CIFS authentication fails due to NetLogon and DNS timeouts on ONTAP
Applies to
- ONTAP 9
- SMB/CIFS with Active Directory (AD)
Issue
- CIFS/SMB authentication intermittently fails on an ONTAP SVM.
- AutoSupport shows secd errors indicating TCP timeouts to AD/DCs on port 445, NetLogon servers not reachable, and DNS queries timing out as following:
[node_01: secd: secd.conn.auth.failure:notice]: Vserver (SVM1) could not make a connection over the network to server (ip 192.168.0.5, port 445). Error: Operation timed out ().[node_01: secd: secd.conn.auth.failure:notice]: Vserver (SVM1) could not make a connection over the network to server (ip 192.168.0.1, port 445). Error: Operation timed out ().[node_01: secd: secd.netlogon.noServers:EMERGENCY]: None of the Netlogon servers configured for Vserver (SVM1) are currently accessible via the network.[node_01: secd: secd.cifsAuth.problem:error]: vserver (SVM1) General CIFS authentication problem. Error: User authentication procedure failed CIFS SMB2 Share mapping - Client Ip = 192.168.0.2 [ 0 ms] Login attempt by domain user abc\admin' using NTLMv2 style security [ 2005] TCP connection to ip 192.168.0.5, port 445 failed: Operation timed out. [ 2081] Unable to connect to NetLogon service on ctc005s.ad.co.jp (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER) [ 4084] TCP connection to ip 192.168.0.1, port 445 failed: Operation timed out. [ 4087] Unable to connect to NetLogon service on ad.com.cn (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER) [ 4094] No servers available for MS_NETLOGON, vserver: 7, domain: ad.co.jp. **[ 4099] FAILURE: Unable to make a connection (NetLogon:AD.CO.JP), Result: RESULT_ERROR_SECD_NO_SERVER_AVAILABLE [ 4110] CIFS authentication failed[node_01: secd: secd.dns.server.timed.out:error]: DNS server 192.168.0.5 did not respond to vserver = SVM1 within timeout interval.[node_01: secd: secd.dns.srv.lookup.failed:error]: DNS server failed to look up service (xxx.xxx.xxx) for vserver (SVM1) with error (Operation timed out).[node_01: secd: secd.cifsAuth.problem:error]: vserver (SVM1) General CIFS authentication problem. Error: User authentication procedure failed CIFS SMB2 Share mapping - Client Ip = 192.168.0.2 [ 0 ms] Login attempt by domain user abc\admin' using NTLMv2 style security [ 0] No servers available for MS_NETLOGON, vserver: 7, domain: ad.co.jp. [ 53] Hostname found in Name Service Cache [ 5056] Failed to connect to 192.168.0.5 for DNS via Source Address 192.169.0.3: Operation timed out [ 7059] Failed to connect to 192.168.0.1 for DNS via Source Address 192.169.0.3: Operation timed out **[ 7070] FAILURE: Unable to contact DNS to discover domain controllers. [ 7070] Unable to make a connection (NetLogon:AD.CO.JP), Result: RESULT_ERROR_DNS_CANT_REACH_SERVER [ 7071] CIFS authentication failed [ 7071] Retry requested, but the retry window (7000 ms) has expired; giving up.
- The latency of Ping is more than 1000ms which is very high.
