Part 4 in a series
So far: the first three parts of this series dealt with the introduction of a problem (multiple servers behind a NAT firewall that use the same port) and solution (Citrix NetScaler VPX Express); laying the groundwork for configuring the solution; an overview of what we'll be configuring.
Because it is possible to set up content switching with a single host (the degenerate case), this is the method we'll begin with. While it doesn't really do much for us, simply repeating the steps for a second (and subsequent) will result in a working solution. Other guides lay down the steps with two hosts already in mind, and teasing apart the pieces to apply it to your situation might be more difficult.
Because it is possible to set up content switching with a single host (the degenerate case), this is the method we'll begin with. While it doesn't really do much for us, simply repeating the steps for a second (and subsequent) will result in a working solution. Other guides lay down the steps with two hosts already in mind, and teasing apart the pieces to apply it to your situation might be more difficult.
Groundwork
Some planning must be done prior to doing this setup. The first is a set of IP addresses that you'll need to have handy. This post will use the following addresses; substitute them with your own:
| Host | IP |
|---|---|
| CS Virtual Server | 192.168.106.37 |
| Target Server A | 192.168.106.38 |
| Target Server B | 192.168.106.39 |
Enable Features
The bare-bones install of the NetScaler has a number of features enabled, but the ones we need for content switching are disabled. Open the System configuration tree and select Settings
Select "Configure basic features" and make sure the following features are enabled (checked):
- Load Balancing
- Content Switching
If you selected "Traffic Management" in the left menu before and after enabling the feature, this is what you'd see:
![]() |
| Default, features disabled |
![]() |
| LB and CS enabled |
Begin the setup by expanding "Load Balancing" under "Traffic Management" and select "Servers":
Then switch to the Services option
and create a protocol-specific entry for the server, including a monitor
(I like to use http because it doesn't require any customization; a custom http-ecv monitor can be created to check for the explicit function of the target server, but that's beyond the scope of this series).
I also recommend using a naming convention that includes the type of object you're creating ('svc' for the service) and the protocol it's tied to ('http'); that will make it more obvious where a given object comes from when you see them bound in other places.
Switch to the Virtual Servers menu
and click [Add...] to build the virtual server.
Make sure you uncheck the "Directly Addressable" option; this eliminates the need to give the virtual server its own address (we want to give an address to the Content Switching virtual server) and select the service we just created.
Switch to the Content Switching menu and select "Policies"
Click [Add...] to create a policy to trigger sending the traffic based on the hostname used in the HTTP header.
Select the Virtual Servers option under Content Switching
and click [Add..] to create a new virtual server.
This server gets the IP address to which we'll be forwarding traffic.
Click "Insert Policy" to insert a new policy
Select the new policy from the drop-down, then pull down the list of targets, selecting the new load balancing server. You will get a warning about the "Goto Expression"
Select [Yes], then [Create] to make the server.
At this point, your setup should function for the first server you configured!
Now: go back to the step for creating the outside server and repeat except for creating a new Content Switching server.
Now: Open the existing server
and add another policy, using the new server's policy and LB virtual server entry:
In the center section, click [Add...] and create the server. The "Server Name" is an identifier used in the NetScaler; it does NOT have to be the FQDN or short name for the server.
Then switch to the Services option
and create a protocol-specific entry for the server, including a monitor
(I like to use http because it doesn't require any customization; a custom http-ecv monitor can be created to check for the explicit function of the target server, but that's beyond the scope of this series).
I also recommend using a naming convention that includes the type of object you're creating ('svc' for the service) and the protocol it's tied to ('http'); that will make it more obvious where a given object comes from when you see them bound in other places.
Switch to the Virtual Servers menu
and click [Add...] to build the virtual server.
Make sure you uncheck the "Directly Addressable" option; this eliminates the need to give the virtual server its own address (we want to give an address to the Content Switching virtual server) and select the service we just created.
Switch to the Content Switching menu and select "Policies"
Click [Add...] to create a policy to trigger sending the traffic based on the hostname used in the HTTP header.
and click [Add..] to create a new virtual server.
This server gets the IP address to which we'll be forwarding traffic.
Click "Insert Policy" to insert a new policy
Select the new policy from the drop-down, then pull down the list of targets, selecting the new load balancing server. You will get a warning about the "Goto Expression"
Select [Yes], then [Create] to make the server.
At this point, your setup should function for the first server you configured!
Now: go back to the step for creating the outside server and repeat except for creating a new Content Switching server.
Now: Open the existing server
and add another policy, using the new server's policy and LB virtual server entry:
You can test this internally by either updating your DNS server entries or adding a line to your machine's HOSTS file:
Point your browser at http://serverA after you make the change, and voila!, you get to the target. Switch to http://serverB, and you get that target instead.
192.168.106.37 serverA serverB
Once you've verified the functionality from the inside, update the forwarding on your NAT firewall and test using an outside address (eg, use a cell phone that's not on your home WiFi).
Parts in this series:
- Intro to using a reverse proxy
- Getting NetScaler VPX going in your lab
- Intro to Content Switching in the NetScaler
- Configure a basic content-switching application (HTTP) (this post)
- Configure an advanced content-switching application (SSL-SSL proxy)

















































