffic that encounters a forwarding session.
- Issue ID 0710023: NetScaler SD-WAN appliance becomes unresponsive when processing GRE fragmented packet.
SD-WAN VPX appliances
- Issue ID 694837: For High Availability in Amazon Web Services (AWS) environment, Virtual WAN service is disabled on a NetScaler SD-WAN VPX Primary (active) appliance citing duplicate IP address when the HA interface on the primary appliance goes down.
- Issue ID 702889: RCN branch that is changed from GEO to Client is not updated to latest build even though it has an active Virtual path available with the RCN.
- Issue ID 701517: Over provisioning of the XenServer can lead to SD-WAN VPX appliance crash.
SD-WAN 4000 WANOP and 4000 SE
- Issue ID 681550: On a NetScaler SD-WAN 4000 WANOP appliance, uploading DER encoded certificate for the SSL profile is ignored and no error message is displayed in the web GUI. Only PEM encoded certificates are accepted.
SD-WAN 2100 EE
Issue ID 704923: The Domain Join/ Delegate user Pre-check Tools Summary Status table is not displayed you try to access them.
Workaround: You can obtain the status summary by selecting the More option in the summary dialog page.
Two box mode
Issue ID 681680: After a factory reset on the SD-WAN SE appliance in a two-box mode, configuration sync between SD-WAN WANOP and SD-WAN SE appliances fails due to stale SSL certificates.
Workaround: Disable and re-enable two-box mode on the SD-WAN WANOP appliance.
SD-WAN 1000 / 2000
Issue ID 681663: When you upgrade SD-WAN 1000 / 2000 appliance from release build version 184.108.40.206 to 9.2.x, a warning is displayed in the browser.
Workaround: Perform the upgrade in an incognito mode window of the Google Chrome browser.
HDX CGP over SSL
Issue ID 690794: HDX ICA/CGP over SSL session’s behavior In Virtual WAN Standard Edition:
HDX sessions are not being negotiated as multi stream sessions even though MSI is enabled on the appliance and MSI+MP policies are set on incoming ICA traffic.
HDX traffic is classified as belonging to Hyper Text Transfer Protocol Secure (https) application and web family.
HDX traffic falls under interactive > very > low class. This can cause issues in QoS, bandwidth allocation, and so on, as application QoS are not triggered because the traffic is not classified as HDX sessions.
DPI- ICMP functionality
Issue ID 677356: A firewall policy for blocking ICMP as an application blocks only pings (echo requests). All other ICMP types are allowed to pass through.
Workaround: Instead of blocking ICMP as an application, block IP-protocol > ICMP.
DPI –Traffic for top app family as “standard” and top app as “unknown virtual protocol” for a Standard edition appliance
Issue IDs 678373, 678339, 678545, 675063, 676017: On a NetScaler SD-WAN Standard Edition appliance, enable EDT policy for MSI+MP for Win7 and Win2K12 XD 7.12 VDAs on ports 2598, 2599, 2600, 2601 and then disable Session Reliability policy for Win7 VDA.
Workaround: Start sending internet traffic and check the monitoring flows in the Standard-Edition web management interface for Classes, Rule groups – ICAUDP and ICACGPUDP, and Firewall. Check the Dashboard and Reporting page in SD-WAN Center web management interface. The results display Top Application Family as Standard and Top Applications as Unknown Virtual Protocol.
- Issue ID 693436: The clear connections/flows clear SD WAN connection table entries and later all the ICA sessions. The SD-WAN Center dashboard shows incorrect results for HDX TCP and EDT classification sessions and reports it as “Not Classified.”
- Issue ID 693026: For HDX configuration, only UDP ICA sessions are classified by ICA classifier. The FrameHawk ICA sessions are ignored. The SD-WAN DPI fails to classify the FrameHawk sessions.
Virtual WAN configuration
- Issue ID 704926: Configuration error occurs when you attempt to override service in a Virtual Path by changing the IP Rule properties.
- Issue ID 704160: The Site Name in Virtual WAN configuration should be configured with alpha-numeric characters between 3-15 characters only. This is due to the hostname restrictions in WAN Optimization which is required for domain join operation.
- Issue ID 699285: The Application family added as one of the match types in the Application Object, which is used for Application Routes configuration is not considered for steering.
Custom application reporting
- Issue ID 703794: When an existing application name is modified and change management is performed, the new application name cannot be listed in the SD-WAN Center under the Top Sites-> Application drop-down menu. If the page is hard refreshed, then the new application name gets listed and reported, if traffic matches the application.
WAN GRE tunnel
- Issue ID 681171: NetScaler SD-WAN appliance does not reassemble fragmented GRE tunnel packets properly.
Transparent proxy support for TLS 1.2
- Issue ID 691900: In NetScaler SD-WAN WANOP 9.3.0, for SSL compression the SSL profile has to be configured in split mode only as transparent proxy mode is not supported.
Change management (single step upgrade) SD-WAN GUI
Issue ID 691953: During software upgrade on an appliance using a Standard Edition license, a WAN optimization related warning message appears. After the scheduled upgrade and after the WAN optimization, SVM and XenServer hotfixes are installed the warning message is cleared.
Workaround: Clear the warning messages manually or open the SD-WAN web UI in an incognito browser window.
Issue ID 705037: In the new Global Multi-Region Summary table, the “Total Sites” value displayed is less than the sum of the remaining columns. For example; when a branch node is not connected, it is possible that the branch is counted twice; once as “Not Connected” and once as “Preparing/Staging.”
Issue ID 704561: Unable to make the routing domain as default for a site after disabling it.
- Disable site routing domain (all).
- Enable routing domain for the site without making it default. Click Apply.
- Make the enabled routing domain for the site as default and click Apply.
Issue ID 705255: Dynamic routes can be installed with path eligibility, LOCAL service as part of Import filters. In NetScaler SD-WAN 10.0, if the path becomes inactive, then all routes are termed as REACHABLE – YES, and ELIGIBLE - NO instead of REACHABLE - NO and ELIGIBLE – NO. These routes which are ineligible stay in the remote SD-WAN routing table instead of being purged.
Secure peering certificate and keys
Issue ID 695363: In the SD-WAN GUI, on the Secure Peering Certificate and Keys page, the CA certificate contents are displayed when the private CA radio button is selected after setting the Key Store password on a new appliance.
Workaround: Switch between the radio buttons of the ‘Private CA’ and ‘CA Certificate’ once to get the correct contents displayed under ‘Private CA’ and ‘CA Certificate’ for Secure Peering Certificate and Keys.
- Issue ID 694894: When you configure Application QoS rule with match type as “Application” to match ‘icmp’ and change the class to Real-time, and mode to load balance which overrides the default rule, the multicast traffic is not processed.