<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Snapvault across domains: CIFS acces denied on destination in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126338#M8619</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aviador -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you see using the 'vserver cifs domain trusts show' command' ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also the man pages for all the vserver cifs domain commands:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP1511539/html/vserver/cifs/domain/toc.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1511539/html/vserver/cifs/domain/toc.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eugene E. Kashpureff, Sr.&lt;BR /&gt;Independent NetApp Consultant &lt;A href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;BR /&gt;Senior NetApp Instructor, FastLane US &lt;A href="http://www.fastlaneus.com/" target="_blank"&gt;http://www.fastlaneus.com/&lt;/A&gt;&lt;BR /&gt;(P.S. I appreciate 'kudos' on any helpful posts.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Dec 2016 21:54:05 GMT</pubDate>
    <dc:creator>ekashpureff</dc:creator>
    <dc:date>2016-12-15T21:54:05Z</dc:date>
    <item>
      <title>Snapvault across domains: CIFS acces denied on destination</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126325#M8618</link>
      <description>&lt;P&gt;Hello, I am trying to mount a snapvaulted volume and can't get acces: "Access is denied. The requested permissions are not granted by the ACE while opening existing file or directory."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The original filer "A" (SVM) is in Domain TEST and had permissions on the folder for groups of Domain TEST.&lt;/P&gt;&lt;P&gt;Destination filer "B" (SVM) is in Domain PROD (trusted by TEST) , I mounted the snapvaulted vol, created the share but cannot get to the files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Groups allowed permissions to the share in domain TEST include Foreign Security Principals (FSP) from domain PROD. They resolve to groups from PROD , my user is a member of one of these groups. I can access the original share in domain TEST while logged with the same user account&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I manually added my username into the security settings of the source folder (TEST) and ran and update of the SnapVault. I hoped that now the filer "B" in PROD would be able to resolve the newly added SID to my username in the domain. Yet I still get the same error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure if there is any configuration from which the filer would know that the NTFS ACLs must be solved by&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Getting the right groups from domain TEST&lt;/LI&gt;&lt;LI&gt;Solving the members (FSP that points to PROD groups)&lt;/LI&gt;&lt;LI&gt;Match the incoming user-name (mine) to the members of one of the groups in the PROD domain from the step above.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Is this even possible?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:04:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126325#M8618</guid>
      <dc:creator>aviador</dc:creator>
      <dc:date>2025-06-04T18:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Snapvault across domains: CIFS acces denied on destination</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126338#M8619</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aviador -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you see using the 'vserver cifs domain trusts show' command' ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also the man pages for all the vserver cifs domain commands:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP1511539/html/vserver/cifs/domain/toc.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1511539/html/vserver/cifs/domain/toc.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eugene E. Kashpureff, Sr.&lt;BR /&gt;Independent NetApp Consultant &lt;A href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;BR /&gt;Senior NetApp Instructor, FastLane US &lt;A href="http://www.fastlaneus.com/" target="_blank"&gt;http://www.fastlaneus.com/&lt;/A&gt;&lt;BR /&gt;(P.S. I appreciate 'kudos' on any helpful posts.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 21:54:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126338#M8619</guid>
      <dc:creator>ekashpureff</dc:creator>
      <dc:date>2016-12-15T21:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Snapvault across domains: CIFS acces denied on destination</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126353#M8623</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did look into trusted domains but it seemed to be related to user-mapping from Unix to Windows. From "Configuring multidomain name-mapping searches"&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This enables Data ONTAP to search every bidirectional trusted domain to find a match when performing UNIX user to Windows user name mapping.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since I am using only Windows names I did not think it would be relevant. Anyway here's what the command returns:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Home Domain&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trusted Domains&lt;BR /&gt;------------------------------ ------------------------------------------------&lt;BR /&gt;PROD.CORP.COMPANY.BIZ&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; CORP.COMPANY.BIZ,&amp;nbsp;&amp;nbsp; SOME.COMPANY..BIZ,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; PROD.CORP.COMPANY.BIZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(TEST domain does not appear)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I imagine I can't use fsecurity to apply new security settings given that the volume is snapvaulted .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran "icacls" from my workstation to both folders:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Filer "A" (TEST) folder returns "No match between account names and SID" plus a match for my PROD\username that I added yesterday evening&lt;/LI&gt;&lt;LI&gt;Filer "B" (PROD) only returns the "No match between account names and SID"&amp;nbsp; even though after running snapvault update I expected it to have my PROD\username as well.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Ran update again, the destination folder now has an entry for PROD\Username that Filer "B" can resolve so I gained access to the share.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 07:23:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Snapvault-across-domains-CIFS-acces-denied-on-destination/m-p/126353#M8623</guid>
      <dc:creator>aviador</dc:creator>
      <dc:date>2016-12-16T07:23:15Z</dc:date>
    </item>
  </channel>
</rss>

