NetApp Data ONTAP 7-Mode Activity Auditing Configuration
The Activity Monitor agent employed to monitor NetApp uses 128-bit encrypted Remote Procedure Calls (RPC), NetApp ONTAP-API, and NetApp FPolicy to monitor file system events. This includes both NetApp 7-Mode and Cluster-Mode configurations. For more information about FPolicy, visit the NetApp website and read the What FPolicy is article.
If the activity agent stops, it sends a notification to the NetApp device to disconnect and disable the associated FPolicy policy, but it doesn't remove the policy.
If the network connection between the activity agent and the NetApp device drops, the NetApp device waits for a response for a default timeout period. If the NetApp device doesn't receive a response from the Activity Agent within the timeout, it disconnects and disables the FPolicy policy. By default, the Activity Agent checks every minute to see if the FPolicy policy is disabled and re-enables it (if the auto-enable functionality is enabled for the agent). The default check interval of one minute is configurable.
The NetApp FPolicy uses a “push” mechanism, so it sends a notification to the activity agent only when a transaction occurs. The Activity Agent creates daily activity log files only when activity occurs. It doesn't create an activity log file for a day with no activity.
Configuration Checklist
Complete the following checklist before configuring activity monitoring of NetApp Data ONTAP 7-Mode devices. Instructions for each item of the checklist are detailed within the following topics.
Checklist Item 1: Plan Deployment
- Gather the following information:
- Names of the vFiler™(s) to be monitored
- DNS name of the CIFS sharess to be monitored
Checklist Item 2: Provision FPolicy Account
-
Group membership with a role granting access to the following commands:
login-http-adminapi-system-api-listapi-system-get-versionapi-cifs-share-list-iter-*api-volume-list-info-iter-* -
For Automatic FPolicy creation (Checklist Item 4), group membership with a role granting access to the following command:
api-fpolicy* -
To use the “Enable and connect FPolicy” option within the Activity Monitor, group membership with a role granting access to the following command:
cli-fpolicy* -
Group membership in:
- ONTAP Power Users
- ONTAP Backup Operators
Checklist Item 3: Firewall Configuration
- HTTP (80) or HTTPS (443)
- HTTP or HTTPS protocols need to be enabled on the NetApp filer
- TCP 135
- TCP 445
- Dynamic port range: TCP/UDP 137-139
- See the Enable HTTP or HTTPS topic for instructions.
Checklist Item 4: Configure FPolicy
-
If using vFilers:
-
FPolicy operates on the vFiler so the FPolicy must be created on the vFiler
noteActivity Monitor must target the vFiler
-
-
Select method:
infoConfigure FPolicy Manually – A tailored FPolicy
- Allow the Activity Monitor to create an FPolicy automatically
- This option is enabled when the Activity Monitor agent is configured to monitor the NetApp device on the NetApp FPolicy Configuration page of the Add New Hosts window.
- It monitors all file system activity.
- Allow the Activity Monitor to create an FPolicy automatically
Checklist Item 5: Activity Monitor Configuration
- Deploy the Activity Monitor Activity Agent to a Windows proxy server
- Configure the Activity Agent to monitor the NetApp device