<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Baffled by Ontap 8 Clustered Mode NFS Export Policies in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134693#M29535</link>
    <description>&lt;P&gt;I am baffed by the ue of export polcies. I have an NFS volume exported as follows:&lt;/P&gt;&lt;PRE&gt;netapp-clr01::&amp;gt; vserver export-policy rule show -policyname templates -vserver netapp-nfs01
             Policy          Rule    Access   Client                RO
Vserver      Name            Index   Protocol Match                 Rule
------------ --------------- ------  -------- --------------------- ---------
netapp-nfs01 templates       1       nfs      10.0.0.0/8            any


netapp-clr01::&amp;gt; vserver export-policy rule show -policyname templates -vserver netapp-nfs01  -ruleindex 1

                                    Vserver: netapp-nfs01
                                Policy Name: templates
                                 Rule Index: 1
                            Access Protocol: nfs
Client Match Hostname, IP Address, Netgroup, or Domain: 10.0.0.0/8
                             RO Access Rule: sys
                             RW Access Rule: sys
User ID To Which Anonymous Users Are Mapped: 65534
                   Superuser Security Types: any
               Honor SetUID Bits in SETATTR: true
                  Allow Creation of Devices: true&lt;BR /&gt;&lt;BR /&gt;netapp-clr01::&amp;gt; volume show -volume templates -fields policy vserver volume policy&lt;BR /&gt;------------ --------- ---------&lt;BR /&gt;netapp-nfs01 templates templates&lt;/PRE&gt;&lt;P&gt;Yet all clients are denied:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;netapp-clr01::&amp;gt; vserver export-policy check-access -vserver netapp-nfs01 -volume templates -authentication-method sys -protocol nfs3 -access-type read -client-ip 10.2.48.1 -policy templates&lt;BR /&gt;There are no entries matching your query.&lt;BR /&gt;&lt;BR /&gt;netapp-clr01::&amp;gt; vserver export-policy check-access -vserver netapp-nfs01 -volume templates -authentication-method sys -protocol nfs3 -access-type read -client-ip 10.2.48.1&lt;BR /&gt; Policy Policy Rule&lt;BR /&gt;Path Policy Owner Owner Type Index Access&lt;BR /&gt;----------------------------- ---------- --------- ---------- ------ ----------&lt;BR /&gt;/ default netapp_nfs01_root&lt;BR /&gt; volume 0 denied&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Showmount -e looks OK:&lt;/P&gt;&lt;PRE&gt;~$ showmount -e 10.2.48.102
Exports list on 10.2.48.102:
/                                   Everyone&lt;/PRE&gt;&lt;P&gt;What am I missing here?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 14:34:10 GMT</pubDate>
    <dc:creator>wsanderstii</dc:creator>
    <dc:date>2025-06-04T14:34:10Z</dc:date>
    <item>
      <title>Baffled by Ontap 8 Clustered Mode NFS Export Policies</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134693#M29535</link>
      <description>&lt;P&gt;I am baffed by the ue of export polcies. I have an NFS volume exported as follows:&lt;/P&gt;&lt;PRE&gt;netapp-clr01::&amp;gt; vserver export-policy rule show -policyname templates -vserver netapp-nfs01
             Policy          Rule    Access   Client                RO
Vserver      Name            Index   Protocol Match                 Rule
------------ --------------- ------  -------- --------------------- ---------
netapp-nfs01 templates       1       nfs      10.0.0.0/8            any


netapp-clr01::&amp;gt; vserver export-policy rule show -policyname templates -vserver netapp-nfs01  -ruleindex 1

                                    Vserver: netapp-nfs01
                                Policy Name: templates
                                 Rule Index: 1
                            Access Protocol: nfs
Client Match Hostname, IP Address, Netgroup, or Domain: 10.0.0.0/8
                             RO Access Rule: sys
                             RW Access Rule: sys
User ID To Which Anonymous Users Are Mapped: 65534
                   Superuser Security Types: any
               Honor SetUID Bits in SETATTR: true
                  Allow Creation of Devices: true&lt;BR /&gt;&lt;BR /&gt;netapp-clr01::&amp;gt; volume show -volume templates -fields policy vserver volume policy&lt;BR /&gt;------------ --------- ---------&lt;BR /&gt;netapp-nfs01 templates templates&lt;/PRE&gt;&lt;P&gt;Yet all clients are denied:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;netapp-clr01::&amp;gt; vserver export-policy check-access -vserver netapp-nfs01 -volume templates -authentication-method sys -protocol nfs3 -access-type read -client-ip 10.2.48.1 -policy templates&lt;BR /&gt;There are no entries matching your query.&lt;BR /&gt;&lt;BR /&gt;netapp-clr01::&amp;gt; vserver export-policy check-access -vserver netapp-nfs01 -volume templates -authentication-method sys -protocol nfs3 -access-type read -client-ip 10.2.48.1&lt;BR /&gt; Policy Policy Rule&lt;BR /&gt;Path Policy Owner Owner Type Index Access&lt;BR /&gt;----------------------------- ---------- --------- ---------- ------ ----------&lt;BR /&gt;/ default netapp_nfs01_root&lt;BR /&gt; volume 0 denied&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Showmount -e looks OK:&lt;/P&gt;&lt;PRE&gt;~$ showmount -e 10.2.48.102
Exports list on 10.2.48.102:
/                                   Everyone&lt;/PRE&gt;&lt;P&gt;What am I missing here?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:34:10 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134693#M29535</guid>
      <dc:creator>wsanderstii</dc:creator>
      <dc:date>2025-06-04T14:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Baffled by Ontap 8 Clustered Mode NFS Export Policies</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134722#M29546</link>
      <description>&lt;P&gt;Hello, not sure you're mssing too much. From the output it looks like the templates export policy is assigned to the templates volume, however in the &lt;STRONG&gt;check-access&lt;/STRONG&gt; it cannot find the templates export policy and assigns the default which gives you the permission denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note sure which version of ONTAP 8 you are using, however burt 863946 entitled&amp;nbsp;&lt;EM&gt;Wrong permissions sent when junctions have different export policy rules&amp;nbsp;&lt;/EM&gt;is not fixed until&amp;nbsp;8.2.3/8.3.2&lt;EM&gt;:&amp;nbsp;&lt;/EM&gt;&lt;A href="https://mysupport.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=863946" target="_blank"&gt;https://mysupport.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=863946&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The workaround is to&amp;nbsp;set the same export policy for all the junctions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Grant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:15:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134722#M29546</guid>
      <dc:creator>sgrant</dc:creator>
      <dc:date>2017-09-25T13:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Baffled by Ontap 8 Clustered Mode NFS Export Policies</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134739#M29552</link>
      <description>&lt;P&gt;Hi wsanderstii,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work for NetApp supporting migration to ONTAP9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output you provided doesn't show the export policy you've applied to the root volume which is where you are getting the denied.&amp;nbsp; Take another look at the check-access output!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can see all volumes' policy and junction-path from the command line by running the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;aff-01::&amp;gt; rows 0; vol show -vserver *nfs* -fields policy,junction-path&lt;/PRE&gt;&lt;P&gt;Security inheritence is in play.&amp;nbsp; The root volume needs to be accessible if you want to let people get at the templates volume, which is junctioned under the root /.&amp;nbsp; I recommend taking a look our cool new docs.netapp.com center for the &lt;A href="http://docs.netapp.com/ontap-9/topic/com.netapp.doc.exp-nfsv3-cg/GUID-FC041987-F793-427E-BB00-19D3DB1F30DA.html" target="_blank"&gt;NFS express guide&lt;/A&gt; on how to open up access to the root volume.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I like locking it down a bit.&amp;nbsp; A great resource for how to do this and almost all things NFS is is &lt;A title="http://www.netapp.com/us/media/tr-4067.pdf" href="http://www.netapp.com/us/media/tr-4067.pdf" target="_blank"&gt;TR-4067&lt;/A&gt; - You are looking for pg 48.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share and enjoy!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please hit the kudos&amp;nbsp;button and mark as solved if this resolved your issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hadrian&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 21:14:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Baffled-by-Ontap-8-Clustered-Mode-NFS-Export-Policies/m-p/134739#M29552</guid>
      <dc:creator>hadrian</dc:creator>
      <dc:date>2017-09-25T21:14:24Z</dc:date>
    </item>
  </channel>
</rss>

