Skip to main content

Create ONTAP LIFs

Contributors netapp-aherbin netapp-aoife netapp-aaron-holt netapp-barbe netapp-thomi netapp-dbagwell netapp-lisa

A storage virtual machine (SVM) serves data to clients through one or more logical interfaces (LIFs), which are IP addresses associated with a physical or logical port. You must create LIFs on the ports you want to use to access data. If a component fails, a LIF can fail over or migrate to a different physical port so that it continues to communicate with the network.

Before you begin
  • You must be a cluster administrator to perform this task.

  • The underlying physical or logical network port must be in the administrative up status.

About this task

You can create both IPv4 and IPv6 LIFs on the same network port.

Creating LIFS with subnets
  • NetApp recommends creating subnet objects for all LIFs on data SVMs. This is especially important for MetroCluster configurations, where the subnet object enables ONTAP to determine failover targets on the destination cluster because each subnet object has an associated broadcast domain. If you are planning to use a subnet name to allocate the IP address and network mask value for a LIF, the subnet must already exist. For instructions, refer to Create a subnet.

  • A LIF handling intracluster traffic between nodes should not be on the same subnet as a LIF handling management traffic or a LIF handling data traffic.

  • When you create an intercluster network interface, you cannot specify an IP address that is in the range of an existing subnet.

  • Beginning with ONTAP 9.7, when you create a network interface with a subnet, ONTAP automatically selects an available IP address from the selected subnet and assigns it to the network interface. You can change the subnet if there is more than one subnet, but you cannot change the IP address.

LIF creation feature support by ONTAP version

Support for features related to LIF creation varies by ONTAP version.

Beginning with ONTAP version Feature

9.12.1

Support for creating network interfaces for NFS over RDMA configurations in System Manager.

For more information, see Configure LIFS for NFS over RDMA.

9.11.1

Support for automatic iSCSI LIF failover on All-Flash SAN Array (ASA) systems.

For a new iSCSI LIF, failover is automatically enabled with the sfo-partner-only policy and auto-revert set to true if the SVM has no existing iSCSI LIFs or if failover is enabled on all existing iSCSI LIFs.

After upgrading to ONTAP 9.11.1 or later, a new iSCSI LIF inherits the disabled failover policy if failover is not enabled on the existing iSCSI LIFs in the same SVM.

Learn more about iSCSI LIF failover for ASA platforms

9.10.1

The network interface commands include an -rdma-protocols parameter for NFS over RDMA configurations

9.7

If other LIFs already exist for the SVM in the same subnet, you do not need to specify the home port of the LIF. ONTAP automatically chooses a random port on the specified home node in the same broadcast domain as the other LIFs already configured in the same subnet.

9.6

LIFs use service policies to specify the type of traffic they handle. Roles are used to specify traffic type in ONTAP 9.5 and earlier

LIF creation restrictions
  • You cannot assign NAS and SAN protocols to the same LIF.

    However, NAS and Ethernet-based SAN protocols can be present on the same physical port.

  • One LIF handling management traffic must be configured for every storage virtual machine (SVM) supporting SAN.

  • NVMe LIFs

    • The NVMe protocol must be supported by the FC adapter on which the LIF is created.

    • NVMe LIFs and namespaces must be hosted on the same node.

    • A maximum of two NVMe LIFs handling data traffic can be configured per SVM, per node.

    • A data LIF cannot be shared between NVMe and any other protocol. NVMe can be the only protocol on NVMe data LIFs.

  • SMB LIFs

    • Do not configure LIFs that carry SMB traffic to automatically revert to their home nodes if the SMB server hosts a solution for nondisruptive operations with Hyper-V or SQL Server over SMB.

Steps

Use System Manager or the CLI to create a LIF.

System Manager
Before you begin

If you have a large number of LIFs in your cluster, you can verify the LIF capacity supported on the cluster before creating additional LIFs. Beginning with ONTAP 9.12.1, you can view the throughput on the Network Interface grid in System Manager.

  1. Select Network > Overview > Network Interfaces.

  2. Select Add icon.

  3. Select one of the following interface roles:

    1. Data

    2. Intercluster

    3. SVM Management

  4. Select the protocol:

    1. SMB/CIFS and NFS

    2. iSCSI

    3. FC

    4. NVMe/FC

    5. NVMe/TCP

  5. Name the LIF or accept the name generated from your previous selections.

  6. Accept the home node or use the drop-down to select one.

  7. If at least one subnet is configured in the IPspace of the selected SVM, the subnet drop-down is displayed.

    1. If you select a subnet, choose it from the drop-down.

    2. If you proceed without a subnet, the broadcast domain drop-down is displayed:

      1. Specify the IP address. If the IP address is in use, a warning message displays.

      2. Specify a subnet mask.

  8. Select the home port from the broadcast domain, either automatically (recommended) or by selecting one from the drop-down menu. The Home port control is displayed based on the broadcast domain or subnet selection.

  9. Save the network interface.

CLI
  1. Optionally, set the privilege level to advanced to view and network interface capacity.

    1. Set the privilege level to advanced:

      set -privilege advanced
    2. View the LIF capacity supported on each node:

      network interface capacity details show

      Learn more about the network interface capacity details show command ONTAP command reference.

  2. Determine which broadcast domain ports you want to use for the LIF.

    network port broadcast-domain show -ipspace _ipspace1_
    IPspace     Broadcast                       Update
    Name        Domain name   MTU   Port List   Status Details
    ipspace1
                default       1500
                                    node1:e0d   complete
                                    node1:e0e   complete
                                    node2:e0d   complete
                                    node2:e0e   complete

    Learn more about network port broadcast-domain show in the ONTAP command reference.

  3. Verify that the subnet you want to use for the LIFs contains sufficient unused IP addresses.

    network subnet show -ipspace _ipspace1_

    Learn more about network subnet show in the ONTAP command reference.

  4. Create one or more LIFs on the ports you want to use to access data.

    network interface create -vserver _SVM_name_ -lif _lif_name_ -service-policy _service_policy_name_ -home-node _node_name_ -home-port port_name {-address _IP_address_ - netmask _Netmask_value_ | -subnet-name _subnet_name_} -firewall- policy _policy_ -auto-revert {true|false}
    • -home-node is the node to which the LIF returns when the network interface revert command is run on the LIF.

      You can also specify whether the LIF should automatically revert to the home-node and home-port with the -auto-revert option.

      Learn more about network interface revert in the ONTAP command reference.

    • -home-port is the physical or logical port to which the LIF returns when the network interface revert command is run on the LIF.

    • You can specify an IP address with the -address and -netmask options, or you can enable allocation from a subnet with the -subnet_name option.

    • When using a subnet to supply the IP address and network mask, if the subnet was defined with a gateway, a default route to that gateway is added automatically to the SVM when a LIF is created using that subnet.

    • If you assign IP addresses manually (without using a subnet), you might need to configure a default route to a gateway if there are clients or domain controllers on a different IP subnet. Learn more about network route create in the ONTAP command reference.

    • -auto-revert enables you to specify whether a data LIF is automatically reverted to its home node under circumstances such as startup, changes to the status of the management database, or when the network connection is made. The default setting is false, but you can set it to true depending on network management policies in your environment.

    • -service-policy Beginning with ONTAP 9.5, you can assign a service policy for the LIF with the -service-policy option.
      When a service policy is specified for a LIF, the policy is used to construct a default role, failover policy, and data protocol list for the LIF. In ONTAP 9.5, service policies are supported only for intercluster and BGP peer services. In ONTAP 9.6, you can create service policies for several data and management services.

    • -data-protocol enables you to create a LIF that supports the FCP or NVMe/FC protocols. This option is not required when creating an IP LIF.

  5. Optionally, assign an IPv6 address in the -address option:

    1. Use the network ndp prefix show command to view the list of RA prefixes learned on various interfaces.

      The network ndp prefix show command is available at the advanced privilege level.

      Learn more about network ndp prefix show in the ONTAP command reference.

    2. Use the format prefix::id to construct the IPv6 address manually.

      prefix is the prefix learned on various interfaces.

      For deriving the id, choose a random 64-bit hexadecimal number.

  6. Verify that the LIF interface configuration is correct.

    network interface show -vserver vs1

              Logical    Status     Network         Current   Current Is
    Vserver   Interface  Admin/Oper Address/Mask    Node      Port    Home
    --------- ---------- ---------- --------------- --------- ------- ----
    vs1
               lif1       up/up      10.0.0.128/24   node1     e0d     true

    Learn more about network interface show in the ONTAP command reference.

  7. Verify that the failover group configuration is as desired.

    network interface show -failover -vserver vs1

             Logical    Home       Failover        Failover
    Vserver  interface  Node:Port  Policy          Group
    -------- ---------- ---------  ---------       --------
    vs1
             lif1       node1:e0d  system-defined  ipspace1
    Failover Targets: node1:e0d, node1:e0e, node2:e0d, node2:e0e
  8. Verify that the configured IP address is reachable:

    To verify an…​

    Use…​

    IPv4 address

    network ping

    IPv6 address

    network ping6

    Examples

    The following command creates a LIF and specifies the IP address and network mask values using the -address and -netmask parameters:

    network interface create -vserver vs1.example.com -lif datalif1 -service-policy default-data-files -home-node node-4 -home-port e1c -address 192.0.2.145 -netmask 255.255.255.0 -auto-revert true

    The following command creates a LIF and assigns IP address and network mask values from the specified subnet (named client1_sub):

    network interface create -vserver vs3.example.com -lif datalif3 -service-policy default-data-files -home-node node-3 -home-port e1c -subnet-name client1_sub - auto-revert true

    The following command creates an NVMe/FC LIF and specifies the nvme-fc data protocol:

    network interface create -vserver vs1.example.com -lif datalif1 -data-protocol nvme-fc -home-node node-4 -home-port 1c -address 192.0.2.145 -netmask 255.255.255.0 -auto-revert true