<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Snapmirror security?  Stopping man-in-the-middle in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Snapmirror-security-Stopping-man-in-the-middle/m-p/78665#M18337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since Snapmirror is a pull method - what stops someone who can packet sniff the network, from pulling volumes off the source filer?&lt;/P&gt;&lt;P&gt;With &lt;SPAN style="font-family: courier new,courier;"&gt;/etc/snapmirror.allow&lt;/SPAN&gt; being the only security on the source, it seems that there is a risk here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use case:&amp;nbsp; OnTap 8.1.1 7-mode, FC SAN w/multiple customers. Customers would replicate over their particular network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Due to FC, can't put any of the volumes in a specific vFiler, must be in vFiler0.&amp;nbsp; &lt;/P&gt;&lt;P&gt;VLANs could be restricted to snapmirror traffic (good)&lt;/P&gt;&lt;P&gt;Restrictions could be made to limit to IP (good, but not enough)&lt;/P&gt;&lt;P&gt;However, anyone with control over their network would be able to spoof the destination IP.&amp;nbsp; Then would be able to initiate snapmirrors and pull data from vol0 and potentially other vols that could be discovered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to stop this?&amp;nbsp; Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ipsec looked to be an option, but is not available in OnTap 8 7-mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2025 06:12:09 GMT</pubDate>
    <dc:creator>JIM_SURLOW</dc:creator>
    <dc:date>2025-06-05T06:12:09Z</dc:date>
    <item>
      <title>Snapmirror security?  Stopping man-in-the-middle</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Snapmirror-security-Stopping-man-in-the-middle/m-p/78665#M18337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since Snapmirror is a pull method - what stops someone who can packet sniff the network, from pulling volumes off the source filer?&lt;/P&gt;&lt;P&gt;With &lt;SPAN style="font-family: courier new,courier;"&gt;/etc/snapmirror.allow&lt;/SPAN&gt; being the only security on the source, it seems that there is a risk here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use case:&amp;nbsp; OnTap 8.1.1 7-mode, FC SAN w/multiple customers. Customers would replicate over their particular network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Due to FC, can't put any of the volumes in a specific vFiler, must be in vFiler0.&amp;nbsp; &lt;/P&gt;&lt;P&gt;VLANs could be restricted to snapmirror traffic (good)&lt;/P&gt;&lt;P&gt;Restrictions could be made to limit to IP (good, but not enough)&lt;/P&gt;&lt;P&gt;However, anyone with control over their network would be able to spoof the destination IP.&amp;nbsp; Then would be able to initiate snapmirrors and pull data from vol0 and potentially other vols that could be discovered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to stop this?&amp;nbsp; Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ipsec looked to be an option, but is not available in OnTap 8 7-mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:12:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Snapmirror-security-Stopping-man-in-the-middle/m-p/78665#M18337</guid>
      <dc:creator>JIM_SURLOW</dc:creator>
      <dc:date>2025-06-05T06:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Snapmirror security?  Stopping man-in-the-middle</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Snapmirror-security-Stopping-man-in-the-middle/m-p/78670#M18338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We put snapmirror traffic on the IPSEC tunnel that is setup by outside router.&amp;nbsp; Also the option snapmirror.check.ip can provide some additional security.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 08:22:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Snapmirror-security-Stopping-man-in-the-middle/m-p/78670#M18338</guid>
      <dc:creator>PZI1234567</dc:creator>
      <dc:date>2013-01-16T08:22:56Z</dc:date>
    </item>
  </channel>
</rss>

