<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Native Policy blocking access to entire cifs share instead of specific file extensions in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Native-Policy-blocking-access-to-entire-cifs-share-instead-of-specific-file/m-p/136688#M30118</link>
    <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it's the first time I post here, don't know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I moved my cifs shares to another system I manage, one that uses Ontap 9.1P7, C-Mode. Applying the native fpolicy I used on the 7-mode system have being a pain...&lt;/P&gt;&lt;P&gt;My objective is to create a fpolicy that blocks read and write (creation) of midia files in some of my shares, here's what I did:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Create the events on the svm, command to check them:&lt;BR /&gt;&lt;BR /&gt;fpolicy policy event show -vserver CIFS_01 -event-name *&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Event&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;File&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Is Volume&lt;BR /&gt;Vserver&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Protocols&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Operations&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Filters&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Operation&lt;BR /&gt;---------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ------------------&amp;nbsp; &amp;nbsp; ---------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&lt;BR /&gt;CIFS_01&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;create&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;cifs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; create, write, rename&amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CIFS_01&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;read&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cifs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read, open&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; false&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2 entries were displayed.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;2. Created the scope. Command to check them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;scope show -vserver CIFS_01 -policy-name restricted_file_type&lt;BR /&gt;(vserver fpolicy policy scope show)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vserver: CIFS_01&lt;BR /&gt;Policy: restricted_file_type&lt;BR /&gt;Shares to Include: compartilhados, grupos, programas&lt;BR /&gt;Shares to Exclude: -&lt;BR /&gt;Volumes to Include: -&lt;BR /&gt;Volumes to Exclude: -&lt;BR /&gt;Export Policies to Include: -&lt;BR /&gt;Export Policies to Exclude: -&lt;BR /&gt;File Extensions to Include: 3G2, 3GP, AIF, ASX, AVI,DIVX, FLV, IFF, M3U, M4A,MOV, MP3, MP4, MPA, MPG,PIF, RA, RM, RMB, SWF, VOB,WMA, WMV&lt;BR /&gt;File Extensions to Exclude: -&lt;BR /&gt;Is File Extension Check on Directories Enabled: false&lt;BR /&gt;Is Monitoring of Objects with No Extension Enabled: false&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;3. Just to be sure, here's my shares list. Checking shares list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;share show -vserver CIFS_01 -fields share-name&lt;BR /&gt;(vserver cifs share show)&lt;BR /&gt;vserver share-name&lt;BR /&gt;------- ----------&lt;BR /&gt;CIFS_01 admin$&lt;BR /&gt;CIFS_01 arquivo_ascom&lt;BR /&gt;CIFS_01 c$&lt;BR /&gt;CIFS_01 cifs_audio_turmas$&lt;BR /&gt;CIFS_01 compartilhados&lt;BR /&gt;CIFS_01 grupos&lt;BR /&gt;CIFS_01 ipc$&lt;BR /&gt;CIFS_01 midia_ascom&lt;BR /&gt;CIFS_01 programas&lt;BR /&gt;CIFS_01 publico&lt;BR /&gt;CIFS_01 root$&lt;BR /&gt;CIFS_01 share_logs$&lt;BR /&gt;CIFS_01 usuarios&lt;BR /&gt;13 entries were displayed.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;4. And here's the policy. Command to check policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy show -vserver CIFS_01 -policy-name restricted_file_type -instance&lt;/P&gt;&lt;P&gt;Vserver: CIFS_01&lt;BR /&gt;Policy: restricted_file_type&lt;BR /&gt;Events to Monitor: create, read&lt;BR /&gt;FPolicy Engine: native&lt;BR /&gt;Is Mandatory Screening Required: true&lt;BR /&gt;Allow Privileged Access: yes&lt;BR /&gt;User Name for Privileged Access: TRT18\Administrator&lt;BR /&gt;Is Passthrough Read Enabled: false&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So far... If I understood how fpolicy works in C-Mode, it should block only those file extensions on the included shares (&lt;SPAN&gt;compartilhados, grupos,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;programas&lt;/SPAN&gt;) right?&lt;BR /&gt;Well, when I activate the policy with that command (enable -vserver CIFS_01 -policy-name restricted_file_type -sequence-number 1), I lost access to these shares completely, I cant even browse these three shares&amp;nbsp;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;compartilhados, grupos,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;programas&lt;/SPAN&gt;&lt;SPAN&gt;), while the other shares I can access without problems.&lt;BR /&gt;&lt;BR /&gt;Am I doing anything wrong? Can anyone lend a hand?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 14:15:03 GMT</pubDate>
    <dc:creator>ericknoleto</dc:creator>
    <dc:date>2025-06-04T14:15:03Z</dc:date>
    <item>
      <title>Native Policy blocking access to entire cifs share instead of specific file extensions</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Native-Policy-blocking-access-to-entire-cifs-share-instead-of-specific-file/m-p/136688#M30118</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it's the first time I post here, don't know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I moved my cifs shares to another system I manage, one that uses Ontap 9.1P7, C-Mode. Applying the native fpolicy I used on the 7-mode system have being a pain...&lt;/P&gt;&lt;P&gt;My objective is to create a fpolicy that blocks read and write (creation) of midia files in some of my shares, here's what I did:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Create the events on the svm, command to check them:&lt;BR /&gt;&lt;BR /&gt;fpolicy policy event show -vserver CIFS_01 -event-name *&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Event&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;File&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Is Volume&lt;BR /&gt;Vserver&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Protocols&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Operations&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Filters&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Operation&lt;BR /&gt;---------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ------------------&amp;nbsp; &amp;nbsp; ---------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------&lt;BR /&gt;CIFS_01&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;create&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;cifs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; create, write, rename&amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CIFS_01&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;read&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cifs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; read, open&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; false&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2 entries were displayed.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;2. Created the scope. Command to check them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;scope show -vserver CIFS_01 -policy-name restricted_file_type&lt;BR /&gt;(vserver fpolicy policy scope show)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vserver: CIFS_01&lt;BR /&gt;Policy: restricted_file_type&lt;BR /&gt;Shares to Include: compartilhados, grupos, programas&lt;BR /&gt;Shares to Exclude: -&lt;BR /&gt;Volumes to Include: -&lt;BR /&gt;Volumes to Exclude: -&lt;BR /&gt;Export Policies to Include: -&lt;BR /&gt;Export Policies to Exclude: -&lt;BR /&gt;File Extensions to Include: 3G2, 3GP, AIF, ASX, AVI,DIVX, FLV, IFF, M3U, M4A,MOV, MP3, MP4, MPA, MPG,PIF, RA, RM, RMB, SWF, VOB,WMA, WMV&lt;BR /&gt;File Extensions to Exclude: -&lt;BR /&gt;Is File Extension Check on Directories Enabled: false&lt;BR /&gt;Is Monitoring of Objects with No Extension Enabled: false&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;3. Just to be sure, here's my shares list. Checking shares list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;share show -vserver CIFS_01 -fields share-name&lt;BR /&gt;(vserver cifs share show)&lt;BR /&gt;vserver share-name&lt;BR /&gt;------- ----------&lt;BR /&gt;CIFS_01 admin$&lt;BR /&gt;CIFS_01 arquivo_ascom&lt;BR /&gt;CIFS_01 c$&lt;BR /&gt;CIFS_01 cifs_audio_turmas$&lt;BR /&gt;CIFS_01 compartilhados&lt;BR /&gt;CIFS_01 grupos&lt;BR /&gt;CIFS_01 ipc$&lt;BR /&gt;CIFS_01 midia_ascom&lt;BR /&gt;CIFS_01 programas&lt;BR /&gt;CIFS_01 publico&lt;BR /&gt;CIFS_01 root$&lt;BR /&gt;CIFS_01 share_logs$&lt;BR /&gt;CIFS_01 usuarios&lt;BR /&gt;13 entries were displayed.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;4. And here's the policy. Command to check policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy show -vserver CIFS_01 -policy-name restricted_file_type -instance&lt;/P&gt;&lt;P&gt;Vserver: CIFS_01&lt;BR /&gt;Policy: restricted_file_type&lt;BR /&gt;Events to Monitor: create, read&lt;BR /&gt;FPolicy Engine: native&lt;BR /&gt;Is Mandatory Screening Required: true&lt;BR /&gt;Allow Privileged Access: yes&lt;BR /&gt;User Name for Privileged Access: TRT18\Administrator&lt;BR /&gt;Is Passthrough Read Enabled: false&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So far... If I understood how fpolicy works in C-Mode, it should block only those file extensions on the included shares (&lt;SPAN&gt;compartilhados, grupos,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;programas&lt;/SPAN&gt;) right?&lt;BR /&gt;Well, when I activate the policy with that command (enable -vserver CIFS_01 -policy-name restricted_file_type -sequence-number 1), I lost access to these shares completely, I cant even browse these three shares&amp;nbsp;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;compartilhados, grupos,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;programas&lt;/SPAN&gt;&lt;SPAN&gt;), while the other shares I can access without problems.&lt;BR /&gt;&lt;BR /&gt;Am I doing anything wrong? Can anyone lend a hand?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:15:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Native-Policy-blocking-access-to-entire-cifs-share-instead-of-specific-file/m-p/136688#M30118</guid>
      <dc:creator>ericknoleto</dc:creator>
      <dc:date>2025-06-04T14:15:03Z</dc:date>
    </item>
  </channel>
</rss>

