Active IQ Wellness Incident: Many secd.rpc.authRequest.blocked alerts after upgrading to ONTAP 9.12+
Applies to
- ONTAP 9.12+
- CIFS/SMB
Risk Summary
- One or more CIFS/SMB clients get access denied due to sending a wrong password at the rate of over 30 per 1 minute.
- ONTAP 9.12.1+ logs the EMS entry
secd.rpc.authRequest.blocked
and denies access from the IP for 1 minute.
Example:
secd.rpc.authRequest.blocked: Too many CIFS authentication attempts with wrong password from client "X.X.X.X" on Vserver "vserver".