跳转到主内容

如何在 ONTAP 9 中评估 NFS 导出策略?

Views:
224
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

适用于

  • ONTAP 9
  • NFS

回答

  1. 当客户端尝试访问 NFS 命名空间且没有缓存任何现有访问规则时,将评估导出策略
    • 挂载期间,在卷或 qtree 策略之前评估根卷导出策略
    • 除非是 qtree 且已启用 qtree-exports,否则将对之后的所有访问评估卷策略
  2. 收到来自 NFS 客户端的请求
  3. NBLADE 将解码文件句柄以查找适当的卷并确定适当的导出策略规则集以评估访问权限。
    • 在此期间,NBLADE 可能会引用 VLDB
  4. NBLADE 根据与 QTREE/卷导出策略关联的规则集 ID,在 AccessCache 中检查相关客户端。
  5. 如果客户端未缓存,NBLADE 将向 MGWD 发送查询以评估此客户端的导出策略
    • IP 导出规则
      • 将收到的 IP 地址与导出规则中的 IP 地址进行字符串匹配比较
      • 未使用 DNS
    • 主机名导出规则
      • MGWD 对所有主机名规则执行正向查找。
        • MGWD 将收到的 IP 与 DNS 响应进行 IP 字符串匹配评估
        • 名称服务缓存已更新
    • 子网导出规则
      • IP 地址与子网规则进行比较
      • DNS 服务未在使用中
    • 域名导出规则
      • 需要 IP 的 PTR 来确定主机名和域
      • 根据 PTR 查找中返回的域授予访问权限
    • 网络组导出规则      
      • ONTAP 将执行客户端 IP 的 PTR(反向 DNS 查找),以获取主机名以检查网络组。
      • MGWD 将检查其缓存,以确定是否存在客户端的 netgroup.byhost 缓存条目。
      • 如果没有缓存,mgwd 将利用 libc 向 NIS/ns-switch 网络组服务器发送请求。 
  6. MGWD 将按数字顺序逐一评估每个规则,直到将客户端与规则匹配为止。
    • 匹配规则后,不会对此客户端进行进一步评估。
    • 如果 MGWD 无法及时解析请求,ONTAP 将响应"jukebox"错误。  NFSv4 ERR Delay。 
      • 这表明 ONTAP 无法及时完成操作,我们将放弃此次调用。
      • 如果客户端希望执行该请求,则需要重新提交请求。
      • 客户端将在 X 时间后重新发送操作(通常为 5 秒)
        1. 这对客户端来说看起来像是挂起。
        2. MOUNT 协议对此没有错误,ONTAP 将显示为完全无响应。

追加信息

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.