<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cross Vlan communication in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158872#M36251</link>
    <description>&lt;P&gt;Just have a LIF per VLAN for each SVM.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Aug 2020 14:51:12 GMT</pubDate>
    <dc:creator>paul_stejskal</dc:creator>
    <dc:date>2020-08-21T14:51:12Z</dc:date>
    <item>
      <title>Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158840#M36241</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am running ontap 9.7 and I am trying to figure out if there is a way to connect to a lif that is in a different vlan.&lt;/P&gt;
&lt;P&gt;To give some background on our network it is set up like this with firewall open from workstations to servers in each department&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.10.20.0/24 = Department A workstations&lt;/P&gt;
&lt;P&gt;10.10.25.0/24 = Department A Servers&lt;/P&gt;
&lt;P&gt;10.10.30.0/24= Department B workstations&lt;/P&gt;
&lt;P&gt;10.10.35.0/24 = Department B Servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My networking Team is requesting that we mount our CIFS shares on our workstations through IPs in the server subnets to keep non workstation things off of the workstation subnets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our set up on the netapp side currently looks like this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have ports e0c and e0d aggregated into a0a on both nodes and ports e0e and e0f aggregated into a0b on both nodes.&lt;/P&gt;
&lt;P&gt;we then have VLANS set up on all 4 aggregated ports. ie a0a-20 a0a-25 a0a-30 a0a-35 on all 4 aggregated ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I can see the VLANs are supposed to prevent traffic going between them. So is there a way for me to get the a workstation in vlan 20 to mount a share in vlan 25?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for any guidance you have!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 21:26:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158840#M36241</guid>
      <dc:creator>joesmith</dc:creator>
      <dc:date>2020-08-20T21:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158848#M36246</link>
      <description>&lt;P&gt;Vlans are designed to separate traffic. A router can connect the two networks or a layer 3 switch could be configured to connect the networks. You could also create multiple LIFs on the SVM, one for each Vlan.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 03:03:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158848#M36246</guid>
      <dc:creator>NetApp_SR</dc:creator>
      <dc:date>2020-08-21T03:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158872#M36251</link>
      <description>&lt;P&gt;Just have a LIF per VLAN for each SVM.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 14:51:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158872#M36251</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-21T14:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158877#M36252</link>
      <description>&lt;P&gt;Thanks for reaching out to help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a firewall policy set up at the layer 3 level to allow all traffic from the 10.10.20 subnet to the 10.10.25 subnet but when I try to mount a lif with a 10.10.25 IP from my workstation it won't connect. Everything is working correctly trying to mount with in the workstation subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 16:31:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158877#M36252</guid>
      <dc:creator>joesmith</dc:creator>
      <dc:date>2020-08-21T16:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158879#M36254</link>
      <description>&lt;P&gt;If the share is going to be open anyway, why not&amp;nbsp; use a LIF in 10.10.20 on the same VLAN? Unless the network/security team wants to log the traffic going in? But fpolicy could be used for that too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 16:39:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158879#M36254</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-21T16:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158881#M36255</link>
      <description>&lt;P&gt;That was their desire, to be able to log information about who/what was being accessed. My main concern was the firewall slowing things down a bit, but then when i tried to connect to the SVM from a lif on a different vlan it wouldn't let me access it through that Lif. Thats why i am trying to figure out if/how to make that happen. As I said, the company firewall policy is wide open from 10.10.20 to 10.10.25, so i would think that the netapp is blocking that traffic somehow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 17:14:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158881#M36255</guid>
      <dc:creator>joesmith</dc:creator>
      <dc:date>2020-08-21T17:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158882#M36256</link>
      <description>&lt;P&gt;And the LIF is on like a0a-123 where 123 is the VLAN ID?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the switch configured for that interface for the VLANs?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 17:24:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158882#M36256</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-21T17:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158889#M36259</link>
      <description>&lt;P&gt;Also, if you wish to monitor, fpolicy will do just that. Just throwing it out there. It may work better because it doesn't have to perform any in-flight packet inspection but just logs exactly what is being accessed and when.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 21:50:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/158889#M36259</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2020-08-21T21:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454757#M43896</link>
      <description>&lt;P&gt;Hi Gents, did anyone find a solution to this thread ? Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 17:26:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454757#M43896</guid>
      <dc:creator>Tzammel</dc:creator>
      <dc:date>2024-08-29T17:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454772#M43897</link>
      <description>&lt;P&gt;You need to set your switch to allow VLANs to cross or layer 3 cross-VLAN connectivity. Alternatively set up a LIF on the user VLAN.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:52:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454772#M43897</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2024-08-29T18:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Vlan communication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454782#M43900</link>
      <description>&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;I found this NetApp article that describes the situation we are facing:&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Network_traffic_not_sent_or_sent_out_of_an_unexpected_interface_after_upgrade_to_9.2_due_to_elimination_of_IP_Fastpath" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Network_traffic_not_sent_or_sent_out_of_an_unexpected_interface_after_upgrade_to_9.2_due_to_elimination_of_IP_Fastpath&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any idea how to create the return routes ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 15:41:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cross-Vlan-communication/m-p/454782#M43900</guid>
      <dc:creator>Tzammel</dc:creator>
      <dc:date>2024-08-30T15:41:24Z</dc:date>
    </item>
  </channel>
</rss>

