Skip to main content
NetApp Knowledge Base

NFS mount points not accessible when using netgroups from LDAP

Views:
449
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • ONTAP 9 and later
  • NFS
  • Netgroups

Issue

  • NFS mount fails when using netgroup as client match in export policy with below error on client:
mount.nfs: access denied by server while mounting nfs-server-name:/mount-point
 
  • Export-policy rule includes netgroup and ns-switch configured to use files,ldap and nis for netgroup.
  • Export policy check access fails:
cdot_vsim_9_8::> check-access -vserver vs1 -volume vol1 -client-ip 10.x.2.x -authentication-method sys -protocol nfs3 -access-type read-write
(vserver export-policy check-access)
Policy    Policy       Rule
Path                          Policy     Owner     Owner Type  Index Access
----------------------------- ---------- --------- ---------- ------ ----------
/                             default    vs1_root    volume          1 read
/vol1                         policy-name   vol1      volume          0 denied
2 entries were displayed.
 
  • "netgrpcheck" shows client is not member of netgroup added in export policy rule.
cdot_vsim_9_8::*> getxxbyyy netgrpcheck -node node1 -vserver vs1 -netgroup netgroup1 -clientIP 10.x.2.x -enable-domain-search-flag true -trust-any-source false -show-source true
Client 10.x.2.x is not a member of netgroup netgroup1
Searched using NETGROUP_BYHOST_CACHE
Source used for lookup: NS Cache
 
  • Trace shows mount call fails with error "ERR_ACCESS" (access denied) for client IP 10.x.2.x.
No     Date     Source       Destination  Proto     Info
57     01:17:01 10.x.2.x     10.x.2.x     MOUNT     V3 MNT Call (Reply In 59) /vol1
59     01:17:01 10.x.2.x     10.x.2.x     MOUNT     MNT Reply (Call In 57) Error:ERR_ACCESS

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.