<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Altavault Having issues accessing CIFS/SMB in NetApp Console</title>
    <link>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137331#M73</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Need a bit of help, we have recently installed AltaVault (4.4), we are having issues accesing CIFS shares, here are errors we are seeing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;an 16 14:12:28 localhost smbd[4484]: [function/auth.WARN] (5003) [UserLogin] oem_auth_handover: Unsupported NTLMv1 authentication (user attempting login:chaitanc)&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [function/auth.INFO] (5003) [UserLogin] oem_auth_handover: NTLMv2 user (mfladm-chaitanc) login status 0xc0000022&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [handler/base.INFO] (18464) NetBiosTransport [0x19865e0] getBytes: sockFD: 21 errno: 104&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [handler/base.INFO] (18464) NetBiosTransport [0x19865e0] terminate: sockFD: 21&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: connection terminated. status: 0xc000020d&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: start termination&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18465) Connection [0x19d4000] sendWorker: terminated&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: terminated&lt;BR /&gt;Jan 16 14:12:33 localhost statsd[5803]: event_pending: event has no event_base set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have followed this, but no help..&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="rn_AnswerTitle rn_AnswerTitle"&gt;&lt;DIV class="rn_AnswerDetail rn_AnswerHeader"&gt;How to ensure Kerberos connections to AltaVault data interfaces&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerStatus"&gt;&lt;DIV class="rn_AnswerDetail rn_AnswerHeader"&gt;&lt;DIV class="rn_AnswerInfo"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_A_B"&gt;&lt;SPAN class="rn_Info rn_Bold"&gt;Document ID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;HO1008&lt;/SPAN&gt; Description&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerContent rn_AnswerContent"&gt;&lt;DIV&gt;&lt;DIV class="rn_Indent"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions_Description"&gt;&lt;DIV class="rn_SchemaAttribute"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_SchemaAttributeValue"&gt;How to accomplish Kerberos-based connections to AltaVault data interfaces.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;It is often found that AltaVault is joined to a domain using the management interface and that creates a DNS entry for the management interface.&lt;BR /&gt;While backup applications can still connect to the data interfaces, close observation shows that this connection to data interfaces is using the NTLM protocol.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;In some situations, connections over NTLM are considered undesirable&lt;BR /&gt;Example:&lt;UL&gt;&lt;LI&gt;FIPS mode prohibits the use of NTLM including NTLMv2&lt;/LI&gt;&lt;LI&gt;Some customers may have deployed a domain policy that prohibits NTLM.&lt;BR /&gt;&lt;A href="https://technet.microsoft.com/en-us/library/jj852241(v=ws.11).aspx" target="_blank"&gt;Network Security: Restrict NTLM: NTLM authentication in this domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;provides some details of how this is accomplished.&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions-1"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_Indent"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions_Description-1"&gt;&lt;DIV class="rn_SchemaAttribute"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_SchemaAttributeValue"&gt;Assume the management interface is used to domain join. This creates a DNS entry for the management interface.&lt;BR /&gt;To enable Kerberos, for EACH data interface:&lt;UL&gt;&lt;LI&gt;You MUST manually add a DNS entry (for each data interface)&lt;/LI&gt;&lt;LI&gt;You MUST manually add an SPN (for each data interface)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;You MUST manually flush the SMB client cache (reboot the Windows client(s) or logoff and logon (from the Windows client(s))&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyone had similar problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chaitan&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 04 Jun 2025 14:08:48 GMT</pubDate>
    <dc:creator>Chiatan</dc:creator>
    <dc:date>2025-06-04T14:08:48Z</dc:date>
    <item>
      <title>Altavault Having issues accessing CIFS/SMB</title>
      <link>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137331#M73</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Need a bit of help, we have recently installed AltaVault (4.4), we are having issues accesing CIFS shares, here are errors we are seeing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;an 16 14:12:28 localhost smbd[4484]: [function/auth.WARN] (5003) [UserLogin] oem_auth_handover: Unsupported NTLMv1 authentication (user attempting login:chaitanc)&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [function/auth.INFO] (5003) [UserLogin] oem_auth_handover: NTLMv2 user (mfladm-chaitanc) login status 0xc0000022&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [handler/base.INFO] (18464) NetBiosTransport [0x19865e0] getBytes: sockFD: 21 errno: 104&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [handler/base.INFO] (18464) NetBiosTransport [0x19865e0] terminate: sockFD: 21&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: connection terminated. status: 0xc000020d&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: start termination&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18465) Connection [0x19d4000] sendWorker: terminated&lt;BR /&gt;Jan 16 14:12:28 localhost smbd[4484]: [object/connection.INFO] (18464) Connection [0x19d4000] receiveWorker: terminated&lt;BR /&gt;Jan 16 14:12:33 localhost statsd[5803]: event_pending: event has no event_base set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have followed this, but no help..&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="rn_AnswerTitle rn_AnswerTitle"&gt;&lt;DIV class="rn_AnswerDetail rn_AnswerHeader"&gt;How to ensure Kerberos connections to AltaVault data interfaces&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerStatus"&gt;&lt;DIV class="rn_AnswerDetail rn_AnswerHeader"&gt;&lt;DIV class="rn_AnswerInfo"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_A_B"&gt;&lt;SPAN class="rn_Info rn_Bold"&gt;Document ID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;HO1008&lt;/SPAN&gt; Description&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerContent rn_AnswerContent"&gt;&lt;DIV&gt;&lt;DIV class="rn_Indent"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions_Description"&gt;&lt;DIV class="rn_SchemaAttribute"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_SchemaAttributeValue"&gt;How to accomplish Kerberos-based connections to AltaVault data interfaces.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;It is often found that AltaVault is joined to a domain using the management interface and that creates a DNS entry for the management interface.&lt;BR /&gt;While backup applications can still connect to the data interfaces, close observation shows that this connection to data interfaces is using the NTLM protocol.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;In some situations, connections over NTLM are considered undesirable&lt;BR /&gt;Example:&lt;UL&gt;&lt;LI&gt;FIPS mode prohibits the use of NTLM including NTLMv2&lt;/LI&gt;&lt;LI&gt;Some customers may have deployed a domain policy that prohibits NTLM.&lt;BR /&gt;&lt;A href="https://technet.microsoft.com/en-us/library/jj852241(v=ws.11).aspx" target="_blank"&gt;Network Security: Restrict NTLM: NTLM authentication in this domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;provides some details of how this is accomplished.&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions-1"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_Indent"&gt;&lt;DIV class="rn_AnswerField rn_AnswerField rn_AnswerField_How_To_Descriptions_Description-1"&gt;&lt;DIV class="rn_SchemaAttribute"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="rn_SchemaAttributeValue"&gt;Assume the management interface is used to domain join. This creates a DNS entry for the management interface.&lt;BR /&gt;To enable Kerberos, for EACH data interface:&lt;UL&gt;&lt;LI&gt;You MUST manually add a DNS entry (for each data interface)&lt;/LI&gt;&lt;LI&gt;You MUST manually add an SPN (for each data interface)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;You MUST manually flush the SMB client cache (reboot the Windows client(s) or logoff and logon (from the Windows client(s))&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyone had similar problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chaitan&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:08:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137331#M73</guid>
      <dc:creator>Chiatan</dc:creator>
      <dc:date>2025-06-04T14:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Altavault Having issues accessing CIFS/SMB</title>
      <link>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137368#M74</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When you map the share, you should be using the FQDN of the share and AVA interface. For example, if I've set the share called share1, and an interface e0a to an IP address 10.20.30.40, then you should have a corresponding DNS entry like AVA_e0a mapping to 10.20.30.40. Then, when you map a drive in Windows Explorer, you can use the path \\AVA_e0a\share1. NTLM only occurs if you're unable to use kerberos, such as when calling a share by IP and not DNS name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 21:36:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137368#M74</guid>
      <dc:creator>chriswong</dc:creator>
      <dc:date>2018-01-17T21:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Altavault Having issues accessing CIFS/SMB</title>
      <link>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137377#M75</link>
      <description>&lt;P&gt;Thanks a lot Chris, it worked with DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chaitan&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 09:34:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/NetApp-Console/Altavault-Having-issues-accessing-CIFS-SMB/m-p/137377#M75</guid>
      <dc:creator>Chiatan</dc:creator>
      <dc:date>2018-01-18T09:34:32Z</dc:date>
    </item>
  </channel>
</rss>

