<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filer-initiated network connections egressing on cluster_mgmt lif in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152480#M33957</link>
    <description>&lt;P&gt;Expected behavior. Management traffic is allowed to go out any node or cluster-mgt interface. Your ACLs should include every node management, cluster management and service-processors (SP) or baseboard management controllers (BMC) IP addresses.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 16:09:01 GMT</pubDate>
    <dc:creator>TMACMD</dc:creator>
    <dc:date>2019-11-21T16:09:01Z</dc:date>
    <item>
      <title>Filer-initiated network connections egressing on cluster_mgmt lif</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152463#M33953</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;dc2-nc1::*&amp;gt; network interface show -vserver dc2-nc1
            Logical    Status     Network            Current       Current Is
Vserver     Interface  Admin/Oper Address/Mask       Node          Port    Home
----------- ---------- ---------- ------------------ ------------- ------- ----
dc2-nc1
            cluster_mgmt up/up    10.20.8.70/21      dc2-nc1-node1 a0b     true
            mgmt1        up/up    10.20.8.71/21      dc2-nc1-node1 a0b     true
            mgmt2        up/up    10.20.8.72/21      dc2-nc1-node2 a0b     true
3 entries were displayed.

dc2-nc1::*&amp;gt; network route show
Vserver             Destination     Gateway         Metric
------------------- --------------- --------------- ------
dc2-nc1             0.0.0.0/0       10.20.8.1       20

dc2-nc1::*&amp;gt; network route show-lifs

Vserver: dc2-nc1
Destination             Gateway                 Logical Interfaces
----------------------  ----------------------  ------------------------------
0.0.0.0/0               10.20.8.1               cluster_mgmt, mgmt1, mgmt2&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a 2-node filer on 9.1.&amp;nbsp; I had jobs doing backups (system configuration backup settings show) that would PUT to a webserver, and I had ASUPs going to NTAP over our proxies.&amp;nbsp; Those connections would emerge from the node_mgmt IPs (I'm positive about this, as only .71 and .72 were on certain ACLs), and all was well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of going to 9.3 (finally), I'm seeing ASUPs from node 1 being denied by the proxies because they're egressing from .70, the cluster_mgmt LIF.&amp;nbsp; Node2's filer-initiated connections come out of the node LIF's IP, .72, as I would expect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not seeing any particular advice on this.&amp;nbsp; Not seeing something in the release notes for 9.2/9.3.&amp;nbsp; I found a &lt;A href="https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-sag/GUID-F15E7666-EA7F-463F-9AC1-CFA592BC0196.html" target="_self"&gt;troubleshooting-ASUP doc&lt;/A&gt; that makes it sound like connections are expected to emerge from the cluster_mgmt LIF, but it's unclear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My questions are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Should ASUPs/uploads be initiating out of the cluster_mgmt LIF in 9.3-and-beyond?
&lt;UL&gt;
&lt;LI&gt;If so, can you show me what changed between 9.1 and 9.3 so I can learn from my previous expectation?&lt;/LI&gt;
&lt;LI&gt;If not, any advice on what I should tweak in the routes so the node LIF is preferred over the cluster LIF in sourcing connections?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:08:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152463#M33953</guid>
      <dc:creator>FULLSTEAM</dc:creator>
      <dc:date>2025-06-04T12:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Filer-initiated network connections egressing on cluster_mgmt lif</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152469#M33955</link>
      <description>&lt;P&gt;What happens if you move cluster management LIF to another node?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My guess is that simply takes first interface on network with (default) gateway (where "first" is in some internal kernel order of creation).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 09:10:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152469#M33955</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2019-11-21T09:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Filer-initiated network connections egressing on cluster_mgmt lif</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152478#M33956</link>
      <description>&lt;P&gt;That's odd...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know with changes in 9.2+, we removed part of the network stack to optimize it, but that also removed IP fastpath. As far as I know it is supposed to go out the node management LIF, not cluster LIF.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I mean the simple solution would just be to add a route to your proxy out the node management LIF, or modify the routing table. Or you could modify your proxy to allow the cluster management LIF.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you really want a detailed dive, if you have support entitlements I'd suggest opening a case. I couldn't pull up the ASUPs searching for that node name so we'll need to probably pull logs and see what is going on.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 15:42:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152478#M33956</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2019-11-21T15:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Filer-initiated network connections egressing on cluster_mgmt lif</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152480#M33957</link>
      <description>&lt;P&gt;Expected behavior. Management traffic is allowed to go out any node or cluster-mgt interface. Your ACLs should include every node management, cluster management and service-processors (SP) or baseboard management controllers (BMC) IP addresses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 16:09:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152480#M33957</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2019-11-21T16:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Filer-initiated network connections egressing on cluster_mgmt lif</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152482#M33958</link>
      <description>&lt;P&gt;Thanks for looking, y'all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To aborzenkov:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;cluster_mgmt lif on node 1: traffic coming out .70 (the cluster_mgmt lif) and .72 (node2).&lt;/LI&gt;
&lt;LI&gt;cluster_mgmt lif on node 2: traffic coming out .71 (node1) and .70 (the cluster_mgmt lif).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To paul_stejskal:&lt;/P&gt;
&lt;P&gt;We did add the cluster_mgmt lif to the proxy ACLs as a workaround, because we needed ASUPs to fly for a case (side note, I can't believe burt 1156898 is not getting fixed in 9.3).&amp;nbsp; This question was mostly to determine whether my proxy edit was a 'temp workaround for a misconfigured filer' or if this was an intentional change in ONTAP and my proxy change needed to be made permanent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume y'all can talk internally and reach a consensus, but I'm going to assume here that TMAC_CTG's answer is correct vs paul_stejskal's 'huh that's weird'&amp;nbsp; (sorry!).&amp;nbsp; I wish I had a cite or I had spotted this in some kind of changelog, but, oh well, I'm happy with someone telling me it's expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the replies.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 17:03:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Filer-initiated-network-connections-egressing-on-cluster-mgmt-lif/m-p/152482#M33958</guid>
      <dc:creator>FULLSTEAM</dc:creator>
      <dc:date>2019-11-21T17:03:11Z</dc:date>
    </item>
  </channel>
</rss>

