Skip to content

Network Grouping

PerformanceGuard automatically places computers that belong to the same IP subnet in the same group. This type of group is called a network group because only computers that belong to a certain IP network can be a member of this group.

Only PerformanceGuard can place computers in these groups, based on the IP addresses and subnet masks of computers that have PerformanceGuard agents installed. If a computer is moved to another subnet (that is the computer’s IP address changes), PerformanceGuard will automatically move the computer to the corresponding network group.

You can influence the size of the network groups with network grouping rules in ADMINISTRATION → Computer Grouping → Network Grouping. Each rule has:

  • Network: a network address and a subnet mask length, for example 10.0.0.0/8. The rule applies to computers with an IP address in this network.
  • Min length and Max length: the shortest and the longest subnet mask length that network groups for these computers can have.

How computers are placed in network groups

Section titled “How computers are placed in network groups”

This section describes what PerformanceGuard does to place computers that have PerformanceGuard agents installed in the correct network groups.

  1. The PerformanceGuard agent reports the configured IP address and subnet mask length of a computer.
  2. PerformanceGuard calculates the network address of the computer by applying the subnet mask to the IP address.
  3. PerformanceGuard checks whether the IP address of the computer is contained in the network of a network grouping rule.
  4. There may be more than one rule that matches the IP address. In that case PerformanceGuard uses the most specific rule, that is the rule with the longest subnet mask.
  5. If a match is found, PerformanceGuard changes the subnet mask length of the computer so that it’s between the rule’s Min length and Max length, and calculates the network address again.
  6. PerformanceGuard looks for an existing network group with exactly this network address and subnet mask length. If it doesn’t find one, it creates a new network group with the network address and subnet mask.
  7. The computer becomes a member of the network group matching the network address and subnet mask length.

Example:

  1. A computer has the IP address 10.1.2.193 (193 in base 10 equals 1100 0001 in base 2) with subnet mask length 26.
  2. Then the network address of the computer must be 10.1.2.192 (the network 10.1.2.192 to 10.1.2.255).
  3. A network grouping rule exists for the network 10.0.0.0/8 with a Max length of 24.
  4. The IP address 10.1.2.193 fits into the network 10.0.0.0/8, so PerformanceGuard must apply the max length of 24 to the network address of the computer. This yields 10.1.2.0/24.
  5. PerformanceGuard now looks for an existing network group 10.1.2.0/24. If it doesn’t find one, it creates a new network group 10.1.2.0/24.
  6. The agent becomes a member of the network group 10.1.2.0/24.

Computers that run AutoSteps script executors are placed in separate network groups. The names of these groups end with - AutoSteps.

Computers behind a NAT (Network Address Translation)-enabled router usually have IP addresses in private address ranges, such as 192.168.0.0/16 and 10.0.0.0/8. Because of this you may experience that agents on different physical locations have the same private IP addresses configured. To avoid conflicts, PerformanceGuard will group the agents based on the public IP address of the router instead.

The public IP address of the router is defined as the client endpoint of the TCP communication between the server that runs PerformanceGuard and the PerformanceGuard agent. If you have several NAT-enabled routers behind each other, PerformanceGuard will only recognize the first public router.

Whether a router is NAT-enabled or not is decided by comparing the client endpoint IP address and the reported agent network. If the client endpoint IP address isn’t in the network that the agent reports, PerformanceGuard assumes that Network Address Translation has taken place.

In PerformanceGuard, the network groups are called something like Net 123.76.76.42/192.168.101.0/24, which means computers located on private subnet 192.168.101.0/24 behind a router with a public IP address of 123.76.76.42.

The following describes the complete process of putting computers behind NAT-enabled routers into the correct network groups:

  1. The PerformanceGuard agent reports the configured IP address and subnet mask length of the computer when started.

  2. The network address of the computer is calculated by applying the subnet mask to the IP address.

  3. PerformanceGuard checks whether the IP address of the computer is contained in the network of a network grouping rule.

  4. There may be more than one rule that matches the IP address. In that case PerformanceGuard uses the most specific rule.

  5. If a match is found, PerformanceGuard changes the subnet mask length of the computer so that it’s between the rule’s Min length and Max length.

  6. The PerformanceGuard frontend server knows the socket address of the TCP connection with the PerformanceGuard agent. If the socket IP address isn’t in the network that the computer reports, it’s assumed that the computer is behind a NAT-enabled router. The IP address of the NAT router is assumed to be the socket IP address.

  7. If the computer is behind a NAT-enabled router, PerformanceGuard checks the network grouping rules again. This time, PerformanceGuard checks for a rule whose network contains the NAT router IP address.

  8. If a match is found:

    1. PerformanceGuard sets a network address based on the public router address, and uses the rule’s Max length as the subnet mask length.
    2. PerformanceGuard looks for an existing network group with exactly this network address and subnet mask length. If it doesn’t find one, it creates a new network group with the network address and subnet mask.
    3. The computer becomes a member of the network group matching the network address and subnet mask length.
  9. If a match isn’t found, a special type of network group is created where the socket/router IP address is part of the network address.

    1. PerformanceGuard looks for an existing network group with exactly this router address, network address and subnet mask length.
    2. If it doesn’t find one, it creates a new network group with the router address, network address and subnet mask.
    3. The computer becomes a member of the network group matching the network address and subnet mask length.
  1. The Citrix server reports the IP address of the ICA Client, but unfortunately not the subnet mask.
  2. The network address is set to the IP address with a subnet mask length of 32.
  3. PerformanceGuard checks whether the IP address of the ICA Client is contained in the network of a network grouping rule.
  4. There may be more than one rule that matches the IP address. In that case PerformanceGuard uses the most specific rule.
  5. If a match is found, PerformanceGuard changes the network address and subnet mask of the ICA Client to comply with the rule.
  6. PerformanceGuard looks for any existing network group that’s large enough to contain the network address and subnet mask.
  7. If any match is found, the network group with the highest subnet mask length (that is the smallest and most specific network) is chosen, and data from the ICA Client will belong to this group.
  8. If no match is found, a new network group is created from the ICA Client IP address. If no network grouping rule matched, the subnet mask length is still 32, and it’s changed to a default value of 24 before the group is created.

Let’s look at an example:

  1. The ICA Client has the IP address 10.1.2.193.
  2. The network address of the ICA Client is set to be 10.1.2.193/32.
  3. A network grouping rule exists for the network 10.0.0.0/8 with a Max length of 16.
  4. The IP address 10.1.2.193 fits into the network 10.0.0.0/8, so the max length of 16 is applied to the network address of the ICA Client. This yields 10.1.0.0/16.
  5. PerformanceGuard now looks for any existing network group that contains the network 10.1.0.0/16.
  6. If a match is found, the ICA Client belongs to that network group, for example 10.1.0.0/16.
  7. If a match isn’t found, a new network group 10.1.0.0/16 is created, and the ICA Client will belong to the new group.

Here’s another example:

  1. The ICA client has the IP address 10.1.2.193.
  2. The network address of the ICA Client is set to be 10.1.2.193/32.
  3. A network grouping rule exists for the network 10.2.0.0/16 with a Max length of 16.
  4. The IP address 10.1.2.193 doesn’t fit any network grouping rule.
  5. PerformanceGuard now looks for any existing network group that contains the network 10.1.2.193/32.
  6. If a match is found, the ICA Client belongs to that network group, for example 10.1.0.0/16.
  7. If a match isn’t found, a new network group 10.1.2.0/24 is created, and the ICA Client will belong to the new group.