Even after removing client IP from local netgroup file client still shows part of netgroup
Applies to
- ONTAP 9
- Local netgroups
Issue
- Even after removing the client IP from local netgroup file, client is still able to mount volumes.
- Netgroup check shows client still part of netgroup.
::*> getxxbyyy netgrpcheck -vserver svm -netgroup netgroup -clientIP 10.xx.xx.xxx -show-source true -node node1
(vserver services name-service getxxbyyy netgrpcheck)
Success. Client 10.xx.xx.xx is member of netgroup netgroup1
Searched using NETGROUP_BYHOST
Source used for lookup: LDAP
- nsswitch has files and LDAP as source for netgroup.
::*> ns-switch show -vserver svm
(vserver services name-service ns-switch show)
Source
Vserver Database Order
--------------- ------------ ---------
svm hosts files,
dns
svm group files
svm passwd files
svm netgroup files,
ldap
svm namemap files,
ldap
5 entries were displayed.