<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nfs mount denied while using vpn tunnel in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443693#M42093</link>
    <description>&lt;P&gt;Firewall : Is the Client allowed outbound traffic to TCP Port 2049 (NFSV4) ? It may be worth checking if this port is open.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2023 08:51:29 GMT</pubDate>
    <dc:creator>Ontapforrum</dc:creator>
    <dc:date>2023-04-25T08:51:29Z</dc:date>
    <item>
      <title>nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443650#M42077</link>
      <description>&lt;P&gt;I'm testing vpn access for our future remote workers. It's mostly done except I cannot mount to the storage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the packets and confirmed they can communicate each other. But lookup to the storage denied with NFS4ERR_ACCESS error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I allowed access from IP range of vpn clients in ontap. I cannot guess another reason to be blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could I check the reason why an access didn't allowed in ontap by commands? Or some hints would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:50:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443650#M42077</guid>
      <dc:creator>yb</dc:creator>
      <dc:date>2025-06-04T09:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443693#M42093</link>
      <description>&lt;P&gt;Firewall : Is the Client allowed outbound traffic to TCP Port 2049 (NFSV4) ? It may be worth checking if this port is open.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:51:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443693#M42093</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-04-25T08:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443706#M42096</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case the client is a mac. (I got a linux pc too, but unfortunately it just broke.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found it sends calls via port 61508, but ontap storage replies via 2049. I see they connects well, success to SETCLIENTID, SETCLIENTID_COFIRM call/reply. But lookup for the mount is denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I be able to send the message through port 2409?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 14:27:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443706#M42096</guid>
      <dc:creator>yb</dc:creator>
      <dc:date>2023-04-25T14:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443712#M42098</link>
      <description>&lt;P&gt;Mac, interesting. Could you try linux ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering if the client OS is supported. Which NFSv4 version is it? 4.0/4.1/4.2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It may be worth checking which NFS clients ONTAP supports, see the Interoperability Matrix:&lt;BR /&gt;&lt;A href="https://mysupport.netapp.com/matrix" target="_blank"&gt;https://mysupport.netapp.com/matrix&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check this blog:&lt;BR /&gt;&lt;A href="https://whyistheinternetbroken.wordpress.com/2021/04/14/macos-nfs-clients-with-ontap-tips-and-considerations/" target="_blank"&gt;https://whyistheinternetbroken.wordpress.com/2021/04/14/macos-nfs-clients-with-ontap-tips-and-considerations/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:35:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443712#M42098</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-04-25T15:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443922#M42133</link>
      <description>&lt;P&gt;We have successfully run mac nfs clients inside of the network. That's the reason I think this is related with vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of them uses nfs4.0 and krb5i for connection. And setup on my mac isn't different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, ssd on my linux is broken. I will try soon.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 14:44:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443922#M42133</guid>
      <dc:creator>yb</dc:creator>
      <dc:date>2023-05-01T14:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: nfs mount denied while using vpn tunnel</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443928#M42134</link>
      <description>&lt;P&gt;Ok. In that case, we can rule out 'mac' as an issue. Have you done pktt (packet) trace on the ONTAP side ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, you could try the following command to check-access to particular client for test purpose:&lt;BR /&gt;vserver export-policy check-access command checks whether a specific client is allowed access to a specific export path.&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap-cli-93/vserver-export-policy-check-access.html#description" target="_blank"&gt;https://docs.netapp.com/us-en/ontap-cli-93/vserver-export-policy-check-access.html#description&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 20:09:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/nfs-mount-denied-while-using-vpn-tunnel/m-p/443928#M42134</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-05-01T20:09:14Z</dc:date>
    </item>
  </channel>
</rss>

