<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>NetApp Community</title>
        <link>https://community.netapp.com/community/</link>
        <pubDate>Tue, 22 Sep 2026 02:04:08 +0000</pubDate>
        <language>en</language>
            <description>NetApp Community</description>
    <atom:link href="https://community.netapp.com/community/discussions/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>AFF A220 Inband ACP issues.</title>
        <link>https://community.netapp.com/community/discussion/468395/aff-a220-inband-acp-issues</link>
        <pubDate>Mon, 21 Sep 2026 06:36:14 +0000</pubDate>
        <category>AFF, AFX, ASA, &amp; FAS</category>
        <dc:creator>Draanee</dc:creator>
        <guid isPermaLink="false">468395@/community/discussions</guid>
        <description><![CDATA[<p>Good day Fellow Netapp Users,<br /><br />
I have a netapp with an interesting error:<br /><br />
Inband ACP is active on Port 0b keeps sporadically failing.</p><p>Node01 hat an hard reboot error of the ACP module, this was also visible in the shelf-log-iom log.</p><p>With this error we decided to replace node01 but the issue presists with the sporadic ACP errors. <br /><br />
We restarted both nodes both BMC and turned ACP off and on.<br /><br />
Since the issue presists we are thinking to replace the node02, since the system has no expansion shelfes. If the issue then presits my only thought is that the midplane of the Controller shelf is faulty. </p><p>System has one Controller shelf and is hosting CIFS/NFS <br /><br />
Any other ideas or would you also replace the other node? </p>]]>
        </description>
    </item>
    <item>
        <title>Azure VM Sizes Not Available for CVO and CVOHA</title>
        <link>https://community.netapp.com/community/discussion/468396/azure-vm-sizes-not-available-for-cvo-and-cvoha</link>
        <pubDate>Mon, 21 Sep 2026 08:01:24 +0000</pubDate>
        <category>Cloud</category>
        <dc:creator>Sharmila2601</dc:creator>
        <guid isPermaLink="false">468396@/community/discussions</guid>
        <description><![CDATA[<p></p><p>Hi Team,<br />
We are currently setting up the IHCAZ CV4 lab environment in Azure. The lab guide specifies Standard_E4ds_v4 for CVO and Standard_E8ds_v4 for CVOHA. However, Azure has informed us that these VM sizes are currently under growth control and are not available for our subscription. Could you please confirm whether any other supported Azure VM sizes with similar specifications can be used as alternatives for CVO and CVOHA?</p><p>If yes, could you please recommend the appropriate VM sizes that we can use?</p><p></p><p>Thank you.</p>]]>
        </description>
    </item>
    <item>
        <title>Expanding C-190 aggregates</title>
        <link>https://community.netapp.com/community/discussion/468388/expanding-c-190-aggregates</link>
        <pubDate>Thu, 17 Sep 2026 14:30:51 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>sc2111</dc:creator>
        <guid isPermaLink="false">468388@/community/discussions</guid>
        <description><![CDATA[<p>I'm really new on ONTAP and got the task of expanding the aggregates on C-190 NETAPP storage.<br />
I need help in put down the correct steps to expand the aggregates and the volumes presented to esxi cluster.<br />
Can anyone help on this ?</p><p>thanks</p>]]>
        </description>
    </item>
    <item>
        <title>VDDK Is No Longer Available. NetApp’s Shift Toolkit Never Needed It</title>
        <link>https://community.netapp.com/community/discussion/468394/vddk-is-no-longer-available-netapp-s-shift-toolkit-never-needed-it</link>
        <pubDate>Sat, 19 Sep 2026 09:00:40 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>NiMo</dc:creator>
        <guid isPermaLink="false">468394@/community/discussions</guid>
        <description><![CDATA[<p>Over the past week, I've received several messages from customers asking the same question: <em>Does the removal of public VDDK downloads affect NetApp Shift Toolkit migrations?</em></p><p>It's a valid concern. Many migration solutions in the market have historically relied on VMware's Virtual Disk Development Kit (VDDK) as a core component for moving virtual machine data between hypervisor platforms. With public access to VDDK now restricted, organizations are understandably assessing the potential impact on their migration plans.</p><p>The answer is simple: <strong>No.</strong></p><p>Shift Toolkit has <strong>never relied</strong> on VDDK, qemu-img or storage array copy offload mechanisms such as VAAI XCOPY/vmkfstools as part of its migration architecture. As a result, recent changes surrounding VDDK availability do not impact migration workflows, existing projects, or our product roadmap.</p><h3 data-id="why-this-matters">Why This Matters</h3><p>For years, VDDK has been a common component used by VM migration solutions to access and transfer virtual machine data. As a result, many organizations have found themselves exposed to changes beyond their control when those dependencies become restricted, altered, or unavailable.</p><p>The recent VDDK situation is a reminder that critical migration projects should not hinge on a single hypervisor vendor's SDK or utility. When a migration platform depends on external tooling, unexpected changes can introduce complexity, delays, or additional operational overhead.</p><h3 data-id="the-shift-toolkit-difference">The Shift Toolkit Difference</h3><p>For Shift Toolkit customers, the recent VDDK changes are not triggering product redesigns, engineering workarounds, or alternative migration workflows.</p><p>That's because Shift Toolkit was designed from day one without a dependency on VDDK, qemu-img or storage array copy offload mechanisms.</p><p>While some migration vendors may now be evaluating alternative approaches following the VDDK changes or leaning more heavily on storage copy offload technologies such as VAAI XCOPY/vmkfstools, our engineering team remains focused on what we've always focused on: delivering new hypervisor choice, enhancing migration capabilities, and improving the customer experience.</p><h3 data-id="what-s-new-in-netapp-shift-toolkit-8-2">What's New in NetApp Shift Toolkit 8.2</h3><p>NetApp Shift Toolkit continues the journey by building on the capabilities introduced in previous releases and delivering further enhancements to simplify and accelerate virtualization migrations.</p><p>These investments are about innovation, not dependency replacement. Because Shift Toolkit has never depended on VDDK, qemu-img or storage array copy offload mechanisms, we've been able to keep evolving the platform without being pulled off course by changes to third-party migration components.</p><p>Highlights in v8.2</p><ul><li>Optimized VMware to AWS VM migrations using the EBS Direct API for improved performance and efficiency. </li><li>Bi-directional support for Proxmox to VMware, enhancing workload portability. </li><li>Cross-SVM support for OpenShift virtualization for greater deployment flexibility. </li><li>Standard Port Group support during discovery of VMware environments.</li></ul><h3 data-id="key-benefits-of-using-shift-toolkit">Key Benefits of Using Shift Toolkit:</h3><ul><li>Zero copy migration with no block copy process, the true storage offloading for any hypervisor migrations, making Shift toolkit the fastest migration tool</li><li>Unparalleled VM mobility across on-premises hypervisor platforms and now to the cloud.</li></ul><p>Note: Shift Toolkit now supports Hyper-V, VMware, OpenShift, OLVM, Proxmox, and AWS EC2 as first-class citizens, and our proprietary conversion mechanism can support any hypervisor and disk format, making VM mobility a breeze.</p><ul><li>No dependency on VDDK for VM migrations.</li><li>No reliance on qemu-img conversion processes.</li><li>No dependency on VAAI XCOPY or vmkfstools based storage copy offload.</li><li>Reduced exposure to third-party licensing or product availability changes.</li><li>Consistent migration experience regardless of shifts in the VMware ecosystem.</li><li>Continued innovation focused on customer outcomes, not dependency management.</li><li>And finally, it's free.</li></ul><h3 data-id="the-bottom-line">The Bottom Line</h3><p>Others may be looking for a path beyond VDDK. Shift Toolkit never had to. </p><p>No VDDK. No qemu-img. No migration roadblocks. Just a dependable path to the hypervisor of your choice with Shift Toolkit.</p><p>Industry changes will keep happening, licensing models will keep evolving, and technologies will come and go. What's important is having a data mobility platform that isn't tied to those changes. With Shift Toolkit and ONTAP, organizations can migrate virtual machines across hypervisors without worrying about VDDK availability, qemu-img dependencies, or unexpected ecosystem shifts.</p><p>If your organization is looking for migrating virtual machines, try <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fnetapp-solutions-virtualization%2Fmigration%2Fshift-toolkit-overview.html" target="_blank" rel="nofollow noopener ugc">NetApp Shift toolkit</a> and see the difference.</p>]]>
        </description>
    </item>
    <item>
        <title>Need Clarity on on FAS70 to DS212C shelf connectivity</title>
        <link>https://community.netapp.com/community/discussion/468369/need-clarity-on-on-fas70-to-ds212c-shelf-connectivity</link>
        <pubDate>Sat, 05 Sep 2026 11:32:02 +0000</pubDate>
        <category>AFF, AFX, ASA, &amp; FAS</category>
        <dc:creator>PunitWaghela</dc:creator>
        <guid isPermaLink="false">468369@/community/discussions</guid>
        <description><![CDATA[<p></p><p>Recently one of our customer has purchase the FAS70 with 2 Qty of DS212C shelf... Now we want to do the connectivity from controller to shelf.. for which I am referring this document : <span data-embedjson="{&quot;body&quot;:&quot;Management network ports on the controllers are connected to switches. The HA interconnect and cluster interconnect ports are cabled on both controllers. The...&quot;,&quot;photoUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/logo-tophat-social.png&quot;,&quot;url&quot;:&quot;https:\/\/community.netapp.com\/community\/home\/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-systems%2Ffas-70-90%2Finstall-cable.html%23step-4-cable-the-shelf-connections&quot;,&quot;embedType&quot;:&quot;link&quot;,&quot;name&quot;:&quot;Cable the FAS70 or FAS90 hardware for network and storage connectivity&quot;,&quot;faviconUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/favicon.ico&quot;,&quot;embedStyle&quot;:&quot;rich_embed_inline&quot;}">
    <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-systems%2Ffas-70-90%2Finstall-cable.html%23step-4-cable-the-shelf-connections" rel="nofollow noopener ugc">
        https://docs.netapp.com/us-en/ontap-systems/fas-70-90/install-cable.html#step-4-cable-the-shelf-connections
    </a>
</span>
 . In this document it has show connetivity from FAS70 to 2 Qty of DS460C.. Referring the I have prepared the document which I have attached. But while also going through netapp website : <span data-embedjson="{&quot;body&quot;:&quot;Disk shelves with IOM12, IOM12B, or IOM12C modules can be cabled in HA pair and single-controller configurations (for supported platforms).&quot;,&quot;photoUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/logo-tophat-social.png&quot;,&quot;url&quot;:&quot;https:\/\/community.netapp.com\/community\/home\/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-systems%2Fsas3%2Finstall-cabling-rules.html%23controller-a-and-c-port-connection-rules-for-platforms-without-internal-storage&quot;,&quot;embedType&quot;:&quot;link&quot;,&quot;name&quot;:&quot;SAS cabling rules and concepts for DS212C, DS224C, or DS460C shelves&quot;,&quot;faviconUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/favicon.ico&quot;,&quot;embedStyle&quot;:&quot;rich_embed_inline&quot;}">
    <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-systems%2Fsas3%2Finstall-cabling-rules.html%23controller-a-and-c-port-connection-rules-for-platforms-without-internal-storage" rel="nofollow noopener ugc">
        https://docs.netapp.com/us-en/ontap-systems/sas3/install-cabling-rules.html#controller-a-and-c-port-connection-rules-for-platforms-without-internal-storage
    </a>
</span>
 .. I got this image (Attached). Now i am confused which connecivity i should use? Attached PDF it is created by me by taking reference of NetApp docs (FAS70 to 2 Qty of DS460C shelf connecivity) and attached image is again from NetApp docs only. Please someone help here.</p><div data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/EBQ6CA4RFBC2\/controller-and-shelf-connectivity-pdf.pdf&quot;,&quot;name&quot;:&quot;Controller and shelf connectivity.pdf.pdf&quot;,&quot;type&quot;:&quot;application\/pdf&quot;,&quot;size&quot;:45837,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FEBQ6CA4RFBC2%2Fcontroller-and-shelf-connectivity-pdf.pdf&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5613,&quot;dateInserted&quot;:&quot;2026-09-05T11:30:54+00:00&quot;,&quot;insertUserID&quot;:112976,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;file&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <a rel="nofollow" href="https://community.netapp.com/api/v2/media/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FEBQ6CA4RFBC2%2Fcontroller-and-shelf-connectivity-pdf.pdf" download="" aria-label="Controller and shelf connectivity.pdf.pdf">
        Controller and shelf connectivity.pdf.pdf
    </a>
</div>
<span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/AHQ0OXYWS4HZ\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:133036,&quot;width&quot;:979,&quot;height&quot;:619,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FAHQ0OXYWS4HZ%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5614,&quot;dateInserted&quot;:&quot;2026-09-05T11:31:17+00:00&quot;,&quot;insertUserID&quot;:112976,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FAHQ0OXYWS4HZ%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/AHQ0OXYWS4HZ/image.png" alt="image.png" height="619" width="979" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/AHQ0OXYWS4HZ/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/AHQ0OXYWS4HZ/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/AHQ0OXYWS4HZ/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/AHQ0OXYWS4HZ/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/AHQ0OXYWS4HZ/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/AHQ0OXYWS4HZ/image.png 2000w, https://us.v-cdn.net/6038798/uploads/AHQ0OXYWS4HZ/image.png" sizes="100vw" /></a>
    </span>
</span>
]]>
        </description>
    </item>
    <item>
        <title>AFX setup failed</title>
        <link>https://community.netapp.com/community/discussion/468391/afx-setup-failed</link>
        <pubDate>Fri, 18 Sep 2026 02:27:06 +0000</pubDate>
        <category>AFF, AFX, ASA, &amp; FAS</category>
        <dc:creator>yyx</dc:creator>
        <guid isPermaLink="false">468391@/community/discussions</guid>
        <description><![CDATA[<p>4-Node AFX-A1K Installation Version 9.19.1<br />
Wipeconfig was executed in boot_cenu;<br />
In loader according to KB（ https://kb.netapp.com/on-prem/ASAr2/ASAr2_KBs/How_to_reinitialize_disaggregated_storage ）Operated<br />
When entering setup cli, the configuration still reports an error: storage pod setup for create failed<br />
Is there any reason causing it? We have checked the physical connection.</p>]]>
        </description>
    </item>
    <item>
        <title>NCDA: New Title, Same Credential</title>
        <link>https://community.netapp.com/community/discussion/468389/ncda-new-title-same-credential</link>
        <pubDate>Thu, 17 Sep 2026 23:05:34 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>Nita5</dc:creator>
        <guid isPermaLink="false">468389@/community/discussions</guid>
        <description><![CDATA[<p>As part of an update, the NCDA credential and exam received revised titles in December 2025.</p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p>NEW Credential Title</p></th><th><p><strong>NetApp Certified Data ONTAP Administrator Professional</strong></p></th></tr><tr><td><p>OLD Credential Title</p></td><td><p>NetApp Certified Data Administrator ONTAP Professional</p></td></tr><tr><td><p>NEW Exam Title</p></td><td><p> NetApp Data ONTAP Administrator Exam (NCDA)</p></td></tr><tr><td><p>OLD Exam Title</p></td><td><p>NetApp Data Administrator ONTAP Professional Exam (NCDA)</p></td></tr></table></div><p>The core content of the exam remains unchanged and continues to cover the areas outlined below:</p><ul><li>Storage Platforms<br /></li><li>Core ONTAP<br /></li><li>ONTAP Storage<br /></li><li>Networking</li><li>Storage Protocols and Connectivity</li><li>Data Protection<br /></li><li>Security</li><li>Performance<br /></li></ul>]]>
        </description>
    </item>
    <item>
        <title>Uncertified drive detected</title>
        <link>https://community.netapp.com/community/discussion/468372/uncertified-drive-detected</link>
        <pubDate>Mon, 07 Sep 2026 12:15:57 +0000</pubDate>
        <category>StorageGRID</category>
        <dc:creator>AU-TT</dc:creator>
        <guid isPermaLink="false">468372@/community/discussions</guid>
        <description><![CDATA[<p>A hard drive has failed in a grid node at one of my clients’ sites.</p><p>We installed a new, previously used hard drive.</p><p>Now the following message appears in the grid log:</p><p></p><p>Uncertified drive detected.</p><p></p><p>Has anyone else experienced this before?</p><p>As I understand it, this is because the drive came from a system that had newer firmware installed.</p><p>I’ve only found information from HPE on the internet regarding this.</p><div data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/Z8KM5UXTCG79\/hpe-sg1560en-us-netapp-storage-array-reporting-27uncertified-drive-detected-27.pdf&quot;,&quot;name&quot;:&quot;HPE_sg1560en_us_NetApp storage array reporting 'Uncertified drive detected'.pdf&quot;,&quot;type&quot;:&quot;application\/pdf&quot;,&quot;size&quot;:156225,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FZ8KM5UXTCG79%2Fhpe-sg1560en-us-netapp-storage-array-reporting-27uncertified-drive-detected-27.pdf&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5618,&quot;dateInserted&quot;:&quot;2026-09-07T12:15:54+00:00&quot;,&quot;insertUserID&quot;:120160,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;file&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <a rel="nofollow" href="https://community.netapp.com/api/v2/media/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FZ8KM5UXTCG79%2Fhpe-sg1560en-us-netapp-storage-array-reporting-27uncertified-drive-detected-27.pdf" download="" aria-label="HPE_sg1560en_us_NetApp storage array reporting 'Uncertified drive detected'.pdf">
        HPE_sg1560en_us_NetApp storage array reporting 'Uncertified drive detected'.pdf
    </a>
</div>
]]>
        </description>
    </item>
    <item>
        <title>get-ncnode on 9.18.1 controllers doesn&#39;t work (REST)</title>
        <link>https://community.netapp.com/community/discussion/468387/get-ncnode-on-9-18-1-controllers-doesnt-work-rest</link>
        <pubDate>Wed, 16 Sep 2026 19:08:14 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>KenPratte</dc:creator>
        <guid isPermaLink="false">468387@/community/discussions</guid>
        <description><![CDATA[<p>On some newly upgraded clusters 9.18.1P6, I receive this error:</p><p>Get-NcNode: </p><p> Line |</p><p>   20 |          $nodes = Get-NcNode -Controller $cluster</p><p>      |                   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p><p>      | Error converting value "All checks passed" to type 'DataONTAP.C.Types.System.Reason'. Path 'ha.takeover_check.reasons[0]', line 143, position 27.</p><p>Other clusters that are 9.16.1 don't have this issue.  Happens on two different 9.18.1 clusters.  The workaround I found is to add "-ONTAPI" to the connect-nccontroller but obviously isn't a long term fix.  Not sure if this is an ONTAP or a powershell toolkit bug.</p>]]>
        </description>
    </item>
    <item>
        <title>Use PowerShell Automation to Maximize Performance and Resilience of VMware Datastores on ASA systems</title>
        <link>https://community.netapp.com/community/discussion/462393/use-powershell-automation-to-maximize-performance-and-resilience-of-vmware-datastores-on-asa-systems</link>
        <pubDate>Tue, 05 Aug 2025 14:56:21 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>ChanceBingen</dc:creator>
        <guid isPermaLink="false">462393@/community/discussions</guid>
        <description><![CDATA[<div><p>With the release last year of our new generation of ASA series of controllers, you may have noticed that I updated the <a href="https://docs.netapp.com/us-en/ontap-apps-dbs/vmware/vmware-vsphere-overview.html" target="_blank" rel="noopener noreferrer nofollow">VMware vSphere with ONTAP Best Practices</a> to recommend <a href="https://docs.netapp.com/us-en/ontap-apps-dbs/vmware/vmware-vsphere-settings.html#multipath-settings-for-performance" target="_blank" rel="noopener noreferrer nofollow">using the latency policy option</a> on the round-robin Path Selection Plugin (PSP) with ASA systems.</p><p>You can also set this option when using the newer High-Performance Plug-in (HPP) on either SCSI LUNs or NVMe namespaces). In fact, it&rsquo;s quite easy with the HPP to just pop into the vCenter UI and click the option on the device.</p><p>Starting with VMware Cloud Foundation (VCF) / vSphere 9.0, this configuration is now the default for NetApp LUNs. Additionally, changes to the default NVMe namespace configuration may be introduced in a future update to ESXi.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/67/67639fb63473d3a8b1a88f8fd1677d1f.png" width="842" height="680" role="button" title="ChanceBingen_0-1754057503225.png" alt="ChanceBingen_0-1754057503225.png" /></span></p><p>But what if you aren&rsquo;t using the HPP? Or if you are on a release that doesn&rsquo;t support using the HPP on SCSI devices, limiting you to the old NMP plugin? Especially if you have a lot of hosts to manage?</p><p>My friend and coworker, <a rel="nofollow" href="/profile/39734">@ScottBell</a>&nbsp;, and I worked up this little PowerShell script using VMware PowerCLI to create a new Storage Array Type Plug-in (SATP) rule to update all of the hosts in the datacenter to use the latency policy.</p><p>It makes setting up demo labs so much faster and easier.</p><p>Before getting to the script, let me explain two things.</p><ol><li>Even though the new ASA systems no longer have aggregates and volumes to manage, sharing a common Storage Availability Zone (SAZ) between the HA pair(s), and all paths being exposed symmetrically as ALUA active/optimized to all Storage Units(SUs,&nbsp;note that LUNs and namespaces are called SUs in the new ASA systems), one controller is still considered the owner of the SU, and IO to that node may be ever so slightly faster, measured in microseconds, than paths to the other controller. Therefore, under heavy sustained load, those microseconds could add up over time.</li><li>VMware added the <a href="https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/vsphere-storage-7-0/understanding-multipathing-and-failover-in-the-esxi-environment/viewing-and-managing-storage-paths-on-esxi-hosts/change-default-parameters-for-latency-round-robin.html" target="_blank" rel="noopener nofollow noreferrer">latency option</a> to the round robin PSP in ESXi way back in the vSphere 6.7 days. For over a decade, Linux (thus including KVM) has used a latency-based round-robin mechanism called <a href="https://docs.kernel.org/admin-guide/device-mapper/dm-service-time.html" target="_blank" rel="noopener nofollow noreferrer">dm-service-time</a>, while Microsoft Windows/Hyper-V has long offered <a href="https://learn.microsoft.com/en-us/powershell/module/mpio/Set-MSDSMGlobalDefaultLoadBalancePolicy?view=windowsserver2025-ps" target="_blank" rel="noopener nofollow noreferrer">similar options</a> like LQD (Least Queue Depth) and LB (Least Blocks).<br /><br />The goal with all of the previously mentioned examples is to prefer paths that perform the fastest. I.e., they have the lowest latency, the lowest number of outstanding commands or bytes, etc..<br /><br />Historically, that has been very helpful in other use cases too, especially instances where you may have asymmetric pathing (i.e., one path may have more hops than another), or you may have one path go flaky with a slowly failing SFP, a slightly over-bent Fibre cable, and other things like that.<br /><br />Flaky is my highly technical term, feel free to use it.</li></ol><p>That&rsquo;s where the advantage of using these types of multipath settings comes in handy with ASA systems. Although generally speaking, you will never notice the difference unless you are running a very storage-intensive workload, using every bit of performance the system has to offer. That being said, even when you aren&rsquo;t pushing the systems very hard, the ability to automatically minimize using flaky paths that aren&rsquo;t quite dead yet is incredibly beneficial.</p><p>Over the years of my career, I have seen many an outage or performance degradation caused by paths that just weren&rsquo;t dead enough to fail out, but also ended up stalling IOs in the host&rsquo;s queuing mechanism.</p><p><span><img src="https://us.v-cdn.net/6038798/uploads/migrated-images/90/9056e68268543e42a19654cc41029ed4.jpg" width="514" height="289" role="button" title="ChanceBingen_1-1754057503228.jpeg" alt="ChanceBingen_1-1754057503228.jpeg" /></span></p><p>So, now that we&rsquo;ve gotten that out of the way, onto the script.</p><p>Keep in mind that you will need to either unclaim/reclaim the LUNs, or put the hosts into maintenance mode and do a rolling reboot. Usually, you have to use the latter method because the former requires there to be no IO at all on a path to be unclaimed. *Sometimes* I have had luck with unclaiming/reclaiming with a host just in maintenance mode. But it seems inconsistent in my experience.</p><pre># Set the latency policy for NetApp ONTAP LUNs in a vCenter environment by specifying the datacenter to update.<br /># By Chance Bingen and Scott Bell, NetApp, 2025.<br /><br /># Load VMware PowerCLI core module if not already available<br />Import-Module VMware.VimAutomation.Core<br /><br /># Uncomment the below Set-PowerCLIConfiguration command if you want to ignore invalid certificates<br /># Note: This is not recommended for production environments as it can expose you to security risks.<br /># Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -Confirm:$false<br /><br /># Prompt for the vCenter Server<br />$vCenter = Read-Host -Prompt "What vCenter do you want to connect to?"<br />Write-Output "You entered: $vCenter"<br /><br /># Prompt for vCenter Server credentials<br />$cred = Get-Credential<br /><br /># Connect to the vCenter Server using the provided credentials<br />Connect-VIServer -Server $vCenter -Credential $cred<br /><br /># Prompt for the datacenter<br />$Datacenter = Read-Host -Prompt "Which datacenter do you want to update?"<br />Write-Output "You entered: $Datacenter"<br /><br />$vmhosts = Get-VMhost -Location $Datacenter<br /><br /># Suppress PowerShell errors<br />$OldErrorActionPreference = $ErrorActionPreference<br />$ErrorActionPreference = "SilentlyContinue"<br /><br />foreach ($vmhost in $vmhosts) {<br />&nbsp; &nbsp; $esxcli = Get-EsxCli -VMHost $vmHost -V2<br />&nbsp; &nbsp; $hostname = Get-VMHost $vmHost.Name<br />&nbsp; &nbsp; $arguments = $esxcli.storage.nmp.satp.rule.add.CreateArgs()<br />&nbsp; &nbsp; $arguments.pspoption="policy=latency"<br />&nbsp; &nbsp; $arguments.description="NetApp ONTAP Latency SATP Rule"<br />&nbsp; &nbsp; $arguments.vendor="NETAPP"<br />&nbsp; &nbsp; $arguments.type="vendor"<br />&nbsp; &nbsp; $arguments.satp="VMW_SATP_ALUA"<br />&nbsp; &nbsp; $arguments.claimoption="tpgs_on"<br />&nbsp; &nbsp; $arguments.psp="VMW_PSP_RR"<br />&nbsp; &nbsp; $arguments.option="reset_on_attempted_reserve"<br />&nbsp; &nbsp; $arguments.model="LUN C-Mode"<br />&nbsp; &nbsp; $esxcli.storage.nmp.satp.rule.add.Invoke($arguments) | Out-Null<br />&nbsp; &nbsp; # Check if the command was successful<br />&nbsp; &nbsp; if ($?) {<br />&nbsp; &nbsp; &nbsp; &nbsp; # Output a message including the hostname<br />&nbsp; &nbsp; &nbsp; &nbsp; Write-Host "Successfully added Latency policy to host: $hostname"<br />&nbsp; &nbsp; } else {<br />&nbsp; &nbsp; &nbsp; &nbsp; Write-Host "Failed to add Latency policy to host $hostname"<br />&nbsp; &nbsp; }<br />}<br /><br /># Reset $ErrorActionPreference to previous value<br />$ErrorActionPreference = $OldErrorActionPreference<br /><br /># Disconnect from the vCenter Server<br />Disconnect-VIServer -Confirm:$false</pre><p>One thing you might change, depending on your environment, is scoping it to a particular vSphere cluster instead of a whole datacenter. To do that, just change this:</p><pre>$Datacenter = Read-Host -Prompt "Which datacenter do you want to update?"<br />Write-Output "You entered: $Datacenter"</pre><p>To this:</p><pre>$vcluster = Read-Host -Prompt "Which cluster do you want to update?"<br />Write-Output "You entered: $vcluster"</pre><p>And change this:</p><pre>$vmhosts = Get-VMhost -Location $Datacenter</pre><p>To this</p><pre>$vmhosts = Get-Cluster -Name $vcluster | Get-VMhost</pre><p>Of course, you may wonder about NVMe namespaces, since they exclusively use the HPP and not the Native Multipathing Plugin (NMP). Those are bit easier to do because there&rsquo;s a native interface for it. But, if you have a lot of hosts to manage, you may want to script that too. If you would like to see some examples of that, let us know.</p><p>If you have any questions, feel free to comment below, and we&rsquo;ll be happy to answer them.</p><p>More resources can be found at:</p><p>ONTAP 9 &ndash; Learn About ONTAP SAN Configuration</p><p><a href="https://docs.netapp.com/us-en/ontap/san-config/index.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.netapp.com/us-en/ontap/san-config/index.html</a></p><p>Learn about SAN host configurations</p><p><a href="https://docs.netapp.com/us-en/ontap-sanhost/overview.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.netapp.com/us-en/ontap-sanhost/overview.html</a></p><p>VMware vSphere with ONTAP Best Practices Guide (Formerly TR-4597)</p><p><a href="https://docs.netapp.com/us-en/ontap-apps-dbs/vmware/vmware-vsphere-overview.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.netapp.com/us-en/ontap-apps-dbs/vmware/vmware-vsphere-overview.html</a></p><p>TR-4080: Best Practices for Modern SAN</p><p><a href="https://www.netapp.com/media/10680-tr4080.pdf" target="_blank" rel="noopener noreferrer nofollow">https://www.netapp.com/media/10680-tr4080.pdf</a></p><p>TR-4684: Implementing and Configuring Modern SANs with NVMe/FC</p><p><a href="https://www.netapp.com/pdf.html?item=/media/10681-tr4684pdf.pdf" target="_blank" rel="noopener noreferrer nofollow">https://www.netapp.com/pdf.html?item=/media/10681-tr4684pdf.pdf</a></p></div>]]>
        </description>
    </item>
    <item>
        <title>Oracle Databases on AWS: Fully managed or self-managed with Amazon FSx for NetApp ONTAP</title>
        <link>https://community.netapp.com/community/discussion/468386/oracle-databases-on-aws-fully-managed-or-self-managed-with-amazon-fsx-for-netapp-ontap</link>
        <pubDate>Wed, 16 Sep 2026 11:49:15 +0000</pubDate>
        <category>Cloud</category>
        <dc:creator>Semion</dc:creator>
        <guid isPermaLink="false">468386@/community/discussions</guid>
        <description><![CDATA[<p>Oracle Database is the backbone for many critical business applications, from Enterprise Resource Planning (ERP) to customer-facing systems. As organizations migrate to <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2F" target="_blank" rel="nofollow noopener ugc">Amazon Web Services (AWS)</a>, they face a key decision for their Oracle deployments—whether to choose a fully managed service or take a self-managed approach using <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Fpm%2Fec2%2F" target="_blank" rel="nofollow noopener ugc">Amazon Elastic Compute Cloud (Amazon EC2)</a>. </p><p>While managed services simplify administration by automating many operational tasks, enterprise Oracle environments often have specific requirements around performance, availability, recovery objectives, database lifecycle management, and operational flexibility. For these environments, architecture decisions are driven less by operational simplicity and more by the need to meet workload requirements. </p><p>This post explores the options for running Oracle Databases on AWS and explains how <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Ffsx%2Fnetapp-ontap%2F" target="_blank" rel="nofollow noopener ugc">Amazon FSx for NetApp ONTAP (FSx for ONTAP)</a> can enhance self-managed deployments.</p><p>What this post covers:</p><ul><li>Two options for running Oracle Databases on AWS<br /></li><li>The managed option: Simplicity and automation<br /></li><li>The self-managed option: Control and flexibility<br /></li><li>Optimizing self-managed Oracle with FSx for ONTAP<br /></li><li>Case study: A global learning company modernizes on AWS<br /></li><li>Summary</li></ul><h2 data-id="two-options-for-running-oracle-databases-on-aws">Two options for running Oracle Databases on AWS</h2><p>There are two main options for deploying Oracle on AWS. The first is to choose a fully managed service, like <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Frds" target="_blank" rel="nofollow noopener ugc">Amazon Relational Database Service (Amazon RDS)</a> for Oracle or <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.oracle.com%2Fil-en%2Fcloud%2Faws%2F" target="_blank" rel="nofollow noopener ugc">Oracle AI Database@AWS</a>, where AWS and Oracle handle most of the infrastructure management, with less configuration control for the customer. The second is to opt for a self-managed deployment on Amazon EC2, giving you full control over the Oracle stack and underlying architecture. </p><p>Both these choices are viable; the best fit depends on your business and technical needs. While this decision is often framed as control versus simplicity, you should also consider factors such as recovery requirements, database copy management, architectural flexibility, performance objectives, and overall cost efficiency. </p><h2 data-id="the-managed-option-simplicity-and-automation">The managed option: Simplicity and automation</h2><p>Managed services like Amazon RDS for Oracle reduce operational effortby automating tasks such as provisioning, patching, backup, and monitoring.</p><h3 data-id="capabilities">Capabilities</h3><p>With Amazon RDS for Oracle, you can scale compute and memory, with storage scaling up to 256 TiB. For demanding workloads, Provisioned IOPS SSD storage up to 256,000 IOPS is supported. High availability is achieved through multi-Availability Zone (AZ) deployments, which maintain synchronous standby volumes and provide automatic failover. </p><p>Amazon RDS also offers managed alternatives to <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.oracle.com%2Fil-en%2Fdatabase%2Freal-application-clusters%2F" target="_blank" rel="nofollow noopener ugc">Oracle Real Application Clusters</a> (RAC) capabilities, through multi-AZ, vertical scaling, and Oracle GoldenGate platform integration. The newer Oracle AI Database@AWS service provides access to Oracle Exadata infrastructure and Autonomous Database services within AWS data centers, which is ideal if you need native Oracle capabilities with low-latency connectivity to AWS applications. </p><p>Overall, these managed options accelerate deployment, simplify maintenance, and reduce operational complexity.</p><h3 data-id="considerations">Considerations</h3><p>It’s important to bear in mind that this simplicity comes with less granular control. With Amazon RDS, you have no direct shell access, get restricted administrative accounts (SYS and SYSTEM), and face limits on certain privileges. This can be a significant drawback for organizations with custom configurations, specific operational tools, or a need for direct OS and storage control. </p><p>Amazon RDS also has service-specific limits, such as a 16 TiB maximum data file size and a fixed 8 KB database block size. Oracle AI Database@AWS adds multi-cloud complexity, requiring management of both AWS and Oracle Cloud Infrastructure (OCI) components. </p><p>While managed services are excellent for prioritizing simplicity, they might not suit organizations with strict architectural standards or advanced operational needs, particularly where multiple database copies, large storage footprints, specialized recovery requirements, or demanding performance objectives are involved. In these scenarios, a self-managed architecture can provide both greater flexibility and a more cost-efficient operating model.</p><h2 data-id="the-self-managed-option-control-and-flexibility">The self-managed option: Control and flexibility</h2><p>Running Oracle on Amazon EC2 provides complete control over your database architecture and operations.</p><h3 data-id="capabilities-1">Capabilities</h3><p>With a self-managed model, you control the OS, database configuration, storage, backup strategy, and high availability (HA) and disaster recovery (DR) designs. So, you can choose the Amazon EC2 instances and storage platform that precisely match your performance, availability, and compliance needs. </p><p>This flexibility is crucial for applications requiring specific Oracle features or custom configurations. It also lets you mirror on-premises architectures, preserving operational consistency while modernizing on AWS.</p><h3 data-id="considerations-1">Considerations</h3><p>The trade-off is greater responsibility. Your team has to design, operate, and maintain the entire environment, including backup, HA and DR, and capacity management. This requires significant in-house expertise in Oracle, AWS, storage, and networking, in addition to responsibility for monitoring, patching, and testing failover processes. </p><p>The self-managed model makes the most sense if you need deep control; but is less suitable for teams wanting to minimize infrastructure management.</p><h2 data-id="optimizing-self-managed-oracle-with-fsx-for-ontap">Optimizing self-managed Oracle with FSx for ONTAP</h2><p>Organizations that require a self-managed Oracle deployment face the challenge of designing and operating an architecture that delivers the required levels of availability, recoverability, performance, scalability, and operational efficiency.</p><p>Amazon FSx for NetApp ONTAP helps address these challenges by combining the control of a self-managed environment with the enterprise-grade storage capabilities of ONTAP®, delivered as a managed AWS service. Many capabilities that would otherwise need to be designed and operated separately are built into the storage layer, helping simplify operations, while retaining flexibility.</p><p>Key benefits include:</p><ul><li><strong>Meeting demanding recovery objectives</strong>: FSx for ONTAP provides storage-level multi-AZ, Snapshot copies, and cross-AWS Region replication, protecting against failures and data loss, while enabling faster recovery. These capabilities can help meet aggressive recovery point objectives (RPO) and recovery time objectives (RTO).</li><li><strong>Delivering high performance</strong>: FSx for ONTAP scales to up to 72 GBps of throughput and 2.4 million IOPS, withconsistent sub-millisecond latency for business-critical applications. So, you can align storage performance with the needs of demanding Oracle workloads.</li><li><strong>Independent scaling</strong>: <a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/How-to-reduce-compute-costs-47-when-migrating-SQL-Server-to-AWS-and-Amazon-FSx/ba-p/462172" target="_blank" rel="nofollow noopener ugc">Storage capacity and performance can be scaled</a> independently of the Amazon EC2 database server, so you can expand storage without re-architecting the compute layer. This flexibility is particularly valuable for large Oracle environments, where storage and compute requirements often evolve at different rates.</li><li><strong>Accelerated workflows through fast cloning</strong>: ONTAP FlexClone® technology enables <a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Speed-up-development-processes-and-cut-costs-with-Amazon-FSx-for-NetApp-ONTAP/ba-p/458633" target="_blank" rel="nofollow noopener ugc">fast, space-efficient, writable copies</a> of Oracle environments, streamlining DevTest, QA, reporting, and analytics workflows. For organizations maintaining numerous database copies, this can significantly reduce both operational effort and storage consumption.</li><li><strong>Optimizing cost at scale</strong>: Features like compression, compaction, thin cloning, and data tiering <a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Lower-your-AWS-database-costs-with-Amazon-FSx-for-NetApp-ONTAP/ba-p/454182" target="_blank" rel="nofollow noopener ugc">significantly reduce storage consumption and costs</a>, particularly in large Oracle environments with multiple database copies. This helps organizations optimize storage economics without compromising performance or functionality.</li></ul><p>With FSx for ONTAP, the storage infrastructure becomes a strategic asset that makes self-managed Oracle on AWS more resilient, agile, and cost-efficient. For some Oracle deployments, these capabilities aren’t merely optimization features; they become architectural requirements. </p><h2 data-id="case-study-a-global-learning-company-modernizes-on-aws">Case study: A global learning company modernizes on AWS</h2><p>A global learning company operating in 70 countries needed to migrate its complex Oracle ERP environment to AWS. The project involved re-architecting Oracle RAC systems to run on hundreds of Amazon EC2 instances with 400 TB of storage. Given the scale and complexity of the environment, maintaining architectural flexibility and enterprise-grade data management capabilities was a key migration requirement.</p><p>By choosing a self-managed approach with FSx for ONTAP, the company went live on AWS in just over 4 months. It saw immediate performance gains, including a 20% improvement in supply chain processing. FSx for ONTAP also reduced operational effort and accelerated workflows, with database refreshes running 10 times faster while financial processing times cut by two-thirds. </p><p>As a result, the company improved agility, performance, and operational efficiency, while maintaining the flexibility needed to support complex enterprise workloads.</p><h2 data-id="summary">Summary</h2><p>Fully managed Oracle services on AWS are an excellent choice for organizations prioritizing operational simplicity. However, many enterprise environments require more than simplified administration; they need greater control over architecture, recovery, performance, database lifecycle management, and storage.</p><p>For these use cases, a self-managed model on Amazon EC2 provides the necessary flexibility. By incorporating Amazon FSx for NetApp ONTAP, organizations can <a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Optimize-Oracle-databases-on-AWS-with-Amazon-FSx-for-NetApp-ONTAP-and-NetApp/ba-p/464814" target="_blank" rel="nofollow noopener ugc">optimize this architecture with enterprise-grade storage capabilities</a> for protection, performance, cloning, scalability, and storage efficiency. </p><p>The key is to start by understanding the requirements of your Oracle workload and then choose the deployment model that best supports them. Where architectural flexibility and advanced storage capabilities are important, FSx for ONTAP can help you modernize Oracle on AWS, without sacrificing control or operational efficiency. </p><p>For more information, read our blog post about how to <a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Optimize-Oracle-databases-on-AWS-with-Amazon-FSx-for-NetApp-ONTAP-and-NetApp/ba-p/464814" target="_blank" rel="nofollow noopener ugc">optimize Oracle databases on AWS with Amazon FSx for NetApp ONTAP and NetApp® Workload Factory™</a>, or watch our webinar on <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DkxS9jkt_b4w" target="_blank" rel="nofollow noopener ugc">Unlocking Oracle performance on AWS with Amazon FSx for NetApp ONTAP</a>.</p>]]>
        </description>
    </item>
    <item>
        <title>Azure Local and NetApp: Bringing Cloud Operations to Enterprise Data</title>
        <link>https://community.netapp.com/community/discussion/468385/azure-local-and-netapp-bringing-cloud-operations-to-enterprise-data</link>
        <pubDate>Tue, 15 Sep 2026 21:24:06 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Robert</dc:creator>
        <guid isPermaLink="false">468385@/community/discussions</guid>
        <description><![CDATA[<p>Every organization I talk to is trying to answer a variation of the same question: How do we modernize infrastructure and take advantage of cloud innovation without giving up control of our data, existing investments, or operational flexibility?</p><p>For many enterprises, the answer is no longer simply "move everything to the public cloud."</p><p>Some workloads must remain close to factories, hospitals, offices, or users. Some data must stay within a country or regulatory boundary. Some applications depend on predictable performance and availability. And many organizations already have years of investment in enterprise storage, data protection, and operational processes that they do not want to replace simply because the virtualization platform is changing.</p><p>At the same time, IT teams still want what the cloud has taught them to expect: consistent operations, automation, centralized management, APIs, policy-driven infrastructure, and faster access to new services.</p><p>The challenge is giving organizations the freedom to place applications and data where they make the most sense while operating them consistently. That's where Azure Local and NetApp come together.</p><p><strong>The best of Azure, where you need it</strong></p><p>Think about what people love about Azure. They love the consistency. The automation. The management tools. The ability to modernize infrastructure without constantly reinventing the wheel.</p><p>Azure Local extends the Azure operating model into customer-controlled environments, allowing organizations to run workloads in their own datacenters and distributed locations while using Azure-based management, governance, monitoring, and automation. Microsoft is increasingly positioning Azure Local as a foundation for sovereign and private cloud environments where control, compliance, and operational consistency matter most.</p><p>In simple terms, Azure Local gives organizations more freedom to decide where workloads run without creating an entirely separate operational model for each location.</p><p><strong>Modernization shouldn't require rebuilding the data layer</strong></p><p>For enterprise customers, however, infrastructure modernization often creates another problem: Why should changing the compute or virtualization platform require changing the storage architecture too?</p><p>Many organizations already operate mature enterprise SAN environments supporting large estates of business-critical workloads. Those environments represent more than storage capacity. They include operational knowledge, resiliency practices, data protection policies, security controls, and years of infrastructure investment.</p><p>Support for external enterprise storage with Azure Local creates a different modernization path. Customers can modernize the virtualization and operational layer while continuing to use enterprise storage for the workloads and data that depend on it.</p><p>This ability to separate compute and storage is particularly important in large datacenters, where compute capacity and storage capacity rarely grow at the same rate. Rather than forcing both to scale together, customers gain greater flexibility to evolve each layer according to business requirements.</p><p><strong>But infrastructure is only half the story</strong></p><p>Anyone who has worked in IT knows the infrastructure isn't usually the hard part.</p><p>The hard part is the data. How do you protect it? Replicate it? Govern it? Move it between environments? Keep it secure while supporting new applications and AI initiatives?</p><p>That's where NetApp becomes strategically important.</p><p>NetApp allows customers to modernize the compute and virtualization layer without forcing a simultaneous redesign of the data layer.</p><p>ONTAP provides enterprise storage capabilities for availability, efficiency, protection, security, replication, and lifecycle management that many organizations already depend on for mission-critical workloads. And because NetApp spans on-premises and Microsoft Azure environments, customers can build a data strategy that extends beyond a single infrastructure platform.</p><p>The result is a cleaner separation of concerns: Azure Local provides the cloud-connected infrastructure and operational model, while NetApp provides the enterprise data foundation underneath it.</p><p>Customers can decide where applications should run while maintaining consistent capabilities for managing and protecting the data those applications depend on.</p><p><strong>A practical path for virtualization modernization</strong></p><p>This becomes particularly relevant as organizations reassess their virtualization strategies.</p><p>Many enterprises considering alternatives to their existing virtualization platforms already run their most important workloads on shared enterprise storage. For those customers, replacing the hypervisor, servers, networking, storage, backup architecture, and operational processes simultaneously creates unnecessary cost and risk.</p><p>Azure Local with NetApp offers another approach: modernize the virtualization platform while preserving the enterprise data architecture where it still makes sense.</p><p>That can reduce the number of variables customers must change at once and allow infrastructure teams to modernize incrementally rather than treating virtualization transformation as a complete datacenter rebuild.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/NRYK0CFOYJD4\/ontap.png&quot;,&quot;name&quot;:&quot;ONTAP.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:80579,&quot;width&quot;:434,&quot;height&quot;:400,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FNRYK0CFOYJD4%2Fontap.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5653,&quot;dateInserted&quot;:&quot;2026-09-15T21:20:56+00:00&quot;,&quot;insertUserID&quot;:13895,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FNRYK0CFOYJD4%2Fontap.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/NRYK0CFOYJD4/ontap.png" alt="ONTAP.png" height="400" width="434" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/NRYK0CFOYJD4/ontap.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/NRYK0CFOYJD4/ontap.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/NRYK0CFOYJD4/ontap.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/NRYK0CFOYJD4/ontap.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/NRYK0CFOYJD4/ontap.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/NRYK0CFOYJD4/ontap.png 2000w, https://us.v-cdn.net/6038798/uploads/NRYK0CFOYJD4/ontap.png" sizes="100vw" /></a>
    </span>
</span>
<p>                                                                                 Diagram: NetApp ONTAP intelligent data infrastructure.</p><p>Azure Local and NetApp give organizations the flexibility to modernize compute and virtualization while maintaining an enterprise data foundation that extends across on-premises and Azure environments for HPC and AI-driven insights, real-time analytics, and secure, scalable workflows.</p><p><strong>A modernization deployment we're seeing more often</strong></p><p>Imagine a global manufacturer running thousands of virtual machines across regional datacenters and production sites.</p><p>Central IT wants to standardize infrastructure operations around Azure, while individual countries must meet local requirements for data residency, security, and availability. At the same time, the company has already invested heavily in enterprise storage, SAN networking, data protection, and operational processes.</p><p>A virtualization modernization should not require replacing all those layers at once.</p><p>With Azure Local, the organization can introduce a cloud-connected operating model for infrastructure in its own datacenters. With NetApp, it can continue using an enterprise data platform designed for the availability, protection, efficiency, and lifecycle requirements of business-critical data.</p><p>The company can modernize the compute and virtualization layer while preserving the data architecture where doing so provides operational and economic value.</p><p>And over time, it can decide workload by workload which applications remain local, which use Azure services, and which move to the public cloud.</p><p>Instead of choosing between cloud innovation and infrastructure control, the organization gains the flexibility to evolve each layer on its own timeline.</p><p><strong>And increasingly, this matters for AI</strong></p><p>AI initiatives often depend on large volumes of proprietary data that cannot simply be copied into every compute environment. In many cases, organizations will need to bring compute and AI services closer to governed enterprise data rather than continually moving that data toward compute. A flexible infrastructure and data architecture lets organizations place compute where it is needed while retaining control over the data that differentiates their business.</p><p><strong>Why this matters now</strong></p><p>The conversation around hybrid cloud has changed. A few years ago, hybrid cloud was primarily about migration. Today, it's about flexibility.</p><p>Organizations want the freedom to decide where applications run and where data resides. They want to meet sovereignty and regulatory requirements without slowing innovation. They want to preserve investments that still provide value rather than replacing infrastructure simply because another layer of the stack is changing.</p><p>And increasingly, they want infrastructure architectures that allow compute and data to evolve independently. Azure Local and NetApp fit naturally into that model. Azure Local provides a cloud-connected infrastructure and operational experience. NetApp provides the enterprise data foundation. The most important benefit isn't simply that Azure Local runs on-premises or that NetApp connects on-premises and cloud storage.</p><p>It is architectural choice.</p><p>Customers can modernize compute without automatically replacing storage. They can adopt a cloud operating model without forcing every workload into the public cloud. They can preserve enterprise data services while changing virtualization platforms. And they can decide over time which applications and data belong locally, in Azure, or across both.</p><p>Enterprise modernization should not require customers to choose between a cloud operating model and the data architecture they already trust.</p><p>Azure Local and NetApp give organizations another path: modernize what needs to change, preserve what continues to deliver value, and evolve the architecture at the pace the business requires.</p><p><strong>Explore More</strong></p><ul><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fazure%2Fazure-local%2Fdeploy%2Fenable-external-storage%3Fview%3Dazloc-2604%26tabs%3DNetApp-Lenovo" target="_blank" rel="nofollow noopener ugc">Microsoft guidance for enabling NetApp external storage with Azure Local</a></li><li><a href="https://community.netapp.com/t5/Tech-ONTAP-Blogs/Bring-Azure-Local-to-Enterprise-Scale-with-NetApp-Now-Generally-Available/ba-p/466886" target="_blank" rel="nofollow noopener ugc">Bring Azure Local to Enterprise Scale with NetApp – Now Generally Available</a></li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fazure%2Fcontact%2F" target="_blank" rel="nofollow noopener ugc">Connect with your NetApp or Microsoft team to validate configurations and plan your deployment.</a></li></ul>]]>
        </description>
    </item>
    <item>
        <title>Preparing Federal Data for the Post-Quantum Era</title>
        <link>https://community.netapp.com/community/discussion/468384/preparing-federal-data-for-the-post-quantum-era</link>
        <pubDate>Tue, 15 Sep 2026 20:30:04 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>MattT</dc:creator>
        <guid isPermaLink="false">468384@/community/discussions</guid>
        <description><![CDATA[<h2 data-id="preparing-federal-data-for-the-post-quantum-era">Preparing Federal Data for the Post-Quantum Era</h2><p>By Matt Trudewind and Bill Rulo</p><p><em>How NetApp helps Federal Agencies adopt PQC and meet requirements today</em></p><div><table><colgroup><col /><col /></colgroup><tr><th><p><strong>Bottom line: </strong>Adversaries can collect encrypted federal data today and keep it until future quantum computers can unlock it. Agencies therefore need to begin updating the systems that protect long-lived mission data now. NetApp helps protect that data where it is stored, accessed, moved, and recovered—without requiring agencies to replace their existing storage infrastructure.</p></th></tr></table></div><h2 data-id="harvest-now-decrypt-later-the-threat-is-already-underway">Harvest now, decrypt later: The threat is already underway</h2><p>Most encryption works like a digital lock: authorized users have the key, while everyone else sees unreadable data. Quantum computers could eventually open some of today’s widely used locks much faster than conventional computers. Post-quantum cryptography, or PQC, replaces those vulnerable locks with new mathematical protections designed to resist both conventional and quantum attacks.</p><p>Quantum computing is no longer just a research topic for labs, academia, and science fiction. For federal agencies, especially Intelligence Community (IC) and the Department of War (DoW) - the security implications are becoming very real, very quickly.</p><p>The concern is not simply what a quantum computer can do today. The bigger concern is what adversaries are already doing in preparation to utilize quantum computers to decrypt and unlock data in the near future.</p><p>One of the most urgent risks is called a harvest-now-decrypt-later attack. An adversary steals encrypted data or network traffic today, stores it, and waits until a sufficiently capable quantum computer can break the public-key encryption protecting it. That future point is sometimes called Q-Day. Data that appears unreadable today could then be exposed after it has already left the agency’s control.</p><p>This threat attack matters more for federal agencies because some mission and intelligence data must remain confidential for decades, potentially longer than the encryption protecting it remains safe. Examples include intelligence reporting, defense plans, weapons-system information, National Security System (NSS) data, citizen records, and long-term archives.</p><p>That is why post-quantum cryptography, or PQC, is not just a future compliance exercise. It is an existing and substantial threat to data security that agencies need to plan for now. Federal agencies cannot control when Q-Day will occur, however they can control whether the mission data they are protecting today will still be protected when Q-Day arrives.</p><h2 data-id="federal-pqc-guidance-is-moving-into-acquisition-decisions">Federal PQC guidance is moving into acquisition decisions</h2><p>Federal policy is moving PQC from long-range planning into near-term acquisition and deployment decisions. White House Executive Orders 14306 and 14412 establish direction for strengthening cybersecurity and preparing for advanced cryptographic attacks. For National Security Systems, NSA’s Commercial National Security Algorithm Suite 2.0, or CNSA 2.0, identifies approved algorithm families and expected transition milestones. The practical message for system owners and vendors is clear: identify where vulnerable cryptography is used, plan the transition, and include PQC readiness in budgets and procurements now.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/6TVQ0U4LA1LK\/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png&quot;,&quot;name&quot;:&quot;Screenshot 2026-09-15 at 4.16.25 PM.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:43590,&quot;width&quot;:1496,&quot;height&quot;:226,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F6TVQ0U4LA1LK%2Fscreenshot-2026-09-15-at-4-16-25-e2-80-afpm.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5650,&quot;dateInserted&quot;:&quot;2026-09-15T20:16:35+00:00&quot;,&quot;insertUserID&quot;:59953,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F6TVQ0U4LA1LK%2Fscreenshot-2026-09-15-at-4-16-25-e2-80-afpm.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png" alt="Screenshot 2026-09-15 at 4.16.25 PM.png" height="226" width="1496" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png 2000w, https://us.v-cdn.net/6038798/uploads/6TVQ0U4LA1LK/screenshot-2026-09-15-at-4-16-25-e2-80-afpm.png" sizes="100vw" /></a>
    </span>
</span>
<p>The transition timeline is especially important for IC and DoW customers. NSA’s CNSA 2.0 guidance identifies January 1, 2027, as the target for new National Security System acquisitions to be CNSA 2.0 compliant where required; December 31, 2030, as the target for equipment and services that cannot support CNSA 2.0 to be phased out; and December 31, 2031, as the target for CNSA 2.0 algorithms to be mandatory for National Security Systems, subject to the applicable policy, mission, and implementation guidance.</p><p>Be aware there is some nuance here. The January 1, 2027 date is referenced in the NSA <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fnam04.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fmedia.defense.gov%252F2022%252FSep%252F07%252F2003071836%252F-1%252F-1%252F1%252FCSI_CNSA_2.0_FAQ_.PDF%26data%3D05%257C02%257CMatt.Trudewind%2540netapp.com%257C6a1243c8d7054291d02d08dee27718e1%257C4b0911a0929b4715944bc03745165b3a%257C0%257C0%257C639197198771038096%257CUnknown%257CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%253D%253D%257C0%257C%257C%257C%26sdata%3DMQuqexSG47r43cBgsD3m8MlNnKiqYjG2Ws%252BtVa79Q5Q%253D%26reserved%3D0" target="_blank" rel="nofollow noopener ugc">CNSA 2.0 FAQ</a>, while the CNSSP-15 (Committee on National Security Systems Policy No. 15) is currently the policy anchor. Because of that, some agencies may treat the 2027 milestone as strong acquisition guidance rather than a hard requirement across every environment. But for NSS, procurement cycles, and mission systems being designed today, the practical takeaway is clear: PQC readiness is becoming a near-term purchasing decision, not a distant roadmap item.</p><h2 data-id="what-nist-standardized-and-why-it-matters">What NIST standardized—and why it matters</h2><p>In August 2024, the National Institute of Standards and Technology (NIST) finalized its first three PQC standards after a multi-year international process. The standards identify quantum-resistant methods for two basic security functions: creating protected connections and proving that a user, system, certificate, or software update is authentic. Over time, these methods will replace vulnerable public-key algorithms such as Rivest-Shamir-Adleman (RSA), Elliptic-Curve Cryptography (ECC), and Digital Signature Algorithm (DSA).</p><ul><li>The three standards address two practical needs. Module-Lattice-Based Key-Encapsulated Mechanism (ML-KEM) helps two systems establish a shared secret for a protected connection. Module-Lattice-Based Digital Signature Algorithm (ML-DSA) and Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) provide quantum-resistant digital signatures that help verify identity and confirm that software, messages, or certificates have not been altered. The table below maps the formal standard names to those everyday functions.</li></ul><h3 data-id="the-initial-nist-pqc-standards">The initial NIST PQC standards</h3><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p><strong>Standard</strong></p></th><th><p><strong>Algorithm</strong></p></th><th><p><strong>Primary use</strong></p></th></tr><tr><td><p>FIPS 203</p></td><td><p>ML-KEM</p></td><td><p>Key establishment, including TLS and encrypted communications</p></td></tr><tr><td><p>FIPS 204</p></td><td><p>ML-DSA</p></td><td><p>Digital signatures, authentication, and certificates</p></td></tr><tr><td><p>FIPS 205</p></td><td><p>SLH-DSA</p></td><td><p>Hash-based digital signatures and code-signing use cases</p></td></tr></table></div><p>These standards matter to storage because federal data is exposed through more than the media on which it resides. Risk also arises when administrators manage systems, applications access data, storage systems replicate data, certificates authenticate connections, and software or firmware is verified.</p><p>NIST has also made clear that agencies and organizations should begin migrating systems to quantum-resistant cryptography now, and that cybersecurity products, services, and protocols will need updates as organizations identify where vulnerable algorithms are used.</p><h2 data-id="netapp-perspective-the-data-layer-belongs-in-the-pqc-plan">NetApp perspective: The data layer belongs in the PQC plan</h2><p>NetApp provides data infrastructure software and systems that organizations use to store, manage, protect, and move data across data centers, remote locations, and cloud environments. Its core storage operating system, ONTAP, provides the software capabilities that control how data is accessed, replicated, encrypted, and recovered.</p><p>A lot of the PQC conversation focuses on networks, browsers, PKI, and applications. Those are all important. But for federal agencies, the data/storage layer is just as critical.</p><p>Why? Because storage is where the mission data lives.</p><p>An agency’s PQC plan must protect more than websites and network connections. Storage systems are where mission data remains for years or decades, where administrators manage it, and where copies move between locations for continuity and recovery. If those management and data-transfer paths continue to use vulnerable cryptography, the agency has closed only part of the security gap.</p><p>That is where NetApp can help.</p><p>Beginning with ONTAP 9.18.1, NetApp can use NIST-standardized post-quantum methods for specific ONTAP connections. This includes replication connections for on premises or cloud-based ONTAP instances.  In practical terms, these capabilities are intended to protect selected administrative and data-movement paths that use supported TLS and certificate workflows. Agencies should validate the exact platform, protocol, certificate, and deployment requirements for each use case. The connections administrators use to manage storage and the connections systems use to move protected copies of data should also be evaluated. The relevant underlying standards are ML-KEM for establishing protected connections and ML-DSA for digital signatures and authentication.</p><p>Many storage operations depend on protected connections and digital certificates. These include the connection an administrator uses to manage a storage system, the connection two systems use to copy data for backup or recovery, and the certificates systems use to confirm that they are communicating with a trusted endpoint. PQC updates the public-key protections inside supported workflows; it does not replace every form of encryption in the storage environment.</p><h2 data-id="end-to-end-pqc-capabilities-without-a-rip-and-replace-model">End-to-end PQC capabilities without a rip-and-replace model</h2><p>A software-based delivery model can reduce transition effort for supported systems. Agencies may be able to add PQC capabilities through an ONTAP upgrade rather than deploying a separate appliance or replacing the storage platform.</p><p>NetApp currently provides end-to-end PQC encryption for all mission and enterprise workloads for both new and existing customers at no additional cost. That is a big deal for federal agencies facing tight timelines, constrained budgets, and complex procurement processes.</p><h3 data-id="practical-federal-pqc-use-cases-netapp-helps-address">Practical federal PQC use cases NetApp helps address</h3><ul><li><strong>Management of storage systems: </strong>Administrators can manage ONTAP through System Manager GUI and APIs using quantum-resistant TLS and certificate mechanisms.</li><li><strong>Safe replication of data: </strong>Data replication workflows for backup and DR can use quantum-resistant algorithms to help protect data as data moves between storage systems.</li><li><strong>Safe access to data: </strong>Client-to-storage access protocols, including File, Block, and Object, can benefit from quantum-resistant cryptography provided through IPsec and TLS.</li><li><strong>Encryption at rest: </strong>NetApp has used AES-256 to encrypt stored data for well over a decade. Current guidance considers AES-256 resistant to known quantum attacks when it is configured and implemented appropriately. This protection addresses data stored on the system, while PQC primarily updates the public-key methods used to establish trusted connections, exchange keys, and verify identities.</li><li><strong>Layered encryption for classified environments: </strong>NetApp Volume Encryption (NVE) provides software-based AES-256 encryption, while NetApp Storage Encryption (NSE) uses self-encrypting drives for hardware-based AES-256 encryption, enabling a layered encryption model validated by the NSA Commercial Solutions for Classified program for hosting top secret data.</li></ul><h2 data-id="why-netapp-is-different">Why NetApp is different</h2><p>Federal cryptographic transitions are routine. When agencies moved from FIPS 140-2 to FIPS 140-3, NetApp’s crypto-agile architecture enabled customer to adopt new validated cryptographic module through an ONTAP software upgrade rather than a hardware refresh. This helped reduce costs, complexity, and operational impact.</p><p>NetApp provided an easy path for existing customers utilizing software encryption at rest to do this.  A simple upgrade to ONTAP 9.15.1 or later automatically updates the NetApp cryptographic module to a FIPS 140-3 validated module without any impact to existing deployed systems.  In other words, NetApp has a history of helping our customer easily transition to new cryptography without impacting existing missions, workflows and operations.</p><p>When it comes to the transition to PQC specifically, some vendors may be able to say they support quantum resistant encryption in a narrow use case. But federal customers should ask a more important question: Where does that PQC support actually apply?</p><p>Does it protect only CLI access? Only Fiber Channel? Only one management path? Only a narrow protocol? Or does it extend across the operational realities and use cases of how agencies manage, access, move, and protect data?</p><p>NetApp differentiation is that PQC support is broader than a single interface or isolated protocol. NetApp supports PQC end-to-end across GUI-based management, API access, replication, certificate authentication, TLS-based operations, client-to-storage encryption in transit, and storage-level encryption. That means agencies are not limited to protecting only one administrative workflow or one data path.  The data is protected throughout the entire workflow path, not just for one workload.  Whether it’s file, block, or object protocols, from the time data leaves the client endpoint until the data lands on the storage device, it is secure with NetApp’s unique end-to-end PQC encryption.</p><p>Because NetApp supports PQC as part of ONTAP core software and capabilities, this helps existing customers move toward quantum-resistant operations for their data layer without adding cost or complexity through a separate purchase. </p><h3 data-id="key-questions-every-agency-should-ask">Key questions every agency should ask</h3><div><table><colgroup><col /><col /></colgroup><tr><th><p>Which data must remain confidential for decades?</p></th></tr><tr><td><p>Which storage workflows rely on vulnerable public-key cryptography?</p></td></tr><tr><td><p>Which systems will still be operational beyond 2030?</p></td></tr><tr><td><p>Are current acquisition programs evaluating PQC readiness?</p></td></tr><tr><td><p>Does the platform support future cryptographic transitions without hardware replacement?</p></td></tr></table></div><h3 data-id="the-bottom-line">The bottom line</h3><p>For federal agencies, PQC is not only about preparing for Q-Day. It is about protecting long-lived mission data from adversaries who may already be collecting encrypted information today.</p><p>The government guided timeline is fast approaching. NIST standards are available. CNSA 2.0 is shaping procurement expectations. IC and DoW agencies need solutions that help them modernize cryptography without disrupting mission operations.</p><p>NetApp helps federal customers take a practical, data-centric approach to post-quantum readiness. Supported PQC capabilities protect selected management, authentication, and replication workflows, while established AES-256 controls continue to protect data at rest. Together, these controls support a layered strategy for safeguarding the data layer where mission information ultimately resides.  NetApp delivers these capabilities through ONTAP software updates at no additional cost for new and existing customers, enabling agencies to prepare for the post-quantum era today - without waiting for a rip-and-replace cycle tomorrow.</p><h3 data-id="the-data-layer-should-be-part-of-every-pqc-roadmap"><strong>The Data Layer Should Be Part of Every PQC Roadmap</strong></h3><p>Most discussions about post-quantum cryptography focus on networks, applications, and PKI. Federal agencies must also evaluate the infrastructure where mission data is stored, protected, replicated, and recovered.</p><p>As agencies build their post-quantum roadmaps, they should ask whether their data infrastructure can:</p><ul><li>Protect long-lived mission data from harvest-now-decrypt-later threats.</li><li>Support evolving quantum-resistant standards.</li><li>Adapt to future cryptographic requirements through software-driven crypto-agility.</li><li>Enable modernization without disrupting ongoing operations.</li></ul><p>The agencies that prepare their data layer today will be better positioned to secure mission outcomes tomorrow.</p>]]>
        </description>
    </item>
    <item>
        <title>PowerShell Slow to Connect</title>
        <link>https://community.netapp.com/community/discussion/468215/powershell-slow-to-connect</link>
        <pubDate>Tue, 21 Jul 2026 13:57:58 +0000</pubDate>
        <category>Automation &amp; IaC</category>
        <dc:creator>MattBaldwin</dc:creator>
        <guid isPermaLink="false">468215@/community/discussions</guid>
        <description><![CDATA[<div><p>When connecting (<span>Connect-NcController)&nbsp;</span>my ontap arrays, it can take around 40 seconds to connect to our main one.&nbsp; When I connect to my others ones, it takes around 3-5 seconds.</p><p>I get no errors, so I am not sure why this is. Is it simply because our main array is busy and API connections have a lower priority?</p><p>I am running PowerShell 7.6.3 with NetApp.ONTAP module version&nbsp;9.18.1.26.</p></div>]]>
        </description>
    </item>
    <item>
        <title>NetApp Advances Veeam Integration with USAPI Plug-in</title>
        <link>https://community.netapp.com/community/discussion/468383/netapp-advances-veeam-integration-with-usapi-plug-in</link>
        <pubDate>Mon, 14 Sep 2026 22:37:17 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>RyanB</dc:creator>
        <guid isPermaLink="false">468383@/community/discussions</guid>
        <description><![CDATA[<p>Resiliency is a key differentiator for NetApp’s Intelligent Data Infrastructure solutions.  NetApp’s native data protection features provide optimized data management and protection functionality, making ONTAP a unified data management platform suitable for any workload.</p><p>NetApp and Veeam have a long-standing partnership focused on data protection innovation, and Veeam Backup &amp; Replication (VBR) – part of Veeam’s Data Platform (VDP) – is a leading solution for enterprise data resilience.      </p><p>The integration between NetApp and Veeam provides faster, more efficient data resilience with almost no impact on your production environment.  This allows you to dramatically improve the RPO and RTO for your applications and more effectively protect them against evolving threats.  </p><p>Now, NetApp and Veeam are taking things to the next level with a new NetApp plug-in developed using Veeam’s <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fhelpcenter.veeam.com%2Fdocs%2Fbackup%2Fstorage%2Funiversal_storage_integration_api.html%3Fver%3D120" target="_blank" rel="nofollow noopener ugc">Universal Storage API</a> framework.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/2CHRWMFLYTLY\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:148037,&quot;width&quot;:1258,&quot;height&quot;:468,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2CHRWMFLYTLY%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5645,&quot;dateInserted&quot;:&quot;2026-09-14T22:34:18+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F2CHRWMFLYTLY%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/2CHRWMFLYTLY/image.png" alt="image.png" height="468" width="1258" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/2CHRWMFLYTLY/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/2CHRWMFLYTLY/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/2CHRWMFLYTLY/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/2CHRWMFLYTLY/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/2CHRWMFLYTLY/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/2CHRWMFLYTLY/image.png 2000w, https://us.v-cdn.net/6038798/uploads/2CHRWMFLYTLY/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 1) NetApp USAPI plug-in for Veeam</p><h2 data-id="new-and-improved-integration">New and improved integration</h2><p>The NetApp USAPI plug-in with Veeam delivers more efficient and advanced ONTAP integration. The plug-in improves on Veeam’s native ONTAP integration by enabling more streamlined and efficient data protection workflows.  The plug-in also delivers new features, functionality and platform support to help make backup and recovery more secure and resilient.  The plug-in allows both NetApp and Veeam to innovate faster, and it reduces the time to value for new feature releases in both ONTAP and VBR.  Here are some key benefits that the NetApp USAPI plug-in delivers:</p><ul><li><strong>Storage Snapshot Backups – </strong>create and manage ONTAP snapshots directly in the VBR console and use ONTAP snapshots to drastically reduce system overhead when protecting VM workloads</li><li><strong>Resiliency and DR – </strong>take advantage of ONTAP’s SnapMirror optimized replication feature that can be managed directly in VBR to replicate snapshots between clusters for maximum resiliency, security and recoverability</li><li><strong>Data Immutability –</strong> Veeam protects VMs using NetApp tamperproof snapshots that help keep data safe against malware and unauthorized deletion</li></ul><p></p><h2 data-id="how-it-works">How it works</h2><p>Configuring VBR to use the NetApp USAPI plug-in is done via the same simple and user-friendly process you’ve come to expect from Veeam. You can download and install the plug-in directly from the VBR user interface.  Then, you can easily connect your NetApp storage to VBR using the Add Storage wizard.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/GXRUZCC8FGLR\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:85217,&quot;width&quot;:766,&quot;height&quot;:371,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FGXRUZCC8FGLR%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5646,&quot;dateInserted&quot;:&quot;2026-09-14T22:34:38+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FGXRUZCC8FGLR%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/GXRUZCC8FGLR/image.png" alt="image.png" height="371" width="766" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/GXRUZCC8FGLR/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/GXRUZCC8FGLR/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/GXRUZCC8FGLR/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/GXRUZCC8FGLR/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/GXRUZCC8FGLR/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/GXRUZCC8FGLR/image.png 2000w, https://us.v-cdn.net/6038798/uploads/GXRUZCC8FGLR/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 2) Add NetApp storage in VBR with the NetApp USAPI plug-in</p><p></p><p>Once your NetApp ONTAP storage systems are connected to VBR, you can browse the storage in the VBR storage explorer. You can rescan a storage system or specific volume, and you can create storage snapshots directly in VBR without the need to switch interfaces.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/DH6VUKPXVS92\/image-c1888a5a0e47a-a774.png&quot;,&quot;name&quot;:&quot;image-c1888a5a0e47a-a774.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:53384,&quot;width&quot;:314,&quot;height&quot;:369,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDH6VUKPXVS92%2Fimage-c1888a5a0e47a-a774.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5643,&quot;dateInserted&quot;:&quot;2026-09-14T22:34:03+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDH6VUKPXVS92%2Fimage-c1888a5a0e47a-a774.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png" alt="image-c1888a5a0e47a-a774.png" height="369" width="314" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png 2000w, https://us.v-cdn.net/6038798/uploads/DH6VUKPXVS92/image-c1888a5a0e47a-a774.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 3) Browse the connected NetApp storage directly in VBR</p><p></p><p>You can create new VMware backup jobs that use ONTAP snapshots and snapshot replication (SnapMirror) the same way you’ve always done it with VBR.  Simply create a backup job and select the appropriate NetApp plug-in workflow in the job creation wizard, fill in the details, and you’re all set.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/3O2G2OYPFIKF\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:250282,&quot;width&quot;:1081,&quot;height&quot;:745,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3O2G2OYPFIKF%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5647,&quot;dateInserted&quot;:&quot;2026-09-14T22:34:53+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3O2G2OYPFIKF%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/3O2G2OYPFIKF/image.png" alt="image.png" height="745" width="1081" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/3O2G2OYPFIKF/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/3O2G2OYPFIKF/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/3O2G2OYPFIKF/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/3O2G2OYPFIKF/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/3O2G2OYPFIKF/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/3O2G2OYPFIKF/image.png 2000w, https://us.v-cdn.net/6038798/uploads/3O2G2OYPFIKF/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 4) VBR backup for VMware vSphere using the NetApp USAPI plug-in</p><p></p><h2 data-id="functionality">Functionality</h2><p>Veeam backup from ONTAP snapshots (BfSS) significantly improves system performance by offloading backup processing from production systems, which nearly eliminates the performance degradation (known as VM stun) that can happen with VMware backups.  </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/XQ3C6IECA63C\/image-51a427fd15e8e-e33b.png&quot;,&quot;name&quot;:&quot;image-51a427fd15e8e-e33b.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:47205,&quot;width&quot;:634,&quot;height&quot;:227,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXQ3C6IECA63C%2Fimage-51a427fd15e8e-e33b.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5642,&quot;dateInserted&quot;:&quot;2026-09-14T22:34:03+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXQ3C6IECA63C%2Fimage-51a427fd15e8e-e33b.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png" alt="image-51a427fd15e8e-e33b.png" height="227" width="634" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png 2000w, https://us.v-cdn.net/6038798/uploads/XQ3C6IECA63C/image-51a427fd15e8e-e33b.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 5) Improve VM performance with VBR backup from ONTAP snapshots </p><p>VBR can create additional backup copies to off-cluster targets – including NetApp StorageGRID – which can be made immutable for additional protection against malware and accidental or malicious deletion. This provides a robust 3-2-1-1 backup strategy. </p><p>VBR can orchestrate snapshot replication in ONTAP, with new functionality delivered by the plug-in:</p><ul><li>VBR automatically detects SnapMirror asynchronous and synchronous relationships in ONTAP and coordinates updates</li><li>Use SnapMirror async or sync replication targets as the source for Veeam BfSS jobs</li></ul><p>The plug-in also delivers new snapshot immutability functionality that is key for building the most secure data protection solution possible:</p><ul><li>Make snapshots immutable in VBR using ONTAP’s tamperproof snapshot feature</li><li>Use ONTAP tamperproof snapshots in a VBR data lab environment</li></ul><p>With ONTAP tamperproof snapshots, VBR’s anomaly detection and threat hunter security features, you can create a unique cyber vault backup solution that will keep your data protected against ransomware and other malware threats.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/P4W1C0REZQFS\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:256395,&quot;width&quot;:975,&quot;height&quot;:846,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FP4W1C0REZQFS%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5648,&quot;dateInserted&quot;:&quot;2026-09-14T22:35:17+00:00&quot;,&quot;insertUserID&quot;:119857,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FP4W1C0REZQFS%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/P4W1C0REZQFS/image.png" alt="image.png" height="846" width="975" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/P4W1C0REZQFS/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/P4W1C0REZQFS/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/P4W1C0REZQFS/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/P4W1C0REZQFS/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/P4W1C0REZQFS/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/P4W1C0REZQFS/image.png 2000w, https://us.v-cdn.net/6038798/uploads/P4W1C0REZQFS/image.png" sizes="100vw" /></a>
    </span>
</span>
<p>Figure 6) Protect data against ransomware using ONTAP tamperproof snapshots </p><h2 data-id="feature-and-platform-support">Feature and Platform Support</h2><p>The NetApp plug-in for VBR is supported with VBR 13.1 and beyond, and it supports a broad range of ONTAP platforms:  FAS, AFF, ASA and ASA r2. </p><p>The plug-in will support the following Veeam workflows:</p><ul><li>Snapshot management</li><li>Snapshot replication </li><li>Snapshot immutability</li><li>Snapshot archiving will be available soon in a future VBR release</li></ul><p>The existing Veeam native ONTAP integration delivers efficient data protection for VMware, with support for: </p><ul><li>ONTAP snapshots</li><li>SnapVault</li><li>SnapMirror asynchronous</li></ul><p>The NetApp plug-in for VBR supports all the above features available in the Veeam native ONTAP integration.  In addition, the plug-in adds support for several new ONTAP features and configurations:</p><ul><li>Tamperproof snapshots </li><li>SnapMirror synchronous </li><li>MetroCluster </li><li>SVM-DR </li><li>SnapMirror active sync</li></ul><p>The plug-in is supported with all currently supported versions of ONTAP.  It can be downloaded <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.veeam.com%2Fproducts%2Fdata-platform-trial-download.html%3Ftab%3Dstorage-plugins" target="_blank" rel="nofollow noopener ugc">here</a>.  The release notes can be seen <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.veeam.com%2Fkb4904" target="_blank" rel="nofollow noopener ugc">here</a>.</p><h2 data-id="summary">Summary</h2><p>NetApp and Veeam continue to jointly innovate to improve and simplify the data protection experience. The NetApp plug-in for VBR enables faster innovation and time to value for new features and NetApp storage platforms. This makes data resilience more efficient and more secure.    </p><p>Stay tuned for upcoming announcements about how NetApp and Veeam are working together to deliver the most advanced solutions for on premises, cloud, and Kubernetes data protection and resilience.</p>]]>
        </description>
    </item>
    <item>
        <title>NetApp AI Security Framework: Zero Trust Architecture</title>
        <link>https://community.netapp.com/community/discussion/468378/netapp-ai-security-framework-zero-trust-architecture</link>
        <pubDate>Wed, 09 Sep 2026 20:50:09 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>MinithP</dc:creator>
        <guid isPermaLink="false">468378@/community/discussions</guid>
        <description><![CDATA[<span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/QAIGSBYC9VJ4\/image-70a7c9b29c7c48-9fd6.png&quot;,&quot;name&quot;:&quot;image-70a7c9b29c7c48-9fd6.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:32652,&quot;width&quot;:1269,&quot;height&quot;:614,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FQAIGSBYC9VJ4%2Fimage-70a7c9b29c7c48-9fd6.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5630,&quot;dateInserted&quot;:&quot;2026-09-09T17:29:04+00:00&quot;,&quot;insertUserID&quot;:112099,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FQAIGSBYC9VJ4%2Fimage-70a7c9b29c7c48-9fd6.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png" alt="image-70a7c9b29c7c48-9fd6.png" height="614" width="1269" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png 2000w, https://us.v-cdn.net/6038798/uploads/QAIGSBYC9VJ4/image-70a7c9b29c7c48-9fd6.png" sizes="100vw" /></a>
    </span>
</span>
<p>As organizations move from AI experimentation to production-scale deployments, the attack surface expands dramatically. Large language models, AI agents, vector databases, training datasets, and inference pipelines all rely on one critical asset: <strong>data</strong>. If data is compromised, manipulated, encrypted, or exposed, the value of AI quickly disappears.</p><p>This is why the<strong>NetApp AI Security Framework</strong> is built upon a <strong>Data-Centric Zero Trust Architecture</strong> with three foundational pillars: <strong>Hardening</strong>, <strong>Detection &amp; Response</strong>, and <strong>Recovery</strong>. Together, these pillars provide a comprehensive approach to protecting AI workloads from cyber threats while ensuring business continuity.</p><h2 data-id="foundation-data-centric-zero-trust">Foundation: Data-Centric Zero Trust</h2><p>Traditional security approaches focus on securing infrastructure and networks. AI environments require a different mindset because data moves across on-premises systems, clouds, AI pipelines, agents, and model repositories.</p><p>The NetApp AI Security Framework embraces three core Zero Trust principles:</p><ul><li><strong>Assign least-privilege access</strong></li><li><strong>Assume breach</strong></li><li><strong>Never trust, always verify</strong></li></ul><p>By placing data at the center of security strategy, organizations can protect AI workloads throughout their lifecycle, from training and fine-tuning to inferencing and retrieval-augmented generation (RAG).</p><h2 data-id="pillar-1-hardening">Pillar 1: Hardening</h2><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/YXCDQE5X3CSQ\/image-f3b9f0837dcce8-2220.png&quot;,&quot;name&quot;:&quot;image-f3b9f0837dcce8-2220.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:38700,&quot;width&quot;:421,&quot;height&quot;:424,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FYXCDQE5X3CSQ%2Fimage-f3b9f0837dcce8-2220.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5627,&quot;dateInserted&quot;:&quot;2026-09-09T17:29:04+00:00&quot;,&quot;insertUserID&quot;:112099,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FYXCDQE5X3CSQ%2Fimage-f3b9f0837dcce8-2220.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png" alt="image-f3b9f0837dcce8-2220.png" height="424" width="421" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png 2000w, https://us.v-cdn.net/6038798/uploads/YXCDQE5X3CSQ/image-f3b9f0837dcce8-2220.png" sizes="100vw" /></a>
    </span>
</span>
<p>The first step in AI security is reducing the attack surface before threats occur. NetApp hardening capabilities are designed to prevent unauthorized access and ensure that only trusted users, applications, and AI agents can interact with sensitive data.</p><p>Key capabilities include:</p><ul><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fmulti-admin-verify%2F" target="_blank" rel="nofollow noopener ugc"><strong>Multi-Admin Verification (MAV)</strong></a> to prevent malicious or accidental administrative changes</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fpdf.html%3Fitem%3D%2Fmedia%2F16886-tr-4160.pdf" target="_blank" rel="nofollow noopener ugc"><strong>Storage Multi-Tenancy (SMT)</strong></a> to isolate workloads and datasets</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fdata-services%2Fclassification%2F" target="_blank" rel="nofollow noopener ugc"><strong>Data Classification</strong></a> to identify and govern sensitive information</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-automation%2Frest%2Frbac_overview.html" target="_blank" rel="nofollow noopener ugc"><strong>Role-Based Access Control (RBAC)</strong></a> for permission enforcement</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fauthentication%2Foverview-oauth2.html" target="_blank" rel="nofollow noopener ugc"><strong>OAuth 2.0 Integration</strong></a> for secure identity-based access</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-technical-reports%2Fabac%2Fabac-overview.html" target="_blank" rel="nofollow noopener ugc"><strong>Attribute-Based Access Control (ABAC)</strong></a> for granular authorization</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fencryption-at-rest%2F" target="_blank" rel="nofollow noopener ugc"><strong>Encryption</strong></a> for protecting data both at rest and in transit</li></ul><p>These controls help establish a secure foundation for AI environments while ensuring compliance and governance requirements are met.</p><h2 data-id="pillar-2-detection-response">Pillar 2: Detection &amp; Response</h2><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/S1VD9W9DXUVS\/image-9ad0dcb509bd68-f9af.png&quot;,&quot;name&quot;:&quot;image-9ad0dcb509bd68-f9af.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:33957,&quot;width&quot;:397,&quot;height&quot;:394,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FS1VD9W9DXUVS%2Fimage-9ad0dcb509bd68-f9af.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5629,&quot;dateInserted&quot;:&quot;2026-09-09T17:29:04+00:00&quot;,&quot;insertUserID&quot;:112099,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FS1VD9W9DXUVS%2Fimage-9ad0dcb509bd68-f9af.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png" alt="image-9ad0dcb509bd68-f9af.png" height="394" width="397" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png 2000w, https://us.v-cdn.net/6038798/uploads/S1VD9W9DXUVS/image-9ad0dcb509bd68-f9af.png" sizes="100vw" /></a>
    </span>
</span>
<p>Even the most secure environment must assume an attacker may eventually gain access. The second pillar focuses on rapidly detecting anomalies and automating responses before significant damage occurs.</p><p>Key capabilities include:</p><ul><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fanti-ransomware%2F" target="_blank" rel="nofollow noopener ugc"><strong>Autonomous Ransomware Protection (ARP)</strong></a> for AI-driven threat detection</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap-technical-reports%2Fontap-security-hardening%2Fcreate-fpolicy.html" target="_blank" rel="nofollow noopener ugc"><strong>File Policy Analytics (FPolicy)</strong></a> for monitoring suspicious activity</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fdata-services-ransomware-resilience%2Ftask-siem.html" target="_blank" rel="nofollow noopener ugc"><strong>SIEM and SOAR Integrations</strong></a> for enterprise-wide visibility and orchestration</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fnas-audit%2Fauditing-process-concept.html" target="_blank" rel="nofollow noopener ugc"><strong>Comprehensive Auditing</strong></a> for compliance and forensic investigations</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fdata-services%2Fransomware-resilience%2F" target="_blank" rel="nofollow noopener ugc"><strong>Ransomware Resilience</strong></a> capabilities that minimize business impact</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fdata-infrastructure-insights%2Fcs_intro.html" target="_blank" rel="nofollow noopener ugc"><strong>Data Infrastructure Insights (DII) and Storage Workload Security (SWS)</strong></a> for behavioral analytics and real-time monitoring</li></ul><p>This pillar provides continuous visibility into user behavior, data access patterns, and emerging threats, enabling security teams to react quickly and confidently.</p><h2 data-id="pillar-3-recovery">Pillar 3: Recovery</h2><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/3GTPFH546TFT\/image-d951c92e7dc3b-ebe5.png&quot;,&quot;name&quot;:&quot;image-d951c92e7dc3b-ebe5.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:37710,&quot;width&quot;:400,&quot;height&quot;:394,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3GTPFH546TFT%2Fimage-d951c92e7dc3b-ebe5.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5628,&quot;dateInserted&quot;:&quot;2026-09-09T17:29:04+00:00&quot;,&quot;insertUserID&quot;:112099,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3GTPFH546TFT%2Fimage-d951c92e7dc3b-ebe5.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png" alt="image-d951c92e7dc3b-ebe5.png" height="394" width="400" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png 2000w, https://us.v-cdn.net/6038798/uploads/3GTPFH546TFT/image-d951c92e7dc3b-ebe5.png" sizes="100vw" /></a>
    </span>
</span>
<p>Cyber resilience is ultimately measured by how quickly an organization can recover from an attack. AI environments often contain irreplaceable datasets, vector embeddings, and model artifacts that must be restored rapidly and accurately.</p><p>NetApp delivers multiple layers of recovery protection:</p><ul><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fsnaplock%2F" target="_blank" rel="nofollow noopener ugc"><strong>SnapLock®</strong></a> for immutable data protection</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fsnaplock%2Fsnapshot-lock-concept.html" target="_blank" rel="nofollow noopener ugc"><strong>Tamperproof Snapshots (TPS)</strong></a> for secure point-in-time recovery</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fcyber-resilience%2Fcyber-vault%2F" target="_blank" rel="nofollow noopener ugc"><strong>NetApp Cyber Vault</strong></a> for isolated recovery environments</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Falliances%2Fcommvault%2F" target="_blank" rel="nofollow noopener ugc"><strong>Commvault Integration</strong></a> for enterprise backup and recovery</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fproduct-updates%2Fcommvault-closed-loop-recovery%2F" target="_blank" rel="nofollow noopener ugc"><strong>Commvault + ARP</strong></a> for enhanced ransomware remediation</li><li><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fdata-services-ransomware-resilience%2Ftask-clean-restore.html" target="_blank" rel="nofollow noopener ugc"><strong>Rapid Recovery and Clean Restore</strong></a> capabilities to restore trusted data quickly</li></ul><p>These technologies help ensure that organizations can recover AI environments with confidence while minimizing downtime and operational disruption.</p><h2 data-id="security-that-enables-ai-innovation">Security That Enables AI Innovation</h2><p>AI adoption should not force organizations to choose between innovation and security. By combining proactive hardening, intelligent threat detection, and rapid recovery capabilities, the NetApp AI Security Framework provides a comprehensive strategy for protecting the data that powers modern AI.</p><p>The result is a security architecture that helps organizations confidently deploy AI agents, train models, build RAG applications, and scale generative AI initiatives while maintaining control over their most valuable asset: <strong>their data</strong>.</p><p>In the age of AI, security is no longer just about protecting infrastructure. It is about protecting the data that fuels intelligence. That's exactly what the NetApp AI Security Framework is designed to do.</p><p>To finish, here is a summarized view of the Security Framework</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/5UJ3T1V67WY2\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:98660,&quot;width&quot;:998,&quot;height&quot;:477,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F5UJ3T1V67WY2%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5631,&quot;dateInserted&quot;:&quot;2026-09-09T17:31:51+00:00&quot;,&quot;insertUserID&quot;:112099,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F5UJ3T1V67WY2%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/5UJ3T1V67WY2/image.png" alt="image.png" height="477" width="998" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/5UJ3T1V67WY2/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/5UJ3T1V67WY2/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/5UJ3T1V67WY2/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/5UJ3T1V67WY2/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/5UJ3T1V67WY2/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/5UJ3T1V67WY2/image.png 2000w, https://us.v-cdn.net/6038798/uploads/5UJ3T1V67WY2/image.png" sizes="100vw" /></a>
    </span>
</span>
]]>
        </description>
    </item>
    <item>
        <title>DII, and Proxmox as a virtualization platform...</title>
        <link>https://community.netapp.com/community/discussion/467577/dii-and-proxmox-as-a-virtualization-platform</link>
        <pubDate>Wed, 10 Jun 2026 18:55:39 +0000</pubDate>
        <category>Data Infrastructure Insights</category>
        <dc:creator>ostiguy</dc:creator>
        <guid isPermaLink="false">467577@/community/discussions</guid>
        <description><![CDATA[<div><p>We find ourselves in the 6th month of the year, so it is time to think about what is happening in calendar Q3 - one of the data collection projects we will be kicking off is research into the possibility of adding Proxmox virtualization support to DII.&nbsp;</p><p>If you would be interested in Proxmox support in DII, drop me a note at ostiguy at netapp dot com . Please let me know what protocols and storage vendors you are using with Proxmox.</p><p>Thanks</p><p>Matt</p></div>]]>
        </description>
    </item>
    <item>
        <title>Enterprise Data Services Arrive at the Edge</title>
        <link>https://community.netapp.com/community/discussion/468377/enterprise-data-services-arrive-at-the-edge</link>
        <pubDate>Wed, 09 Sep 2026 15:25:05 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Steadman</dc:creator>
        <guid isPermaLink="false">468377@/community/discussions</guid>
        <description><![CDATA[<p>Our FlexPod team has published a new <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fpdf.html%3Fitem%3D%2Fblt9b4fd820a7656ffe%2Fnva-1189-flexpod-cisco-unified-edge.pdf" rel="nofollow noopener ugc">NetApp Verified Architecture (NVA) for FlexPod Edge</a>, pairing Cisco's Unified Edge compute platform with NetApp AFF all-flash storage. The architecture gives organizations a validated, ready-to-deploy blueprint for bringing core-datacenter-class infrastructure and the data management capabilities that come with it out to the locations where data is actually created.</p><p>Edge locations have quietly become some of the most data-intensive places in the enterprise. Point-of-sale systems, factory-floor sensors, security cameras, and clinical devices are generating volumes of data that needs to be captured, processed, and protected close to where they originate often with no IT staff on-site and no room for a rack full of disparate point products. That's the gap this NVA is built to close with a proven infrastructure that's compact enough for a closet or cabinet without asking customers to sacrifice the resiliency, security, or manageability they expect from the core data center.</p><p>FlexPod Edge is the edge-optimized variant of the broader FlexPod converged infrastructure family that NetApp and Cisco have co-engineered for more than seventeen years. Rather than shrinking a data center rack and hoping it fits, FlexPod Edge is purpose-designed around the real constraints of remote sites: limited power and cooling, little to no local IT expertise, and a need for centralized, remote management at scale across hundreds of locations.</p><p>The architecture is built on <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.cisco.com%2Fc%2Fen%2Fus%2Fsolutions%2Fedge-computing.html" target="_blank" rel="nofollow noopener ugc">Cisco Unified Edge</a>, which consolidates compute and networking into an integrated platform sized for space and power constrained environments. Because it's managed through Cisco Intersight, IT teams get the same cloud-based operational visibility and lifecycle management they use for core infrastructure without needing hands-on-keyboard support at every site.</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/XWBJRZUO8K8N\/image-e1e2837fc40b3-e2db.png&quot;,&quot;name&quot;:&quot;image-e1e2837fc40b3-e2db.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:129594,&quot;width&quot;:798,&quot;height&quot;:345,&quot;displaySize&quot;:&quot;medium&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXWBJRZUO8K8N%2Fimage-e1e2837fc40b3-e2db.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5611,&quot;dateInserted&quot;:&quot;2026-09-02T17:47:06+00:00&quot;,&quot;insertUserID&quot;:75458,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FXWBJRZUO8K8N%2Fimage-e1e2837fc40b3-e2db.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png" alt="image-e1e2837fc40b3-e2db.png" height="345" width="798" data-display-size="medium" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png 2000w, https://us.v-cdn.net/6038798/uploads/XWBJRZUO8K8N/image-e1e2837fc40b3-e2db.png" sizes="100vw" /></a>
    </span>
</span>
<p>Rather than treating edge storage as a bare-bones storage tier, FlexPod Edge extends full ONTAP data services out to the edge by using NetApp FAS or AFF arrays. </p><ul><li>Snapshot copies for fast, space-efficient local recovery</li><li>SnapMirror replication back to core data centers or the cloud for disaster recovery and centralized backup</li><li>FlexCache speeds up data access and cuts WAN costs for local read-heavy applications </li><li>Inline deduplication and compression to shrink the physical footprint at cost- and space-sensitive sites</li><li>Autonomous Ransomware Protection to detect and contain anomalous encryption behavior before it spreads. </li></ul><p>Managed centrally through NetApp Console, these capabilities let a centralized IT team operate hundreds of edge sites with data protection policies as consistent as anything in the core data center. In each case, the requirement to process and protect data locally, without giving up the visibility and governance IT needs across the whole fleet.</p><p>As with all NetApp Verified Architectures, this whitepaper is the output of joint engineering work between NetApp and Cisco. The teams designed, deployed, and tested the reference architecture in a lab environment, network and storage configuration details, and deployment best practices so field teams and customers can implement it with a predictable outcome rather than DIYing a design from scratch. Full technical details, bill of materials, and validated configuration steps are available in the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fwww.netapp.com%2Fpdf.html%3Fitem%3D%2Fblt9b4fd820a7656ffe%2Fnva-1189-flexpod-cisco-unified-edge.pdf" rel="nofollow noopener ugc">published NVA</a>. </p><p>Customers and partners evaluating an edge infrastructure refresh or standing up edge sites for the first time should start with the NVA, then loop in their NetApp and Cisco account teams to size the specific deployment. For organizations already running FlexPod in the core data center, FlexPod Edge offers a way to extend that same operating model, and the same data services, all the way out to the edge.</p>]]>
        </description>
    </item>
    <item>
        <title>DRO snapshots created by Shift Toolkit ?</title>
        <link>https://community.netapp.com/community/discussion/468357/dro-snapshots-created-by-shift-toolkit</link>
        <pubDate>Mon, 31 Aug 2026 15:42:18 +0000</pubDate>
        <category>Virtualization</category>
        <dc:creator>jperriguey</dc:creator>
        <guid isPermaLink="false">468357@/community/discussions</guid>
        <description><![CDATA[<p>Hello,</p><p>We are using the NetApp Shift Toolkit as part of a VM migration project (from VMware to Proxmox).</p><p>I noticed that there are several “DRO” (Disaster Recovery Orchestrator) snapshots on the volumes. From my understanding, these are related to the Shift Toolkit, which creates a volume snapshot before converting the disks. It then creates a clone (FlexClone) to convert the disk format from .vmdk to .qcow2, without modifying the original virtual machine.</p><p>These snapshots are consuming a significant amount of storage space (more than 18 TB! on flash array for few tests). I assume they are temporary and expected to be automatically cleaned up.</p><p>Is it possible that some blueprints were not executed successfully and that the snapshots were therefore not properly cleaned up?</p><p>Are these snapshots intended to provide a rollback mechanism, allowing us to revert to the original VM running on VMware?</p><p>Could you please confirm whether my understanding is correct, and let us know whether these snapshots can be safely deleted when there is no migration process currently in progress?</p><p>Thank you in advance for your clarification.</p><p>Best regards,</p>]]>
        </description>
    </item>
    <item>
        <title>Modernize VMware Storage on Google Cloud with Certified Google Cloud NetApp Volumes</title>
        <link>https://community.netapp.com/community/discussion/468375/modernize-vmware-storage-on-google-cloud-with-certified-google-cloud-netapp-volumes</link>
        <pubDate>Tue, 08 Sep 2026 16:51:11 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>sajith</dc:creator>
        <guid isPermaLink="false">468375@/community/discussions</guid>
        <description><![CDATA[<p>Moving  VMware workloads  to Google Cloud? Don’t let storage become the limiting factor. You  need more than just a datastore. You  need a storage platform that delivers enterprise data services, scales independently from compute, simplifies disaster recovery, aligns cost to how data is actually used and remains resilient through infrastructure refreshes and node lifecycle changes.</p><p>Google Cloud NetApp Volumes Flex Unified is now Broadcom certified as external storage for Google Cloud VMware Engine (GCVE) and ESXi z3 baremetal deployments, available in every Google Cloud VMware Engine region. VMware teams now have a validated storage architecture that combines enterprise-class storage capabilities with the operational simplicity of a fully managed first party Google Cloud service.</p><p>In this blog, we will examine how Google Cloud NetApp Volumes Flex Unified enables VMware teams to go beyond traditional cluster attached storage. You will learn how certified external storage can help simplify disaster recovery, reduce infrastructure costs, leverage enterprise data services such as snapshots and replication, decouple storage from compute lifecycles, support both NFS and block workloads, and scale capacity and performance independently as VMware environments grow.</p><p></p><h2 data-id="more-than-a-certification">More than a Certification</h2><p>Google Cloud NetApp Volumes Flex Unified solves some of the most common storage challenges VMware teams face. It enables them to: </p><ul><li><strong>Scale: </strong>Scale storage independently of ESXi host count</li><li><strong>Protect workloads:</strong> Apply enterprise data services such as snapshots, clones, and replication at the storage layer without impacting performance</li><li><strong>Disaster Recovery:</strong> Design efficient disaster recovery environments without mirroring production compute resources</li><li><strong>Reduce costs:</strong> control the cost of inactive data as workloads grow through automatic tiering</li><li><strong>Maintain separation:</strong> separate storage lifecycles from compute lifecycles</li><li><strong>Deploy multi protocol:</strong> Support both file(NFS) and block-based(iSCSI, NVMe/TCP) VMware workloads from a single managed storage platform</li><li><strong>Migrate:</strong> Avoid disruptive migrations as infrastructure evolves.</li></ul><p>For organizations deploying Google Cloud VMware Engine infrastructure, Google Cloud NetApp Volumes Flex Unified provides a certified storage foundation that aligns infrastructure growth with workload requirements instead of cluster constraints.</p><h3 data-id="certified-for-production-vmware-deployments">Certified for Production VMware Deployments</h3><p>For VMware platform teams, certification is often the final validation step before a technology enters production. External storage that has not been validated against the platform introduces risk that most organizations are unwilling to accept for business critical workloads.</p><p>Google Cloud NetApp Volumes Flex Unified is listed in the Broadcom Compatibility Guide as a certified external storage for Google Cloud VMware Engine, providing a validated architecture for attaching NetApp storage to VMware private clouds running on Google Cloud.</p><p>With qualification across GCVE and ESXi z3 baremetal deployments, customers can confidently deploy Google Cloud NetApp Volumes Flex Unified in both existing and new environments without waiting for additional storage qualification cycles.</p><p>Availability in every Google Cloud region where VMware Engine operates completes the architecture. The same storage design can be applied consistently across regions, which simplifies standardization for organizations operating multiple private clouds or planning geographically distributed deployments.</p><h3 data-id="enterprise-data-services-at-the-storage-layer">Enterprise Data Services at the Storage Layer</h3><p>Organizations are frequently limited on their recovery point frequency due to the operational impact.  Host-level protection approaches compete with production workloads for resources, forcing administrators to balance recovery objectives against application performance. Google Cloud NetApp Volumes shifts protection to the storage layer through storage-side snapshots that avoid placing additional I/O burden on production virtual machines. This allows you to decrease your recovery point objective all  while maintaining application performance. VMware environments with GCNV benefit from  enterprise data services, including:</p><ul><li>Snapshots for rapid, low-impact recovery points</li><li>Instant Clones for fast provisioning of test, development, refreshes and investigations.</li><li>Integrated backups for long-term data protection, with support for both in-region and cross-region backups</li><li>Replication for cross-region disaster recovery and business continuity</li><li>Encryption with Google Cloud KMS managed as part of the NetApp Volumes security model</li></ul><p>All these capabilities are delivered as a fully managed service. There is no storage infrastructure to procure, deploy, patch, or refresh.</p><h3 data-id="simplified-disaster-recovery">Simplified Disaster Recovery</h3><p>Because legacy storage is typically bound to the production cluster, traditional disaster recovery solutions often require maintaining a similarly sized standby compute environment, increasing infrastructure costs and complexity.</p><p>Google Cloud NetApp Volumes decouples storage from compute, enabling a more efficient disaster recovery design. Organizations can maintain a smaller standby Google Cloud VMware Engine cluster while replicating data with NetApp Volumes replication and scaling storage independently. This allows recovery environments storage to be sized around RPO and RTO requirements, reducing infrastructure costs by eliminating the need to mirror production compute resources.</p><h3 data-id="storage-lifecycle-independent-of-compute-lifecycle">Storage Lifecycle Independent of Compute Lifecycle</h3><p>One of the most significant benefits of external storage in Google Cloud VMware Engine is the ability to separate storage lifecycles from compute lifecycles.</p><p>Many organizations carefully plan capacity, protection, and recovery strategies, only to discover later that cluster-local storage has tied their data lifecycle to node maintenance schedules, infrastructure refreshes, and platform transitions.</p><p>When storage resides within the VMware cluster, infrastructure events often become storage events:</p><ul><li>Node maintenance can impact storage operations</li><li>Hardware refreshes can introduce migration projects</li><li>New node generations may require datastore transitions</li><li>Cluster growth can trigger storage redesign efforts</li></ul><p>Google Cloud NetApp Volumes helps decouple storage from those infrastructure changes:</p><ul><li><strong>Node maintenance</strong> does not require storage migrations</li><li><strong>Node generation transitions</strong> become datastore attachment decisions rather than large-scale migration projects</li><li><strong>Datastores persist independently</strong> of cluster growth and host refresh cycles</li></ul><p>This separation enables VMware teams to manage storage and compute as independent resources, reducing operational complexity and long-term risk.</p><h3 data-id="optimize-vmware-storage-costs-with-auto-tiering">Optimize VMware storage costs with Auto-Tiering</h3><p>Not all data in a VMware estate is active. Content libraries, images, archives, logging and telemetry data, backup targets, and aging virtual machine disks typically account for a significant portion of consumed capacity while being accessed infrequently. In most environments, this inactive data occupies the same storage tier as production data, and cost scales accordingly.</p><p>Google Cloud NetApp Volumes addresses this with automatic tiering. Infrequently accessed data is moved to a lower-cost storage tier automatically, based on access patterns, without administrative intervention.</p><p>For VMware architects, this delivers value in several ways:</p><ul><li>Cost follows actual usage. Capacity that is no longer active does not continue to consume premium storage economics.</li><li>No workload redesign is required. Virtual machines continue to use the same datastore. Data placement is handled by the storage service, not by Storage vMotion campaigns or secondary archive datastores.</li><li>High-capacity estates remain manageable. Archives, backup targets, and content repositories can grow on a single volume while long-term cost is optimized in the background.</li><li>Operational overhead is reduced. There is no separate archival process, tiering policy engine, or data movement project to maintain.</li></ul><p>Auto-tiering is most valuable for workloads with large capacity footprints and relaxed performance and latency requirements for the inactive portion of the dataset. Performance-sensitive virtual machines continue to operate on the storage tier appropriate to their requirements, while the cost of cold data is optimized automatically.</p><p>The result is a storage model where capacity growth does not translate directly into proportional cost growth; an important consideration as VMware estates expand in Google Cloud.</p><h3 data-id="one-storage-platform-for-nfs-and-block-workloads">One Storage Platform for NFS and Block Workloads</h3><p>Most VMware estates contain a mix of workload types and storage requirements. Google Cloud NetApp Volumes Flex Unified supports both NFS datastores and VMFS datastores for Google Cloud VMware Engine, with NFS, iSCSI, and NVMe/TCP.</p><p>Google Cloud NetApp Volumes Flex Unified provides a unified storage platform that supports:</p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p>Workload Requirement</p></th><th><p>Protocol</p></th></tr><tr><td><p>File based VMware datastores</p></td><td><p>NFS</p></td></tr><tr><td><p>Block storage for traditional SAN applications</p></td><td><p>iSCSI</p></td></tr><tr><td><p>High-performance Low-latency workloads</p></td><td><p>NVMe/TCP</p></td></tr></table></div><p>The same storage pool can also serve file and block workloads outside VMware. Consolidating on a single platform simplifies architecture, procurement, and ongoing operations compared with maintaining separate storage services for file and block requirements.</p><h3 data-id="scale-capacity-and-performance-independently">Scale Capacity and Performance Independently</h3><p>In many environments, storage growth drives infrastructure purchases that are unrelated to actual workload needs causing higher costs. However, Google Cloud NetApp Volumes allows capacity, performance, and compute resources to scale independently which eliminates this dependency. That means:</p><ul><li>A 200 TB workload does not need premium performance pricing if it doesn't require high IOPS.</li><li>Performance increases do not require capacity purchases.</li><li>Capacity growth does not require additional ESXi hosts.</li></ul><p>This flexibility helps VMware teams align spending with actual workload requirements rather than infrastructure design limitations.</p><p>Key use cases include:</p><ul><li><strong>High-capacity environments</strong> such as backup repositories, archives, content libraries, and telemetry data.</li><li><strong>Supplemental capacity</strong> for migrations, temporary projects, and datastore expansion.</li><li><strong>Development and test environments</strong> that require cost-efficient storage without sacrificing management capabilities.</li></ul><p></p><h2 data-id="why-choose-google-cloud-netapp-volumes">Why choose Google Cloud NetApp Volumes</h2><p>VMware workloads on Google Cloud no longer need to accept the traditional trade-offs between storage functionality, scalability, and operational simplicity.</p><p>With Google Cloud NetApp Volumes Flex Unified, organizations can:</p><ul><li>Take frequent storage-based snapshots without impacting production VMs.</li><li>Leverage ONTAP data services including snapshots, clones, and replication.</li><li>Maintain storage independently of node maintenance and hardware refresh cycles.</li><li>Design disaster recovery around recovery objectives instead of mirrored production infrastructure.</li><li>Support both NFS and VMFS datastore requirements.</li><li>Integrate encryption with Google Cloud KMS.</li><li>Scale capacity and performance independently of ESXi node count.</li><li>Deploy on Broadcom-certified storage qualified for GCVE  and ESXi z3 baremetal configurations.</li></ul><p>For VMware teams planning disaster recovery initiatives, expanding datastore capacity, supporting storage-intensive applications, or simplifying long-term infrastructure operations, Google Cloud NetApp Volumes provides a modern storage architecture for Google Cloud VMware Engine.</p><p></p><h2 data-id="get-started">Get Started</h2><p>Google Cloud NetApp Volumes Flex Unified is generally available as Broadcom-certified external storage for Google Cloud VMware Engine in every supported Google Cloud region.</p><p>The fastest way to evaluate the service is to start with a single workload:</p><ul><li>A snapshot-sensitive datastore</li><li>A disaster recovery replica</li><li>A capacity-intensive dataset</li><li>A supplemental datastore for cluster expansion</li></ul><p>Measure the results in terms of recovery point frequency, operational effort, storage utilization, and ESXi node requirements.</p><p>To learn more:</p><ul><li>Review the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fcompatibilityguide.broadcom.com%2Fsearch%3Fprogram%3Dsan%26persona%3Dlive%26column%3DpartnerName%26order%3Dasc%26partnerName%3D%255BGoogle%2BLLC%255D%26activePage%3D1%26activeDelta%3D20" target="_blank" rel="nofollow noopener ugc">Broadcom Compatibility Guide certification listing</a></li><li>Follow the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.cloud.google.com%2Fnetapp%2Fvolumes%2Fdocs%2Fdeploy-use-cases%2Fgcve%2Fattach-gcnv-to-gcve" target="_blank" rel="nofollow noopener ugc">deployment guide</a> for Google Cloud NetApp Volumes datastores on Google Cloud VMware Engine</li><li>Explore the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.cloud.google.com%2Fnetapp%2Fvolumes%2Fdocs%2Fdiscover%2Foverview" target="_blank" rel="nofollow noopener ugc">Google Cloud NetApp Volumes documentation</a></li><li>Engage your Google Cloud or NetApp team for architecture and sizing guidance</li></ul><p>For VMware architects looking to modernize storage operations while preserving enterprise data services, Google Cloud NetApp Volumes Flex Unified delivers a certified, scalable, and operationally efficient storage foundation for Google Cloud VMware Engine.</p>]]>
        </description>
    </item>
    <item>
        <title>Simplify migration of enterprise workloads to AWS with AWS Transform  and Amazon FSx for NetApp ONTAP</title>
        <link>https://community.netapp.com/community/discussion/468374/simplify-migration-of-enterprise-workloads-to-aws-with-aws-transform-and-amazon-fsx-for-netapp-ontap</link>
        <pubDate>Tue, 08 Sep 2026 16:21:32 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>khassine</dc:creator>
        <guid isPermaLink="false">468374@/community/discussions</guid>
        <description><![CDATA[<p></p><p><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Ftransform%2F" target="_blank" rel="nofollow noopener ugc">AWS Transform</a>, the service that uses agentic AI to accelerate cloud migrations, now supports <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Ffsx%2Fnetapp-ontap%2F" target="_blank" rel="nofollow noopener ugc">Amazon FSx for NetApp ONTAP</a> as a storage target for block storage migration to the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2F" target="_blank" rel="nofollow noopener ugc">Amazon Web Services (AWS)</a> Cloud. It introduces a direct migration path, eliminating the multi-step workarounds that previously added cost, time, and risk.  </p><p>In this post we cover: </p><p>​​ </p><ul><li>​Background: migrating block-based workloads before AWS Transform </li><li>​How AWS Transform simplifies migration </li><li>​Unified migration flow for compute and block storage </li><li>​How FSx for ONTAP supports day-2 operations  </li><li>​Impact on modernization projects </li><li>​Summary and next steps </li></ul><p>​​ </p><h2 data-id="background-migrating-block-based-workloads-before-aws-transform"><strong>Background: migrating block-based workloads before AWS Transform </strong></h2><p>Enterprise workloads that utilize block storage typically have well‑defined requirements around performance consistency, data protection, security, and rich data management capabilities. In on‑premises environments, these expectations are met through enterprise storage platforms that provide capabilities such as fast backup and recovery, data replication, and security controls. </p><p>As organizations move enterprise workloads to AWS, preserving the storage capabilities those workloads depend on becomes an increasingly important consideration.   </p><p>This is where FSx for ONTAP comes in. FSx for ONTAP is a fully managed storage service that’s built on NetApp’s popular ONTAP storage software to deliver enterprise‑grade storage capabilities that enterprise workloads need to operate effectively on AWS. </p><p>Despite the strong fit, moving data to FSx for ONTAP often required migration teams to plan storage separately from compute, relying on a two-step migration flow, or using third-party tools.   </p><p></p><h2 data-id="how-aws-transform-simplifies-migration">How AWS Transform simplifies migration  </h2><p><a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Ftransform%2Fmigrations%2F" target="_blank" rel="nofollow noopener ugc">AWS Transform</a> is designed to help organizations plan and execute complete resource migration to the AWS Cloud using AI‑assisted workflows.  AWS Transform applies intelligence to analyze environments, generate migration insights, and orchestrate execution across large-scale modernization initiatives. </p><p>AWS Transform brings together the following two distinct but related capabilities under a single service: </p><p><strong>Assessment capabilities</strong> <br />
The assessment functionality analyzes existing environments to identify application dependencies, infrastructure characteristics, and modernization readiness. This AI‑powered assessment helps teams prioritize workloads and build informed migration plans. </p><p><strong>Migration capabilities</strong> <br />
AWS Transform coordinates workload migration to AWS through automated workflows that now support  FSx for ONTAP as a storage target.  Customers familiar with <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Fapplication-migration-service%2F" target="_blank" rel="nofollow noopener ugc">AWS Application Migration Service (MGN)</a>,  now part of AWS Transform, can replicate block storage data directly to FSx for ONTAP<span style="text-decoration: line-through;"> </span> as well. </p><p> </p><h2 data-id="unified-migration-flow-for-compute-and-block-storage">Unified migration flow for compute and block storage  </h2><p>The migration flow is streamlined into a single migration motion, eliminating the need for separate migration steps or tools: </p><p><strong>Source workloads → AWS Transform migration → Amazon EC2 with FSx for ONTAP</strong> </p><p>AWS Transform handles more than replication. After a migration wave is configured and FSx for ONTAP is selected as the storage target, AWS Transform continuously replicates block storage data to FSx for ONTAP LUNs while source applications remain online. </p><p>For testing and cutover, AWS Transform launches the target Amazon EC2 instances, connects the migrated FSx for ONTAP LUNs over iSCSI, and enables validation before final cutover. This creates a more unified motion for migration teams and a cleaner path to production. </p><p>This is particularly relevant for VMware environments, where virtual machines run on  Virtual Machine File System (VMFS) datastores backed by block LUNs or on NFS datastores. Because AWS Transform replicates from an agent inside each virtual machine at the guest operating system level, the source array and protocol don't constrain the target. Whether vSphere sits on NetApp® or on a third-party array, data volumes can land on FSx for ONTAP as iSCSI LUNs, with the OS boot volume on Amazon EBS.</p><p></p><p>AWS Transform also provides flexibility. Teams can define a default storage target for a migration wave and override that choice at the individual server level. This supports workloads to continue landing on <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Febs%2F" target="_blank" rel="nofollow noopener ugc">Amazon Elastic Block Store (Amazon EBS)</a>, while workloads that benefit from ONTAP‑specific capabilities can land directly on FSx for ONTAP. </p><p> </p><p>The following diagram illustrates the AWS Transform VMware migration with FSx for ONTAP as the storage target: </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/3FS45UQ5VFIX\/atx-blog.png&quot;,&quot;name&quot;:&quot;ATX blog.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:389390,&quot;width&quot;:4036,&quot;height&quot;:1833,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FS45UQ5VFIX%2Fatx-blog.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5622,&quot;dateInserted&quot;:&quot;2026-09-08T16:09:55+00:00&quot;,&quot;insertUserID&quot;:122799,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FS45UQ5VFIX%2Fatx-blog.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/3FS45UQ5VFIX/atx-blog.png" alt="ATX blog.png" height="1833" width="4036" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/3FS45UQ5VFIX/atx-blog.png 2000w, https://us.v-cdn.net/6038798/uploads/3FS45UQ5VFIX/atx-blog.png" sizes="100vw" /></a>
    </span>
</span>
<p></p><h2 data-id="how-fsx-for-ontap-supports-day-2-operations">How FSx for ONTAP supports day-2 operations  </h2><p>After migration, the focus shifts from moving workloads to operating them in AWS. For block-based VMware and database workloads, that includes backup and restore, recovery testing, DevTest refreshes, replication, and business continuity planning.  The storage layer influences how much of that operating model can remain consistent.  </p><p>FSx for ONTAP can help teams maintain familiar storage operations in AWS by providing ONTAP capabilities such as snapshot based protection, efficient data copies, replication, encryption, and ransomware protection. </p><p>Because AWS Transform can now migrate data directly to FSx for ONTAP, teams can continue using ONTAP-based storage workflows after cutover instead of redesigning those processes separately. This is especially valuable for organizations already using ONTAP, where existing operational practices can carry forward into AWS with less change. </p><p> </p><h2 data-id="impact-on-modernization-projects">Impact on modernization projects </h2><p><strong>For infrastructure managers and IT professionals</strong>, this release simplifies migration planning. When compute, network, and block storage move together in one coordinated workflow, there are fewer moving parts to align across teams and fewer opportunities for storage to become a late‑stage bottleneck. </p><p><strong>For modernization project leads</strong>, it reduces architectural compromise. Teams no longer need to choose between using AWS Transform for the primary migration workflow and using a separate approach to land block workloads on FSx for ONTAP. The migration process can better reflect the intended steady‑state architecture from day one. </p><p><strong>For VMware administrators</strong>, this creates a cleaner route to move workloads to Amazon EC2, while preserving the block storage semantics that environments depend on. At a time when many organizations are reexamining their VMware strategy, this can help reduce friction between planning and execution. </p><p><strong>For database and application owners</strong>, it means fewer tool transitions and a more consistent operational model after cutover. Business‑critical block workloads such as Microsoft SQL Server, Oracle, and IBM DB2 can move to AWS while continuing to benefit from the data management, storage efficiency, and protection capabilities available in ONTAP. </p><p>For teams with mixed storage environments, AWS Transform provides the migration for block-based workloads, while <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Fdatasync%2F" target="_blank" rel="nofollow noopener ugc">AWS DataSync</a> remains the recommended service for file storage migrations. Together, these services provide a complete migration strategy for complex enterprise estates. </p><p> </p><h2 data-id="summary-and-next-steps">Summary and next steps </h2><p>With support for FSx for ONTAP as a storage target, AWS Transform now offers a more complete path for enterprise block workload migrations. Customers can move block workloads to Amazon EC2 with direct access to managed ONTAP storage in the AWS Cloud, without intermediate steps or third-party tooling. </p><p>For organizations migrating block‑based applications, this release simplifies migration design, broadens storage destination choice, and supports day-2 operations in AWS. </p><p>Next, read the <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Fabout-aws%2Fwhats-new%2F2026%2F09%2Faws-transform-fsx-netapp-ontap-support%2F" target="_blank" rel="nofollow noopener ugc">AWS Transform announcement</a> and review the AWS storage blog for practical guidance on <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Faws.amazon.com%2Fblogs%2Fstorage%2Fmigrate-vmware-storage-to-amazon-fsx-for-netapp-ontap-using-aws-transform%2F" target="_blank" rel="nofollow noopener ugc">Migrating VMware Storage to FSx for ONTAP  using AWS Transform.</a> </p>]]>
        </description>
    </item>
    <item>
        <title>We received The version of Apache Log4j on the remote host is affected by a vulnerability for linux VM which run Netapp SDK</title>
        <link>https://community.netapp.com/community/discussion/468373/we-received-the-version-of-apache-log4j-on-the-remote-host-is-affected-by-a-vulnerability-for-linux-vm-which-run-netapp-sdk</link>
        <pubDate>Tue, 08 Sep 2026 08:44:42 +0000</pubDate>
        <category>ONTAP APIs &amp; SDKs</category>
        <dc:creator>Yashraj Mohite</dc:creator>
        <guid isPermaLink="false">468373@/community/discussions</guid>
        <description><![CDATA[<p>Below is details of vulnerability -</p><p></p><p></p><p>Plugin Output:</p><p> Path              : /data/netapp-manageability-sdk-9.8P10/zedi/zexplore.jar</p><p> Installed version : 2.19.0</p><p> Fixed version     : 2.25.5</p><p><br /></p><p> Path              : /data/netapp-manageability-sdk-9.8P10/lib/java/classes/manageontap-9.8P10.jar</p><p> Installed version : 2.19.0</p><p> Fixed version     : 2.25.5</p><p><br /></p><p>Description:</p><p>The version of Apache Log4j on the remote host is affected by a vulnerability:</p><ul><li>Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. When a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. (CVE-2026-49844)</li></ul><p>Note that Nessus has not tested this issue but has instead relied only on the application's self-reported version number.</p><p>Can someone please provide more details to remediate this issue and way to fix whether we should upgrade SDk to 9.8P12 and it iwll include latest updated .jar file?</p>]]>
        </description>
    </item>
    <item>
        <title>NetApp Data Classification Giving Export-POlicy error</title>
        <link>https://community.netapp.com/community/discussion/468371/netapp-data-classification-giving-export-policy-error</link>
        <pubDate>Mon, 07 Sep 2026 10:08:05 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>SachinD</dc:creator>
        <guid isPermaLink="false">468371@/community/discussions</guid>
        <description><![CDATA[<p>Hi, We have CIFS volumes only but some of the volumes giving error stating that "Access denied. Ensure the ONTAP export policy allows access from the classification instance"</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/DDO34RIUBW0Y\/screenshot-2026-09-07-144440.png&quot;,&quot;name&quot;:&quot;Screenshot 2026-09-07 144440.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:131075,&quot;width&quot;:1189,&quot;height&quot;:386,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDDO34RIUBW0Y%2Fscreenshot-2026-09-07-144440.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5616,&quot;dateInserted&quot;:&quot;2026-09-07T10:07:57+00:00&quot;,&quot;insertUserID&quot;:115695,&quot;foreignType&quot;:null,&quot;foreignID&quot;:null,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDDO34RIUBW0Y%2Fscreenshot-2026-09-07-144440.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png" alt="Screenshot 2026-09-07 144440.png" height="386" width="1189" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png 2000w, https://us.v-cdn.net/6038798/uploads/DDO34RIUBW0Y/screenshot-2026-09-07-144440.png" sizes="100vw" /></a>
    </span>
</span>
]]>
        </description>
    </item>
    <item>
        <title>ONTAP Simulate download page broken</title>
        <link>https://community.netapp.com/community/discussion/468360/ontap-simulate-download-page-broken</link>
        <pubDate>Tue, 01 Sep 2026 09:46:48 +0000</pubDate>
        <category>Virtualization</category>
        <dc:creator>Anetappian</dc:creator>
        <guid isPermaLink="false">468360@/community/discussions</guid>
        <description><![CDATA[<p>Hi there,<br /><br />
Apologies if this isn't the correct place to post this, however the ONTAP Simulate download page fails to provide a download link.<br />
Is there something I could be doing wrong?</p>]]>
        </description>
    </item>
    <item>
        <title>Zero RPO, Zero RTO for NAS: SnapMirror active sync Comes to File Workloads</title>
        <link>https://community.netapp.com/community/discussion/468277/zero-rpo-zero-rto-for-nas-snapmirror-active-sync-comes-to-file-workloads</link>
        <pubDate>Thu, 30 Jul 2026 15:36:58 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>Hashim_Zargar</dc:creator>
        <guid isPermaLink="false">468277@/community/discussions</guid>
        <description><![CDATA[<h2 data-id="zero-rpo-and-zero-rto-for-nas">Zero-RPO and Zero-RTO for NAS</h2><p>For years, zero recovery point objective (RPO) for NAS workloads has been achieved through synchronous replication, but achieving zero recovery time objective (RTO) has been a major bottleneck to achieving business continuity. Although synchronous copies of data were available, accessing those copies when needed required scripting, disruptive cutover procedures, and manual interventions. </p><p>SnapMirror active sync changed the game for SAN by offering zero RPO and zero RTO for block workloads. With ONTAP 9.19.1, that same synchronous replication with automated failover capability extends to NAS workloads, like NFS and SMB. This type of NAS data is often equally mission‑critical as SAN, but transparent failover was out of reach. If you run mission-critical file workloads on AFF or AFX, this release is worth a closer look.</p><p>In this post, you will see the gap SM-as NAS closes, how replication and failover behave under the hood, and where it fits next to other solutions offered by NetApp.</p><h2 data-id="the-problem-business-continuity-for-nas-lagged-behind-san">The problem: Business continuity for NAS lagged behind SAN</h2><p>SnapMirror active sync has delivered zero-RPO, zero-RTO failover for SAN workloads for some time. Critical NAS data, like finance ledgers on SMB, Oracle or virtualization workloads on NFS, custom financial small file workloads, and mixed-protocol departmental shares, was also subject to strict regulatory and operational compliance requirements. The DR options for those workloads included MetroCluster for site-wide protection, using SnapMirror synchronous replication with a manual failover process, or simpler SVM-DR that could deliver a low RPO, but not zero RPO. </p><p>Those options involved trade-offs:</p><ol><li>MetroCluster excels when you need infrastructure-level, site-wide continuity. Still, it comes with architecture and operational constraints that not every file workload can tolerate, and it does not offer the granularity of SnapMirror active sync.</li><li>SVM-DR is approachable for whole-SVM protection, yet asynchronous replication means data loss is possible at failover, and recovery is operator-driven.</li><li>SM-as proved synchronous replication plus automated failover could work at metro distances, but NAS was out of scope until now.</li></ol><p>Before 9.19.1, zero data loss and transparent application failover for these critical NAS workloads was offered with MetroCluster. Without it, customers had to compromise with disruptive procedures, RPO trade-offs, or SAN-only active sync while file services waited. From 9.19.1, critical FlexVol data within SVMs can be protected with zero-RPO, zero-RTO with transparent application failover, leveraging proven SnapMirror and SnapMirror active-sync technologies.</p><h2 data-id="what-s-new-in-ontap-9-19-1">What’s new in ONTAP 9.19.1</h2><p>SnapMirror active sync for NAS ships in ONTAP 9.19.1 and later. Supported platforms are AFF and AFX.</p><p>Table 1: SnapMirror active sync NAS vs SAN</p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p>Area</p></th><th><p>NAS (9.19.1+)</p></th><th><p>SAN</p></th></tr><tr><td><p>Granularity</p></td><td><p>SVM</p></td><td><p>Consistency group</p></td></tr><tr><td><p>Configuration</p></td><td><p>Active-passive with AutomatedFailover</p></td><td><p>Active-active or active-passive</p></td></tr><tr><td><p>Protocols</p></td><td><p>NFS, SMB3 CA shares (non-disruptive failover)<br />
Other SMB versions (disruptive failover)</p></td><td><p>iSCSI, FC, NVMe</p></td></tr></table></div><p>Note: Although the failover in SMB 2.x / SMB 3.x versions and non-CA shares is disruptive (remount/restart apps), the zero RPO for data is still maintained. This is a protocol limitation and not under the control of SnapMirror active sync.</p><p>Unlike SM-as SAN, NAS does not offer active-active client I/O on both sides of the same protected SVM during normal operation. The secondary SVM remains dormant until failover or planned failover.</p><h2 data-id="how-it-works-architecture-overview">How it works: architecture overview</h2><p><strong>1. Synchronous data replication: </strong>Protected FlexVol volumes in an SVM replicate data synchronously to the partner cluster. Writes are acknowledged to clients only after commit on both sides, which delivers zero RPO for protected volumes.</p><p><strong>2. Configuration Replication Service (CRS): </strong>SVM configuration, i.e., LIF definitions, exports, shares, quota configuration, and related settings, are replicated so the secondary can assume the identity of the primary SVM during failover. Identity discard is not supported. You must plan your network environment carefully for matching network design on both sites.</p><p><strong>3. ONTAP Mediator: </strong>The Mediator (on-premises Linux VM or NetApp Console hosted) is required. It provides quorum for cluster health decisions, enables automated failover, and helps prevent split-brain by ensuring only one site serves a given protected SVM relationship.</p><p>Figure 1: SnapMirror active sync NAS</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/X1QXH7THWL1U\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:285081,&quot;width&quot;:1330,&quot;height&quot;:1196,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FX1QXH7THWL1U%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5403,&quot;dateInserted&quot;:&quot;2026-07-30T15:22:52+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FX1QXH7THWL1U%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/X1QXH7THWL1U/image.png" alt="image.png" height="1196" width="1330" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/X1QXH7THWL1U/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/X1QXH7THWL1U/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/X1QXH7THWL1U/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/X1QXH7THWL1U/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/X1QXH7THWL1U/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/X1QXH7THWL1U/image.png 2000w, https://us.v-cdn.net/6038798/uploads/X1QXH7THWL1U/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="secondary-svm-behavior">Secondary SVM behavior</h2><p>Failover does not rely on traditional LIF migration in the sense of moving addresses you never pre-staged. The CRS-replicated LIFs already exist on the secondary and transition to operational up/up on their home nodes.</p><p>Table 2: Secondary SVM behaviour</p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p>Attribute</p></th><th><p>Normal (secondary)</p></th><th><p>After failover (secondary)</p></th></tr><tr><td><p>Subtype</p></td><td><p>dp-destination</p></td><td><p>default</p></td></tr><tr><td><p>Operational state</p></td><td><p>stopped</p></td><td><p>running</p></td></tr><tr><td><p>LIFs</p></td><td><p>up/down (admin state / operational state)<br />
(no IP collision)</p></td><td><p>up/up (same IPs clients already use)</p></td></tr><tr><td><p>Volumes</p></td><td><p>RW, not mounted</p></td><td><p>RW, mounted, serving I/O</p></td></tr></table></div><h2 data-id="granularity">Granularity</h2><p>Protection is SVM-scoped, but you can include or exclude individual volumes when creating the relationship, or when adding volumes later. You can seamlessly add or remove volumes from the SM-as relationship as and when the SLA changes. It does not delete the volumes or the data inside them; instead, internally, volume membership changes trigger a geometry expand or shrink operation.</p><p>Figure 2: Granularity of protection</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/CUXEFR2RTKYW\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:179772,&quot;width&quot;:1428,&quot;height&quot;:870,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FCUXEFR2RTKYW%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5401,&quot;dateInserted&quot;:&quot;2026-07-30T15:11:34+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FCUXEFR2RTKYW%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/CUXEFR2RTKYW/image.png" alt="image.png" height="870" width="1428" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/CUXEFR2RTKYW/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/CUXEFR2RTKYW/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/CUXEFR2RTKYW/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/CUXEFR2RTKYW/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/CUXEFR2RTKYW/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/CUXEFR2RTKYW/image.png 2000w, https://us.v-cdn.net/6038798/uploads/CUXEFR2RTKYW/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="co-existence">Co-existence</h2><p>SnapMirror active sync for SAN and NAS can run on the same cluster. It also allows protected and unprotected SVMs to coexist. To protect a NAS SVM with SnapMirror active sync, the SVM must be dedicated to NAS workloads and must not host SAN or object (S3) protocols.</p><p>Figure 3: Co-existence of SVMs</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/BTX89F6C9189\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:315710,&quot;width&quot;:1382,&quot;height&quot;:1622,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FBTX89F6C9189%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5402,&quot;dateInserted&quot;:&quot;2026-07-30T15:12:34+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FBTX89F6C9189%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/BTX89F6C9189/image.png" alt="image.png" height="1622" width="1382" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/BTX89F6C9189/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/BTX89F6C9189/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/BTX89F6C9189/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/BTX89F6C9189/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/BTX89F6C9189/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/BTX89F6C9189/image.png 2000w, https://us.v-cdn.net/6038798/uploads/BTX89F6C9189/image.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="async-fan-out">Async fan-out</h2><p>SnapMirror active sync for NAS solves metro-distance, zero-RPO continuity between two sites. Many customers also require a 3-way DR solution with a third location, a remote vault, or a recovery region with asynchronous replication and different RPO/RTO expectations. In ONTAP 9.19.1, SM-as NAS supports volume-level async fan-out with one additional SnapMirror async leg per protected volume, layered on top of the synchronous SM-as relationship.</p><p>Figure 4: SnapMirror async fanout</p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/DUJDWA48LPZR\/image-f8eee1eca1d6e8-1efb.png&quot;,&quot;name&quot;:&quot;image-f8eee1eca1d6e8-1efb.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:234958,&quot;width&quot;:1378,&quot;height&quot;:1166,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDUJDWA48LPZR%2Fimage-f8eee1eca1d6e8-1efb.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5399,&quot;dateInserted&quot;:&quot;2026-07-30T15:00:06+00:00&quot;,&quot;insertUserID&quot;:123269,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;123269&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2FDUJDWA48LPZR%2Fimage-f8eee1eca1d6e8-1efb.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png" alt="image-f8eee1eca1d6e8-1efb.png" height="1166" width="1378" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png 2000w, https://us.v-cdn.net/6038798/uploads/DUJDWA48LPZR/image-f8eee1eca1d6e8-1efb.png" sizes="100vw" /></a>
    </span>
</span>
<h2 data-id="key-benefits">Key benefits</h2><ul><li>Zero-RPO: Synchronous replication for protected NAS FlexVols. No application data loss at failover for in-scope protocols.</li><li>Zero-RTO with automated failover.</li><li>Transparent failover where protocols allow, i.e., NFS and SMB3 CA clients can reconnect with no disruption.</li><li>Granular, workload-level protection. Protect critical SVMs (or subsets of volumes within an SVM) without committing the entire cluster to a single DR model.</li><li>Granular workload failover: Selectively fail over individual tenants, departments, or applications at SVM level without impacting the rest of the cluster. This enables targeted DR testing, non‑disruptive maintenance, phased migrations, and even active load balancing between sites.</li><li>Unified operations story: Manage relationships through ONTAP System Manager alongside SM-as SAN; one ONTAP skillset for block and file metro continuity.</li><li>Secondary copy utility: Cross-SVM FlexClone on the destination supports test/dev, analytics, and DR validation without impacting primary I/O.</li><li>Cost-efficient metro DR: Uses a standard inter-cluster network without dedicated replication switches.</li></ul><h2 data-id="use-cases">Use cases</h2><ul><li>Enterprise file services with strict RPO/RTO requirements:<br />
Departmental or business-specific SVMs that must survive site loss without replaying hours of file changes, especially where audit or compliance treats file data like tier-1 applications.</li><li>Financial services and healthcare:<br />
Workloads that already demanded sync block DR can now align selected NAS tiers (e.g., document repositories, imaging interfaces on NFS, SMB CA–enabled application shares) to the same business continuity requirements provided protocol choices match non-disruptive vs disruptive failover expectations.</li><li>Manufacturing and design collaboration:<br />
Project shares that need metro-distance protection and predictable failover without rebuilding every mount point.</li><li>Service providers and multi-tenant clusters:<br />
SVM-level failover independence allows a protected SVM to fail over without forcing unrelated SVMs on the same cluster into the same event. This helps service providers and multi-tenant environments meet client-specific compliance or regulatory requirements by enabling workloads to run from the secondary cluster when needed. After failover, client access to protected volumes is served from the secondary cluster, providing greater flexibility in where data is accessed and hosted.</li><li>Phased Site Migration &amp; Active Load Balancing<br />
Gradually transition operations from one data center to another on an SVM-by-SVM basis for lower-risk migrations. Distribute active workloads optimally by running some enterprise applications on Site A and others on Site B, while protecting both.</li></ul><h2 data-id="considerations-and-limitations">Considerations and limitations</h2><ul><li>Treat SM-as NAS as workload-granular continuity, not a wholesale MetroCluster replacement. MetroCluster remains the answer when you need site-wide, infrastructure-level protection.</li><li>Scale (per HA pair): up to 50 NAS SVMs (combined with SAN CGs: 50 (SVMs + CGs) total), 400 volumes, 80 volumes per SVM, 16 LIFs per SVM.</li><li>Replication topology: Two-way SM-as (each cluster hosts independent protected SVMs for the other) is supported to optimize infrastructure utilization.</li><li>Auto reconfiguration of asynchronous replication fan-out leg, SVM-granular async fan-out, and cascade replication is not supported with SnapMirror active sync for NAS in the first release.</li></ul>]]>
        </description>
    </item>
    <item>
        <title>SnapMirror Active Sync + ONTAP tools for VMware vSphere 10.6 Granular Datastore Protection</title>
        <link>https://community.netapp.com/community/discussion/468300/snapmirror-active-sync-ontap-tools-for-vmware-vsphere-10-6-granular-datastore-protection</link>
        <pubDate>Thu, 06 Aug 2026 05:01:45 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>RajivJain</dc:creator>
        <guid isPermaLink="false">468300@/community/discussions</guid>
        <description><![CDATA[<ul><li>Co-Author: <a data-username="ChanceBingen" data-userid="12714" rel="nofollow" href="https://community.netapp.com/community/profile/ChanceBingen">@ChanceBingen</a> </li></ul><p><strong>Active-Active VM Storage at Datastore Granularity: SnapMirror Active Sync meets ONTAP tools Granular Datastore Protection</strong> </p><p><strong>The two things to remember</strong> </p><ol><li><strong>Active-active with synchronous SnapMirror (SnapMirror active sync / SM-as)</strong> — ONTAP TOOLSONTAP tools Granular Datastore Protection (GDP) lets you hand-pick VMFS-FC or VMFS-iSCSI datastores inside an ESXi host cluster and protect them with <strong>zero recovery time objective (RTO)/zero recovery point objective (RPO)</strong>replication backed by ONTAP SnapMirror Active Sync. VMs can read and write from either site. </li><li><strong>Load balancing across sites: </strong>Workloads can actively use I/O from either location.  </li><li>With <strong>uniform host proximity</strong>, peered datastores at both sites are mapped to ESXi hosts at <strong>both</strong> sites. If one ONTAP cluster becomes unreachable, VMs continue serving I/O from the surviving site with <strong>typical failover latency on the order of ~11 ms</strong> (the actual I/O resumption time [IORT] will be environment-dependent).  </li><li>With <strong>non-uniform host proximity</strong>, ESXi hosts are only mapped to the local copy of the datastore. I.e. If a VM migrates or fails over to a host on the other site, that host only accesses the local ONTAP cluster. If one ONTAP cluster becomes unreachable, the VM will use vSphere HA to failover to the other site since it can only access its local copy.  </li></ol><p>Everything else in this article explains <em>how</em> ONTAP tools 10.6 provisions and governs that experience. </p><p><strong>Why GDP changes the protection conversation</strong> </p><p>Before ONTAP TOOLS 10.6, <strong>Host Cluster Protection (HCP)</strong> was all-or-nothing: protecting a cluster meant protecting <strong>every</strong> eligible VMFS datastore on that cluster together. </p><p><strong>Granular Datastore Protection (GDP)</strong> shifts the unit of protection from the <strong>host cluster</strong> to <strong>individual VMFS datastores</strong> — while still operating within a single ESXi host cluster boundary. </p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p><strong>Aspect</strong> </p></th><th><p><strong>HCP (pre-10.6)</strong> </p></th><th><p><strong>GDP (ONTAP TOOLS 10.6)</strong> </p></th></tr><tr><td><p>Protection unit </p></td><td><p>Entire host cluster </p></td><td><p>Selected VMFS datastores </p></td></tr><tr><td><p>Mixed protected / unprotected DSs </p></td><td><p>No </p></td><td><p>Yes — same cluster can mix </p></td></tr><tr><td><p>Unprotect one datastore </p></td><td><p>Not supported </p></td><td><p>Supported (non-last DS) </p></td></tr><tr><td><p>Multiple protection groups/cluster </p></td><td><p>One group for all DSs </p></td><td><p>Multiple groups allowed (one SVM per group) </p></td></tr><tr><td><p>Write-order consistency </p></td><td><p>One consistency group (CG) per host cluster </p></td><td><p>Multiple CGs can be configured with different combinations of datastores </p></td></tr></table></div><p> </p><p><strong>Customer value:</strong> Protect only the datastores that matter, add/remove datastores over time, and run different SnapMirror targets per SVM, without forcing every datastore in the host cluster into the same protection group. </p><p><strong>What ONTAP SM-as brings to GDP</strong> </p><p><strong>SnapMirror Active Sync (SM-as)</strong> is ONTAP’s synchronous, active-active replication mode used by the Automated Failover Duplex (AFD) policy. Combined with GDP, it delivers: </p><ul><li><strong>RPO = 0</strong> — writes are synchronously committed to NVRAM on both sites before acknowledgment </li><li><strong>RTO = 0 </strong>— because both copies are always available, IO can resume as soon as the mediator initiates the failover and the host multipath driver can retry any required I/Os </li><li><strong>Active-active data path</strong> — both copies are read/write capable (policy and proximity permitting) </li><li><strong>Consistency group (CG) backed protection</strong> — multiple LUNs/datastores in one atomic replication unit </li><li><strong>Automatic host access orchestration</strong> — ONTAP TOOLS manages igroups, LUN maps, mounts, and HBA rescans </li></ul><p>GDP is the <strong>ONTAP TOOLS control plane</strong>; SM-as is the <strong>ONTAP replication engine</strong>. ONTAP TOOLS creates and lifecycle-manages: </p><ul><li><strong>Protection Settings</strong> — which datastores are protected, CG membership, SnapMirror relationship </li><li><strong>Cluster Configuration</strong> — fault domains, host-to-SVM mapping, uniform vs non-uniform proximity </li><li><strong>Initiator groups (igroups)</strong> — host IQNs/WWPNs mapped to protected LUNs at each site </li></ul><p><strong>ONTAP TOOLS 10.6 constructs that you configure</strong> </p><p><strong>1. Protection Setting</strong> </p><p>A protection group ties together: </p><ul><li>One or more <strong>VMFS datastores</strong> (same host cluster, same SVM) </li><li>An ONTAP <strong>consistency group</strong> </li><li>A <strong>SnapMirror Active Sync</strong> relationship (for AFD) </li><li><strong>Initiator groups</strong> for host access </li></ul><p><strong>Typical workflows:</strong> Protect · Modify (add/remove datastore) · Unprotect · Delete </p><p><strong>2. Cluster Configuration (required for AFD / SM-as)</strong> </p><p>Maps an ESXi host cluster to <strong>two fault domains</strong> (Site A / Site B): </p><ul><li>Each fault domain lists ESXi hosts + peered source/target SVMs </li><li>The uniform_host_config attribute is set at <strong>create time</strong> and is <strong>immutable</strong> </li></ul><p>The following table illustrates the two protection constructs. </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Object</strong> </p></th><th><p><strong>Purpose</strong> </p></th></tr><tr><td><p>Cluster Configuration </p></td><td><p>Topology — fault domains, hosts, SVM peers, uniform vs non-uniform </p></td></tr><tr><td><p>Protection Setting </p></td><td><p>Data — which datastores, CG, SnapMirror, igroups </p></td></tr></table></div><p><strong>Prerequisite:</strong> Create Cluster Configuration <strong>before</strong> protecting datastores with AFD/SM-as. Async-only SnapMirror does not require cluster configuration. </p><p><strong>Uniform vs Non-Uniform Host Proximity</strong> </p><p>This is the architectural fork that determines the system behavior during various modes of failure in different fault domains. </p><p><strong>Uniform proximity (uniform_host_config = true)</strong> </p><p><strong>Behavior:</strong> Peered datastores from <strong>both sites</strong> are mapped to ESXi hosts at <strong>both sites</strong>. All hosts in the cluster can access all protected datastores. ONTAP TOOLS manages <strong>igroup replication</strong> and host proximity settings across both SVMs. </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/96HOF24CH44X\/vmsc-uniform-2026-white-bg.png&quot;,&quot;name&quot;:&quot;vMSC Uniform 2026 white bg.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:128564,&quot;width&quot;:1809,&quot;height&quot;:1782,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F96HOF24CH44X%2Fvmsc-uniform-2026-white-bg.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5490,&quot;dateInserted&quot;:&quot;2026-08-06T16:16:04+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F96HOF24CH44X%2Fvmsc-uniform-2026-white-bg.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png" alt="vMSC Uniform 2026 white bg.png" height="1782" width="1809" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png 2000w, https://us.v-cdn.net/6038798/uploads/96HOF24CH44X/vmsc-uniform-2026-white-bg.png" sizes="100vw" /></a>
    </span>
</span>
<p> </p><p><strong>Use cases:</strong> </p><ul><li><strong>Active-active workload distribution</strong> — VMs on either site issue I/O to locally mapped LUNs based on proximity settings </li><li><strong>Metro / stretched cluster</strong> — compute at both sites, storage synchronously mirrored </li></ul><p><strong>How does GDP use SMas to protect you in different failure scenarios:</strong> </p><ul><li><strong>Storage cluster failure </strong>— IO continues without vSphere HA by using remote copy </li><li><strong>Storage network failure on local target side of network </strong>— IO continues without requiring vSphere HA by using the remote copy </li><li><strong>Storage network failure on local initiator side of network </strong>— A vSphere HA event triggers automatic recovery on the remote site with VM reboot </li><li><strong>Compute failure </strong>— vSphere HA reboots VM on an applicable ESXi host based on resource availability. Affinity and anti-affinity rules may dictate which site the VM is rebooted on </li><li><strong>Full site outage</strong> — VM’s on the failed site are rebooted and recovered by vSphere HA on the surviving site, and I/O is resumed; typical switchover latency ~<strong>11 ms</strong> (lab/field reference; actual depends on distance, network, and load) </li></ul><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Metric</strong> </p></th><th><p><strong>Uniform + SM-as</strong> </p></th></tr><tr><td><p>RPO </p></td><td><p>0 </p></td></tr><tr><td><p>RTO </p></td><td><p>Near-zero for I/O continuity (automatic path to surviving copy) </p></td></tr><tr><td><p>I/O pattern </p></td><td><p>Both sites active </p></td></tr></table></div><p><strong>Non-uniform proximity (uniform_host_config = false)</strong> </p><p><strong>Behavior:</strong> Peered datastores are mapped only to hosts <strong>locally within each site</strong>. Site A hosts access Site A SVM LUNs; Site B hosts access Site B SVM LUNs. Replication is still synchronous (SM-as), but with a reduced number of non-disruptive failure scenarios at the VM layer. For this reason, <strong>uniform configurations are considered the best practice</strong> when the environment can support it. </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/3FUIBUSQ7PH7\/vmsc-non-uniform-2026-white-bg.png&quot;,&quot;name&quot;:&quot;vMSC Non Uniform 2026 white bg.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:115496,&quot;width&quot;:1809,&quot;height&quot;:1782,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FUIBUSQ7PH7%2Fvmsc-non-uniform-2026-white-bg.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5491,&quot;dateInserted&quot;:&quot;2026-08-06T16:16:34+00:00&quot;,&quot;insertUserID&quot;:12714,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;12714&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F3FUIBUSQ7PH7%2Fvmsc-non-uniform-2026-white-bg.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png" alt="vMSC Non Uniform 2026 white bg.png" height="1782" width="1809" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png 2000w, https://us.v-cdn.net/6038798/uploads/3FUIBUSQ7PH7/vmsc-non-uniform-2026-white-bg.png" sizes="100vw" /></a>
    </span>
</span>
<p><strong>Use cases:</strong> </p><ul><li>Campus / dual-room: each room’s hosts only access their local copy </li><li>Optimizing limited WAN bandwidth: eliminating host network traffic between failure domains </li><li>Reduced SAN path management: hosts cannot see remote paths </li><li>Sync DR with site affinity: zero data loss </li></ul><p><strong>How does GDP use SMas to protect you in different failure scenarios:</strong> </p><ul><li>Storage cluster failure — A vSphere HA event triggers automatic recovery on the remote site </li><li>Storage network failure on target side of network — A vSphere HA event triggers automatic recovery on the remote site </li><li>Storage network failure on initiator side of network — A vSphere HA event triggers automatic recovery on the remote site </li><li>Compute failure — vSphere HA reboots VM on applicable ESXi host based on resource availability. Affinity and anti-affinity rules may dictate which site the VM is rebooted on </li><li>Full site outage — VM’s on the failed site are recovered by vSphere HA on the surviving site, and I/O is resumed; typical switchover latency ~11 ms (lab/field reference; actual depends on distance, network, and load) </li></ul><p> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Metric</strong> </p></th><th><p><strong>Non-uniform + SM-as</strong> </p></th></tr><tr><td><p>RPO </p></td><td><p>0 </p></td></tr><tr><td><p>RTO </p></td><td><p>Non-zero — hosts at DR site must regain access (mount, igroup, rescan orchestration) </p></td></tr><tr><td><p>I/O pattern </p></td><td><p>Site-local active; other site is sync replica </p></td></tr></table></div><p><strong>Side-by-side comparison</strong> </p><div><table><colgroup><col /><col /><col /><col /></colgroup><tr><th><p><strong>Dimension</strong> </p></th><th><p><strong>Uniform</strong> </p></th><th><p><strong>Non-uniform</strong> </p></th></tr><tr><td><p>Host access to peer DS </p></td><td><p>All cluster hosts → both sites </p></td><td><p>Site-local hosts → local SVM only </p></td></tr><tr><td><p>Igroup model </p></td><td><p>Replicated igroups across SVMs </p></td><td><p>Per-site igroups </p></td></tr><tr><td><p>Load balancing across sites </p></td><td><p><strong>Yes</strong> — primary value prop </p></td><td><p>No — site-affine I/O </p></td></tr><tr><td><p>Site failure behavior </p></td><td><p>Surviving hosts continue I/O (~11 ms class) </p></td><td><p>Failover orchestration needed; RTO &gt; 0 </p></td></tr><tr><td><p>Cluster config flag </p></td><td><p>uniform_host_config=true </p></td><td><p>uniform_host_config=false </p></td></tr><tr><td><p>Immutable after create? </p></td><td><p>Yes </p></td><td><p>Yes </p></td></tr></table></div><p><strong>End-to-end user flow: from datastore selection to protected active-active</strong> </p><p> </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/41JEJSRQCCAJ\/image-0d7bcd621556f-7221.png&quot;,&quot;name&quot;:&quot;image-0d7bcd621556f-7221.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:153913,&quot;width&quot;:738,&quot;height&quot;:936,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F41JEJSRQCCAJ%2Fimage-0d7bcd621556f-7221.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5486,&quot;dateInserted&quot;:&quot;2026-08-06T04:53:20+00:00&quot;,&quot;insertUserID&quot;:73861,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;73861&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F41JEJSRQCCAJ%2Fimage-0d7bcd621556f-7221.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png" alt="image-0d7bcd621556f-7221.png" height="936" width="738" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png 2000w, https://us.v-cdn.net/6038798/uploads/41JEJSRQCCAJ/image-0d7bcd621556f-7221.png" sizes="100vw" /></a>
    </span>
</span>
<p><strong>GDP use cases (where customers win)</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Use case</strong> </p></th><th><p><strong>Why GDP + SM-as fits</strong> </p></th></tr><tr><td><p>Protect critical DS only </p></td><td><p>Dev/test DSs stay unprotected; production DSs get SM-as </p></td></tr><tr><td><p>Incremental adoption </p></td><td><p>Add newly created DSs to an existing protection group via Modify </p></td></tr><tr><td><p>Multi-SVM on one cluster </p></td><td><p>Different SnapMirror targets per SVM — separate protection settings </p></td></tr><tr><td><p>Uniform metro cluster </p></td><td><p>Active-active I/O + sync replication + ~11 ms class failover </p></td></tr><tr><td><p>Non-uniform dual-room </p></td><td><p>Sync data protection with strict site-local compute affinity </p></td></tr><tr><td><p>Decommission one DS </p></td><td><p>Non-last unprotect shrinks CG; others stay protected </p></td></tr></table></div><p><strong>Version and platform guardrails (ONTAP TOOLS 10.6)</strong> </p><p><strong>Supported</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Requirement</strong> </p></th><th><p><strong>Detail</strong> </p></th></tr><tr><td><p>ONTAP TOOLS </p></td><td><p>10.6 </p></td></tr><tr><td><p>Datastore type </p></td><td><p>VMFS only </p></td></tr><tr><td><p>Protocol </p></td><td><p>iSCSI or FC (FCP) </p></td></tr><tr><td><p>ONTAP for SM-as </p></td><td><p>SVM ONTAP <strong>≥  9.16.1</strong> </p></td></tr><tr><td><p>ONTAP cluster size </p></td><td><p><strong>≤ 4 nodes</strong> </p></td></tr><tr><td><p>SnapMirror policy </p></td><td><p>AFD (Automated Failover Duplex) for active sync </p><p>Standard SnapMirror policies are also supported </p></td></tr><tr><td><p>Disaggregated individual unprotect/delete </p></td><td><p>ONTAP <strong>≥ 9.17.1</strong> </p></td></tr></table></div><p><strong>Not supported in 10.6</strong> </p><ul><li>NFS and NVMe datastore protection </li><li>Sync / strict-sync policies outside AFD SM-as scope </li><li>Local snapshot policies for GDP workflows </li><li>Protecting datastores across <strong>different SVMs</strong> in one protection setting </li><li>Moving a datastore between protection groups (unprotect + re-protect required) </li><li>Custom async SnapMirror policies </li><li>MetroCluster-backed configurations </li><li>ONTAP clusters with <strong>&gt; 4 nodes</strong> </li><li>Mixing uniform and non-uniform protection on the same host cluster </li><li>Protection failover initiated from ONTAP TOOLS UI (use <strong>ONTAP System Manager</strong>) </li><li>ONTAP TOOLS discovering CGs / SnapMirror created outside ONTAP TOOLS (CLI/SM) </li></ul><p><strong>Operational guardrails customers should know</strong> </p><div><table><colgroup><col /><col /><col /></colgroup><tr><th><p><strong>Guardrail</strong> </p></th><th><p><strong>Impact</strong> </p></th></tr><tr><td><p>Cluster config is immutable </p></td><td><p>Cannot switch uniform ↔ non-uniform without delete/recreate (blocked if AFD protection exists) </p></td></tr><tr><td><p>One DS unprotect at a time </p></td><td><p>Parallel unprotect of multiple DSs not supported </p></td></tr><tr><td><p>Last DS = full delete </p></td><td><p>Unprotecting the last datastore deletes the entire protection group </p></td></tr><tr><td><p>Protected DS unmount </p></td><td><p>Only from hosts <strong>outside</strong> the protection host cluster </p></td></tr><tr><td><p>Async SM on unified (O9) </p></td><td><p>Individual (non-last) unprotect <strong>blocked</strong> </p></td></tr><tr><td><p>Sequential ops in cluster </p></td><td><p>Create/delete DS blocked while another protected DS op is in-flight </p></td></tr><tr><td><p>Parallel protection ops </p></td><td><p>Second op on same group returns <strong>409</strong> while state=updating </p></td></tr></table></div><p><strong>Host proximity and igroups — what ONTAP TOOLS automates</strong> </p><p>When you protect a datastore, ONTAP TOOLS 10.6: </p><ol><li>Creates or extends an ONTAP <strong>consistency group</strong> spanning the protected LUNs/volumes </li><li>Establishes <strong>SnapMirror Active Sync</strong> to the peered SVM </li><li>Creates <strong>nested igroups</strong> (parent per datastore, child per host) with host <strong>IQNs/WWPNs</strong> from participating sites </li><li>For <strong>uniform AFD:</strong> replicates igroups across sites so all hosts retain access </li><li>For <strong>non-uniform AFD:</strong> creates site-local igroups mapped to local fault-domain hosts </li><li>Mounts peer datastores and rescans HBAs when topology changes (cluster config modify) </li></ol><p>You do not manually patch igroups for GDP lifecycle operations — ONTAP TOOLS owns add/remove host, mount, unmount, and shrink flows. </p><p><strong>Deeper dive, what happens when a complete site or failure domain goes down?</strong> </p><p><strong>Uniform proximity + SM-as</strong> </p><ul><li>Both copies were actively serving I/O </li><li>SM-as maintains synchronous consistency </li><li>ESXi hosts at the surviving site continue I/O on the accessible LUN paths </li><li><strong>Expected:</strong> I/O continuity with failover latency typically in the <strong>~11 ms</strong> range (not a guaranteed SLA — validate in your environment) </li></ul><p><strong>Non-uniform proximity + SM-as</strong> </p><ul><li>Source-site hosts were actively using local LUNs; target site held the sync replica </li><li><strong>RPO remains 0</strong> — no committed write loss </li><li><strong>RTO is non-zero</strong> — DR-site hosts (or orchestrated failover) must establish access via igroup/mount/rescan workflows </li><li>ONTAP TOOLS cluster configuration modify / protection discovery may be needed after topology events </li></ul><p><strong>Quick decision guide</strong> </p><span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/0MM0MZC46VCS\/image-aba7b4a5423df-03c2.png&quot;,&quot;name&quot;:&quot;image-aba7b4a5423df-03c2.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:133496,&quot;width&quot;:886,&quot;height&quot;:936,&quot;displaySize&quot;:&quot;small&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0MM0MZC46VCS%2Fimage-aba7b4a5423df-03c2.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5487,&quot;dateInserted&quot;:&quot;2026-08-06T04:53:20+00:00&quot;,&quot;insertUserID&quot;:73861,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;73861&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F0MM0MZC46VCS%2Fimage-aba7b4a5423df-03c2.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png" alt="image-aba7b4a5423df-03c2.png" height="936" width="886" data-display-size="small" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png 2000w, https://us.v-cdn.net/6038798/uploads/0MM0MZC46VCS/image-aba7b4a5423df-03c2.png" sizes="100vw" /></a>
    </span>
</span>
<p> </p><p><strong>Summary</strong> </p><p><strong>ONTAP SnapMirror active sync</strong> provides the synchronous, active-active replication engine. <strong>ONTAP TOOLS 10.6 Granular Datastore Protection</strong> provides the VMware-native control plane to: </p><ul><li>Hand-pick which VMFS datastores to protect inside a host cluster </li><li>Model <strong>uniform</strong> or <strong>non-uniform host proximity</strong> via Cluster Configuration </li><li>Lifecycle-manage consistency groups, SnapMirror, igroups, mounts, and rescans </li></ul><p><strong>Key Takeaways </strong> </p><p><strong>Active-active sync SnapMirror:</strong> GDP + SM-as delivers zero-RPO, dual-site VMFS protection at datastore granularity. </p><p><strong>Load balancing:</strong> SnapMirror active sync enables both sites to actively serve I/O, maximizing resource utilization with best of breed business continuity on failure. </p>]]>
        </description>
    </item>
    <item>
        <title>NetApp Extends Symmetric Active-Active SAN Pathing to Unified AFF</title>
        <link>https://community.netapp.com/community/discussion/468316/netapp-extends-symmetric-active-active-san-pathing-to-unified-aff</link>
        <pubDate>Tue, 11 Aug 2026 04:21:05 +0000</pubDate>
        <category>Tech ONTAP Blogs</category>
        <dc:creator>sydamin</dc:creator>
        <guid isPermaLink="false">468316@/community/discussions</guid>
        <description><![CDATA[<span data-embedjson="{&quot;url&quot;:&quot;https:\/\/us.v-cdn.net\/6038798\/uploads\/04UWGCQOVWWD\/image.png&quot;,&quot;name&quot;:&quot;image.png&quot;,&quot;type&quot;:&quot;image\/png&quot;,&quot;size&quot;:201733,&quot;width&quot;:734,&quot;height&quot;:426,&quot;displaySize&quot;:&quot;large&quot;,&quot;float&quot;:&quot;none&quot;,&quot;downloadUrl&quot;:&quot;https:\/\/community.netapp.com\/api\/v2\/media\/download-by-url?url=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F04UWGCQOVWWD%2Fimage.png&quot;,&quot;active&quot;:true,&quot;mediaID&quot;:5534,&quot;dateInserted&quot;:&quot;2026-08-11T04:17:52+00:00&quot;,&quot;insertUserID&quot;:126054,&quot;foreignType&quot;:&quot;embed&quot;,&quot;foreignID&quot;:&quot;126054&quot;,&quot;embedType&quot;:&quot;image&quot;,&quot;embedStyle&quot;:&quot;rich_embed_card&quot;}">
    <span>
        <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fus.v-cdn.net%2F6038798%2Fuploads%2F04UWGCQOVWWD%2Fimage.png" rel="nofollow noopener ugc" target="_blank">
            <img src="https://us.v-cdn.net/6038798/uploads/04UWGCQOVWWD/image.png" alt="image.png" height="426" width="734" data-display-size="large" data-float="none" data-type="image/png" data-embed-type="image" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6038798/uploads/04UWGCQOVWWD/image.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6038798/uploads/04UWGCQOVWWD/image.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6038798/uploads/04UWGCQOVWWD/image.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6038798/uploads/04UWGCQOVWWD/image.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6038798/uploads/04UWGCQOVWWD/image.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6038798/uploads/04UWGCQOVWWD/image.png 2000w, https://us.v-cdn.net/6038798/uploads/04UWGCQOVWWD/image.png" sizes="100vw" /></a>
    </span>
</span>
<h5 data-id="figure-1-symmetric-active-active-san-pathing-on-netapp-aff">Figure 1: Symmetric Active-Active SAN pathing on NetApp AFF</h5><p>Modern enterprise SAN environments cannot tolerate downtime. Mission‑critical databases and large‑scale VMware deployments demand continuous availability and predictable I/O behavior, with little tolerance for controller failovers or path transition delays. At the same time, organizations are under pressure to consolidate workloads onto fewer platforms without sacrificing resilience.</p><p>NetApp addresses this challenge by extending symmetric active-active SAN pathing to NetApp AFF systems with ONTAP 9.19.1, bringing the same nondisruptive SAN access model that customers value on NetApp ASA into NetApp’s unified all-flash portfolio. For AFF, this capability enables simultaneous, active-optimized access across both nodes in an HA pair, helping mission-critical SAN applications maintain continuous availability and predictable I/O behavior while running alongside NAS and other workloads on a single, proven ONTAP platform.</p><p>This extension does not blur the lines between AFF and ASA; it sharpens the role of each platform. AFF is the right choice when customers want to consolidate mission-critical SAN, NAS, and mixed enterprise workloads with shared ONTAP services, cloud mobility, and operational consistency across protocols. ASA remains NetApp’s purpose-built, block-only SAN platform, optimized for customers that want a simplified SAN experience while sustaining predictable performance and efficiency. Together, AFF and ASA give customers two strong architectural choices: unified consolidation where flexibility matters most, and dedicated block simplicity where a SAN-only operating model is a priority.</p><h4 data-id="unified-workload-centralization-on-netapp-aff"><strong>Unified Workload Centralization on NetApp AFF</strong></h4><p>Active-active architecture moves AFF closer to true mission-critical centralization. Customers can run demanding block workloads alongside file and object services on one ONTAP foundation, providing consistent availability, protection, mobility, and management across on-premises and the cloud. The result is stronger continuity for the workloads that demand it most. The primary use cases include:</p><ul><li><strong>Centralize mission-critical mixed workloads:</strong> Run performance and latency sensitive databases, VMware, enterprise applications, electronic health record (EHR) systems, file services, and object-enabled workflows on AFF to reduce silos while preserving the availability and predictability that critical SAN environments require.</li><li><strong>Extend one data architecture across environments:</strong> Apply consistent replication, protection, dev/test, tiering, and disaster recovery across SAN, NAS, and object data, enabling movement between AFF and ONTAP-based cloud services without using separate operating models.</li><li><strong>Modernize data pipelines on production data:</strong> Run analytics, AI/ML, backup, and data services alongside your primary production datasets, using the right protocol for each stage and avoiding redundant copies, slow ETL workflows, and isolated staging platforms.</li></ul><h4 data-id="technical-value"><strong>Technical Value</strong></h4><p>ONTAP 9.19.1 improves host I/O performance on AFF systems by introducing symmetric active-active pathing. This feature allows hosts to use concurrent active-optimized paths across both controllers in an HA pair to access data volumes. Since alternate paths stay active and optimized, host operations resume quickly during path failures, avoiding the latency associated with ALUA/ANA path state transitions. [GR1] [FD2] SAN pathing is configured at the Storage Virtual Machine (SVM) creation time, where administrators can select either symmetric active-active or traditional active-local pathing for each SVM. Existing SVMs remain unchanged, and customers can adopt active-active incrementally by creating new SVMs with active-active pathing and moving workloads over time. The core technical advantages include:[FD3] </p><ul><li><strong>Continuous Availability:</strong> Active‑optimized paths across both nodes eliminate ALUA/ANA transition delays, isolating mission-critical applications from underlying network path failures.</li><li><strong>Simplified Storage Operations: </strong>Consolidates asymmetric structures like SCSI ALUA Target Port Groups and NVMe ANA Access Groups into a single policy in mixed block-storage environments.</li><li><strong>Enable Host Side Load Balancing:</strong> The storage array presents all links as active &amp; optimized, allowing the host to perform network load balancing and distribute I/O traffic across multiple paths.</li></ul><h4 data-id="the-takeaway"><strong>The Takeaway</strong></h4><p>With symmetric active-active SAN pathing on AFF systems, ONTAP extends mission-critical availability to unified workloads without giving up the platform advantages customers already rely on: efficiency, resilience, security, cloud mobility, and operational consistency. AFF becomes an even stronger foundation for customers standardizing mixed block, file, and object workloads across on-premises and cloud—delivering a secure, efficient, multi-protocol architecture built for today’s demands and tomorrow’s growth.</p><h4 data-id="getting-started"><strong>Getting Started</strong></h4><p>Whether you are modernizing your SAN infrastructure or consolidating mixed workloads, active‑active pathing on AFF provides a new design option at no additional licensing cost. Start by identifying workloads most sensitive to path disruption—such as VMware, databases, and transactional applications—and evaluate how active‑active pathing on AFF can help simplify architecture, improve access continuity, and standardize your environment on a unified platform. For configuration guidance and technical details, see the official documentation at: <span data-embedjson="{&quot;body&quot;:&quot;You can nondisruptively update the version of ONTAP on your cluster.&quot;,&quot;photoUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/logo-tophat-social.png&quot;,&quot;url&quot;:&quot;https:\/\/community.netapp.com\/community\/home\/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fsan-admin%2Fmultipath-automatic-lif-failover-support.html&quot;,&quot;embedType&quot;:&quot;link&quot;,&quot;name&quot;:&quot;Learn about SAN multipath and automatic LIF failover support for ONTAP systems&quot;,&quot;faviconUrl&quot;:&quot;https:\/\/docs.netapp.com\/common\/2\/images\/favicon.ico&quot;,&quot;embedStyle&quot;:&quot;rich_embed_inline&quot;}">
    <a href="https://community.netapp.com/community/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fdocs.netapp.com%2Fus-en%2Fontap%2Fsan-admin%2Fmultipath-automatic-lif-failover-support.html" rel="nofollow noopener ugc">
        https://docs.netapp.com/us-en/ontap/san-admin/multipath-automatic-lif-failover-support.html
    </a>
</span>
.</p>]]>
        </description>
    </item>
    <item>
        <title>monitor storage volume capacity over time</title>
        <link>https://community.netapp.com/community/discussion/468368/monitor-storage-volume-capacity-over-time</link>
        <pubDate>Fri, 04 Sep 2026 20:50:47 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>tortiz</dc:creator>
        <guid isPermaLink="false">468368@/community/discussions</guid>
        <description><![CDATA[<p>Out biggest challenge is staying on top of  growing volumes but also not knowing what folders are growing within the volumes. Does anyone know of a tool or script that can monitor volumes and do a deep dive as to what folders are grwoing.</p><p>We have Active iq but it just gives you the volume growth not folder level.</p><p>Does anyone use the ontap API's to do any monitoring of storage? </p>]]>
        </description>
    </item>
    <item>
        <title>FAS50 upgrade 9.16.1P7 to 9.17.1P10 - SnapCenter 5.0 EOVS compatibility?</title>
        <link>https://community.netapp.com/community/discussion/468367/fas50-upgrade-9-16-1p7-to-9-17-1p10-snapcenter-5-0-eovs-compatibility</link>
        <pubDate>Fri, 04 Sep 2026 11:14:07 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>JoaoDuarte</dc:creator>
        <guid isPermaLink="false">468367@/community/discussions</guid>
        <description><![CDATA[<p>Hi all,</p><p>We are planning upgrade of a FAS50 from ONTAP 9.16.1P7 to 9.17.1P10.</p><p>Reason for upgrade is controller panic/reboot related with mgwd becoming unresponsive. Fix for our issue is confirmed on 9.17.1P10 and not available on 9.16.1 patches.</p><p>Before upgrade we want make sure nothing on our environment can be affected.</p><p>Current applications using storage:</p><ul><li>SnapCenter 5.0 SP2 for Oracle</li><li>SnapCenter 6.2P1 for SQL Server and Exchange</li><li>No VMware / ESXi</li></ul><p>Main concern is SnapCenter 5.0 SP2 because components are showing as EOVS in IMT.</p><p>We are trying to confirm if SnapCenter 5.0 SP2 Oracle environment can still be supported with ONTAP 9.17.1, or if SnapCenter must be upgraded first.</p><p>For Oracle we requested:</p><ul><li>Linux OS/version</li><li>Oracle version/RU</li><li>standalone or RAC</li><li>ASM yes/no</li><li>physical or virtual</li><li>storage protocol, looks like FC currently</li><li>exact Oracle and UNIX/FileSystem plug-in versions</li></ul><p>For SQL:</p><ul><li>Windows Server version</li><li>SQL version/edition/CU</li><li>standalone, FCI/WSFC or Always On AG</li><li>physical or virtual</li><li>storage protocol, looks like iSCSI</li><li>exact SQL and Windows plug-in versions</li></ul><p>For Exchange:</p><ul><li>Windows Server version</li><li>Exchange version/CU/SU</li><li>standalone or DAG</li><li>physical or virtual</li><li>iSCSI/FC usage</li><li>exact Exchange and Windows plug-in versions</li></ul><p>Also requested:</p><ul><li>confirm 5.0 SP2 and 6.2P1 are separate SnapCenter Server installations</li><li>Windows version of both SnapCenter Servers</li><li>confirm all protected storage is on same FAS50</li><li>other production applications/hosts using cluster</li><li>any secondary ONTAP used for SnapMirror/DR/backups</li></ul><p>Depending protocol we will also check Host Utilities, multipathing/MPIO, HBA driver/firmware, SAN switches etc.</p><p>We will run Upgrade Advisor and also check shelf/disk firmware before upgrade.</p><p>Main question:</p><p>Is there anything else you would validate before going from 9.16.1P7 to 9.17.1P10?</p><p>And especially, anyone know correct position for SnapCenter 5.0 SP2 Oracle with ONTAP 9.17.1 when 5.0 components are EOVS in IMT?</p><p>Would EOVS mean we should upgrade SnapCenter 5.0 first even if IMT can show a compatible configuration, or can the ONTAP upgrade still be supported?</p><p><strong>CONTAP-621129 - this was the contap we used as RCA</strong></p><p>Thanks in advance</p>]]>
        </description>
    </item>
    <item>
        <title>I would need a download link for 9.12.1 VSIM</title>
        <link>https://community.netapp.com/community/discussion/468366/i-would-need-a-download-link-for-9-12-1-vsim</link>
        <pubDate>Thu, 03 Sep 2026 16:56:21 +0000</pubDate>
        <category>ONTAP</category>
        <dc:creator>Sobhan</dc:creator>
        <guid isPermaLink="false">468366@/community/discussions</guid>
        <description><![CDATA[<p>I am not able to see 9.12.1 VSIM version on NetApp support. Can anyone share me this version of simulator</p>]]>
        </description>
    </item>
   </channel>
</rss>
