OneFS 8.2: Error 403: Accessing OneFS web administration interface using SmartConnect service
Summary: Cannot access WebUI to nodes using SmartConnect Service IPs with OneFS 8.2. How to monitor and manage your Isilon cluster from the browser-based web administration interface.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Prior to OneFS 8.2 Clients could access cluster Management using WebUI or SSH using the SmartConnect Service IP (SSIP/VIP/SIP).
However, there were unexpected behavior noticed when using the SSIP. And so, it is not advisable to use the SSIP for Management.
In OneFS 8.2, the SSIP was moved from a SYSTEM_ZONE to a DISABLED_ZONE. This change no longer allows authentication through the SSIP when in the DISABLED_ZONE. Access to the Cluster Management using WebUI or SSH and the SSIP will not work due to disable authentication.
The 403 Forbidden error is an HTTP status code that means that accessing the page or resource trying to reach is forbidden.
Unable to access Isilon Cluster management using WebUI using the SmartConnect Service IP (SSIP/VIP/SIP)
It fails with the below error:
However, there were unexpected behavior noticed when using the SSIP. And so, it is not advisable to use the SSIP for Management.
In OneFS 8.2, the SSIP was moved from a SYSTEM_ZONE to a DISABLED_ZONE. This change no longer allows authentication through the SSIP when in the DISABLED_ZONE. Access to the Cluster Management using WebUI or SSH and the SSIP will not work due to disable authentication.
The 403 Forbidden error is an HTTP status code that means that accessing the page or resource trying to reach is forbidden.
Unable to access Isilon Cluster management using WebUI using the SmartConnect Service IP (SSIP/VIP/SIP)
It fails with the below error:
403: Forbidden Accessing OneFS web administration interface over a configured SmartConnect service IP address is forbidden.
Cause
Prior to 8.2 the SSIP belongs to the System access zone, which is Zone 1. However, in 8.2 it is no longer in the System access zone and is part Zone 0. Hence the access to WebUI and SSH has been forbidden.
The SSIP should only be used for SmartConnect Load balancing. It should not be used to access the Cluster Management using SSH or WebUI. Also, it should not be used by clients to access Data on the Cluster.
The SSIP should only be used for SmartConnect Load balancing. It should not be used to access the Cluster Management using SSH or WebUI. Also, it should not be used by clients to access Data on the Cluster.
Resolution
Do not use SSIP for Cluster Management using WebUI or SSH or Client Data Access.
Use IPs from a System Access Zone network pool to Access the Cluster Via WebUI or SSH. To monitor and manage your Isilon cluster from the browser-based web administration interface:
Use IPs from a System Access Zone network pool to Access the Cluster Via WebUI or SSH. To monitor and manage your Isilon cluster from the browser-based web administration interface:
- Open a browser window and type the URL for your cluster in the address field, replacing <YourNodeIPAddress> with the IP address provided when ext-1 was configured in one of the following examples:
IPv4: https://<YourNodeIPAddress>:8080
IPv6: https://[YourNodeIPAddress]:8080
IPv6: https://[YourNodeIPAddress]:8080
The system displays a message if your security certificates have not been configured. Resolve any certificate configurations and continue to the website.
- Log in to OneFS by typing your OneFS credentials in the Username and Password fields.
After logging into the web administration interface, there is a 4-hour login timeout.
Additional Information
For additional information, see Isilon OneFS Version 8.2.0 Web Administration Guide. Page 31 has a chapter on "Connecting to the cluster."
Affected Products
IsilonProducts
Isilon, PowerScale OneFSArticle Properties
Article Number: 000078817
Article Type: Solution
Last Modified: 10 Oct 2024
Version: 4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.