Performing Basic Citrix ADC Operations
-
Log on to a Citrix ADC Appliance
-
Log on to a Citrix ADC appliance that has two factor authentication configured for system users
-
Enable Citrix ADC Features and Modes
-
Save Citrix ADC Configurations
-
Kill a system Session
-
Disconnect from the Citrix ADC Appliance
Log on to a Citrix ADC Appliance
-
When restricted timeout param is enabled, NITRO, by default, uses the timeout value that is configured for the logged in user. You can customize this value but it must be limited to the value specified for the user. If no value is specified for the user, the default timeout value of 15 minutes is used.
-
When restricted timeout param is not enabled, NITRO uses the default value of 30 minutes as session timeout.
-
Using REST APIs through HTTPYou must specify the username and password in the login object. The session ID that is created must be specified in the request header of all further operations in the session.
Notes:
-
You must have a user account on the appliance to log on to it. The configuration operations that you can perform are limited by the administrative roles assigned to your account.
-
To ensure secure communication, use the HTTPS protocol in NITRO requests.
-
Instead of creating a NITRO session, you can log on to the Citrix ADC appliance while performing individual operations. To do this, you must specify the username and password in the request header of the NITRO request as follows:
-
X-NITRO-USER:<username\>
-
X-NITRO-PASS:<password\>
-
Content-Type:application/json
-
-
RequestHTTP Method:POST
URL: http://10.102.29.60/nitro/v1/config/login
Request Headers: Content-Type:application/json
Request Payload:
{
"login":
{
"username":"admin",
"password":"verysecret"
}
}
-
ResponseHTTP Status Code on Success:201 Created
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.
Response Header:
Set-Cookie:NITRO_AUTH_TOKEN=<tokenvalue>;
path=/nitro/v1
-
Using REST APIs through SDKsYou must create an object of the com.citrix.netscaler.nitro.service.nitro_service class by specifying the Citrix ADC IP (NSIP) address and the protocol to connect to the appliance (HTTP or HTTPS). You then use this object and log on to the appliance by specifying the user name and the password of the Citrix ADC administrator.
Note:
-
For the python SDK, the package path is of the form nssrc.com.citrix.netscaler...
-
You must have a user account on that appliance. The configuration operations that you perform are limited by the administrative roles assigned to your account.
Java - Sample code to establish session
//Specify the Citrix ADC appliance IP address and protocol
nitro_service ns_session = new nitro_service("10.102.29.60","https");
//Specify the login credentials
ns_session.login("admin","verysecret",3600);
.NET - Sample code to establish session
//Specify the Citrix ADC appliance IP address and protocol
nitro_service ns_session = new nitro_service("10.102.29.60","https");
//Specify the login credentials
ns_session.login("admin","verysecret",3600);
Python - Sample code to establish session
# Specify the Citrix ADC appliance IP address and protocol
ns_session = nitro_service("10.102.29.60","https")
# Specify the login credentials
ns_session.login("admin","verysecret",3600)
Disable SSL Checks
-
Using REST APIs through SDKsDisable these validations as shown in the following sample codes.
Java - Sample code for disabling SSL checks
ns_session.set_certvalidation(false);
ns_session.set_hostnameverification(false);
.NET - Sample code for disabling SSL checks
ns_session.certvalidation = false;
ns_session.hostnameverification = false;
Python - Sample code for disabling SSL checks
ns_session.certvalidation = false
Log on to a Citrix ADC appliance that has two factor authentication configured for system users
Steps to log on to a Citrix ADC appliance that has two factor authentication configured
-
Send user credentials for the first level authentication
-
Send user credentials for the second level authentication
Send user credentials for the first level authentication
login API object to send the username and first password to the Citrix ADC appliance for first level authentication.
Request structure
| Request field | Value |
|---|---|
| HTTP Method | POST |
| URL | http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/login |
| Request Headers | Content-Type: application/x-www-form-urlencoded |
| Request Payload | {"login":{"username":"<username>","password":"<first password>"}} |
Send user credentials for the second level authentication
loginnextfactorresponse API object to send the following information to the Citrix ADC appliance for second level authentication.
-
Second password (next factor password)
-
Session ID (received as part of first level authentication)
0 and a message of Done indicate that the two factor authentication process is completed with success. The session ID received must be specified in the request header of all further operations in the session.
Request structure
| Request field | Value |
|---|---|
| HTTP Method | POST |
| URL | http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/loginnextfactorresponse |
| Request Headers | Content-Type: application/x-www-form-urlencoded |
| Request Payload | {"loginnextfactorresponse":{"nextfactorpassword":"<second password>","sessionid":"<session id>"}} |
Sample configuration
| Steps | Curl requests | Response |
|---|---|---|
| Send user credentials for the first level authentication | curl -X POST -H "Content-Type:application/json" http://10.102.29.30/nitro/v1/config/login -d '{"login":{"username":"exampleusername","password":"examplepassword"}}' |
{"errorcode": 3816, "message": "Nextfactor Login [singleauth_password]", "severity": "ERROR", "sessionid":"##73EF2C4487554615539D52FDAAF5D1"} |
| Send user credentials for the second level authentication | curl -X POST -H "Content-Type:application/json" http://192.0.0.33/nitro/v1/config/loginnextfactorresponse -d '{"loginnextfactorresponse":{"nextfactorpassword":"examplesecondpassword"},"sessionid":"##73EF2C4487554615539D52FDAAF5D1"}’ |
{ "errorcode": 0, "message": "Done", "severity": "NONE", "sessionid": "##73EF2C4487554615539D52FDAAF5D1" } |
Enabling Citrix ADC Features and Modes
-
Using REST APIs through HTTPTo disable a feature or mode, in the URL query string, specify the action as "disable".
-
RequestHTTP Method:POST
URL: http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/nsfeature?action=enable
Request Headers:
Request Payload:
{
"nsfeature":
{
"feature":
[
"LB",
"CS"
]
}
}
-
ResponseHTTP Status Code on Success:200 OK
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.
-
RequestHTTP Method:POST
URL: http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/nsmode?action=enable
Request Headers:
Request Payload:
{
"nsmode":
{
"mode":
[
"L2",
"FR"
]
}
}
-
ResponseHTTP Status Code on Success:200 OK
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.
Saving Citrix ADC Configurations
-
Using REST APIs through HTTPTo save the configurations: -
RequestHTTP Method:POST
URL: http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/nsconfig?action=save
Request Headers:
Request Payload:
{
"nsconfig":
{}
}
-
ResponseHTTP Status Code on Success:200 OK
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.
Killing a System Session
-
Using REST APIs through HTTPFor example, to kill a system session that has ID as 311: -
RequestHTTP Method:POST
URL: http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/systemsession?action=kill
Request Headers:
Request Payload:
{
"systemsession":
{
"sid":"311"
}
}
-
ResponseHTTP Status Code on Success:200 OK
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.
Disconnecting from the Citrix ADC Appliance
-
Using REST APIs through HTTPTo logout of the Citrix ADC appliance: -
RequestHTTP Method:POST
URL: http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/logout
Request Headers:
Request Payload:
{
"logout":{}
}
-
ResponseHTTP Status Code on Success:201 Created
HTTP Status Code on Failure: 4xx <string> (for general HTTP errors) or 5xx <string> (for Citrix-ADC-specific errors). The response payload provides details of the error.