<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fpolicy - screening server required? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11743#M2693</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also checkout Northern Storage Suite. It's not quite as mature as NTP QFS, but it is still a very comprehensive product and does the job very well. Deep scanning (opening a file and checking it's properties to work out whether it's been renamed or not) is always an intensive process I have found, so use with caution and make sure you over-spec the scanning server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fpolicy directly on the filer is a good tool though, and if you don't want to do anything too fancy, then it gives you a pretty good starting block. While you're there, checkout quota's. Even if it's just soft quota's, it's a really good way to get a picture of what your users / departments are using. The reason I mention it is that most of the fpolicy servers have some sort of quota functionality also built into them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 May 2009 16:23:56 GMT</pubDate>
    <dc:creator>chriskranz</dc:creator>
    <dc:date>2009-05-12T16:23:56Z</dc:date>
    <item>
      <title>fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11711#M2679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been messing about with fpolicy on the simulator, trying to work out what functionality is provided without a file screening server.&amp;nbsp; i've managed to get the following to work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- block copying blocked extension into share&lt;/P&gt;&lt;P&gt;- block renaming/creation of the blocked file in a share&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot get it to block a file that has been renamed outside of the share, and then copied in (renamed a .mp3 to .txt and it let me copy the file into the share)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've confused myself as to when a server is required and when you can just natively use fpolicy to handle all your file blocking requirements.&amp;nbsp; Can I get all the following functionality with using a third party file screening server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- block copy of .mp3 into share&lt;/P&gt;&lt;P&gt;- block creation/renaming existing .mp3 inside the share&lt;/P&gt;&lt;P&gt;- block renaming .mp3 to .txt outside of share and then copied into the share&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found the config/example guides a little confusing on NOW as it seems to hint that fpolicy can handle all aspects of file-blocking without the addition of a server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hopefully it all makes sense, if a server is required does anyone have a recommendation - prefer to not use one, just rely the awesome-ness of Ontap!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:28:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11711#M2679</guid>
      <dc:creator>rogilvieisc</dc:creator>
      <dc:date>2025-06-05T07:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11716#M2681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Ross,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience you would need a third party software product such as NTP QFS, and you would need a server running the App to connect to the Fpolicy client (on the vfiler/filer) to block the software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used the software in two financial firms, one managing 40,000 users and 300TB of useable data and one with 5,000 users, so I can tell you that Fpolicy works well in the correct implementation, just watch the version of Ontap you are using.&amp;nbsp; But I think it is critical to have third party hardware and software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2009 12:34:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11716#M2681</guid>
      <dc:creator>anthonyfeigl</dc:creator>
      <dc:date>2009-05-04T12:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11725#M2684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anthony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply - if only I was as quick responding!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you, I've used file screening servers in the past, especially when granularity is required - actually the only product i've used is StorageExec, from Veritas which I think has now been rolled into EV?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to exclude one directory within a volume using fpolicy - but it does specifically state fpolicy is implemented at volume level.&amp;nbsp; I thought I'd have a go anyway!! ...I was wasting my time &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you had much experience with file screening servers, any you'd recommend over others?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 07:08:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11725#M2684</guid>
      <dc:creator>rogilvieisc</dc:creator>
      <dc:date>2009-05-12T07:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11730#M2686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Ross,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a bit confused on your statement of file screening servers.&lt;/P&gt;&lt;P&gt;We use Wintel boxes to run the NTP QFS application which connects to our fpolicy configuration on our vfilers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used NTP QFS extensively in financial Production environments to block non business related file content such as mp3, mpg and avi.&lt;/P&gt;&lt;P&gt;NTP QFS was recommended for use (2004-2005) by our NetApp sales team and it has been very effective at managing home directory folder level quotas (acl based) vs qtrees.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NTP QFS is very granular and will allow to lock down specific folders.&amp;nbsp; I suggest you contact them for an evaluation license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any other specific questions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 13:00:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11730#M2686</guid>
      <dc:creator>anthonyfeigl</dc:creator>
      <dc:date>2009-05-12T13:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11739#M2691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Anthony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about the confusion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was just babbling on really, thinking out loud &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon"&gt;&lt;/SPAN&gt;.&amp;nbsp; I was trying to enforce a more granular file-blocking policy without using a 3rd party product, so just using the fpolicy CLi commands via Ontap, it was a clutching at straws effort really - trying to save some money...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not to worry, you answered my question with NTP QFS - think I'll download the trial and have a poke around.&amp;nbsp; Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 13:26:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11739#M2691</guid>
      <dc:creator>rogilvieisc</dc:creator>
      <dc:date>2009-05-12T13:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11743#M2693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also checkout Northern Storage Suite. It's not quite as mature as NTP QFS, but it is still a very comprehensive product and does the job very well. Deep scanning (opening a file and checking it's properties to work out whether it's been renamed or not) is always an intensive process I have found, so use with caution and make sure you over-spec the scanning server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fpolicy directly on the filer is a good tool though, and if you don't want to do anything too fancy, then it gives you a pretty good starting block. While you're there, checkout quota's. Even if it's just soft quota's, it's a really good way to get a picture of what your users / departments are using. The reason I mention it is that most of the fpolicy servers have some sort of quota functionality also built into them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 16:23:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11743#M2693</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2009-05-12T16:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: fpolicy - screening server required?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11751#M2697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the other recommendation Chris, I'll also have a better look into the quota's at some stage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already got fpolicy blocking and its working very well!&amp;nbsp; I just need to exclude some directories within a volume - only one actually which is a little painful but still required, and my understanding is fpolicy is set at a volume level only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully NTP QFS and/or Northern Storage suite will give me that functionality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 May 2009 12:29:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/fpolicy-screening-server-required/m-p/11751#M2697</guid>
      <dc:creator>rogilvieisc</dc:creator>
      <dc:date>2009-05-18T12:29:09Z</dc:date>
    </item>
  </channel>
</rss>

