<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NFS Share Access Denied in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455242#M43975</link>
    <description>&lt;P&gt;hi:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;The read-only&amp;nbsp; rule option is set the value to any&amp;nbsp; and then checks permissions because never specifies that no client can get read-only access.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;if you want to apply the export policy to all possible IP4 addresses,set the clientmatch to 0.0.0.0/0&lt;/P&gt;&lt;P&gt;Refer to the following article&amp;nbsp; for options for creating an export policy&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_do_export_policies_work_in_clustered_Data_ONTAP" target="_blank" rel="noopener"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_do_export_policies_work_in_clustered_Data_ONTAP&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2024 03:30:27 GMT</pubDate>
    <dc:creator>chenguanghui</dc:creator>
    <dc:date>2024-09-19T03:30:27Z</dc:date>
    <item>
      <title>NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455230#M43970</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a new volume via ontap and want to mount it using NFS on a Ubuntu Linux VM (hosted on VMWare)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within the volume i have enabled the NFS option and created an export policy where i have specified the VM IP and given read/write permissions to all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LeeLSTM_0-1726662305341.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/29053iCD6930544C27CD0A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="LeeLSTM_0-1726662305341.png" alt="LeeLSTM_0-1726662305341.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I keep getting access denied when running the mount command. I can ping the NetApp from the VM so not sure what else to try?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 12:27:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455230#M43970</guid>
      <dc:creator>LeeLSTM</dc:creator>
      <dc:date>2024-09-18T12:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455231#M43971</link>
      <description>&lt;P&gt;start with verifying the IP of the nfs client is in that list.&lt;/P&gt;&lt;P&gt;Then make sure the export-policy is applied to both the root volume and the data volume&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 13:39:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455231#M43971</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2024-09-18T13:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455232#M43972</link>
      <description>&lt;P&gt;Cheers TMA, the IP of the client is correct and i can ping both ways..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you elaborate on "&lt;SPAN&gt;Then make sure the export-policy is applied to both the root volume and the data volume"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 14:00:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455232#M43972</guid>
      <dc:creator>LeeLSTM</dc:creator>
      <dc:date>2024-09-18T14:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455233#M43973</link>
      <description>&lt;P&gt;I am asking to verify IPs because it is NOT uncommon to have multiple IPs and the route the hsot chooses may not be the one you want, Pinging is not the tell all in every case. You need to verify IPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every volume must have an export-policy attached to it to allow NFS access. By default, there is a policy in every SVM called default. Looks like you created a new policy called "mount" with two entries.&lt;/P&gt;&lt;P&gt;The default policy attached to the root volume of the SVM needs to have an entry to allow access also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically, I will do this:&lt;/P&gt;&lt;P&gt;export-policy rule create -vserver xxx -policy default -client 0.0.0.0/0 -ro=sys -rw=none -super=none -proto nfs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That allows any client to attach to the root, but only with read permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the volume export-policies.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 15:13:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455233#M43973</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2024-09-18T15:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455238#M43974</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the read-only rule has been set to &lt;STRONG&gt;Never&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- Never&lt;/STRONG&gt; means "For an incoming request from a client matching the client match criteria, do not allow any access to the volume regardless of the security type of that incoming request."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- So, I would suggest to you first change this value to &lt;STRONG&gt;Any &lt;/STRONG&gt;and check the access.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;vserver export-policy rule create: &lt;FONT face="courier new,courier"&gt;&lt;A href="https://docs.netapp.com/us-en/ontap-cli-9111/vserver-export-policy-rule-create.html#description" target="_blank"&gt;https://docs.netapp.com/us-en/ontap-cli-9111/vserver-export-policy-rule-create.html#description&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- If it still fails, run below command which will show you where the access is failing.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;vserver export-policy check-access -vserver &amp;lt;VSERVER_NAME&amp;gt; -client-ip &amp;lt;CLIENT_IP&amp;gt; -volume &amp;lt;VOLUME_NAME&amp;gt; -authentication-method sys -protocol &amp;lt;nfs3/nfs4&amp;gt; -access-type read-write&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: (you need to key in the vserver name, client IP, volume name and nfs version in the command. This will tell you if there is any access issues.)&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;vserver export-policy check-access: &lt;FONT face="courier new,courier"&gt;&lt;A href="https://docs.netapp.com/us-en/ontap-cli-9131/vserver-export-policy-check-access.html#description" target="_blank"&gt;https://docs.netapp.com/us-en/ontap-cli-9131/vserver-export-policy-check-access.html#description&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Possible KB match: &lt;FONT face="courier new,courier"&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/NFS_client_access_denied_when_mounting_because_RO_Access_Rule_is_set_to_never" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/NFS_client_access_denied_when_mounting_because_RO_Access_Rule_is_set_to_never&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Mounting Process: The NFS client must first access the root volume&amp;nbsp;of the data vserver before it can reach the data volume.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the issue persists, share the export-policy check-access output here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this will help you with t-shooting the issue.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 19:48:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455238#M43974</guid>
      <dc:creator>ChLokesh</dc:creator>
      <dc:date>2024-09-18T19:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: NFS Share Access Denied</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455242#M43975</link>
      <description>&lt;P&gt;hi:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;The read-only&amp;nbsp; rule option is set the value to any&amp;nbsp; and then checks permissions because never specifies that no client can get read-only access.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;if you want to apply the export policy to all possible IP4 addresses,set the clientmatch to 0.0.0.0/0&lt;/P&gt;&lt;P&gt;Refer to the following article&amp;nbsp; for options for creating an export policy&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_do_export_policies_work_in_clustered_Data_ONTAP" target="_blank" rel="noopener"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_do_export_policies_work_in_clustered_Data_ONTAP&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 03:30:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-Share-Access-Denied/m-p/455242#M43975</guid>
      <dc:creator>chenguanghui</dc:creator>
      <dc:date>2024-09-19T03:30:27Z</dc:date>
    </item>
  </channel>
</rss>

