<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with SSH to nas Vserver in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152532#M33970</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you share this output:&lt;/P&gt;
&lt;P&gt;::&amp;gt; system services firewall policy show&lt;BR /&gt;::&amp;gt; network interface show -fields firewall-policy,lif,address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note:firewall-policy 'mgmt' applies to both node-mgmt &amp;amp; cluster-mgmt.&lt;/P&gt;</description>
    <pubDate>Sun, 24 Nov 2019 23:19:05 GMT</pubDate>
    <dc:creator>Ontapforrum</dc:creator>
    <dc:date>2019-11-24T23:19:05Z</dc:date>
    <item>
      <title>Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152530#M33969</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I have a cluster consisting of 4 nodes, two "long existing" FAS9000 and 2 recently added A200.&lt;/P&gt;
&lt;P&gt;All nodes are running 9.5P8.&lt;/P&gt;
&lt;P&gt;Now I have a NAS vserver providing CIFS &amp;amp; NFS services.&lt;/P&gt;
&lt;P&gt;The vserver has 1 mgmt ip with data role and none data-protocols, and 4 data ips (one on each node) with cifs and nfs data-protocols and data firewall policy.&lt;/P&gt;
&lt;P&gt;the issue is that the ips that reside on nodes 1&amp;amp;2 are reachable through ssh although ssh is not permitted in the firewall policy.&lt;/P&gt;
&lt;P&gt;lifes 3&amp;amp;4 that are newer and reside on the A200 (created after 1&amp;amp;2) are not reachable through ssh and the configuration for all the lifs seem to be identical.&lt;/P&gt;
&lt;P&gt;I tried to bring lifs 1&amp;amp;2 down for a few seconds and then up and also change their firewall policy to mgmt and then back to data but it didn't help.&lt;/P&gt;
&lt;P&gt;Does anyone have an idea why this might happen and how to resolve this?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:07:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152530#M33969</guid>
      <dc:creator>elic_co</dc:creator>
      <dc:date>2025-06-04T12:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152532#M33970</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you share this output:&lt;/P&gt;
&lt;P&gt;::&amp;gt; system services firewall policy show&lt;BR /&gt;::&amp;gt; network interface show -fields firewall-policy,lif,address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note:firewall-policy 'mgmt' applies to both node-mgmt &amp;amp; cluster-mgmt.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 23:19:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152532#M33970</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2019-11-24T23:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152555#M33974</link>
      <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;system services firewall policy show:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;data:&lt;/P&gt;
&lt;P&gt;dns&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ndmp&amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ndmps&amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;portmap 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mgmt:&lt;/P&gt;
&lt;P&gt;dns&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0/0&lt;/P&gt;
&lt;P&gt;http&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;https&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ndmp&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ndmps&amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ntp&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;portmap&amp;nbsp; &amp;nbsp;0.0.0.0/0&lt;/P&gt;
&lt;P&gt;snmp&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;ssh&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0/0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;all under allowed tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;net int show -fields firewall-policy,lif,address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vserver&amp;nbsp; &amp;nbsp;lif&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;address&amp;nbsp; &amp;nbsp; firewall-policy&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------&lt;/P&gt;
&lt;P&gt;vs-nas&amp;nbsp; &amp;nbsp; mgmt&amp;nbsp; &amp;nbsp; &amp;nbsp;x.x.x.a&amp;nbsp; &amp;nbsp; mgmt&lt;/P&gt;
&lt;P&gt;vs-nas&amp;nbsp; &amp;nbsp; nas1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;x.x.x.b&amp;nbsp; &amp;nbsp; &amp;nbsp;data&lt;/P&gt;
&lt;P&gt;vs-nas&amp;nbsp; &amp;nbsp; nas2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;x.x.x.c&amp;nbsp; &amp;nbsp; &amp;nbsp;data&lt;/P&gt;
&lt;P&gt;vs-nas&amp;nbsp; &amp;nbsp; nas3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;x.x.x.d&amp;nbsp; &amp;nbsp; &amp;nbsp;data&lt;/P&gt;
&lt;P&gt;vs-nas&amp;nbsp; &amp;nbsp; nas4&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;x.x.x.e&amp;nbsp; &amp;nbsp; &amp;nbsp;data&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 16:50:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152555#M33974</guid>
      <dc:creator>elic_co</dc:creator>
      <dc:date>2019-11-25T16:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152559#M33975</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the output, looks like there are no restriction from the filer side, all clients are allowed to 'ssh' into cluster-mgnt,node-mgmt and data-lif.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Could&amp;nbsp; you verify the following :&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Is Windows firewall policy - outbound tcp 22 is denied from where you are trying to ssh?&lt;BR /&gt;If so, then you will straight away see - Network error: Access denied.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2) What is the output of the following in your filer:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example: I am on ONTAP 9.6, if you observe the output below, firewall-policy is 'data' just as in your case, but under services it allows 'management-ssh'. Therefore i am able to ssh to data LIF.&lt;/P&gt;
&lt;P&gt;ONTAP96::&amp;gt; network interface show -role data -fields firewall-policy,services&lt;BR /&gt;vserver lif services firewall-policy&lt;BR /&gt;-------- ------------------ --------------------------------------------------- ---------------&lt;BR /&gt;SVM_CIFS SVM_CIFS_cifs_lif1 data-core,data-cifs,management-ssh,management-https data&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;However, if I remove this 'management-ssh' from service-policy&lt;/P&gt;
&lt;P&gt;ONTAP96::&amp;gt; network interface modify -vserver SVM_CIFS -lif SVM_CIFS_cifs_lif1 -service-policy default-data-files&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I will get Network error : Access denied.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Could you verify the two points I mentioned.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 18:35:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152559#M33975</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2019-11-25T18:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152592#M33983</link>
      <description>&lt;P&gt;Hey, I was able to figure it out with a little help from a friend as the song says &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It was "system services firewall show"&lt;/P&gt;
&lt;P&gt;the firewall was off for nodes 1+2 and on for 3+4&lt;/P&gt;
&lt;P&gt;I guess it is because of upgrades from old versions of ontap on nodes 1+2, I also notich these behaviors on other clusters that were upgraded.&lt;/P&gt;
&lt;P&gt;I haven't changed it to on yet but i will do it in the next few days and see if it helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks a lot for the help&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 15:19:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152592#M33983</guid>
      <dc:creator>elic_co</dc:creator>
      <dc:date>2019-11-26T15:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH to nas Vserver</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152595#M33984</link>
      <description>&lt;P&gt;Great, glad to hear that! thanks for the update.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 16:03:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Issue-with-SSH-to-nas-Vserver/m-p/152595#M33984</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2019-11-26T16:03:31Z</dc:date>
    </item>
  </channel>
</rss>

