<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multiple ip cifs connection in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139065#M30692</link>
    <description>&lt;P&gt;Thanksso much for your reply,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will modify the routes asap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have just one question&lt;/P&gt;
&lt;P&gt;Question is you said "&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;all nodes hosting LIFS that use to access CIFS or other protocols that need NTP/DNS&amp;nbsp; would need to have connectivity to AD - e.g add more dedicated LIFS for AD. or just start using the NAS LIFS for it - to keep it scalable.."&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;if client lif can not connect ad or dns, is it trying just home node other lifs to connect ad or dns?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tuncay&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 20:04:29 GMT</pubDate>
    <dc:creator>tuncay</dc:creator>
    <dc:date>2018-03-22T20:04:29Z</dc:date>
    <item>
      <title>multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139038#M30686</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer has multiple ip adress and vlan&amp;nbsp; in their svm just one of them can reach ad server and dns. Client using other lifs to connect cifs shares but sometimes cifs connections droping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My quesiton is, the other lifs which can not reach ad&amp;nbsp; and dns is causing this problem or not ? When I check logs it says this ip adress (other lifs)&amp;nbsp; can not reach this dns and adress&amp;nbsp;secd.conn.auth.failure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tuncay&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:53:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139038#M30686</guid>
      <dc:creator>tuncay</dc:creator>
      <dc:date>2025-06-04T13:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139041#M30687</link>
      <description>&lt;P&gt;it could be both. AD and DNS having issues....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;let's see what the routing look like. and then we can go furter and see you have the correct firewall rules open for the correct interface by KB:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1030571/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1030571/loc/en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you print the following please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dns show -fields name-servers -vserver &amp;lt;SVM name&amp;gt;&lt;/P&gt;
&lt;P&gt;cifs domain discovered-servers show -vserver &amp;lt;SVM name&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; # can remove everything that is not the address. and preference&lt;/P&gt;
&lt;P&gt;network interface show -vserver &amp;lt;SVM name&amp;gt;&lt;/P&gt;
&lt;P&gt;network route show -vserver &amp;lt;SVM name&amp;gt;&lt;/P&gt;
&lt;P&gt;network connections active show&amp;nbsp;-Print-ip-addresses -vserver &amp;lt;SVM name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gidi&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 13:02:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139041#M30687</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2018-03-22T13:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139045#M30689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;GidonMarcus,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I attached the output, you can check.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tuncay&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 18:35:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139045#M30689</guid>
      <dc:creator>tuncay</dc:creator>
      <dc:date>2018-09-17T18:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139061#M30691</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your current AD and DNS connectivity:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;the current routing causes all the outgoing traffic from the NAS SVM on node "ntap_cluster_krt-01" to go via interface "svm_krt_nas_ad".and can go via "svm_krt_nas_154"&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;all the other nodes cannot access the AD and DNS at the moment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;i suspect that node "Ntap9000-KRT-01" managed to initiate an AD connectivity when LIF "svm_krt_dmz_lif3" was at home and up.&amp;nbsp; currently it's on a port and node that not allowing it to be up. &lt;STRONG&gt;maybe that's how you started to notice that something is funny and if you would revert it to home it will all start to "work" again.&lt;/STRONG&gt; you can use the interface revert command if you like to try and fix it. &lt;STRONG&gt;but i can't take&amp;nbsp;responsibility on this. - do at your own risk.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for the actual config:&lt;/P&gt;
&lt;P&gt;in a nutshell - you would need to rebuild everything around the network config (mainly to add stuff. but may gain something from removing some as well).&lt;/P&gt;
&lt;P&gt;the reason is that your current routing very depanded on fastpath, a feature that is discontinued. &lt;A href="https://whyistheinternetbroken.wordpress.com/2018/02/16/ipfastpath-ontap92/" target="_blank"&gt;https://whyistheinternetbroken.wordpress.com/2018/02/16/ipfastpath-ontap92/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;iv'e started to look on each of your current use cases and routes - but they are just wrong, a workaround on top of a workaround.... with effectively only one currently valid (and another one if you sort #2 above) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So let me put some end-goals when you re-design it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;all nodes hosting LIFS that use to access CIFS or other protocols that need NTP/DNS&amp;nbsp; would need to have connectivity to AD - e.g add more dedicated LIFS for AD. or just start using the NAS LIFS for it - to keep it scalable..&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;the AD sites and subnet needs to be amended to include the filer subnet. or a preferred DC need to be set via "vserver cifs domain preferred-dc" command.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;the routing need rebuild in a way that allow communication back without a dependency on fast-path.&amp;nbsp;&amp;nbsp; the way i see it you would likely going to end up with:&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A static route or multiple ones for the 192.168.0.0/16.range&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if adding new AD LIFS. so add static routes for the DNS and AD on 10.200.120.0/24 + 10.210.154.0/24&amp;nbsp; (with setting these as pref DC)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A default route for the NAS LIFs to 10.210.224.1&lt;/P&gt;
&lt;P&gt;i don't have real visibility of the network, and some engagement with the network admins in the organization will be required. - you would need to fully understand the client connectivity with them. and make sure you route everything optimally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;All LIFs failover group need to be set correctly via a group or broadcast domains. so you don't end up with LIF migrated to a port it can't live in.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Gidi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 08:13:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139061#M30691</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2018-03-26T08:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139065#M30692</link>
      <description>&lt;P&gt;Thanksso much for your reply,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will modify the routes asap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have just one question&lt;/P&gt;
&lt;P&gt;Question is you said "&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;all nodes hosting LIFS that use to access CIFS or other protocols that need NTP/DNS&amp;nbsp; would need to have connectivity to AD - e.g add more dedicated LIFS for AD. or just start using the NAS LIFS for it - to keep it scalable.."&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;if client lif can not connect ad or dns, is it trying just home node other lifs to connect ad or dns?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tuncay&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 20:04:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139065#M30692</guid>
      <dc:creator>tuncay</dc:creator>
      <dc:date>2018-03-22T20:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139091#M30701</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;each node is&amp;nbsp;independent in the AD connection. if it can't reach AD locally (via the&amp;nbsp;available LIFs and routing) it will deny the client request.&lt;/P&gt;
&lt;P&gt;the SVM will not attempt to&amp;nbsp;authenticate or serve the client via another node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however - if you have some load balancing across the LIFs (like DNS&amp;nbsp;round robin. DNS load balancing. or actual load balancer) the client may try to reconnect i assume and may hit&amp;nbsp;different node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gidi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 11:36:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139091#M30701</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2018-03-23T11:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: multiple ip cifs connection</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139120#M30709</link>
      <description>&lt;P&gt;Hi Gidi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your detailed investigation, I opened a case from Netapp about this issue but you solved before they ask any question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Like you said after we create ad lif for all nodes, problem solved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we are going to fixed our routing problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;Tuncay&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 05:16:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/multiple-ip-cifs-connection/m-p/139120#M30709</guid>
      <dc:creator>tuncay</dc:creator>
      <dc:date>2018-03-26T05:16:45Z</dc:date>
    </item>
  </channel>
</rss>

