You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Azure NetApp Files SMB, dual-protocol, and Kerberos NFSv4.1 volumes require reliable and low-latency network connectivity (less than 10ms RTT) to AD DS domain controllers. Poor network connectivity or high network latency between Azure NetApp Files and AD DS domain controllers can cause client access interruptions or client timeouts.
30
+
Azure NetApp Files SMB, dual-protocol, and Kerberos NFSv4.1 volumes require reliable and low-latency network connectivity (less than 10 ms RTT) to AD DS domain controllers. Poor network connectivity or high network latency between Azure NetApp Files and AD DS domain controllers can cause client access interruptions or client timeouts.
31
31
32
32
Ensure that you meet the following requirements about network topology and configurations:
33
33
34
34
* Ensure that a [supported network topology for Azure NetApp Files](azure-netapp-files-network-topologies.md) is used.
35
35
* Ensure that AD DS domain controllers have network connectivity from the Azure NetApp Files delegated subnet hosting the Azure NetApp Files volumes.
36
36
* Peered virtual network topologies with AD DS domain controllers must have peering configured correctly to support Azure NetApp Files to AD DS domain controller network connectivity.
37
37
* Network Security Groups (NSGs) and AD DS domain controller firewalls must have appropriately configured rules to support Azure NetApp Files connectivity to AD DS and DNS.
38
-
* Ensure that the latency is less than 10ms RTT between Azure NetApp Files and AD DS domain controllers.
38
+
* Ensure that the latency is less than 10 ms RTT between Azure NetApp Files and AD DS domain controllers.
39
39
40
40
The required network ports are as follows:
41
41
@@ -77,11 +77,11 @@ Ensure that you meet the following requirements about the DNS configurations:
77
77
78
78
### Time source requirements
79
79
80
-
Azure NetApp Files uses **time.windows.com** as the time source. Ensure that the domain controllers used by Azure NetApp Files are configured to use time.windows.com or another accurate, stable root (stratum 1) time source. If there is more than a five-minute skew between Azure NetApp Files and your client or AS DS domain controllers, authentication will fail; access to Azure NetApp Files volumes might also fail.
80
+
Azure NetApp Files uses **time.windows.com** as the time source. Ensure that the domain controllers used by Azure NetApp Files are configured to use time.windows.com or another accurate, stable root (stratum 1) time source. If there's more than a five-minute skew between Azure NetApp Files and your client or AS DS domain controllers, authentication will fail; access to Azure NetApp Files volumes might also fail.
81
81
82
82
## Decide which AD DS to use with Azure NetApp Files
83
83
84
-
Azure NetApp Files supports both Active Directory Domain Services (AD DS) and Azure Active Directory Domain Services (AAD DS) for AD connections. Before you create an AD connection, you need to decide whether to use AD DS or AAD DS.
84
+
Azure NetApp Files supports both Active Directory Domain Services (AD DS) and Azure Active Directory Domain Services (Azure AD DS) for AD connections. Before you create an AD connection, you need to decide whether to use AD DS or Azure AD DS.
85
85
86
86
For more information, see [Compare self-managed Active Directory Domain Services, Azure Active Directory, and managed Azure Active Directory Domain Services](../active-directory-domain-services/compare-identity-solutions.md).
87
87
@@ -91,7 +91,7 @@ You should use Active Directory Domain Services (AD DS) in the following scenari
91
91
92
92
* You have AD DS users hosted in an on-premises AD DS domain that need access to Azure NetApp Files resources.
93
93
* You have applications hosted partially on-premises and partially in Azure that need access to Azure NetApp Files resources.
94
-
* You don’t need AAD DS integration with an Azure AD tenant in your subscription, or AAD DS is incompatible with your technical requirements.
94
+
* You don’t need Azure AD DS integration with an Azure AD tenant in your subscription, or Azure AD DS is incompatible with your technical requirements.
95
95
96
96
> [!NOTE]
97
97
> Azure NetApp Files doesn't support the use of AD DS Read-only Domain Controllers (RODC).
@@ -100,18 +100,18 @@ If you choose to use AD DS with Azure NetApp Files, follow the guidance in [Exte
100
100
101
101
### Azure Active Directory Domain Services considerations
102
102
103
-
[Azure Active Directory Domain Services (AAD DS)](../active-directory-domain-services/overview.md) is a managed AD DS domain that is synchronized with your Azure AD tenant. The main benefits to using Azure AD DS are as follows:
103
+
[Azure Active Directory Domain Services (Azure AD DS)](../active-directory-domain-services/overview.md) is a managed AD DS domain that is synchronized with your Azure AD tenant. The main benefits to using Azure AD DS are as follows:
104
104
105
-
*AAD DS is a standalone domain. As such, there is no need to set up network connectivity between on-premises and Azure.
105
+
*Azure AD DS is a standalone domain. As such, there's no need to set up network connectivity between on-premises and Azure.
106
106
* Provides simplified deployment and management experience.
107
107
108
-
You should use AAD DS in the following scenarios:
108
+
You should use Azure AD DS in the following scenarios:
109
109
110
110
* There’s no need to extend AD DS from on-premises into Azure to provide access to Azure NetApp Files resources.
111
111
* Your security policies do not allow the extension of on-premises AD DS into Azure.
112
-
* You don’t have strong knowledge of AD DS. AAD DS can improve the likelihood of good outcomes with Azure NetApp Files.
112
+
* You don’t have strong knowledge of AD DS. Azure AD DS can improve the likelihood of good outcomes with Azure NetApp Files.
113
113
114
-
If you choose to use AAD DS with Azure NetApp Files, see [Azure AD DS documentation](../active-directory-domain-services/overview.md) for [architecture](../active-directory-domain-services/scenarios.md), deployment, and management guidance. Ensure that you also meet the Azure NetApp Files [Network](#network-requirements) and [DNS requirements](#ad-ds-requirements).
114
+
If you choose to use Azure AD DS with Azure NetApp Files, see [Azure AD DS documentation](../active-directory-domain-services/overview.md) for [architecture](../active-directory-domain-services/scenarios.md), deployment, and management guidance. Ensure that you also meet the Azure NetApp Files [Network](#network-requirements) and [DNS requirements](#ad-ds-requirements).
115
115
116
116
## Design AD DS site topology for use with Azure NetApp Files
117
117
@@ -165,7 +165,7 @@ Incorrect or incomplete AD DS site topology or configuration can result in volum
165
165
166
166
Azure NetApp Files uses the AD DS Site to discover the domain controllers and subnets assigned to the AD DS Site defined in the AD Site Name. All domain controllers assigned to the AD DS Site must have good network connectivity from the Azure virtual network interfaces used by ANF and be reachable. AD DS domain controller VMs assigned to the AD DS Site that are used by Azure NetApp Files must be excluded from cost management policies that shut down VMs.
167
167
168
-
If Azure NetApp Files is not able to reach any domain controllers assigned to the AD DS site, the domain controller discovery process will query the AD DS domain for a list of all domain controllers. The list of domain controllers returned from this query is an unordered list. As a result, Azure NetApp Files may try to use domain controllers that are not reachable or well-connected, which which can cause volume creation failures, problems with client queries, authentication failures, and failures to modify Azure NetApp Files AD connections.
168
+
If Azure NetApp Files is not able to reach any domain controllers assigned to the AD DS site, the domain controller discovery process will query the AD DS domain for a list of all domain controllers. The list of domain controllers returned from this query is an unordered list. As a result, Azure NetApp Files may try to use domain controllers that are not reachable or well-connected, which can cause volume creation failures, problems with client queries, authentication failures, and failures to modify Azure NetApp Files AD connections.
169
169
170
170
You must update the AD DS Site configuration whenever new domain controllers are deployed into a subnet assigned to the AD DS site that is used by the Azure NetApp Files AD Connection. Ensure that the DNS SRV records for the site reflect any changes to the domain controllers assigned to the AD DS Site used by Azure NetApp Files. You can check the validity of the DNS (SRV) resource record by using the `nslookup` utility.
171
171
@@ -209,7 +209,7 @@ To create the subnet object that maps to the Azure NetApp Files delegated subnet
209
209
210
210
[Azure NetApp Files cross-region replication](cross-region-replication-introduction.md) enables you to replicate Azure NetApp Files volumes from one region to another region to support business continuance and disaster recovery (BC/DR) requirements.
211
211
212
-
Azure NetApp Files SMB, dual-protocol, and NFSv4.1 Kerberos volumes support cross-region replication. Replication of these volumes requires the following:
212
+
Azure NetApp Files SMB, dual-protocol, and NFSv4.1 Kerberos volumes support cross-region replication. Replication of these volumes requires:
213
213
214
214
* A NetApp account created in both the source and destination regions.
215
215
* An Azure NetApp Files Active Directory connection in the NetApp account created in the source and destination regions.
0 commit comments