I have a isilon ONEfs 7.1.0.0 setup with 2 Nodes. Am implementing a test SMB share access for a folder under /ifs/data/oraprod001.
I have created the share as oraprod001_share after checking the ONEfs 7.1 user guide but when am trying to access the SMB / CIFS share - am unable to access it. (Its a simple CIFS share which I want to setup without any user security and the folder should be accessed by everyone without any login credentials).
For troubleshooting, I took some snapshots (attached to this thread) of all the pages which are needed to create a SMB share.
Any help with setting up a simple SMB share (which can be accessed without any login security) is highly appreciated.
I cant map the share and even I get a access denied error. But when am accessing the VNX shares, it does fine. So there is no firewall issue. It cant be a subnet issue as well.
I followed the knowledge base from Peter and tested this on a fresh ISILON OneFS 7.0 virtual node. But all I get is a Access Denied message when I try to map the drive.
Did anyone try a simple SMB share creation on a brand new ISILON ?
Hi Taz, I noticed that you have two zones, system and another user-defined zone. But, you have no authentication source other than 'local' on your user-defined zone. Additionally, your system zone (which has local & file but nothing external) has no SMB shares defined. I suspect your user authentication - guest or otherwise - is accessing the system zone and therefore cannot see any shares.
When I use virtual Isilon in my home lab I join it to an instance of AD. No problems whatsoever with either defined users or guest access.
Peter's advice is sound - look at the log for lsassd. I suspect your access is being sent to the system zone which is set for no visibility to any shares.
Peter_Sero
6 Operator
•
1169 Posts
10029
0
Posted April 1st, 2014 02:00
Thanks Rob, of course access zones are not mentioned in the KB article ("6.5, or later").
Here is the catch, tested in 7.1 virtual nodes, no AD:
In the user-defined access zone, use "lsa-local-provider:System"
for the LOCAL provider. Looks a bit weird, but works (for me).
One would expect enabling Guest (like in the KB article)
within the user-defined access zone should do it, but no luck with that so far.
Cheers
-- Peter