1、Citrix Netscaler 运维命令1Citrix Netscaler 运维命令Citrix Netscaler 运维命令2目 录引言 3报告摘要 4DCC-ITS-GSLB-0C 报告 5系统摘要 5配置摘要 8巡检建议总结 13Citrix Netscaler 运维命令3引言XXXX 是 Netscaler 在中国的大客户之一,目前采用了各种系列的 Netscaler 产品并且广泛应用在GSLB 链路负载均衡,SLB 服务器负载均衡。为了确保用户 Netscaler 的稳定和高可用性,XXXX 对7 台 Netscaler 设备进行详细巡检。设备主机名称 管理 IP 地址 版本 开启
2、功能DCC-ITS-GSLB-0C 10.5.36.20NS9.3: Build 57.5.cl GSLB+LB+CSDCC-ITS-GS-B 10.5.36.19 NS9.3: Build 57.5.cl GSLB+LBDCC-ITS-GS-A 10.5.36.18NS9.3: Build 57.5.cl GSLB+LB+SSL+WL+SPDCC-90LB0B-S3 10.2.126.3NS9.3: Build 57.5.cl LB+CS+CMP+REWRITE+RESPONDERDCC-90LB0A-S3 10.2.126.2NS9.3: Build 57.5.cl LB+CS+CMP+R
3、EWRITE+RESPONDERns-1 10.1.46.11NS9.1: Build 98.5.cl LB+CS +REWRITE+RESPONDERns-0 10.1.46.10NS9.1: Build 98.5.cl LB+CS +REWRITE+RESPONDERCitrix Netscaler 运维命令4报告摘要本次报告对 7 台 Citrix Netscaler 设备进行运行检查。本次检测包括了各设备的软件版本,service, vserver,cpu,内存等运作状况,CPU 和内存负载检测, netscaler 的工作情况,检查正在运行的进程和最占资源的进程,网络接口,硬盘存储空
4、间和健康检测等等。通过查看这次巡检报告,网络管理人员能够详细的了解这个季度 Netscaler 的详细运作状况,对于以后设备维护能够提供一些帮助。设备主机名称 管理 IP 地址 工作方式 运行情况DCC-ITS-GSLB-0C 10.5.36.20NOT HA 运行良好DCC-ITS-GS-B 10.5.36.19 NOT HA 运行良好DCC-ITS-GS-A 10.5.36.18 NOT HA 运行良好DCC-90LB0B-S3 10.2.126.3HA Secondary 运行良好DCC-90LB0A-S3 10.2.126.2HA Primary 运行良好ns-1 10.1.46.11
5、 HA Primary 运行良好ns-0 10.1.46.10 HA Secondary 运行良好评测:设备运行情况良好;Citrix Netscaler 运维命令5DCC-ITS-GSLB-0C 报告系统摘要Netscaler 版本 NS9.3: Build 57.5.cl软件版本日期 Jun 27 2012, 17:40:09主要实现功能 GSLB未重启运行时间 103 days, 11 hrs运行方式 NOT HA评测:该设备在 6 月 27 号升级过,已运行了 103 天,如果设备运行较长时间,可重启设备,让系统在重启过程中对所有硬件做一次全面自检,以及释放所有系统资源。设备运行进程情
6、况rootDCC-ITS-GSLB-0C# ps -auxUSER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMANDroot 369 99.0 0.0 1224 520 ? Rs 17Aug12 0:00.00 /netscaler/nswsrun (ns_slave01)root 370 99.0 0.0 1224 520 ? Rs 17Aug12 0:00.00 /netscaler/nswsrun (ns_slave02)root 371 99.0 0.0 1224 520 ? Rs 17Aug12 0:00.00 /netscaler
7、/nswsrun (ns_slave03)root 400 99.0 0.0 1224 520 ? Ls 17Aug12 148553:46.12 /netscaler/nswsrun (ns_master)root 0 0.0 0.0 0 0 ? WLs 17Aug12 0:01.86 swapperroot 1 0.0 0.0 772 400 ? ILs 17Aug12 0:00.09 /sbin/init -root 2 0.0 0.0 0 8 ? DL 17Aug12 7:55.49 g_eventroot 3 0.0 0.0 0 8 ? DL 17Aug12 10:17.94 g_u
8、proot 4 0.0 0.0 0 8 ? DL 17Aug12 9:23.91 g_downroot 5 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 cryptoroot 6 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 crypto returnsroot 7 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 acpi_task_0root 8 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 acpi_task_1root 9 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 acpi_task_2
9、root 10 0.0 0.0 0 8 ? RL 17Aug12 1:55.37 idle: cpu3root 11 0.0 0.0 0 8 ? RL 17Aug12 1:55.37 idle: cpu2root 12 0.0 0.0 0 8 ? RL 17Aug12 1:55.37 idle: cpu1root 13 0.0 0.0 0 8 ? RL 17Aug12 1:34.31 idle: cpu0root 14 0.0 0.0 0 8 ? WL 17Aug12 124:26.30 swi4: clock sioroot 15 0.0 0.0 0 8 ? WL 17Aug12 0:00.
10、00 swi3: vmroot 16 0.0 0.0 0 8 ? WL 17Aug12 2:50.22 swi1: netroot 17 0.0 0.0 0 8 ? DL 17Aug12 7:51.24 yarrowroot 18 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 kqueue taskqroot 19 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 xpt_thrdroot 20 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 swi2: cambioroot 21 0.0 0.0 0 8 ? WL 17Aug12 0:00
11、.00 swi6: task queueroot 22 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 swi6: Giant taskqroot 23 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 thread taskqroot 24 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 swi5: +root 25 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 irq9: acpi0root 26 0.0 0.0 0 8 ? WL 17Aug12 9:50.37 irq17: cavium0+root 27 0.0 0
12、.0 0 8 ? WL 17Aug12 0:00.00 irq18: cavium1+*root 28 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 irq19: cavium2+root 29 0.0 0.0 0 8 ? WL 17Aug12 0:00.04 irq16: cavium3+root 30 0.0 0.0 0 8 ? WL 17Aug12 1:14.64 irq14: ata0root 31 0.0 0.0 0 8 ? WL 17Aug12 0:00.00 irq15: ata1root 32 0.0 0.0 0 8 ? WL 17Aug12 0:00.00
13、 irq1: atkbd0root 33 0.0 0.0 0 8 ? WL 17Aug12 4:22.85 swi0: sioroot 34 0.0 0.0 0 8 ? DL 17Aug12 0:16.37 md0Citrix Netscaler 运维命令6root 35 0.0 0.0 0 8 ? DL 17Aug12 0:09.32 pagedaemonroot 36 0.0 0.0 0 8 ? DL 17Aug12 0:00.00 vmdaemonroot 37 0.0 0.0 0 8 ? DL 17Aug12 0:28.86 pagezeroroot 38 0.0 0.0 0 8 ?
14、RL 17Aug12 136:23.35 nsidlerroot 39 0.0 0.0 0 8 ? SL 17Aug12 26:49.44 nshealthroot 40 0.0 0.0 0 8 ? DL 17Aug12 0:45.73 bufdaemonroot 42 0.0 0.0 0 8 ? DL 17Aug12 5:15.60 syncerroot 43 0.0 0.0 0 8 ? DL 17Aug12 0:47.63 vnlruroot 44 0.0 0.0 0 8 ? DL 17Aug12 0:47.91 softdepflushroot 45 0.0 0.0 0 8 ? DL 1
15、7Aug12 2:35.41 schedcpuroot 46 0.0 0.1 14128 2092 ? S 17Aug12 3:39.55 nspitboss (pitboss)root 227 0.0 0.0 1352 1028 ? Ss 17Aug12 0:11.06 /usr/sbin/syslogd -b 127.0.0.1 -n -v -v -8root 229 0.0 0.0 1412 1016 ? Is 17Aug12 0:00.00 /usr/sbin/inetdroot 231 0.0 0.0 1348 1020 ? Is 17Aug12 0:28.46 /usr/sbin/
16、cronroot 235 0.0 0.5 22736 16792 ? Ss 17Aug12 1:22.03 /bin/httpdroot 241 0.0 0.1 3436 2404 ? S 17Aug12 3:51.43 /usr/local/bin/monit -c /etc/monitrcroot 243 0.0 0.1 12332 2792 ? Is 17Aug12 0:00.07 /usr/sbin/sshd -f /etc/sshd_configroot 322 0.0 0.7 45396 22812 ? Ss 17Aug12 0:26.37 /netscaler/nsnetsvc
17、-Sroot 354 0.0 0.1 14232 2148 ? Is 17Aug12 0:00.00 /netscaler/nsmap -lroot 403 0.0 0.0 19296 1132 ? I 17Aug12 0:00.00 /netscaler/nsreadfileroot 404 0.0 0.0 19788 1328 ? I 17Aug12 0:00.00 /netscaler/nscrlrefreshroot 408 0.0 0.1 14020 1960 ? Is 17Aug12 0:00.00 /netscaler/nsfsyncd -droot 412 0.0 0.0 27
18、32 1312 ? I 17Aug12 0:00.00 /netscaler/nsvpnd 7776root 413 0.0 0.1 15000 2628 ? S 17Aug12 0:12.79 /netscaler/nsaaad -n 10 -p 8766root 416 0.0 0.0 1748 1284 ? I 17Aug12 0:00.08 sh /netscaler/nslog.sh startroot 417 0.0 0.0 1700 1248 ? I 17Aug12 0:00.00 sh /netscaler/nssync.sh startroot 419 0.0 0.0 172
19、0 1232 ? I 17Aug12 0:05.66 sh /netscaler/nsdiskspace.sh startroot 424 0.0 2.7 108316 94964 ? S 17Aug12 18:33.23 /netscaler/nscollect startroot 429 0.0 0.1 14896 2992 ? Ss 17Aug12 0:38.88 /netscaler/aslearn -start -f /netscaler/aslearn.confroot 437 0.0 0.1 3068 2240 ? S 17Aug12 1:49.30 /netscaler/nsv
20、pnd 7776root 443 0.0 0.1 29072 4996 ? S 17Aug12 4:22.81 /netscaler/snmpdroot 450 0.0 0.1 2948 1820 ? Ss 17Aug12 1:44.67 /usr/sbin/ntpd -g -l /var/log/ntpd.logroot 472 0.0 0.1 17924 3296 ? I 17Aug12 0:00.00 /netscaler/nssyncroot 498 0.0 0.0 1308 828 ? Is 17Aug12 0:00.00 /netscaler/nsumondnsmonitor 49
21、9 0.0 0.0 1308 864 ? I 17Aug12 0:00.00 /netscaler/nsumondroot 502 0.0 0.1 14072 2088 ? Ss 17Aug12 18:02.96 /netscaler/nslcd -kroot 516 0.0 0.1 15692 3948 ? Ss 17Aug12 1:27.48 /netscaler/imi -d -f /nsconfig/ZebOS.confnobody 871 0.0 0.6 40044 21632 ? I 17Aug12 0:20.11 /bin/httpdnobody 872 0.0 0.6 4002
22、0 21844 ? S 17Aug12 0:20.45 /bin/httpdnobody 873 0.0 0.6 39660 21680 ? S 17Aug12 0:20.48 /bin/httpdnobody 874 0.0 0.7 40708 22628 ? S 17Aug12 0:20.36 /bin/httpdnobody 875 0.0 0.7 41612 23508 ? S 17Aug12 0:20.63 /bin/httpdroot 28069 0.0 0.1 16152 3116 ? S Tue04PM 0:00.98 /netscaler/nsconmsg -O -k /va
23、r/nslog/newnslog -T 172800 -s logsize=300m -S currentroot 35563 0.0 0.1 12364 3100 ? Ss 3:10AM 0:00.05 sshd: nsrootttyp0 (sshd)root 35570 0.0 0.0 1224 452 ? I 3:10AM 0:00.00 sleep 600root 538 0.0 0.0 1316 892 d0 Is+ 17Aug12 0:00.00 /usr/libexec/getty std.9600 ttyd0root 530 0.0 0.0 1316 892 v0 Is+ 17
24、Aug12 0:00.00 /usr/libexec/getty Pc ttyv0root 531 0.0 0.0 1316 892 v1 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv1root 532 0.0 0.0 1316 892 v2 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv2root 533 0.0 0.0 1316 892 v3 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv3root 534 0.0 0.0 1316 892 v4 Is
25、+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv4root 535 0.0 0.0 1316 892 v5 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv5root 536 0.0 0.0 1316 892 v6 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv6root 537 0.0 0.0 1316 892 v7 Is+ 17Aug12 0:00.00 /usr/libexec/getty Pc ttyv7root 35565 0.0 0.2 18544 57
26、56 p0 Is 3:10AM 0:00.05 nscliroot 35577 0.0 0.1 11936 2088 p0 I 3:12AM 0:00.00 login pam (login)root 35578 0.0 0.1 2164 1836 p0 R 3:12AM 0:00.01 -bash (bash)root 35584 0.0 0.0 1476 992 p0 R+ 3:12AM 0:00.00 ps aux评测:该设备无异常进程。设备巡检时的 CPU、MEM 使用情况rootDCC-ITS-GSLB-0C# vmstat 2 5procs memory page disks fa
27、ults cpur b w avm fre flt re pi po fr sr ad0 ad4 in sy cs us sy idCitrix Netscaler 运维命令74 0 1 556312 75792 8 0 0 1 6 0 0 0 196 71 171 -0 100 -03 1 0 556312 75792 1 0 0 0 4 0 2 0 200 83 661 0 100 03 1 0 556312 75792 0 0 0 0 0 0 4 0 251 138 843 0 100 03 1 0 556312 75792 0 0 0 0 0 0 0 0 200 114 650 0 1
28、00 03 1 0 556312 75792 0 0 0 0 0 0 0 0 197 90 648 0 100 0评测:因为该设备 CPU 负载几乎为 0,内存剩余充足。Netscaler 开启功能检查 show featureFeature Acronym Status- - -1) Web Logging WL OFF2) Surge Protection SP OFF3) Load Balancing LB ON4) Content Switching CS ON5) Cache Redirection CR OFF6) Sure Connect SC OFF7) Compression
29、 Control CMP OFF8) Priority Queuing PQ OFF9) SSL Offloading SSL OFF10) Global Server Load Balancing GSLB ON11) Http DoS Protection HDOSP OFF12) Content Filtering CF OFF13) Integrated Caching IC OFF14) SSL VPN SSLVPN OFF15) AAA AAA OFF16) OSPF Routing OSPF OFF17) RIP Routing RIP OFF18) BGP Routing BG
30、P OFF19) Rewrite REWRITE OFF20) IPv6 protocol translation IPv6PT OFF21) Application Firewall AppFw OFF22) Responder RESPONDER OFF23) HTML Injection HTMLInjection OFF24) NetScaler Push push OFF25) AppFlow AppFlow OFF26) CloudBridge CloudBridge OFFDone评测:该设备开启了 LB+CS+GSLB。设备磁盘空间使用情况rootDCC-ITS-GSLB-0C
31、# dfFilesystem 1K-blocks Used Avail Capacity Mounted on/dev/md0c 160430 150940 6282 96% /devfs 1 1 0 100% /devprocfs 4 4 0 100% /proc/dev/ad4s1a 3929326 66890 3548090 2% /flash/dev/ad0s1e 260532690 2442364 237247712 1% /var评测:空间充足,平时维护请多注意/VAR 的使用率,如果超过 30%需要查找原因。设备主备状态 show ha node1) Node ID: 0 IP:
32、 10.5.36.20 (DCC-ITS-GSLB-0C) Node State: UPMaster State: PrimaryCitrix Netscaler 运维命令8Fail-Safe Mode: OFFEnabled Interfaces : 1/8 1/7 1/6 1/5 1/4 1/3 1/2 1/1 0/1 0/2Disabled Interfaces : NoneSSL Card Status: UPHello Interval: 200 msecsDead Interval: 3 secsNode in this Master State for: 103:10:55:45
33、 (days:hrs:min:sec)Local node information:Critical Interfaces: 1/8 1/7 1/6 1/5 1/4 1/3 1/2 1/1 0/1 0/2Done评测:该设备没有做 HA,因为该设备是实现 GSLB 多链路中的一台,在链路上采取了冗余。配置摘要端口信息 show interface1) Interface 0/1 (Gig Ethernet 10/100/1000 MBits) #8 flags=0x4001 MTU=1514, native vlan=1, MAC=00:30:48:fb:02:28, downtime 248
34、1h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 02) Interface 0/2 (Gig Ethernet 10/100/1000 MBits) #9 flags=0x4001 MTU=1514, native vlan=1, MAC=00:30:48:fb:02:29, downtime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 03) Interface 1/1 (Gi
35、g Ethernet 10/100/1000 MBits) #7 flags=0x4001 MTU=1514, native vlan=1, MAC=00:e0:ed:1a:06:a9, downtime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 04) Interface 1/2 (Gig Ethernet 10/100/1000 MBits) #6 flags=0xc021 MTU=1514, native vlan=1, MAC=00:e0:ed:1a:06:a8, upt
36、ime 2481h41m55sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 0Actual: media UTP, speed 1000, duplex FULL, fctl OFF, throughput 10005) Interface 1/3 (Gig Ethernet 10/100/1000 MBits) #5 flags=0x4001 MTU=1514, native vlan=1, MAC=00:e0:ed:1a:06:a7, downtime 2481h41m58sRequested: me
37、dia AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 06) Interface 1/4 (Gig Ethernet 10/100/1000 MBits) #4 flags=0x4001 Citrix Netscaler 运维命令9MTU=1514, native vlan=1, MAC=00:e0:ed:1a:06:a6, downtime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 07) Interface 1/5 (G
38、ig Ethernet 10/100/1000 MBits) #3 flags=0x4001 MTU=1514, native vlan=1, MAC=00:e0:ed:18:9f:05, downtime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 08) Interface 1/6 (Gig Ethernet 10/100/1000 MBits) #2 flags=0x4001 MTU=1514, native vlan=1, MAC=00:e0:ed:18:9f:04, do
39、wntime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 09) Interface 1/7 (Gig Ethernet 10/100/1000 MBits) #1 flags=0xc021 MTU=1514, native vlan=1, MAC=00:e0:ed:18:9f:03, uptime 2481h41m55sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 0Actual: medi
40、a UTP, speed 1000, duplex FULL, fctl OFF, throughput 100010) Interface 1/8 (Gig Ethernet 10/100/1000 MBits) #0 flags=0x4001 MTU=1514, native vlan=1, MAC=00:e0:ed:18:9f:02, downtime 2481h41m58sRequested: media AUTO, speed AUTO, duplex AUTO, fctl OFF,throughput 011) Interface LO/1 (Netscaler Loopback
41、interface) #10 flags=0x20008021 MTU=1514, native vlan=1, MAC=00:30:48:fb:02:28, uptime 2481h41m57sDone评测:接口配置正确,接口状态正常。设备时间检查rootDCC-ITS-GSLB-0C# dateThu Nov 29 03:12:25 UTC 2012评测:该设备的时间设置不对,建议修改成正确时间。设备使用 ip 列表和接口 vlan 情况 show ns ipIpaddress Type Mode Arp Icmp Vserver State- - - - - - -1) 10.5.36.
42、20 NetScaler IP Active Enabled Enabled NA Enabled2) 120.196.127.114 MIP|GSLB|ADNS Active Enabled Enabled NA Enabled3) 120.196.127.115 SNIP Active Enabled Enabled NA EnabledDone show vlanCitrix Netscaler 运维命令101) VLAN ID: 1Member Interfaces : 1/8 1/7 1/6 1/5 1/4 1/3 1/2 1/1 0/1 0/2 LO/1 Tagged: None2
43、) VLAN ID: 2 VLAN Alias Name: Member Interfaces : NoneDone评测:配置了 3 个 ip 和 2 个 vlan,其中有一 vlan 在使用。设备 license 情况 show licenseLicense status:Web Logging: YESSurge Protection: YESLoad Balancing: YESContent Switching: YESCache Redirection: YESSure Connect: YESCompression Control: YESDelta Compression: NO
44、Priority Queuing: YESSSL Offloading: YESGlobal Server Load Balancing: YESGSLB Proximity: YESHttp DoS Protection: YESDynamic Routing: YESContent Filtering: YESIntegrated Caching: NOSSL VPN: YES (Maximum users = 5) (Maximum ICA users = 0)AAA: YESOSPF Routing: YESRIP Routing: YESBGP Routing: YESRewrite: YESIPv6 protocol translation: YESApplication Firewall: NOResponder: YESHTML Injection: NONetScaler Push: YESWeb Interface on NS: YESAppFlow: NOCloudBridge: NOModel Number ID: 7500Done评测