Wednesday, 19 December 2018

ONTAP 8.3 and later does NOT use node_mgmt LIF for external services such as DNS, LDAP etc.

In Data ONTAP 8.3 or later, each SVM initiates outbound connections to name servers using its own LIFs and routes, not those of the node_mgmt LIF as in previous releases.

IMPORTANT information for ONTAP 8.3 and later customers:
SVMs (vserver) lacking a specific route, and also having multiple default routes containing the same routing metric (possibly from separate routing groups before the upgrade) could fail to reach the name servers if any of the specified gateways do not provide a path to those servers as the node_mgmt_LIF can no longer be used to reach such services.

Protocols that could be affected:
Any protocol that relies on name services (LDAP, NIS, DNS, Active Directory) is susceptible, for example : NFS and CIFS data protocols are particularly susceptible.


Symptoms:
1. CIFS: clients cannot reach share names.
2. AD: SVM fails to join AD.
3. NFS: Clients cannot mount exports that include host-names instead of IP.

Workaround/Solution:
1. If each gateway can reach all name services, then no changes are needed.
2. Ensure that the correct default route with access to all names services has the lowest metric.
3. Create a specific routing group and add a specific route to the destination.


Courtesy: KBID:1000317

No comments:

Post a Comment