Export policy evaluation intermittently fails for hostnames
Applies to
- ONTAP 9
- NFS
- Export Policies
Issue
- Clients will occasionally get denied access when export policies are re-evaluated
- This may occur when changing the existing export policy rules or clearing the access cache
- This only impacts clients that gain access via hostname-based clientmatch rules (ip-based clientmatch rules are unaffected)
- The ns-switch host database is configured with the specific order of
files,dns
- Packet traces of this behavior do not show ONTAP querying DNS to resolve the hostname when the resolved hostname is not already cached