<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ONTAP System Manager IP Limiting in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/161699#M36948</link>
    <description>&lt;DIV&gt;Hi,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am wondering if it is possible to block all access to the NetApp ONTAP System Manager web console on port 80/443 unless you have a specific IP address?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I want to only allow staff within our IT department to be able to connect to the web console and only from their own computers with fixed IP addresses.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Best Regards&lt;/DIV&gt;&lt;DIV&gt;Jamie&lt;/DIV&gt;</description>
    <pubDate>Wed, 04 Jun 2025 10:43:15 GMT</pubDate>
    <dc:creator>JamieTalbot</dc:creator>
    <dc:date>2025-06-04T10:43:15Z</dc:date>
    <item>
      <title>ONTAP System Manager IP Limiting</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/161699#M36948</link>
      <description>&lt;DIV&gt;Hi,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am wondering if it is possible to block all access to the NetApp ONTAP System Manager web console on port 80/443 unless you have a specific IP address?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I want to only allow staff within our IT department to be able to connect to the web console and only from their own computers with fixed IP addresses.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Best Regards&lt;/DIV&gt;&lt;DIV&gt;Jamie&lt;/DIV&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:43:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/161699#M36948</guid>
      <dc:creator>JamieTalbot</dc:creator>
      <dc:date>2025-06-04T10:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP System Manager IP Limiting</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/161701#M36949</link>
      <description>&lt;P&gt;Hi Jamie,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I understand the question correctly, you should be able to block access to the System Manager Web server with firewall rules in ONTAP itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to ONTAP 9.5 (or so), these were called "Firewall Policies". On the CLI you use "system services firewall policy ...".&lt;/P&gt;&lt;P&gt;In newer releases they are termed "LIF Service Policies" and are accessed via "network interface service-policy ...".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously those are configured per LIF. You would need to add a new policy for the admin and node vservers of the cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Status of the firewall itself can be seen with "system services firewall show". I think by default it is normally on, but does not do any logging (thats's what I see here, on a ONTAP 9.7 system). It might be useful to enable logging for testing or longer term for analytics/correlation/intrusion detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the nature of your question, you may also want to think about how to limit access to the Service Processor, typically a physically separate piece of hardware, accessed via a URI ending in ".../spi/", which can give access to the system logs, for example. But I am not sure if that can also be done via this same mechanism ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Robb.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 15:46:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/161701#M36949</guid>
      <dc:creator>WAFLHERDER</dc:creator>
      <dc:date>2020-12-02T15:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP System Manager IP Limiting</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/162134#M37026</link>
      <description>&lt;P&gt;One idea will be to separate the management from data network. you can create a management vlan for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 08:17:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-System-Manager-IP-Limiting/m-p/162134#M37026</guid>
      <dc:creator>Mjizzini</dc:creator>
      <dc:date>2020-12-15T08:17:32Z</dc:date>
    </item>
  </channel>
</rss>

