Start a Conversation


This post is more than 5 years old


August 11th, 2016 06:00

Multiple groupnets using the same subnet


Could someone advise with onefs 8.x, we can setup multiple groupnets from the same network subnet ?

Our Customer intends to accommodate 2 AD domains using 2 groupnets on their isilon from the same network subnet due to fewer network resorces at DR site. As far as i tested in lab, it does't allow overlapping subnet between different groupnets. I'm wondering if this is by design and if there's a future plan for any enhancement.



iq221-1# isi network groupnet list

ID        DNS Cache Enabled  DNS Search    DNS Servers   Subnets


groupnet0 True               isidom1.local subnet0

groupnet1 True               isidom.local   subnet0


Total: 2


iq221-1# isi network subnet list

ID                Subnet         Gateway|Priority  Pools  SC Service


groupnet0.subnet0|10    pool0


groupnet1.subnet0|20        -


Total: 2



iq221-1# isi network subnets modify groupnet1.subnet0 --gateway=

Subnet 'subnet0' ( overlaps with




Thanks in advnace!!

24 Posts

August 11th, 2016 07:00

Thanks sjones, i understand isilon's subnet only can belong to single groupnet.

252 Posts

August 11th, 2016 07:00

Hi tezusky,

This is by design, and I am not aware of any plan to change this. Groupnets are designed to enable multi-tenant DNS support per access zone.

This explanation comes from the OneFS 8.0.0 Release notes on page 12:

Multi-tenant DNS support

OneFS 8.0.0 supports multiple DNS servers for each access zone so different tenants

that operate on the same Isilon cluster can use different DNS servers to perform host

name lookups. DNS servers are configured by a new network object called a

groupnet, which lives above a subnet. Each groupnet is associated with a single

access zone. The default system access zone is automatically associated with the

default groupnet. Authentication providers that communicate with an external server

must be associated with a groupnet. The DNS cache has been enhanced to maintain

separate caches for separate groupnets. You must create new access zones in order

for the groupnets to be used by protocols. The protocols that support groupnets are

SMB, NFS, HDFS, and Swift.

2 Intern


1.2K Posts

August 11th, 2016 07:00

For each AD domain there will be one access zone on the cluster

(not counting the system access zone).

From a networking standpoint, the access zones are configured at the

same level as the SmartConnect zones, namely on the address pool level.

So you would use

one groupnet

one subnet

two address pools (specific IP addresses used by Isilon nodes, not clients)

     - per pool: one SmartConnect zone, one access zone, one AD domain

Makes sense?

-- Peter

24 Posts

August 11th, 2016 07:00

Thank you, Peter. In our case, we have to consolidate CIFS servers on 2 VNX to the single isilon from two separate AD domains. There's no DNS forwarding or other equivalent feature between these AD domains, so we need to have 2 groupnets as per DNS server.
