<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Authentication onto the cluster in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137462#M30316</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;SPAN&gt;JGPSHNTAP says this is how it works - the "tunnel" part of the domain-tunnel is a key concept to keep in mind. The cluster SVM talks to AD via the configured data SVM, through the domain-tunnel. With ONTAP 9.3, we also support two factor authentication via this method (2FA)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2018 04:11:45 GMT</pubDate>
    <dc:creator>AlexDawson</dc:creator>
    <dc:date>2018-01-22T04:11:45Z</dc:date>
    <item>
      <title>AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137381#M30292</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; I'm looking to integrate our clusters into AD so that when we log into the CLI/GUI we can do so with our AD logons.&amp;nbsp; Maybe I'm missing something but the only thing I can see in the documentation is that you can set up a domain tunnel from a data vserevr.&amp;nbsp; This isn't what I'm after as when you log onto the CLI to admin the filer you login to the cluster vserver.&amp;nbsp; I've not really seen much mentioned of RADUIS apart from using that as the authentication method for CHAPS using ISCSI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone point me in the right direction of getting ontap&amp;nbsp;8.3.2 working with AD lognos for the cluster level CLI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:08:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137381#M30292</guid>
      <dc:creator>chris_mckean</dc:creator>
      <dc:date>2025-06-04T14:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137384#M30294</link>
      <description>&lt;P&gt;On our clusters, we setup dedicated domain tunnel vservers.&amp;nbsp; &amp;nbsp; The CLI functions of the domain need to pass thru this vserver.&amp;nbsp; The reason why we chose to dedicate a vserver was for our svm-dr and all that, we didn't want to remember to move the domain tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's part one, and then on security login you need to create your group which you want SSH access too.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You cannot do priv/pub key&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 13:37:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137384#M30294</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2018-01-18T13:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137386#M30296</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;How does that work then?&amp;nbsp; So you have a dedicated vserver&amp;nbsp;just for the domain tunnell. Lets call that VS_TUN.&amp;nbsp; Your cluster mgmt IP lives in your cluster vserver.&amp;nbsp; Lets call that VS_CLUS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when I want to log into the cluster CLI to create a volume in any of the vservers&amp;nbsp;I'd log onto the cluster mgmt IP which lives in VS_CLUS.&amp;nbsp; Doesn't that mean you cant do the AD logon piece otherwise you'd be logging onto a data vserver&amp;nbsp;where you wouldn't have full control over the cluster?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or am I misunderstanding you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 13:52:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137386#M30296</guid>
      <dc:creator>chris_mckean</dc:creator>
      <dc:date>2018-01-18T13:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137390#M30299</link>
      <description>&lt;P&gt;You should be always logging into the cluster via the cluster management IP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's say you log into svm_mgt - with your domain creds&amp;nbsp; &amp;nbsp;userid / password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that will get funnelled over to the domain tunnel svm and you will get in.&amp;nbsp; But you need to have your security login setup as well with SSH for your admin groups&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 14:21:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137390#M30299</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2018-01-18T14:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137393#M30300</link>
      <description>&lt;P&gt;But If I log into any SVM other than the&amp;nbsp;Cluster SVM I can only control that SVM that I've logged into.&amp;nbsp; I get how the ad auth works with the tunnel on those SVM's but I want to know if there is a way to logon to the cluster SVM and have an AD tunnel or similar setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 14:40:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137393#M30300</guid>
      <dc:creator>chris_mckean</dc:creator>
      <dc:date>2018-01-18T14:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137396#M30301</link>
      <description>&lt;P&gt;There is only one domain-tunnel for the entire cluster.&amp;nbsp; it will service all your AD requests.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We dont' allow SSH directly to our SVM's, everything is done to the cluster, and unless you are secure multitenandcy, I would recommend that.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 14:47:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137396#M30301</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2018-01-18T14:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137462#M30316</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;SPAN&gt;JGPSHNTAP says this is how it works - the "tunnel" part of the domain-tunnel is a key concept to keep in mind. The cluster SVM talks to AD via the configured data SVM, through the domain-tunnel. With ONTAP 9.3, we also support two factor authentication via this method (2FA)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 04:11:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137462#M30316</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2018-01-22T04:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication onto the cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137470#M30319</link>
      <description>&lt;P&gt;VMHi&amp;nbsp;&lt;SPAN&gt;JGPSHNTAP,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This is now working thanks.&amp;nbsp; I guess what I wasn't clear about is that the tunnel has to be attached to a data SVM but then this allows domain authentication to work on any&amp;nbsp;SVM on that cluster.&amp;nbsp; I thought that if you set the tunnel up, on SVM01 then it only enabled domain authentication on that SVM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Chris&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 09:15:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/AD-Authentication-onto-the-cluster/m-p/137470#M30319</guid>
      <dc:creator>chris_mckean</dc:creator>
      <dc:date>2018-01-22T09:15:13Z</dc:date>
    </item>
  </channel>
</rss>

