Additional administration for an AFX storage system cluster
In addition to the typical AFX cluster administration, there may be other tasks you need to perform based on your environment. Most of the additional tasks can be performed using System Manager, although in some cases you may need to use the CLI.
|
|
The ONTAP features and administration described are common to AFX storage systems and AFF or FAS systems running Unified ONTAP. Links to the relevant Unified ONTAP documentation are included as appropriate. |
Licensing
AFX systems are licensed in a similar way as Unified ONTAP AFF and FAS systems. An AFX cluster includes most features by default for the protocols supported.
ONTAP license management
An ONTAP license is a record of one or more software entitlements. All licenses are defined and provided using a NetApp license file (NLF). Refer to ONTAP licensing overview for more information.
Install a license on an AFX system
You can install license files to activate additional features as needed for your AFX storage system.
-
In System Manager, select Cluster and then Settings.
-
Next to Licenses, select
. -
Select the Features tab to display the available ONTAP features.
-
To optionally install a licenses, select the Installed licenses tab.
-
Select
. -
Select a local license file and select Add.
Performance
Use common ONTAP features to optimize the performance of your AFX storage system cluster.
Modify default settings that control automatic QoS throughput ceiling increases
Adaptive and non-adaptive QoS policy groups are automatically enabled to temporarily increase a workload’s throughput ceiling by 50% for a duration of 1 second to respond to short-term demands for higher performance by default. Beginning with ONTAP 9.19.1, you can modify these default settings. In ONTAP 9.18.1 and earlier, these settings cannot be changed.
Refer to QoS throughput ceilings.
IPspace TCP performance
Beginning with ONTAP 9.19.1, ONTAP improves TCP data transfer performance over lossy, high-latency WAN links by integrating two loss-recovery features, PRR and RACK, into the ONTAP TCP stack. PRR is suitable for all networks and is enabled by default. RACK is suitable for congested networks with link speeds of approximately 25 Gigabits/second and is disabled by default.
Refer to Improve TCP WAN performance with PRR and RACK for more information.
Security
There are several optional security features you can configure and use with your AFX deployment.
ONTAP security and data encryption
It's important to protect the security and priacy of your AFX storage system. Refer to Security and data encryption
ONTAP authentication and access control
The AFX storage system provides several options for configuring authentication and access control services. Refer to Authentication and access control for more information.
ONTAP TLS hardware offload
You can offload Transport Layer Security (TLS) encryption and decryption for your entire cluster to supported Ethernet cards. This reduces CPU overhead and improves performance for systems using TLS. Refer to Configure ONTAP TLS hardware offload for more information.
Administer OAuth 2.0 on an AFX system
OAuth 2.0 is the industry standard authorization framework used to restrict and control access to protected resources using signed access tokens.
-
In System Manager, select Cluster and then Settings.
-
In the Security section, next to OAuth 2.0 authorization, select
. -
Enable OAuth 2.0
-
Select Add configuration and provide the configuration details.
-
Select Save.
Data protection
You should be aware of the following ONTAP data protection features and how they relate to the AFX storage system.
Load-share mirrors
With ONTAP, a load-sharing mirror (LSM) is a SnapMirror replica of a storage VM (SVM) root volume which serves as the entry point to the SVM's NAS namespace. By maintaining one or more read-only copies of the root volume on other nodes, load-sharing mirrors help keep the NAS namespace accessible to clients even if both nodes of an HA pair become unavailable.
The AFX storage system does not support load-sharing mirrors. You cannot create, initialize, or update a load-sharing mirror relationship on AFX. To achieve namespace resiliency, data distribution, or read scaling on AFX, use FlexCache volumes or SnapMirror replication instead. These features provide equivalent or greater capability for keeping data and namespaces available to clients, and they are fully supported on AFX.