data:image/s3,"s3://crabby-images/c0483/c048309c734a3eea919d9dc3f5d6c1e4704b4095" alt=""
Security has always been a concern, regardless of whether your NetApp storage array is locked in a data center or not. A good practice is to enable Active Directory Authentication and disable the local admin account.
As I continue to build out my lab, that now consists of several Intel NUCs with NetApp ONTAP Select (OTS), vCenter and a Windows Active Directory VM. Make sure to check out my previous blog posts on how I deployed the various components.
In order for you to enable Active Directory (AD) domain users to access your NetApp ONTAP cluster, you must set up an authentication tunnel through a CIFS-enabled SVM.
Before you begin
NetAPP Document CIFS Setup Requirements
- The CIFS license must be installed on your storage system.
- While configuring CIFS in the Active Directory domain, the following requirements must be met:
- DNS must be enabled and configured correctly.
- The storage system must be able to communicate with the domain controller using the fully qualified domain name (FQDN).
- The time difference (clock skew) between the cluster and the domain controller must not be more than five minutes.
- If CIFS is the only protocol configured on the storage virtual machine (SVM), the following requirements must be met:
- The root volume security style must be NTFS.
By default, NetApp System Manager sets the security style as UNIX.
- Superuser access must be set to Any for CIFS protocol.
- A user account with appropriate permissions will be required to join the domain.
Configure / Setup CIFS
- Click Setup
data:image/s3,"s3://crabby-images/31e16/31e16c4a7cc0e83e36377c74bd67b3ab29048e43" alt=""
2. Enter Details
data:image/s3,"s3://crabby-images/a1d6e/a1d6e97530cb1a39c36abca9e0d23010b875e9b7" alt=""
data:image/s3,"s3://crabby-images/7fdef/7fdeffa72c5d3713ed9b49806bab7e8d5e6099ee" alt=""
3. Click Setup
data:image/s3,"s3://crabby-images/f6534/f6534141a5077d4207f7f5f37fcb39a05106014a" alt=""
Create Active Directory Security Group
- Create an Organizational Group “HDC Admin Accounts”
- Create Subfolders for Admin, Security and Service accounts
data:image/s3,"s3://crabby-images/1075a/1075a0a73438122f644f088a0f6ed05af57b3d37" alt=""
data:image/s3,"s3://crabby-images/a13e6/a13e6e16c73eacec2455de46ba07e263f8b6f760" alt=""
3. Create Users (Administrator) to the Admin Account Subfolder
data:image/s3,"s3://crabby-images/2e28b/2e28b0e5ec1dda5e8019d8406a7390a563c61a38" alt=""
4. Create Security Group and add Users (Administrator)
data:image/s3,"s3://crabby-images/046b6/046b6cc0b941557b22d4ab4a74b12d974df57418" alt=""
How to Setup Authentication
- Create the Security Tunnel
ots100::> security login domain-tunnel create -vserver svm100
ots100::> security login domain-tunnel show
2. Allow Active Directory (AD) user or Group Access
ots100::> security login create -vserver ots100 -user-or-group-name HDC\NetAppAdmins -authmethod domain -application http
ots100::> security login create -vserver ots100 -user-or-group-name HDC\NetAppAdmins -authmethod domain -application ontapi
ots100::> security login create -vserver ots100 -user-or-group-name HDC\NetAppAdmins -authmethod domain -application ssh
3. Allow Specific Domain Users
ots100::> security login create -vserver ots100 -user-or-group-name HDC\Administrator -authmethod domain -application http
ots100::> security login create -vserver ots100 -user-or-group-name HDC\Administrator -authmethod domain -application ontapi
ots100::> security login create -vserver ots100 -user-or-group-name HDC\Administrator -authmethod domain -application ssh
NOTE:
If the authentication tunnel or SVM is deleted, subsequent login sessions cannot be authenticated, and Active Directory domain users cannot access the cluster.
data:image/s3,"s3://crabby-images/f3547/f3547105a0df3877e1e3705820c2215ecf6ed147" alt=""
data:image/s3,"s3://crabby-images/f674f/f674fb9e22d73ce802140a51c18c0f8b688bfa62" alt=""