<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting NFS-Access to specific volumes in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/819#M108</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mrinal,&lt;/P&gt;&lt;P&gt;changing the unix-permissions of the root-volume to 771 did the trick...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="xml" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_13609142276759321" jivemacro_uid="_13609142276759321" modifiedtitle="true"&gt;&lt;P&gt;st228::&amp;gt;&amp;nbsp; volume show -fields volume,unix-permissions,junction-path,policy&lt;/P&gt;&lt;P&gt;vserver&amp;nbsp;&amp;nbsp; volume policy unix-permissions junction-path&lt;/P&gt;&lt;P&gt;--------- ------ ------ ---------------- -------------&lt;/P&gt;&lt;P&gt;test_bl_2 level1 no-nfs &lt;SPAN style="color: rgba(0, 0, 0, 0); font-family: helvetica, arial; font-size: 12px;"&gt;---rwxrwxrwx&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1&lt;/P&gt;&lt;P&gt;test_bl_2 level2 nfs&amp;nbsp;&amp;nbsp;&amp;nbsp; ---rwxrwxrwx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1/level2&lt;/P&gt;&lt;P&gt;test_bl_2 vsroot no-nfs ---rwxrwx--x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /&lt;/P&gt;&lt;P&gt;3 entries were displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;st228::&amp;gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Bernd&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Feb 2013 07:44:23 GMT</pubDate>
    <dc:creator>bloehlein</dc:creator>
    <dc:date>2013-02-15T07:44:23Z</dc:date>
    <item>
      <title>Restricting NFS-Access to specific volumes</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/805#M103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to restrict the nfs access to volumes mounted in 1st or 2nd level of the namespace, but the linux client let's me mount all volumes and the client also sees all files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using clustered ONTAP 8.1.2P1 and defined two export policies, one called no-nfs allowing no access at all and the other one called nfs giving access to the volumes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="xml" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_13608321625115583" jivemacro_uid="_13608321625115583"&gt;&lt;P&gt;st228::*&amp;gt; volume show -fields volume,unix-permissions,junction-path,policy&lt;/P&gt;&lt;P&gt;vserver&amp;nbsp;&amp;nbsp; volume policy unix-permissions junction-path&lt;/P&gt;&lt;P&gt;--------- ------ ------ ---------------- -------------&lt;/P&gt;&lt;P&gt;test_bl_2 level1 no-nfs ---rwxrwxrwx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1&lt;/P&gt;&lt;P&gt;test_bl_2 level2 nfs&amp;nbsp;&amp;nbsp;&amp;nbsp; ---rwxrwxrwx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1/level2&lt;/P&gt;&lt;P&gt;test_bl_2 vsroot no-nfs ---rwxrwxrwx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /&lt;/P&gt;&lt;P&gt;3 entries were displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;st228::*&amp;gt; export-policy rule show -policyname no-nfs -fields vserver,policyname,ruleindex,protocol,clientmatch,rorule,rwrule,superuser,anon&lt;/P&gt;&lt;P&gt;&amp;nbsp; (vserver export-policy rule show)&lt;/P&gt;&lt;P&gt;vserver&amp;nbsp;&amp;nbsp; policyname ruleindex protocol clientmatch rorule rwrule anon&amp;nbsp; superuser&lt;/P&gt;&lt;P&gt;--------- ---------- --------- -------- ----------- ------ ------ ----- ---------&lt;/P&gt;&lt;P&gt;test_bl_2 no-nfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0&amp;nbsp;&amp;nbsp; none&amp;nbsp;&amp;nbsp; none&amp;nbsp;&amp;nbsp; 65534 none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;st228::*&amp;gt; export-policy rule show -policyname nfs -fields vserver,policyname,ruleindex,protocol,clientmatch,rorule,rwrule,superuser,anon&lt;/P&gt;&lt;P&gt;&amp;nbsp; (vserver export-policy rule show)&lt;/P&gt;&lt;P&gt;vserver&amp;nbsp;&amp;nbsp; policyname ruleindex protocol clientmatch rorule rwrule anon&amp;nbsp; superuser&lt;/P&gt;&lt;P&gt;--------- ---------- --------- -------- ----------- ------ ------ ----- ---------&lt;/P&gt;&lt;P&gt;test_bl_2 nfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nfs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp; 65534 none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I have to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bernd&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:10:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/805#M103</guid>
      <dc:creator>bloehlein</dc:creator>
      <dc:date>2025-06-05T06:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting NFS-Access to specific volumes</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/810#M105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Irapua,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we're talking about clustered ONTAP, so sadly no qtree-level exports this time, just at the volume level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bernd&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 14:29:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/810#M105</guid>
      <dc:creator>bloehlein</dc:creator>
      <dc:date>2013-02-14T14:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting NFS-Access to specific volumes</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/815#M107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bernd,&lt;/P&gt;&lt;P&gt;Have a look at this KB, &lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1013380&amp;amp;actp=LIST" title="https://kb.netapp.com/support/index?page=content&amp;amp;id=1013380&amp;amp;actp=LIST" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1013380&amp;amp;actp=LIST&lt;/A&gt;. It has a good explanation along with examples of how you can achieve your objective. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 20:49:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/815#M107</guid>
      <dc:creator>mrinal</dc:creator>
      <dc:date>2013-02-14T20:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting NFS-Access to specific volumes</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/819#M108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mrinal,&lt;/P&gt;&lt;P&gt;changing the unix-permissions of the root-volume to 771 did the trick...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="xml" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_13609142276759321" jivemacro_uid="_13609142276759321" modifiedtitle="true"&gt;&lt;P&gt;st228::&amp;gt;&amp;nbsp; volume show -fields volume,unix-permissions,junction-path,policy&lt;/P&gt;&lt;P&gt;vserver&amp;nbsp;&amp;nbsp; volume policy unix-permissions junction-path&lt;/P&gt;&lt;P&gt;--------- ------ ------ ---------------- -------------&lt;/P&gt;&lt;P&gt;test_bl_2 level1 no-nfs &lt;SPAN style="color: rgba(0, 0, 0, 0); font-family: helvetica, arial; font-size: 12px;"&gt;---rwxrwxrwx&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1&lt;/P&gt;&lt;P&gt;test_bl_2 level2 nfs&amp;nbsp;&amp;nbsp;&amp;nbsp; ---rwxrwxrwx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /level1/level2&lt;/P&gt;&lt;P&gt;test_bl_2 vsroot no-nfs ---rwxrwx--x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /&lt;/P&gt;&lt;P&gt;3 entries were displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;st228::&amp;gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Bernd&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 07:44:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Restricting-NFS-Access-to-specific-volumes/m-p/819#M108</guid>
      <dc:creator>bloehlein</dc:creator>
      <dc:date>2013-02-15T07:44:23Z</dc:date>
    </item>
  </channel>
</rss>

