Create ONTAP LIFs
A storage virtual machine (SVM) serves data to clients through one or more logical interfaces (LIFs), which are IP addresses associated with a physical or logical port. You must create LIFs on the ports you want to use to access data. If a component fails, a LIF can fail over or migrate to a different physical port so that it continues to communicate with the network.
-
You must be a cluster administrator to perform this task.
-
The underlying physical or logical network port must be in the administrative
upstatus.
You can create both IPv4 and IPv6 LIFs on the same network port.
-
NetApp recommends creating subnet objects for all LIFs on data SVMs. This is especially important for MetroCluster configurations, where the subnet object enables ONTAP to determine failover targets on the destination cluster because each subnet object has an associated broadcast domain. If you are planning to use a subnet name to allocate the IP address and network mask value for a LIF, the subnet must already exist. For instructions, refer to Create a subnet.
-
A LIF handling intracluster traffic between nodes should not be on the same subnet as a LIF handling management traffic or a LIF handling data traffic.
-
When you create an intercluster network interface, you cannot specify an IP address that is in the range of an existing subnet.
-
Beginning with ONTAP 9.7, when you create a network interface with a subnet, ONTAP automatically selects an available IP address from the selected subnet and assigns it to the network interface. You can change the subnet if there is more than one subnet, but you cannot change the IP address.
Support for features related to LIF creation varies by ONTAP version.
| Beginning with ONTAP version | Feature |
|---|---|
9.12.1 |
Support for creating network interfaces for NFS over RDMA configurations in System Manager. |
9.11.1 |
Support for automatic iSCSI LIF failover on All-Flash SAN Array (ASA) systems. |
9.10.1 |
The |
9.7 |
If other LIFs already exist for the SVM in the same subnet, you do not need to specify the home port of the LIF. ONTAP automatically chooses a random port on the specified home node in the same broadcast domain as the other LIFs already configured in the same subnet. |
9.6 |
LIFs use service policies to specify the type of traffic they handle. Roles are used to specify traffic type in ONTAP 9.5 and earlier |
-
You cannot assign NAS and SAN protocols to the same LIF.
However, NAS and Ethernet-based SAN protocols can be present on the same physical port.
-
One LIF handling management traffic must be configured for every storage virtual machine (SVM) supporting SAN.
-
NVMe LIFs
-
The NVMe protocol must be supported by the FC adapter on which the LIF is created.
-
NVMe LIFs and namespaces must be hosted on the same node.
-
A maximum of two NVMe LIFs handling data traffic can be configured per SVM, per node.
-
A data LIF cannot be shared between NVMe and any other protocol. NVMe can be the only protocol on NVMe data LIFs.
Learn more about NVMe configuration, support and limitations.
-
-
SMB LIFs
-
Do not configure LIFs that carry SMB traffic to automatically revert to their home nodes if the SMB server hosts a solution for nondisruptive operations with Hyper-V or SQL Server over SMB.
-
Use System Manager or the CLI to create a LIF.
If you have a large number of LIFs in your cluster, you can verify the LIF capacity supported on the cluster before creating additional LIFs. Beginning with ONTAP 9.12.1, you can view the throughput on the Network Interface grid in System Manager.
-
Select Network > Overview > Network Interfaces.
-
Select
. -
Select one of the following interface roles:
-
Data
-
Intercluster
-
SVM Management
-
-
Select the protocol:
-
SMB/CIFS and NFS
-
iSCSI
-
FC
-
NVMe/FC
-
NVMe/TCP
-
-
Name the LIF or accept the name generated from your previous selections.
-
Accept the home node or use the drop-down to select one.
-
If at least one subnet is configured in the IPspace of the selected SVM, the subnet drop-down is displayed.
-
If you select a subnet, choose it from the drop-down.
-
If you proceed without a subnet, the broadcast domain drop-down is displayed:
-
Specify the IP address. If the IP address is in use, a warning message displays.
-
Specify a subnet mask.
-
-
-
Select the home port from the broadcast domain, either automatically (recommended) or by selecting one from the drop-down menu. The Home port control is displayed based on the broadcast domain or subnet selection.
-
Save the network interface.
-
Optionally, set the privilege level to advanced to view and network interface capacity.
-
Set the privilege level to advanced:
set -privilege advanced -
View the LIF capacity supported on each node:
network interface capacity details showLearn more about the
network interface capacity details showcommand ONTAP command reference.
-
-
Determine which broadcast domain ports you want to use for the LIF.
network port broadcast-domain show -ipspace _ipspace1_IPspace Broadcast Update Name Domain name MTU Port List Status Details ipspace1 default 1500 node1:e0d complete node1:e0e complete node2:e0d complete node2:e0e completeLearn more about
network port broadcast-domain showin the ONTAP command reference. -
Verify that the subnet you want to use for the LIFs contains sufficient unused IP addresses.
network subnet show -ipspace _ipspace1_Learn more about
network subnet showin the ONTAP command reference. -
Create one or more LIFs on the ports you want to use to access data.
network interface create -vserver _SVM_name_ -lif _lif_name_ -service-policy _service_policy_name_ -home-node _node_name_ -home-port port_name {-address _IP_address_ - netmask _Netmask_value_ | -subnet-name _subnet_name_} -firewall- policy _policy_ -auto-revert {true|false}-
-home-nodeis the node to which the LIF returns when thenetwork interface revertcommand is run on the LIF.You can also specify whether the LIF should automatically revert to the home-node and home-port with the -auto-revert option.
Learn more about
network interface revertin the ONTAP command reference. -
-home-portis the physical or logical port to which the LIF returns when thenetwork interface revertcommand is run on the LIF. -
You can specify an IP address with the
-addressand-netmaskoptions, or you can enable allocation from a subnet with the-subnet_nameoption. -
When using a subnet to supply the IP address and network mask, if the subnet was defined with a gateway, a default route to that gateway is added automatically to the SVM when a LIF is created using that subnet.
-
If you assign IP addresses manually (without using a subnet), you might need to configure a default route to a gateway if there are clients or domain controllers on a different IP subnet. Learn more about
network route createin the ONTAP command reference. -
-auto-revertenables you to specify whether a data LIF is automatically reverted to its home node under circumstances such as startup, changes to the status of the management database, or when the network connection is made. The default setting isfalse, but you can set it totruedepending on network management policies in your environment. -
-service-policyBeginning with ONTAP 9.5, you can assign a service policy for the LIF with the-service-policyoption.
When a service policy is specified for a LIF, the policy is used to construct a default role, failover policy, and data protocol list for the LIF. In ONTAP 9.5, service policies are supported only for intercluster and BGP peer services. In ONTAP 9.6, you can create service policies for several data and management services. -
-data-protocolenables you to create a LIF that supports the FCP or NVMe/FC protocols. This option is not required when creating an IP LIF.
-
-
Optionally, assign an IPv6 address in the -address option:
-
Use the
network ndp prefix showcommand to view the list of RA prefixes learned on various interfaces.The
network ndp prefix showcommand is available at the advanced privilege level.Learn more about
network ndp prefix showin the ONTAP command reference. -
Use the format
prefix::idto construct the IPv6 address manually.prefixis the prefix learned on various interfaces.For deriving the
id, choose a random 64-bit hexadecimal number.
-
-
Verify that the LIF interface configuration is correct.
network interface show -vserver vs1Logical Status Network Current Current Is Vserver Interface Admin/Oper Address/Mask Node Port Home --------- ---------- ---------- --------------- --------- ------- ---- vs1 lif1 up/up 10.0.0.128/24 node1 e0d trueLearn more about
network interface showin the ONTAP command reference. -
Verify that the failover group configuration is as desired.
network interface show -failover -vserver vs1Logical Home Failover Failover Vserver interface Node:Port Policy Group -------- ---------- --------- --------- -------- vs1 lif1 node1:e0d system-defined ipspace1 Failover Targets: node1:e0d, node1:e0e, node2:e0d, node2:e0e -
Verify that the configured IP address is reachable:
To verify an…
Use…
IPv4 address
network ping
IPv6 address
network ping6
ExamplesThe following command creates a LIF and specifies the IP address and network mask values using the
-addressand-netmaskparameters:network interface create -vserver vs1.example.com -lif datalif1 -service-policy default-data-files -home-node node-4 -home-port e1c -address 192.0.2.145 -netmask 255.255.255.0 -auto-revert true
The following command creates a LIF and assigns IP address and network mask values from the specified subnet (named client1_sub):
network interface create -vserver vs3.example.com -lif datalif3 -service-policy default-data-files -home-node node-3 -home-port e1c -subnet-name client1_sub - auto-revert true
The following command creates an NVMe/FC LIF and specifies the
nvme-fcdata protocol:network interface create -vserver vs1.example.com -lif datalif1 -data-protocol nvme-fc -home-node node-4 -home-port 1c -address 192.0.2.145 -netmask 255.255.255.0 -auto-revert true