Quantcast
Channel: ONTAP Discussions topics
Viewing all 4962 articles
Browse latest View live

7MTT 3.0 RH GUI Acces HTTP 500

$
0
0

Hi Community folks,

 

Trying to access the 7MTT gui and got the below message.

Anybody had a similar behavior?

 

I can't find the tomcat logs and documentation is always related to windows installation.

 

HTTP Status 500 -


type Exception report

message

descriptionThe server encountered an internal error () that prevented it from fulfilling this request.

exception

java.io.IOException: Stream closed
	java.io.BufferedInputStream.getBufIfOpen(BufferedInputStream.java:170)
	java.io.BufferedInputStream.reset(BufferedInputStream.java:446)
	com.netapp.autozapi.server.zapi.ZapiRequestHandler.handleRequest(ZapiRequestHandler.java:107)
	org.springframework.web.context.support.HttpRequestHandlerServlet.service(HttpRequestHandlerServlet.java:67)
	javax.servlet.http.HttpServlet.service(HttpServlet.java:722)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:369)
	com.netapp.transition.server.logging.PostSecurityAuditLoggerConfigFilter.doFilter(PostSecurityAuditLoggerConfigFilter.java:46)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.access.intercept.FilterSecurityInterceptor.invoke(FilterSecurityInterceptor.java:109)
	org.springframework.security.web.access.intercept.FilterSecurityInterceptor.doFilter(FilterSecurityInterceptor.java:83)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.access.ExceptionTranslationFilter.doFilter(ExceptionTranslationFilter.java:97)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.session.SessionManagementFilter.doFilter(SessionManagementFilter.java:100)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.authentication.AnonymousAuthenticationFilter.doFilter(AnonymousAuthenticationFilter.java:78)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter.doFilter(SecurityContextHolderAwareRequestFilter.java:54)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.savedrequest.RequestCacheAwareFilter.doFilter(RequestCacheAwareFilter.java:35)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	waffle.spring.NegotiateSecurityFilter.doFilter(Unknown Source)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:79)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	com.netapp.transition.server.logging.PreSecurityAuditLoggerConfigFilter.doFilter(PreSecurityAuditLoggerConfigFilter.java:46)
	org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:381)
	org.springframework.security.web.FilterChainProxy.doFilter(FilterChainProxy.java:168)
	org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:237)
	org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:167)

 

noteThe full stack trace of the root cause is available in the Apache Tomcat/7.0.27 logs.

 

Cheers,

RomSmiley Wink


NSeries Gateway ("V" Model) - need software license

$
0
0

Hi - looking for ideas.

 

I need a FlexClone license f or an old NSeries 6270 running in Gateway Mode (so V3270A in NetApp terms).

 

IBM has withdrawn all options to obtain the license and we're not having much luck in the used space with a V3270 equivalent.

 

Any suggestions on how to get the license?

 

 

SnapMirror Network Ports

$
0
0

I have snapmirror traffic between two datacenters where there is a separate CDOT cluster in each datacenter.  Should I be expecting all snapmirror traffic to go over port 11104 and 11105 on the intercluster network or should I be expecting snapmirror traffic to be using ports 10565-10569?

 

Thanks!

SnapMirror and Backup

$
0
0

What are the risks of relying only on SnapMirror volume replication between sites for backups of data? 

Netapp cluster mode ifgrp lacp problem

$
0
0

Hi

 

I have an issue with an ifgrp configured as LACP on a FAS8020 controller in cluster mode. Each controller has e0c and e0d configured as LACP, however, one of my ifgrp's which is on node1 is showing as disabled, although when i check both e0c and e0d ports individually, they both show status as UP. Both connections link back to separate Juniper switches of which both ports show in the UP state but status as ATTACHED. The ifgrp that is working on controller node 2 is showing port and ifgrp status UP and on the juniper switches as status COLLECTING DISTRIBUTING. 

Everything was working fine up until a few days ago when the all my lifs that where on the ifgrp on controller node 1 that is no longer working failed over one night.

 

We've disabled and enabled the ports from the switches and also from the netapp controller for e0c, e0d and the ifgrp. Our networks guys have checked their config and logs and that all seems to be fine. I've pulled down the LACP log from controller node 1, part extract is below.

 

So let me break this down, both configurations are identical and have been working fine for a while until a few days ago.

 

Controller node 1 -

 

ifgrp a0a : comprises of e0c and e0d in LACP mode. Was working perfectly, but is now in disabled state. Both e0c and e0d are in up state

 

Controller node 2 -

 

ifgrp a0b : comprises of e0c and e0d in LACP mode. a0b status is enabled. Both e0c and e0d are in up state

 

 

 

Extract from LACP log controller node 1

 

---
2016-07-29 03:23:42: ERROR: lag_link_up_to_down (e0d)
2016-07-29 03:23:42: ERROR: lag_link_up_to_down (e0c)
2016-07-29 03:23:42: ERROR: lag_link_up_to_down (e0c)
2016-07-29 03:23:42: ERROR: lag_link_up_to_down (e0d)
2016-07-29 02:32:22: ERROR: Rx_machine (Actor- Remote device, Partner- Local):
LAG_PKT: View of partner incorrect:e0c moving select to unselected
Actor - SysPri:127 , SysID: , key: 247, PortPri: 127, PortID:52
Actv:1 ,Timeout:1, Agg:1, Sync:0, Coll:0, Dist:0, Default:0, Expired:0
Partner - SysPri:1 , SysID: , key: 1, PortPri: 0, PortID:2
Actv:1 ,Timeout:0, Agg:1, Sync:0, Coll:0, Dist:0, Default:1, Expired:1
---
2016-07-29 02:32:22: ERROR: Prev_stored (Actor- Local, Partner- Remote device):
LACP state information: e0c
Actor - SysPri:1 , SysID: , key: 1, PortPri: 0, PortID:2
Actv:1 ,Timeout:0, Agg:1, Sync:0, Coll:0, Dist:0, Default:1, Expired:1
Partner - SysPri:0 , SysID: 0:0:0:0:0:0, key: 0, PortPri: 0, PortID:0
Actv:0 ,Timeout:1, Agg:1, Sync:0, Coll:0, Dist:0, Default:0, Expired:0
---
2016-07-29 02:32:22: ERROR: Rx_machine (Actor- Remote device, Partner- Local):
LAG_PKT: e0c setting partner port sync to FALSE
Actor - SysPri:127 , SysID: , key: 247, PortPri: 127, PortID:52
Actv:1 ,Timeout:1, Agg:1, Sync:0, Coll:0, Dist:0, Default:0, Expired:0
Partner - SysPri:1 , SysID: , key: 1, PortPri: 0, PortID:2
Actv:1 ,Timeout:0, Agg:1, Sync:0, Coll:0, Dist:0, Default:1, Expired:1

 

 

Please can someone point me in the right direction as to where the problem may be and a possible fix. Your input is greatly appreciated.

 

Cheers

Clustered DOT - Changing FC to initiator

$
0
0

Hi everyone.

I hava a FAS2554 with DOT 8.3.2.

The storage is used for CIFS share and VM repository with FC Lun.

I have to set up CIFS share backup on tape using NDMP protocol.

I have read that the fc interface of the filer needs to be  "initiator". So I need to change the type from the current "target" and need to reboot the node.

 

There are 2  FC physical interface. There is a way to use both FC interfaces for NDMP (initiator) and  FC LUN (target)?

Can I reboot the node without making "takeover" or it is preferable to make "takeover"?

The active node takes over the volumes of the node  that is restarted, it is correct? My colleagues can continue to work during the reboot

After the reboot, the restarted node resumes its volumes, disconnecting again CIFS and FC sessions?

 

Thank you.

Marcello

    

 

 

Half of Drives in a Shelf Use One Slot/Port, The Other Half Uses Another

$
0
0

I am making plans to remove three unused shelves from a 7-mode system. The three shelves form a complete stack so it's pretty straightforward, however I noticed that one of the three shelves contain about half of it's disks with one slot/port and the other half with a different slot/port. I don't know if this is common or not. The other two shelves show the same slot/port on each disk.

 

Any thoughts/ideas? Is this a concern?

 

Examples:

Some disks on shelf 21 look like this: 3d.21.0, 3d.21.2, 3d.21.4

The others look like this: 5a.21.1, 5a.21.3, 5a.21.5

Raid-DP Vs Raid-6

$
0
0

Hello Everyone,

Could someone shed some light as to how the 2nd parity bit is calculated for both RAID-DP and RAID-6. Is it the same?
I understand ,the only difference between RAID-6 and RAID-DP is that, the 2nd parity bit is distributed in raid-6 unlike Raid-Dp. But how is the 2nd parity bit calculated in both the case?



What are these snapshots that appear on my vol0?

$
0
0

I've been noticing some oddly named snapshots show up on vol0 on a system where I have snapshots completely turned for vol0. Anyone else ever see these or know what causes them?

 

FWIW: this is an 8.3.2 simulator environment.

 

= = = = = = = = = = = 

 

hq-stor::> vol snap show vol0

                                                                 ---Blocks---

Vserver  Volume   Snapshot                                  Size Total% Used%

-------- -------- ------------------------------------- -------- ------ -----

hq-stor-01 

         vol0

                  .tmp.bk.hq-stor.8hour.6.1480580100    325.2MB     4%   16%

 

hq-stor::> vol snap show vol0 -fields create-time 

vserver    volume snapshot                           create-time              

---------- ------ ---------------------------------- ------------------------ 

hq-stor-01 vol0   .tmp.bk.hq-stor.8hour.6.1480580100 Thu Dec 01 03:34:40 2016 

 

hq-stor::> vol show vol0 -fields snapshot-policy 

vserver    volume snapshot-policy 

---------- ------ --------------- 

hq-stor-01 vol0   -               

 

hq-stor::> run local -command snap sched vol0

Volume vol0: 0 0 0

 

Honeypot for crypto viruses

$
0
0

Hello,

 

We are a University with around 20'000 users with all their files on NetApp filers running ONTAP 9.0/CDOT, and from time to time, we have users who get infected with a crypto-virus and starts encrypting files on all shares they have access to.  Cryptoviruses are often not detected by antivirus software, and we were thinking about making an automated lock-down system with a honeypot to detect and stop the outbreak before it becomes a problem/lots of cleanup work.

 

Before I start, I would just like to check if anyone else already had done this?

 

My idea is to make a share with enough files so the cryptovirus is busy for a while on this share, and mount it as an early letter in windows on all clients.  Then make a script that detects changes on this share and who is doing the changes - then lock down this users account so the user doesn't have access to encrypt anything on later network shares mapped - like home directories and common file areas.

 

Any ideas or input on this before I start making a solution is welcome.

 

-- 
Morten-Christian Bernson,
Section for infrastructure, Systems Architect Storage and Backup
IT-department, University of Bergen

NFS rsize/wsize

$
0
0

Hi,

 

ONTAP 9.1RC1

RHEL 5.7

 

I just migrated from Isilon to NetApp and I notice from a Linux 5.7 host, it used to have much larger rsize/wsize (128k/512k) but now has 64k/64k when mounted onto NetApp.Nothing changed on the Linux side so I believe the sizes are negotiated.

 

1. What's the maximun values NetApp support?

2. If I manually specify larger values on Linux, is it correct it will negotiate to the max values when it reconnects?

 

Thanks,

 

 

Ontap select evaluation license issue

$
0
0

I managed to get evaluation template DataONTAPv-esx-standalone.ova for single node cluster and i was able to bypass the ontap deploy as i had to deploy ontap select on nfs datastore, during the initial setup it asks for the base key and i just pressed enter key.

 

It installs perfectly but when i create SVM all the protocol services are disabled and i believe that this is a license issue, somebody tell me what should be used for the base key during the initial setup.

 

Reason why i bypassed ontap deploy utility is that they dont support only vmfs formats.

Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ?

$
0
0

Hi,

 

We are testing an upgrade to Ontap 9.0 & 9.1rc from Ontap 8.3;

 

This name mapping works in Ontap 8.3:

Kerberos to UNIX:

Pattern: (.+)\$@DOMAIN.COM Replacement: nfsuser

 

 

This name mapping doesn't work in Ontap 9.x:

Kerberos to UNIX:

Pattern: (.+)\$@DOMAIN.COM Replacement: nfsuser

 

This is the error from my netapp:

12/2/2016 15:19:23  MYNODE     ERROR         secd.nfsAuth.problem: vserver (nfsv4) General NFS authorization problem. Error: RPC accept GSS token procedure failed

 [ 24 ms] Acquired NFS service credential for logical interface 1027 (SPN='nfs/nfsv4.domain.com@DOMAIN.COM').

 [    31] GSS_S_COMPLETE: client = 'MYCOMPUTER$@DOMAIN.COM'

 [    32] Trying to map SPN 'MYCOMPUTER$@DOMAIN.COM' to UNIX user 'MYCOMPUTER$' using implicit mapping

 [    37] Entry for user-name: MYCOMPUTER$ not found in the current source: FILES. Ignoring and trying next available source

 [    48] Successfully connected to ip 1.1.1.1 port 389 using TCP

 [  3063] LDAP search for the "uid, uidNumber, gidNumber, unixUserPassword, name, unixHomeDirectory, loginShell" attribute(s) within base "dc=domain,dc=com" (scope: 2) using filter "(&(objectClass=User)(uid=MYCOMPUTER$))" failed with error: Timed out

 [  3063]   Additional info:

 [  3064] Source: LDAP unavailable. Entry for user-name:MYCOMPUTER$ not found in any of the available sources

 [  3064] Unable to map SPN 'MYCOMPUTER$@DOMAIN.COM'

**[  3064] FAILURE: Unable to map Kerberos NFS user 'MYCOMPUTER$@DOMAIN.COM' to appropriate UNIX user

 [  3065] Failed to accept the context: The routine completed successfully (minor: Unknown error). Result = 6916

 

 

Note: this one works on the Ontap 9:

Kerberos to UNIX:

Pattern: (.+)@DOMAIN.COM Replacement: nfsuser

 

Though, I do not want all the domain krb users mapped to nfsuser only MACHINESHORTNAME$@DOMAIN.COM

 

Additionally, my LDAP translations are working:

 

diag secd authentication translate -node MYNODE -vserver NFS4  -unix-user-name MYUSERNAME
12345

 

Also, is there an easier way to test krb like unix ids?

diag secd authentication translate -node MYNODE -vserver NFS4  -unix-user-name MYUSERNAME

 

Thanks in advance.

 

Ben

Any way to collect historical data for NVRAM stats?

$
0
0

Hi,

 

ONTAP 9.1RC1

AFF8040 HA

 

We have a Linux sever running SAS software and NFS mounts to the AFF for SAS data access. SAS software is heavy on sequential writes. I'd like to find out whether NVRAM keeps getting full when there is large amount of sequential writes thus gets flushed to SSDs so frequently that it acutally becomes a bottleneck. I can do ssysstat to get some NVRAM related realtime stats but is there a way to retrive historical data for such NVRAM stats? I don't see it's possible in Unified Manager.

 

Thanks,

How do i enable an ifgrp in clustered mode

$
0
0

Hi 

 

Can someone help me with the command to enable an ifgrp in cluster mode (cdot). I currently have an ifgrp which entered a disabled state and if i run the command 'ifgrp show' i get 'active ports = none' on the ifgrp with the fault. All other ifgrps have 'activeports = full' and list their associated ports. There doesn't seem to be an option to enable the ifgrp from system manager. 

 

Thanks in advance


CDOT 8.3 Create Role to limit a user to only Shutdown nodes in a Cluster

$
0
0

I am trying to create a role that will limit a user to login via ssh and only halt the nodes in the Cluster, using the -inhibit-takeover true and -skip-lif-migration-before-shutdown true options.

 

The user will connect to the first node and run:

cluster1::> system node halt -node Cluster-01 -inhibit-takeover true -skip-lif-migration-before-shutdown true

 

Connect second controller and run:

cluster1::> system node halt -node Cluster-02 -inhibit-takeover true -skip-lif-migration-before-shutdown true

 

I have created a role named rHaltUser with the following permissions:

cluster1::> security login role create -role rHaltUser -access admin -cmddirname "system node halt"

 

Also created a user named haltuser and assigned the rHaltUser role..

cluster1::> security login create -vserver cluster1 -user-or-group-name haltuser -application ontapi -authmethod password -role rHaltUser

cluster1::> security login create -vserver cluster1 -user-or-group-name haltuser -application ssh -authmethod password -role rHaltUser

 

I am able to halt the nodes, but not invoke the -inhibit-takeover true and -skip-lif-migration-before-shutdown true options.

do I need to add addtional -cmddirname permissions?

 

Any suggestions welcomed.  Thanks

NDMPCOPY bind to data lif

$
0
0

Hi

 

Any idea why NDMPCOPY command fails to unable to bind protocol to data lif IP. I have been looking this with support but let's say they "are bit lost". Ontap version 8.3.x CDOT

Problem with AD - group permissions not working unless "cifs setup" is invoked again

$
0
0

Hi!

 

I have strange problem with FAS2240 running ONTAP 8.2.4P3 in 7-mode. I've recently added some additional uplinks for file services (was running iSCSI only) and confiured CIFS service with Active Directory. AD itself is pretty ancient: Win2003 servers running AD with Win2000 functional level, with 2-way trust with another domain (same servers and functional level).

 

And I have pretty strange problem: when I set up new volume and configure user-based permissions, everything works just fine. However when I try to build exactly same permissions using group management, I have "access denied" when trying to access share. Permissions are fine, FAS talks to AD without any issues.

 

But here's the best part: if i "cifs terminate" and then "cifs setup", configure everything again exatly the same as previously, group permissions automagically start working. If I try adding another group to acces the share - access denied. If I try add another user to already configured group, then sometimes it works, sometimes it doesn't.

 

Any ideas? I've tried everything permission-related I could find across the web, nothing helps so far. Domain communication works, users and groups are accesible from filer, wcc -x doesn't help.

volume distribution along the agregate / Raid Groups

$
0
0

Hi everybody,

 

I run a FAS3220 cluster, running the 8.2.1 version, 7 mode.

 

I have one aggregate aggr0. This aggregate contains around 10 volumes.

On the other side, this aggregate is composed of 2 raid groups, of each 23 disks, in raid DP.

 

here is the issue I have...

 

some users encounter lag & performance issues.

When I checked disk activity, I saw that the disks of the 1st raid group are almost allways over busy, with IOPS almost at the limit for that kind of disk,

and on the other side, the disks of the 2nd raid group, are almost unused! (around 10 - 15IOPS average...)

 

So I guess that there is an issue with the volumes distribution along the aggregate and the Raid groups?

 

I identified the 3 volumes the more "IOPS-greedy"

Is there a way to better distribute these 3 volumes along the 2 Raid groups? Would a volume reallocate make that? Or is there maybe an other way to do that?

 

Thanks a lot for your help!

 

Thomas

ONTAP Select Deploy failed

$
0
0

Hi,

 

I'm trying to deploy ONTAP Select 9.0P1, but everytime the deploy utility wants to write the sdotconfig_<NODE>.iso to the datastore it fails.

I get the following error:

  • NodeCreateFailed: Node (<CLUSTER NODE>) create failed: (Failed to write file (https://<vCenter URL>/folder/<CLUSTER NODE>/sdotconfig_<CLUSTER NODE>.iso?dcPath=GNT&dsName=ONTAP_SELECT): 500 write failed: ).

I think the issue in with the dcPath parameter (marked in red). If I change it to 'dcPATH=BE%252fGNT' I can browse to it. My Datacenter is indeed in a folder BE.

 

Anybody an idea on how to get the correct URL for the deployement? I can't change the structure in vCenter.

 

Thanks,

Ian

Viewing all 4962 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>