NFS client retains read-write access despite restrictive export-policy rule
Applies to
- ONTAP 9
- NFSv3
- Export-policy
Issue
- The export policy rule is configured with read-only (RO) intent
- The NFS client 192.168.0.4 continues to have read-write (RW) access
- The export policy contains multiple rules
- Unmounting and remounting the export on the client does not change the access behavior
Example:Vserver: svm01Policy Name: policy01Rule Index: 1Access Protocol: any
List of Client Match Hostnames, IP Addresses, Netgroups, or Domains:192.168.0.1,192.168.0.2,192.168.0.3
RO Access Rule: anyRW Access Rule: anyUser ID To Which Anonymous Users Are Mapped: 0Superuser Security Types: noneHonor SetUID Bits in SETATTR: trueAllow Creation of Devices: true
Vserver: svm01Policy Name: policy01Rule Index: 2Access Protocol: any
List of Client Match Hostnames, IP Addresses, Netgroups, or Domains:192.168.0.4
RO Access Rule: anyRW Access Rule: neverUser ID To Which Anonymous Users Are Mapped: 65534Superuser Security Types: noneHonor SetUID Bits in SETATTR: trueAllow Creation of Devices: true
