UNSOLVED

marco72

updated

16 years ago

M

marco72

10 Posts

0

1640

August 9th, 2010 06:00

Virtual Datamover and NFS

Hello,

i have a celerra with 2 physical datamover configured in failover mode.

I created 2 Virtual Datamover (VDM) for 2 different CIFS environments.

I need also an NFS server for UNIX servers.

I assigned one IP address and a dns name to the first VDM, a different IP and hostname to the second VDM and another different IP and hostname to the phisical DM (server_2).

I created an NFS export.

Here the network configuration:

VDM1

dpr1 protocol=IP device=fsn0
     inet=xxx.xxx.xxx.xx3 netmask=255.255.255.0 broadcast=xxx.xxx.xxx.255
    UP, ethernet, mtu=1500, vlan=0, macaddr=0:60:16:26:a8:40

VDM2
usr1 protocol=IP device=fsn0
     inet=xxx.xxx.xxx.xx2 netmask=255.255.255.0 broadcast=xxx.xxx.xxx.255
    UP, ethernet, mtu=1500, vlan=0, macaddr=0:60:16:26:a8:40

PHYSICAL
nfs1 protocol=IP device=fsn0
     inet=xxx.xxx.xxx.xx1 netmask=255.255.255.0 broadcast=xxx.xxx.xxx.255
    UP, ethernet, mtu=1500, vlan=0, macaddr=0:60:16:26:a8:40

Here the NFS export:

export "/xythos1" root=xxxxxx.xxxxxx.georgetown.edu access=xxxxxx.xxxxxx.georgetown.edu

Security made a scan of the all NAS system and figured out that the NFS export is accessible through all the IP addresses of the NAS (xx1, xx2, xx3).

Is it possible to make the NFS exports accessible only through the IP associated with the physical DM (xx3)?

Thank you in advance

  • minksg

    2 Intern

    •

    546 Posts

    591

    0

    Posted August 9th, 2010 12:00

    Hi - I moved your question to the support forums, so you'll get the best answer. -Gina

  • dynamox

    11 Legend

    •

    20419 Posts

    •

    87439 Points

    375

    0

    Posted August 9th, 2010 13:00

    take a look at this document

    https://community.emc.com/docs/DOC-7003

  • nandas

    6 Operator

    •

    1473 Posts

    592

    0

    Posted August 9th, 2010 14:00

    I think this is a duplicate post - there is already one thread in the Celerra Support forum for this subject -

    http://community.emc.com/thread/108549?tstart=0

    Anyway - there has been few replies to both the threads. But I understand what  mz99 was asking about is something different. It's not about hiding the NFS export from any unauthorized hosts or not about configuring permission for different hosts.

    What I understand from the post, the NFS Exports are seen on the properly configured hosts - there is no issue with that, but the hosts can mount the NFS export using either of the 3 IP Addresses defined on the data mover. Although 2 IP Addresses are configured for the CIFS servers on the VDM and the third one is for NFS use, but all 3 IP Addresses are on the data mover and technically, you can use any of these 3 IP Addresses for contacting the Data mover Network Interface.

    Since, NFS v3 works with the MAC address -it does not differentiate by the IP Addresses defined on the same MAC address. All the 3 IP Addresses are on the same subnet and VLAN - so, I don't think there is anyway to configure the NFS exports not to be available on other two IP Addresses.

    However, if you want, you may configure a different VLAN for the UNIX hosts and configure the IP Addresses you planned for the NFS export to use that VLAN and the hosts and use the VLAN option with the NFS export configuration to restrict the access from the UNIX hosts limited to use only one Interface.

    By the way, I don't think this is a security concern that an authorized host can see the NFS export - by using any of the IP Addresses. Typically the hosts will use the DNS name or the IP Address for the desired Interface for NFS only - and more importantly the hosts can not see any thing else rather that the NFS export when they are using the other two IP Addresses and similarly no other hosts can see the NFS exports as well - so it should not be a security concern.

    My 2 cents

    Thanks,
    Sandip

  • marco72

    10 Posts

    592

    0

    Posted August 10th, 2010 00:00

    Thank you Sandip.

    That was exactly what i meant.

    Unfortunatly i can't use different VLAN for Unix and Windows at the moment.

    But i'm with you that this shouldn't be a scurity concern.

    Let's see if i can convice the security guys about this

    Marco

  • marco72

    10 Posts

    376

    0

    Posted August 10th, 2010 00:00

    Thank you Gina.

    I put the same discussion in two different section because i was not sure which section was correct.

    This is my first discussion

  • vijayscsa1

    26 Posts

    592

    0

    Posted August 10th, 2010 02:00

    Hi,

    sorry for posting in the wrong discussion...

    I would like to know, how can we measure the Data mover efficiency and Data mover uptime.... from Celerra...

    Can we use through commands, or need other third party tools ?

    Thanks

    regards

    VJ

  • 592

    0

    Posted August 10th, 2010 02:00

    Hi,

    We can use the command server_uptime ALL or server_uptime server_x command to see the Data mover uptime.


    can you please elobrate as to what exactly are you looking for when you say "how can we measure the Data mover efficiency "

    Thanks

    Vanitha

  • vijayscsa1

    26 Posts

    592

    0

    Posted August 10th, 2010 03:00

    Hi,

    Thanks for the inputs.

    The efficiency here refers like, ratio of Production serving data movers with the total no of data movers

    more or less, we can say as Data mover utilization....

    thank you

  • ral67_xyz

    147 Posts

    592

    0

    Posted August 10th, 2010 03:00

    Hi VJ,

    what specifically do you need ?

    you can get a lot of info through server_stats and some through SNMP.

    Rainer

    P.S.: do you know that as an EMC employee you can use the internal forum at http://celerra.emc.com ?

  • 348

    0

    Posted August 10th, 2010 03:00

    Hi Vijayakumar,


    you can use the command  server_sysstat ALL


    please let us know if this helps


    Thanks

    Vanitha