Quantcast
Channel: ONTAP Discussions topics
Viewing all articles
Browse latest Browse all 4944

Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?

$
0
0

Based on  https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_create_a_root_squash_export_policy_rule_in_ONTAP,

 

 

filer::> vserver export-policy rule create -vserver sv1 -policyname default -clientmatch 192.168.0.0/24 -rorule any -rwrule any -superuser none -anon 65534
filer::> vserver export-policy rule show -vserver sv1 -policyname default -ruleindex 8 -instance

                                    Vserver: sv1
                                Policy Name: default
                                 Rule Index: 8
                            Access Protocol: any
List of Client Match Hostnames, IP Addresses, Netgroups, or Domains: 192.168.0.0/24
                             RO Access Rule: any
                             RW Access Rule: any
User ID To Which Anonymous Users Are Mapped: 65534   <<<<
                   Superuser Security Types: none    <<<<
               Honor SetUID Bits in SETATTR: true
                  Allow Creation of Devices: true

 

 

Basically, this is "root_squash" option. Is this a recommended export policy/configurations?

Any concerns?


Viewing all articles
Browse latest Browse all 4944

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>