迁移LIF后、由于防火墙阻止DNS、CIFS将失败
适用场景
- ONTAP 9
- CIFS/SMB
- DNS
- 防火墙
问题描述
- 当
LIF1位于Node1上时,CIFS客户端可以通过访问文件\\LIF1 - 将
LIF1迁移到之后Node2- CIFS客户端无法通过访问文件
\\LIF1 cifs check由于缺少域控制器连接而失败
- CIFS客户端无法通过访问文件
- EMS日志记录secd无法连接到域控制器
[?] Tue Dec 10 22:48:16 -0600 [Node2: secd: secd.conn.auth.failure:notice]: Vserver (SVM1) could not make a connection over the network to server (ip 10.222.44.22, port 389) via interface 10.222.11.111. Error: Operation timed out (Service: LDAP (Active Directory), Operation: SiteDiscovery).[?] Wed Dec 11 00:02:21 -0600 [Node2: secd: secd.conn.auth.failure:notice]: Vserver (SVM1) could not make a connection over the network to server (ip 10.222.44.22, port 445) via interface 10.222.11.111. Error: Operation timed out ().
- 上无法连接到DNS的EMS日志
[?] Tue Dec 10 19:02:05 -0600 [Node2: secd: secd.dns.srv.lookup.failed:error]: DNS server failed to look up service (_ldap._tcp.dc._msdcs.cii_encrypt/JBUoMK2QNFgN2xPC7pUcyTx0UhbekfSoyenbCQb5y3om4BnlETKxslSls82+DxFs/cii_encrypt) for vserver (SVM1) with error (Operation timed out).
- 数据包跟踪显示、当
LIF1发送DNS查询时、未收到响应