跳转到主内容

无法 SSH 到 SP IP,错误连接被拒绝

Views:
61
Visibility:
Public
Votes:
0
Category:
aff-series
Specialty:
hw
Last Updated:

适用于

  • AFF/FAS
  • ONTAP 9

问题

  • 已为集群中的所有节点配置服务处理器,并且已启动和在线。
  • 无法远程访问服务处理器。
  • 能够从串行控制台端口登录到 SP。

原因

已配置所有节点 Service Processor 以接受来自特定主机 IP 地址的 SSH 连接请求。

解决方案

  • 检查以下命令输出并验证是否已分配任何特定 IP 地址:
::> system service-processor ssh show
 

例如: 我们看到允许登录 Service Processor 的访问权限仅来自以下管理主机。限制 Service Processor 访问仅限于指定的 IP 地址。

::> system service-processor ssh show
 Allowed Addresses: 192.168.1.XX, 172.16.XX.XX

从上面可以看到,存储管理员指定了两个管理主机的 IP 地址。只有以下两台主机才能从其网络访问 SP。要删除此内容,请按以下步骤操作:

  • 从访问列表中删除指定的 IP 地址,然后还原所有 IP 地址的默认 Service Processor 访问权限。

::> system service-processor ssh remove-allowed-addresses -allowed-addresses 192.168.1.XX, 172.16.XX.XX

Warning: If all IP addresses are removed from the allowed address list, all IP addresses will be denied access. To restore the "allow all" default, use the "system service-processor ssh add-allowed-addresses -allowed-addresses 0.0.0.0/0, ::/0" command. Do you want to continue? {y|n}: 

Enter Y

  • 删除 IP 后,所有主机都无法远程与 Service Processor 通信。若要远程访问 Service Processor,请尝试还原默认访问权限。
  • 恢复默认的 Service Processor 访问权限:

::> system service-processor ssh add-allowed-addresses -allowed-addresses 0.0.0.0/0, ::/0

::> system service-processor ssh show

Allowed Addresses: 0.0.0.0/0, ::/0

  • 进行上述更改后,客户网络中的所有主机都应能够使用 SP 用户名和密码远程访问 Service Processor。

Please contact NetApp Technical Support or log into the NetApp Support Site to create a technical case. Reference this article for further assistance.

 

内部参考

NA

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.