Configuring DNSSEC for GSLB Domain Names

Feb 13, 2017

If global server load balancing (GSLB) is configured on the Citrix® NetScaler® ADC and the ADC is authoritative for the zone to which the GSLB domain names belong, all GLSB domain names are signed when the zone is signed. For more information about signing a zone for which the ADC is authoritative, see Configuring DNSSEC When the NetScaler Appliance Is Authoritative for a Zone.

If the GSLB domains belong to a zone for which the backend name servers are authoritative, you must first sign the zone on the name servers, and then sign the partial zone on the ADC to complete the DNSSEC configuration for the zone. For more information, see Configuring DNSSEC for a Partial Zone Ownership Configuration.