[ Applies to ] StorageGuard 9.x and later / NetApp ONTAP clusters / ONTAP REST API and ONTAPI
StorageGuard collects configuration data from NetApp ONTAP storage systems by connecting over HTTPS and running read-only ONTAP API calls. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| Cluster address | The network name or IP address of each ONTAP cluster. |
| Credentials | A user name and password for each ONTAP cluster. |
| Role and permissions | A role that can run all read-only API calls. Examples of read-only REST API calls used: GET name-services/dns, GET cluster/ntp/servers, GET security/ssh/svms, and GET private/cli/system/timeout. |
| Network access | HTTPS connectivity (port 443 by default) from the StorageGuard server to each ONTAP cluster. |
Create a scan account
The following procedure is a suggested way to create a user with read-only roles for the REST API and ONTAPI, using the ONTAP CLI. The examples use the user name cntuser; you can use any user name.
-
Make sure HTTP (REST) access is enabled:
system services web show -
Create a read-only role for the REST API:
security login role create -role cntsw_rest_ro -cmddirname "DEFAULT" -access readonly security login role create -role cntsw_rest_ro -cmddirname "security" -access readonly -
Create a read-only role for ONTAPI:
security login role create -role cntsw_zapi_ro -cmddirname "DEFAULT" -access readonly -
Assign the roles to the user:
security login create -username cntuser -application http -authmethod password -role cntsw_rest_ro security login create -username cntuser -application ontapi -authmethod password -role cntsw_zapi_ro - Repeat these steps on each ONTAP cluster that StorageGuard scans.
Note: If you use only the REST API, you can use REST roles instead of traditional roles (ONTAP 9.6 and later).
Optional: additional scanning
Tip: To extend the built-in collection with your own commands (custom collection), enable SSH access and grant the user read-only CLI permissions. You can define custom collection with either the REST API or the CLI.
Tip: StorageGuard can also scan NetApp Active IQ Unified Manager by running read-only API queries on port 443.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.