<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153671#M34380</link>
    <description>&lt;P&gt;Are those LIFs in the same SVM just a different node? This document talks about how to check configuration: &lt;A href="https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-nmg/GUID-2A6B1345-0C1D-4E3D-B01B-ED724A69D376.html?cp=11_0_10" target="_blank"&gt;https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-nmg/GUID-2A6B1345-0C1D-4E3D-B01B-ED724A69D376.html?cp=11_0_10&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd recommend a packet trace honestly, to see what is being accessed. This KB is about bully workloads, but there is a nice section on packet tracing about a quarter way down and has some good commands and references: &lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1071353" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1071353&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2020 15:36:20 GMT</pubDate>
    <dc:creator>paul_stejskal</dc:creator>
    <dc:date>2020-01-21T15:36:20Z</dc:date>
    <item>
      <title>Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153654#M34373</link>
      <description>&lt;P&gt;We have a nuber of PCs in various subnets that are attempting to try and access LIFs on our CDOT cluster that are in various part of our enterprise that they shoud have no reason to access and we can't figure out why.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, the cluster has a LIF with an IP of 172.19.240.7 /20 and that LIF is in an isolated VLAN that PCs do not have any direct connectivity to.&amp;nbsp; However, a Windows PC with an IP of 172.21.133.25 /24 is for some reason attempting to access the IP of that LIF.&amp;nbsp; When looking at "netstat -ano" on the PC, we see:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Protocol&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Foreign Address&amp;nbsp; &amp;nbsp; &amp;nbsp;State&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PID&lt;/P&gt;
&lt;P&gt;TCP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;172.21.133.25:58905&amp;nbsp; &amp;nbsp;172.19.240.7:135&amp;nbsp; &amp;nbsp; &amp;nbsp;SYN_SENT&amp;nbsp; &amp;nbsp;2976&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With PID 2976 being "Service Host: Network Service - Workstation".&amp;nbsp; &amp;nbsp;While DFS does point to some shares on the NetApp cluster, none of them are on the node to which&amp;nbsp;172.19.240.7 is associated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are three other LIFs on the cluster (all similar to the one noted above in that PCs don't have connectivity to them, but the PCs are trying to contact the IP addresses of those LIFs).&amp;nbsp; What can we check to try and figure out what is attempting all of these connections?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:22:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153654#M34373</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2025-06-04T11:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153657#M34374</link>
      <description>&lt;P&gt;Is it possible those interface you&amp;nbsp; dont want clients accessing are using:&lt;/P&gt;
&lt;P&gt;1. The On-Box Load Balancer&lt;/P&gt;
&lt;P&gt;2. Off Box DNS round-robin (multiple IPs associated with the same CIFS name)&lt;/P&gt;
&lt;P&gt;3. DDNS -&amp;gt; all your&amp;nbsp; LIFs are are participating in DDNS and when the client gets the DNS referral, it is going to an IP it is not supposed to?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 23:30:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153657#M34374</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-01-20T23:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153664#M34378</link>
      <description>&lt;P&gt;The on box load balancer must be manually configured, correct?&amp;nbsp; If so, we aren't using it as we don't have any DNS zones configured on the cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We don't have any DNS entries for the interfaces for the LIFs that PCs are trying to connect to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DDNS is disabled.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 11:10:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153664#M34378</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2020-01-21T11:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153671#M34380</link>
      <description>&lt;P&gt;Are those LIFs in the same SVM just a different node? This document talks about how to check configuration: &lt;A href="https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-nmg/GUID-2A6B1345-0C1D-4E3D-B01B-ED724A69D376.html?cp=11_0_10" target="_blank"&gt;https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-nmg/GUID-2A6B1345-0C1D-4E3D-B01B-ED724A69D376.html?cp=11_0_10&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd recommend a packet trace honestly, to see what is being accessed. This KB is about bully workloads, but there is a nice section on packet tracing about a quarter way down and has some good commands and references: &lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1071353" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1071353&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 15:36:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153671#M34380</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-01-21T15:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153676#M34382</link>
      <description>&lt;P&gt;Yes, the LIFs are all in the same SVM and on the same node.&amp;nbsp; We do not have any DNS zones configured on the cluster, which if I understand things correctly means that load balancing is not configured at all?&amp;nbsp; The only way that users access these filers is via DFS shares and all of those shares are on the 03/04 nodes and not the 02 node where these LIFs that are connected to the isolated networks or DMZ networks are located.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately a packet trace won't work, as this traffic is attempting to pass through our firewall to get to the filer (the LIFs in question are in our DMZ or in totally isolated VLANs) so the traffic isn't making it to the cluster; we are trying to fgure out how to even stop it from happening.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 19:23:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153676#M34382</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2020-01-21T19:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153677#M34383</link>
      <description>&lt;P&gt;That's a Microsoft question unfortunately, not a NetApp. Maybe if it connects you could see what it reaches out and accesses? This might be a good time to use the Sysinternals suite.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes that is correct, DNS RR is disabled as DNS zoning isn't specified.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 19:28:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153677#M34383</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-01-21T19:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153700#M34394</link>
      <description>&lt;P&gt;Ok, exactly HOW are you accessing the CIFS data on your NetApp?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using a NAME, FQDN, IP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not an IP, try first doing a NSlookup on that IP and see what happens.&lt;/P&gt;
&lt;P&gt;Also try doing an NSLOOKUP of the IP it is going to (the one you do not want it to go to)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;maybe there is something borked in your DNS&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 13:17:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153700#M34394</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-01-22T13:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153701#M34395</link>
      <description>&lt;P&gt;How about for one of the IP addresses from the NetApp, run this and report back:&lt;/P&gt;
&lt;P&gt;set diag ; network interface show -lif &amp;lt;LIF_NAME&amp;gt; -instance ; set admin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That should give some info that may help.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 13:19:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153701#M34395</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-01-22T13:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153710#M34399</link>
      <description>&lt;P&gt;More information regarding this, as soon as I log into a PC (before loading any applications) I see the blocked connections logged in our Check Point firewall between the PC in question and those LIFs.&amp;nbsp; Three drives are mapped at logon which are mapped via DFS.&amp;nbsp; On the DFS server, those directories are located on volumes of the 01 and 04 nodes in the cluster and are referenced via oriole-01-int and oriole-04-int.&amp;nbsp; A NSlookup or ping of those two DNS names does return the correct IP address.&amp;nbsp; A NSlookup of two of the "isolated" IPs (172.19.240.7 and 172.19.220.5) returns a non-existent domain error as expected because we do not have DNS entries for either of those interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the "network interface show -lif" output, output from two of the LIFs (172.19.240.7 and 172.19.220.5) that keep showing up are below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Oriole::*&amp;gt; network interface show -lif Oriole-02_Hosting_Storage -instance&lt;/P&gt;
&lt;P&gt;Vserver Name: oriole-svm&lt;BR /&gt;Logical Interface Name: Oriole-02_Hosting_Storage&lt;BR /&gt;Service Policy: default-data-files&lt;BR /&gt;Service List: data-core, data-nfs, data-cifs&lt;BR /&gt;(DEPRECATED)-Role: data&lt;BR /&gt;Data Protocol: nfs, cifs&lt;BR /&gt;Network Address: 172.19.240.7&lt;BR /&gt;Netmask: 255.255.240.0&lt;BR /&gt;Bits in the Netmask: 20&lt;BR /&gt;Is VIP LIF: false&lt;BR /&gt;Subnet Name: -&lt;BR /&gt;Home Node: Oriole-02&lt;BR /&gt;Home Port: e3a&lt;BR /&gt;Current Node: Oriole-02&lt;BR /&gt;Current Port: e3a&lt;BR /&gt;Operational Status: up&lt;BR /&gt;Extended Status: -&lt;BR /&gt;Numeric ID: 1032&lt;BR /&gt;Is Home: true&lt;BR /&gt;Administrative Status: up&lt;BR /&gt;Failover Policy: system-defined&lt;BR /&gt;Firewall Policy: data&lt;BR /&gt;Auto Revert: true&lt;BR /&gt;Sticky Flag: false&lt;BR /&gt;Fully Qualified DNS Zone Name: none&lt;BR /&gt;DNS Query Listen Enable: false&lt;BR /&gt;(DEPRECATED)-Load Balancing Migrate Allowed: false&lt;BR /&gt;Load Balanced Weight: load&lt;BR /&gt;Failover Group Name: Hosting_Storage&lt;BR /&gt;FCP WWPN: -&lt;BR /&gt;Address family: ipv4&lt;BR /&gt;Comment: -&lt;BR /&gt;IPspace of LIF: Default&lt;BR /&gt;Is Dynamic DNS Update Enabled?: false&lt;BR /&gt;Probe-port for Azure ILB: -&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Oriole::*&amp;gt; network interface show -lif Oriole-02_Database_Storage -instance&lt;/P&gt;
&lt;P&gt;Vserver Name: oriole-svm&lt;BR /&gt;Logical Interface Name: Oriole-02_Database_Storage&lt;BR /&gt;Service Policy: default-data-files&lt;BR /&gt;Service List: data-core, data-nfs, data-cifs&lt;BR /&gt;(DEPRECATED)-Role: data&lt;BR /&gt;Data Protocol: nfs, cifs&lt;BR /&gt;Network Address: 172.19.220.5&lt;BR /&gt;Netmask: 255.255.255.0&lt;BR /&gt;Bits in the Netmask: 24&lt;BR /&gt;Is VIP LIF: false&lt;BR /&gt;Subnet Name: -&lt;BR /&gt;Home Node: Oriole-02&lt;BR /&gt;Home Port: e0g&lt;BR /&gt;Current Node: Oriole-02&lt;BR /&gt;Current Port: e0g&lt;BR /&gt;Operational Status: up&lt;BR /&gt;Extended Status: -&lt;BR /&gt;Numeric ID: 1030&lt;BR /&gt;Is Home: true&lt;BR /&gt;Administrative Status: up&lt;BR /&gt;Failover Policy: system-defined&lt;BR /&gt;Firewall Policy: data&lt;BR /&gt;Auto Revert: true&lt;BR /&gt;Sticky Flag: false&lt;BR /&gt;Fully Qualified DNS Zone Name: none&lt;BR /&gt;DNS Query Listen Enable: false&lt;BR /&gt;(DEPRECATED)-Load Balancing Migrate Allowed: false&lt;BR /&gt;Load Balanced Weight: load&lt;BR /&gt;Failover Group Name: Database_Storage&lt;BR /&gt;FCP WWPN: -&lt;BR /&gt;Address family: ipv4&lt;BR /&gt;Comment: -&lt;BR /&gt;IPspace of LIF: Default&lt;BR /&gt;Is Dynamic DNS Update Enabled?: false&lt;BR /&gt;Probe-port for Azure ILB: -&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 20:29:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/153710#M34399</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2020-01-22T20:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Windows PCs are randomly attempting to access LIFs that they should have no reason to access</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/154202#M34537</link>
      <description>&lt;P&gt;Opened a support case with NetApp who suggested that we contact Microsoft about the behavior.&amp;nbsp; We found that:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If a PC has no drives mapped, there are no connections between that PC and Oriole.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When a drive is mapped, a connection is made on the correct oriole-0x-int interface. Soon after, rolling attempts begin involving the PC trying to connect to e0g (Database Storage), e3a (Hosting Storage), and other interfaces that the PC has no reason to connect to and for which there is no configuration in DNS, DHCP, Active Directory Sites and Services. PCs are able to establish connections to the FPolicy related LIFs on each node as they are in the 172.22.16.x subnet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The connections are all epmap (endpoint mapper).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;At this point I think our only option is firewall rules on each PC that block connections to port 135 in the three associated subnets where the LIFs (that PCs should not be connecting to) are located.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 16:43:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-PCs-are-randomly-attempting-to-access-LIFs-that-they-should-have-no/m-p/154202#M34537</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2020-02-10T16:43:51Z</dc:date>
    </item>
  </channel>
</rss>

