It will only work when the domain is right, because the NetApp is joined to exactly one domain and can only validate credentials from that domain. So if you joined DOM1 then the user DOM1\foo would be mapped to unix user foo. If a different user (with the same name) from a different domain tries to connect, say, DOM2\foo, he would get an "access denied" since the filer has no means of checking his credentials (the filer knows nothing about domain DOM2, and even if it knew, since it is not joined to DOM2 it could not check the user's credentials)