メインコンテンツへスキップ

CONTAP-84776:クラスタLIF IPに対する外部DNSの過剰なリバースルックアップ

Views:
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:

問題

  • パケットトレースには 、ノード管理LIFによって生成されたPTR要求のバーストが表示され 、 クラスタLIFのIP(11.22.33.44)を逆検索します。
    1 < node management IP >                                                 50445 <DNS IP>ドメインDNS       標準クエリ0xdf71 PTR 44.33.22.11.in-addr.arpa2 <DNS IP>ドメイン<ノード管理IP > 50445 DNS標準クエリ応答0xdf71 No such name PTR
    44.33.22.11.in-addr.arpa SOA localhost

  • DNSストームが発生すると、DNSサーバがクラスタSVMからの質問への応答を停止し、dns.server.timed.outエラー
    mgwd:dns.server.timed.out:error]: DNSサーバ111.111.111.11 did not respond to vserver=svm within  timeout interval. mgwd:dns.server.timed.out:error]: DNSサーバ111.111.111.12 did not respond to
    vserver=svan within timeout interval. 

  • 監査ログには、/api/private/cli/network/connections/activeに対するREST要求 が記録されます。REMOTE_HOSTフィールドが要求される場所は次のとおりです
    。Wed Dec 06 2023 20:00:21+09:00 [kern_audit:info:2412] xxx:admin -vserver:http:::xx.xx.xx.xx.xx:47068:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver:admin -vserver
    /api/private/cli/network/connections/active


    Wed Dec 06 2023 20:00:27+09:00 [kern_audit:info:2412] xxx::admin -vserver:http:::xx.xx.xx.xx:47068:admin -vserver:admin:
    get /api/private/cli/network/connections/active?return_records=true &fields = service、blocks_lb、lif_name、local_address、node、proto、remote_host、cid、remote_port、ru

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.