Professional Documents
Culture Documents
Description
Description
This article describes the steps that should be performed to configure netgroups in clustered
Data ONTAP.
Procedure
Step
In clustered Data ONTAP, netgroups can be used to segment and organize hosts in groups.
Export policy rules can be created on a per netgroup basis. These netgroups can be stored
locally on the cluster (one netgroup table per Vserver) or pulled dynamically using NIS.
Clustered Data ONTAP only supports the host part of a netgroup tuple, and expects the other
two parts of the tuple to be empty.
Note: When using netgroups, the hostname in the netgroup of the relevant clients need to
correctly resolve to the ip address of the client, for a netgroup to affect a client. Always test if
the host entries in a netgroup match the hostname in a DNS lookup for a certain client ip.
Host lookup for hosts stored in netgroups is done through the Vserver specific DNS settings.
CIFS client access can be limited through the use of netgroups in clustered Data ONTAP.
However, with regards to CIFS, clustered Data ONTAP only supports netgroups for export
https://kb-stage.netapp.com/support/index?page=content&id=1014146&pmv=print&impre... 10/5/2016
NetApp Knowledgebase - How to configure netgroups in clustered Data ONTAP Page 2 of 4
policy rule authentication. As export policies are tied to volumes, not shares, this means that
netgroup based access restrictions for CIFS are volume based restrictions in cDOT, not
share restrictions (unlike 7-Mode). If you want export policies with netgroups to determine
access and compliment ACL-based access for CIFS, make sure you change the advanced
CIFS option required for this to true on your relevant vsever. See below for the relevant
option, you need to set this to yes to have export policies determine CIFS access for a
vserver.
cm3240c-rtp::> set advanced
Warning: These advanced commands are potentially dangerous; use them only when
directed to do so by NetApp personnel.
Do you want to continue? {y|n}: y
Mode?
In the example, the file netgroup.file is stored on a Web server. The contents of the
netgroup file are as below:
groupa(hosta,,) (hostb,,) (hostc,,)
There are three important caveats for importing netgroups stored externally:
https://kb-stage.netapp.com/support/index?page=content&id=1014146&pmv=print&impre... 10/5/2016
NetApp Knowledgebase - How to configure netgroups in clustered Data ONTAP Page 3 of 4
Step
Disclaimer
COMPANY SALES
Our Story How To Buy
News@NetApp Find a Partner
Events US Public Sector Contracts
Customer Stories E-based OEM Partners
Investors NetApp Capital Solutions
Careers
LEGAL RESOURCES
Privacy & Cookie Policy Subscriptions
Copyright Library
Trademarks Site Map
Community Terms of Use
Slavery and Human Trafficking Statement
https://kb-stage.netapp.com/support/index?page=content&id=1014146&pmv=print&impre... 10/5/2016
NetApp Knowledgebase - How to configure netgroups in clustered Data ONTAP Page 4 of 4
Accessibility
© 2016 NetApp
https://kb-stage.netapp.com/support/index?page=content&id=1014146&pmv=print&impre... 10/5/2016