Load Balancing AD FS v3.0 with WAP across Citrix Netscaler

***I know this is not a FIM question, but as it's ADFS it belongs under IDM but there is no option for that.***

I am trying to get AD FS 3.0 up and working being load balanced through a pair of physical Citrix NetScaler ADC's. The load balancing part of the AD FS side is working fine, it is creating the trust relationship between the WAP's (which are in the DMZ) and the AD FS servers (which are in the LAN) that are being load balanced across the NS.

So the topology is 2*WAP in the DMZ and 2*ADFS in the LAN. There are two vServers one for the DMZ and LAN side, there is a NAT rule configured to forward traffic from the external IP to the DMZ vServer for the WAP's. Load balancing is working across the LAN vServer as I can browse to the ADFS URL's using the vServer IP. 

The real issue is when I try to run the WAP trust relationship wizard to pair the WAP's and ADFS servers, there is an entry in the hosts file configured with the ADFS service name which points to the IP of the vServer in the LAN.

I also know this is not a Citrix forum but the NS is configured with a service pointing to each of the four servers, I have tried using the following protocols SSL_TCP, SSL_Bridge and SSL. The result is the same for all of the protocols, there does not have to be SSL offloading done on the WAP/ADFS

The error on the WAP is simply cannot save the configuration there is nothing in the events.

I know ADFS has changed in v3.0 and in 2012 it used to be like load balancing any other SSL website.

June 10th, 2015 4:25am

Hello Ryan,

I have had the same issue today and fixed it with temporary replacing the vServers IP in the Hostfile through the IP of my first ADFS Farm Server.

Cheers

Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 1:49pm

Hello Ryan,

I have had the same issue today and fixed it with temporary replacing the vServers IP in the Hostfile through the IP of my first ADFS Farm Server.

Cheers

June 11th, 2015 5:49pm

Try this ADFS forum:

https://social.msdn.microsoft.com/Forums/vstudio/en-US/home?forum=Geneva

Free Windows Admin Tool Kit Click here and download it now
June 12th, 2015 2:03am

Julian,

Yeah I have also tried that, I am on a call with MS today.

Did you get it fixed? I'll keep you posted if we get it sorted.

Ryan

June 12th, 2015 4:15am

Hello Ryan,

sorry for this late answer! Yes, I have fixed it. Pointing the ADFS URL directly to the IPs of the internal ADFS servers worked for me.

On the WAPs you do not have to point the URL on to the internal ADFS vServer. WAP is able to monitor the internal ADFS servers by itself and redirects allways to the healthy ADFS Server.

Julian


Free Windows Admin Tool Kit Click here and download it now
June 18th, 2015 7:26am

Thanks Julian, yeah got it sorted in the end.

Written a post on the configuration if anyone else is interested;

http://blog.ryanbetts.co.uk/2015/06/configuring-citrix-netscaler-to-load.html

June 22nd, 2015 7:25am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics