I am trying to setup monitoring on vFoglight Storage on a NetApp Filer. HTTP access has been disabled on the filer due to a security vulnerablity. Can someone tell me exactly how to setup the user on the filer with the appropriate permissions so I can begin monitoring?
Foglight Storage requires either port 80 (HTTP) or 443(HTTPS) to be open for monitoring on the Filer.
The permissions needed on the filer are:
• Allowed Capabilities: login-http-admin The above will enable DataONTAP® API.
For general access:
• Allowed Capabilities: api-*
For limited access, the following are the explicit capabilities required by vFoglight Storage:
• Allowed Capabilities:
api-system-get-version,api-system-get-info,api-system-get-ontapi-version,api-aggr-list-info,api-volume-list-info,api-volume-get-root-name,api-volume-options-list-info,api-qtree-list,api-quota-report,api-disk-list-info,api-cifs-share-list-iter-start,api-cifs-share-list-iter-next,api-cifs-share-list-iter-end,api-nfs-exportfs-list-rules,api-nfs-exportfs-list-rules-2,api-snapshot-delta-info,api-snapshot-get-reserve,api-snapshot-list-info,api-lun-map-list-info,api-lun-list-info,api-lun-get-occupied-size,api-lun-get-space-reservation-info,api-lun-get-serial-number,api-iscsi-node-get-name,api-fcp-node-get-name,api-fcp-adapter-list-info,api-portset-list-info,api-snmp-get,api-snmp-get-next,api-vfiler-list-info, perf-object-get-*
The account needs to be defined as other in the vFoglight Storage user interface.
Mike
Is vFoglight Storage set for both 80 and 443 to be monitored by default or is there a setting that must be changed in order for SSL 443 to be monitored?
DELL-Mike Mck
24 Posts
348
0
Posted January 28th, 2011 20:00
The permissions needed on the filer are:
• Allowed Capabilities: login-http-admin The above will enable DataONTAP® API.
For general access:
• Allowed Capabilities: api-*
For limited access, the following are the explicit capabilities required by vFoglight Storage:
• Allowed Capabilities:
api-system-get-version,api-system-get-info,api-system-get-ontapi-version,api-aggr-list-info,api-volume-list-info,api-volume-get-root-name,api-volume-options-list-info,api-qtree-list,api-quota-report,api-disk-list-info,api-cifs-share-list-iter-start,api-cifs-share-list-iter-next,api-cifs-share-list-iter-end,api-nfs-exportfs-list-rules,api-nfs-exportfs-list-rules-2,api-snapshot-delta-info,api-snapshot-get-reserve,api-snapshot-list-info,api-lun-map-list-info,api-lun-list-info,api-lun-get-occupied-size,api-lun-get-space-reservation-info,api-lun-get-serial-number,api-iscsi-node-get-name,api-fcp-node-get-name,api-fcp-adapter-list-info,api-portset-list-info,api-snmp-get,api-snmp-get-next,api-vfiler-list-info, perf-object-get-*
The account needs to be defined as other in the vFoglight Storage user interface.
Mike