Software Releases
Release 2.5.6 - Release Notes DR Edition
Home






What’s New in Superna Eyeglass PowerScale Edition Release 2.5.6

What’s New! In Superna Eyeglass PowerScale Edition Release 2.5.6 for DR can be found .




Supported OneFS releases

8.0.0.x

8.0.1.x

8.1.x.x

8.1.2.x

8.1.3.x

8.2.0.x

8.2.1.x

8.2.2.x

9.0 ** as of 2.5.6-20258

9.1 ** as of 2.5.6-20258


DR Edition Feature Release Compatibility


Feature

Source Cluster  Release

Target SyncIQ Cluster Release

Configuration Replication

non-DFS mode



Configuration Replication

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**

Configuration Replication

8.1.x.x

8.1.x.x***

8.2.x.x**

8.0.x.x**

Configuration Replication
8.2.x.x

8.2.x.x**

8.1.x.x**

Configuration Replication   

9.0          9.0
Configuration Replication
9.1          9.1

Configuration Replication

DFS mode



Configuration Replication - DFS Mode

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**

Configuration Replication - DFS Mode

8.1.x.x

8.1.x.x***

8.0.x.x**

8.2.x.x**

Configuration Replication - DFS Mode
8.2.x.x
8.2.x.x

8.1.x.x**

Configuration Replication - DFS Mode
9.0          9.0
Configuration Replication - DFS Mode
9.1          9.1

SyncIQ Policy Failover

non-DFS mode



SyncIQ Policy Failover

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**


SyncIQ Policy Failover

8.1.x.x

8.1.x.x***

8.0.x.x**

8.2.x.x**

SyncIQ Policy Failover
8.2.x.x
8.2.x.x

8.1.x.x**

8.0.x.x**

         SyncIQ Policy Failover          9.0           9.0
         SyncIQ Policy Failover          9.1           9.1

SyncIQ Policy Failover

DFS mode



SyncIQ Policy Failover - DFS mode

8.0.x.x

8.0.x.x

8.2.x.x**


SyncIQ Policy Failover - DFS mode

8.1.x.x

8.1.x.x***

SyncIQ Policy Failover - DFS mode
8.2.x.x
8.2.x.x

8.1.x.x**

8.0.x.x**

SyncIQ Policy Failover - DFS mode
9.0          9.0
SyncIQ Policy Failover - DFS mode
9.1          9.1

Access Zone Failover



Access Zone Failover

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**


Access Zone Failover

8.1.x.x

8.1.x.x***

8.0.x.x**

8.2.x.x**

Access Zone Failover
8.2.x.x
8.2.x.x

8.1.x.x**

8.0.x.x**

        Access Zone Failover 9.0           9.0
        Access Zone Failover 9.1           9.1

Runbook Robot cluster pairs

SyncIQ Policy Failover



SyncIQ Policy Failover

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**


SyncIQ Policy Failover

8.1.x.x

8.1.x.x***

8.0.x.x**

8.2.x.x**

SyncIQ Policy Failover
8.2.x.x
8.2.x.x

8.1.x.x**

8.0.x.x**

SyncIQ Policy Failover 9.0          9.0
SyncIQ Policy Failover 9.1          9.1

Runbook Robot* cluster pairs

Access Zone Failover



Access Zone Failover

8.0.x.x

8.0.x.x

8.1.x.x**

8.2.x.x**


Access Zone Failover

8.1.x.x

8.1.x.x***

8.0.x.x**

8.2.x.x**

Access Zone Failover
8.2.x.x
8.2.x.x

8.1.x.x**

8.0.x.x**

Access Zone Failover 9.0          9.0
Access Zone Failover 9.1          9.1

Live Ops - DR Test Mode



Live Ops DR Test Mode

8.1.x.x

8.1.x.x***

Live Ops DR Test Mode
8.2.x.x
8.2.x.x
Live Ops DR Test Mode
    9.0.x.x         9.0.x.x
Live Ops DR Test Mode
    9.1.x.x         9.1.x.x

Snapshots and Schedules

8.0.x.x

8.0.x.x

Snapshots and Schedules

8.1.x.x

8.1.x.x***

Snapshots and Schedules
8.2.x.x
8.2.x.x - pending testing

8.1.x.x - pending testing

Dedupe Path Settings

8.0.x.x

8.0.x.x

Dedupe Path Settings

8.1.x.x

8.1.x.x**

Dedupe Path Settings
8.2.x.x
8.2.x.x - pending testing

8.1.x.x - pending testing


** Inter-version capabilities: In the case of inter-version operation, the capabilities of the lower OneFS API version will be applied across both OneFS versions.  Capabilities of the higher OneFS version that are not present in the lower OneFS version will not be available.


***Due to PowerScale OneFS PAPI API defect, the following configuration change must be made on the Eyeglass appliance to support OneFS releases lower than these releases.

  • Not Required on lower releases than below but note the bug is present and does not affect Eyeglass

    • OneFS 8.0.0.6 (Fixed)

    • OneFS 8.0.1.3 (Fixed)

  • Requires Change below on lower Releases

    • OneFS 8.1.0.2 (Fixed does not require change below)

    • OneFS 8.1.1.1 (Fixed does not require change below)

ssh to the Eyeglass appliance

  1. Elevate to root user by using command below and entering admin password

sudo su -

  1. cd /opt/superna/sca/data

  2. edit system.xml

  3. Find the line

<runconfigsyncinparallel>true</runconfigsyncinparallel>

  1. And modify to false

<runconfigsyncinparallel>false</runconfigsyncinparallel>

  1. Save your changes

  2. Restart the sca service

systemctl restart sca

  1. Done




Feature Support Matrix


Description

Supported

Overlapping Access Zone with System (/ifs)


Configuration Replication (non DFS mode)

Yes - Create / Update

No -  Delete

Configuration Replication (DFS mode)

Yes - Create / Update

No - Delete

SyncIQ Failover

Yes

SyncIQ Failover - DFS Mode

Yes

Access Zone Failover

No

Overlapping Access Zone - non System Zones


Configuration Replication (non DFS mode)

Yes - shares / export / alias

No - Access Zone

Configuration Replication (DFS mode)

Yes

No - Access Zone

SyncIQ Failover

Yes

SyncIQ Failover - DFS Mode

Yes

Access Zone Failover

No

Runbook  Robot Access Zone Multi cluster

No (only cluster pairs with no common cluster)

Failover with SyncIQ Encryption (Access Zone, SyncIQ, DFS, IP pool failover modes) Yes (8.2 or later only)


End of Life Notifications

End of Life Notifications for all products are available .



Support Removed in Eyeglass Release 2.5.6

Support for following OneFS releases has been removed in Release 2.5.6:

7.1.1.x

7.2.x.x

7.2.1.x


Deprecation Notices 

Following features will no longer be supported as indicated below:
  1. As of Release 2.5.7
    1. OpenSUSE 42.3 operating system: Upgrade on OpenSUSE 42.3 operating system will no longer be supported. Use Backup & Restore to the latest OVF to be on a supported release.
    2. Custom Jobs: Eyeglass custom jobs for configuration replication will no longer be supported. 
    3. Configuration of SYSLOG forwarding from /var/log/messages.  The new alarm architecture in 2.5.7 will use a dedicated log that will roll over and provide alarm history external from the database and alarm history in the GUI.


  1. As of Release 2.5.6
    1. Quota Request Management Icons:  Affects User Storage icon, Quota Request Management workflow, Cluster Storage Usage Icon quotas tab are unsupported as of 2.5.6.  The Icons will be removed from the GUI in the next update release.    Recommended solution for user managed quota is through AD Managed quota solution documented here.
      1. Release 2.5.6 update 2
        1. The cluster usage icon has  a quota share export tab that will be removed. 
        2. The Quota Request Management Icon will remove the requests, history and auto tabs along with request column.  This Icon's search features and bulk apply of quotas will be retained and enhanced in later releases. 
        3. The share export report CSV will be removed along with the AD group and user CSV report.
        4. The User role for User Storage will be removed from the RBAC roles list.
        5. Replacement Report:  The master CSV report contains all quotas and all information that was provided in the other two CSV reports is already available in the quota CSV report.
    2. Data Recovery Management Icons:  Part of cluster storage monitor are removed.
    3. Web widgets: Embeddable Widgets functionality will no longer be available.  Eyeglass API now can be used to retrieve DR readiness information - please refer to documentation here.

Issues Fixed in Eyeglass Release 2.5.6

Enhancements and Fixes in 2.5.6-20263

Refer to Enhancements and Fixes in 2.5.6-20258

Enhancements and Fixes in 2.5.6-20258

OneFS Version Support

New: T17099 OneFS 9.1 Support

As of 2.5.6-20258 build OneFS 9.1 is supported.

—————————————————

Configuration Replication

T15639 Error replicating AD Group Run as Root SMB Share permissions

In some cases an SMB Share permission that is configured with an AD group that has Run as Root privileges results in errors when replication the share to the target cluster due to duplication of the permissions. This may result in an AEC Duplicate Permission error from the PowerScale cluster or no error until duplicate permissions exceeds allowed space and an AEC Message Too Long error occurs.

Resolution: Permissions no longer duplicated for AD Group Run as Root SMB Share permissions.

—————————————————

Failover

New: T16448 Zone/Pool Readiness DNS Dual Delegation Validation SSIP reachability check removed

The Zone/Pool Readiness DNS Dual Delegation Validation no longer checks for PowerScale SSIP reachability from Eyeglass as the reachability of SSIP from Eyeglass is not related to client access to PowerScale.

—————————————————

New: T16455 Zone/Pool Readiness AD SPN Delegation Validation Configurable Delay between create and delete test

The time between the create and delete steps for the AD SPN Delegation Validation is now configurable. If AD domain controllers do not execute the create and delete fast enough this can fail the validation test. Default is no delay. This delay is not applied to SPN steps during failover. Related documentation is available here.

—————————————————

New: T16564 Zone/Pool Readiness AD SPN Delegation Validation Retry

AD SPN Validation steps will not be retried for 20 s (default) until they succeed or fail. Retry interval is configurable. Contact support.superna.net for assistance.

—————————————————

New: T16597 New settings for DNS Dual Delegation

These settings allow control over DNS query servers and recursion options required for some environments:

1. If Eyeglass has no access to reach the groupnet DNS due to firewall option is provided to use local Eyeglass DNS.

2. If DNS is Bluecat, Bind or Infoblox recommendation is to use option provided to disable recursive lookup.

Related documentation is here.

—————————————————

New: T16747 Zone/Pool Readiness AD SPN Delegation Validation Logging Enhancement

Additional logging provided for AD SPN Delegation Validation.

—————————————————

New: T16949 DR Rehearsal Mode available for OneFS 9.0, 9.1

DR Rehearsal Mode is now available for OneFS 9.0 and OneFS 9.1 clusters.

—————————————————

T15111 DR Rehearsal Enable incorrectly results in REHEARSAL_ERROR status when failover includes AUTOSKIPCONFIG type jobs

When you enable DR Rehearsal mode and it includes an Eyeglass job that is of AUTOSKIPCONFIG type the end result status will incorrectly be REHEARSAL_ERROR for local target and corrupt failover snapshots for those policies.

This has no impact to the failover itself, steps to enable rehearsal mode complete successfully and no impact to dr test.

The Rehearsal_Error does block the revert for rehearsal mode.

Resolution: DR Rehearsal Mode is now available where Eyeglass job is of AUTOSKIPCONFIG for rehearsal enable and rehearsal revert.

————————————

T15249 Post Failover script runs even if failover fails

If a post failover script is configured, it will run once the failover finishes even if the failover has failed.

Resolution: Post failover scripting now has additional variables available to indicate whether or not a failover has run and its status. These can be used in scripting to determine whether steps in a script should run in the case of a failure of the failover.

————————————

T15628 Zone/Pool Readiness in DR Dashboard not updated when source cluster is unreachable

If Zone/Pool Readiness job runs when source cluster is unreachable the Readiness job does not complete (shows as ERROR status in Jobs window) and the Zone/Pool DR Failover Status is not updated in the DR Dashboard. The DR Dashboard shows the results from the previous successful execution of the Readiness Job.

Resolution: Zone/Pool Readiness job now completes successfully when the source cluster is unreachable and shows the correct time that job was run and DR Status in the DR Dashboard.

————————————

T15830, T17232 OneFS 9.0 Known Limitations with Eyeglass

OneFS 9.0 has following limitations with Eyeglass:

1) Access Zone Readiness Validation

  • DNS Dual Delegation readiness validation does not work and should be disabled and verified manually.
  • AD SPN Delegation readiness validation does not work and should be disabled and verified manually.

2) IP Pool Failover not supported for OneFS 9.0

Resolution:

1) Access Zone Readinses validations for DNS Dual Delegation and AD SPN Delegation are not available for OneFS 9.0 and 9.1.

2) IP Pool failover is now available for OneFS 9.0 and 9.1

————————————

Features

New: Unlock My Files Enhancements

1. Unlock My Files now executed on selected cluster.

2. Partial results will be shown when search times out. GUI will indicate this with message "Result list is truncated - please use a more restrictive search term!".

3. Audit of unlock command will be completed after breaking lock to confirm state of lock.

4. Maximum results limit is now applied per Access Zone instead of per cluster.

————————————

New: Quota Search

Cluster Storage Monitor User Storage and Quota Requests Management have been deprecated and replaced with Quota Search window. Quota Search window continues to have Quota Search and bulk Quota Modify capabilities. Quota workflow features have been removed.

————————————

T11882/T14354 Storage Monitor Report - UserGroupQuotasReport is empty

The UserGroupQuotasReport which reports on quotas created by the Superna Eyeglass Quota Automation is generated with no content.

Resolution: UserGroupQuotas and ShareExportUsage reports have been deprecated. The Quota Summary report should be used and contains all quotas and user/group information for user/group quotas.

—————————————————

T9621, T14813:  Unable to break lock for filenames/path with special characters

When a filename/path contains special characters, Unlock My Files is unable to break the lock. Message displayed says "No open session...."

Resolution: Able to break lock now for filenames/path with special characters.

—————————————————

 T16555 Unlock My Files incorrectly reports Error when unlocking file

In some cases the Unlock My Files will successfully unlock a file but the GUI presents the message "Error unlocking file!".

Resolution: Audit feature to verify that lock has been broken.

—————————————————


General

New: RBAC 2.0

Role Based Access Control now validates AD groups and users when saving the role and blocks save if cannot be resolved. Upon resolution the user or group SID is saved in the configuration. This will ensure that the login process can easily match the user.

1. Adding user s or groups with any case is now supported.

2. Adding group with syntax group@domain is now supported.

Note:

  • PowerScale local users not supported going forward (Eyeglass local users are supported)
  • AD groups with @ & or ' in the name is not supported
  • T17408 AD user with language specific characters or special characters such as ',.{}() is not supported

—————————————————

T15280 Web widgets: Embeddable Widgets functionality Deprecated

Embeddable widgets functionality is no longer be available.  Eyeglass API now can be used to retrieve DR readiness information - please refer to documentation .

—————————————————

 T16683 Phone Home Dedicated Log

Phone home logging can now be found in the dedicated log /opt/superna/sca/logs/phonehome.log .

—————————————————

T16955 ssh command issued as part of daily Eyeglass backup

Unnecessary ssh commands for open files, network information and array status issued when creating daily Eyeglass backup.

Resolution: ssh commands no longer issued when backup is created.

—————————————————


Enhancements and Fixes in 2.5.6-20158

Failover

New: T15063 Failover Readiness Date-Time Validation has increased tolerance for time skew between Isilon nodes

By default a 1 second time skew tolerance between Isilon nodes is now taken into account when executing the Date-Time Validation for failover readiness. Contact support.superna.net if you continue to get a warning with the default time skew tolerance setting.

Features

T16496 Config Only Migration deletes existing objects in the Destination Access Zone

A config only migration job to a Destination Access Zone with existing shares and nfs exports, will delete any shares or exports in the Destination Access Zone which fall at or under the Migration Path of the migration job such that at the end of the migration job shares and exports on source and destination are an exact match. For example if your source and destination path is /ifs/data/Zone1 and on source you have nfs export /ifs/data/Zone1/project1 but on Destination Access Zone you have other share or exports with path /ifs/data/Zone1 or subfolders thereof, after the config migration job runs the destionation access zone will only have the nfs export /ifs/data/Zone1/project1 such that source and destination are an exact match.

Resolution: Config Only Migration job now only creates/updates/deletes based on the source access zone. Any shares or exports that are unrelated (extra) on the target access zone are not affected.

—————————————————

T16370 DR Runbook Robot create export / mount steps disabled by default

Note: To be replaced with SMB data access testing feature in future release


General

T16340 Customization of alarm settings for SCA0080 and SCA0081 result in "Invalid alarm code" error

Using the isi alarm settings set command to customize settings for SCA0080 or SCA0081 alarms results in "Invalid alarm code" error.

Resolution: Settings for SCA0080 or SCA0081 can now be set using the isi alarm settings set command.

—————————————————–

T16372 Disk Space Management for OpenSUSE 42.3

Resolution: Improved management of disk space related to Eyeglass backups.

—————————————————–

T16381, T16382 Firewall port fix for ECA clusters on 42.3

Resolution: Correct settings for transfer of ECA logs for OpenSUSE 42.3

—————————————————–



Enhancements and Fixes in 2.5.6-20084

Configuration Replication

T11893 Eyeglass unable to create Configuration Replication Jobs for OneFS 8.2 SyncIQ policy using SSIP as target host

When using OneFS 8.2 if the SyncIQ policy target host is set to use SSIP of target cluster Eyeglass will be unable to create the related Configuration Replication job. This could also affect mirror policy jobs that are created by PowerScale OneFS as part of failover where PowerScale has selected SSIP as target host.

Resolution: Eyeglass now able to create Configuration Replication job for OneFS 8.2 SyncIQ policy that has target host configured as SSIP of target cluster.

—————————————————


Failover

T15481 Failover Readiness Warning Alarm Additional Information

The Failover Readiness Alarm for Warning state SCA0081 has been updated to include additional information on the details of the warning state in the Alarm info.

—————————————————

T15870 Failover Readiness does not show readiness for both directions

In some environments where source and target cluster names are overlapping (example cluster1 and cluster1dr) after failover only one direction is displayed inf DR Dashboard.

Resolution: For above environments, DR Dashboard now displays readiness in both directions.

—————————————————



General

T15359 Backup & Restore does not restore Ransomware Defender or Easy Auditor settings

A Backup & Restore does not restore the Ransomware Defender or Easy Auditor settings.

Resolution: Ransomware Defender settings now restored on restore from release 2.5.5 to 2.5.6 There is no restore of settings from release 2.5.4 and earlier. For release 2.5.4 and earlier continue to capture all Ransomware settings (False Positive, Ignore List, Allowed Extensions, Security Guard) and Easy Auditor settings (Active Auditor Trigger settings, RoboAudit). Post restore verify settings and update where required before cluster up on ECA. Following Expected to not be restored on an AnyRelease restore: Ransomware Defender Event History, Threats Detected, Easy Auditor: Finished Reports, Scheduled Reports, Saved Queries

—————————————————–

T15504 Threshold for SCA0075 Disk Space Consumption Alarm Increased

The alarm threshold for SCA0075 Disk Space Consumption on the /srv/www.htdocs/archive has been increased from 800 MB to 2100 MB to more accurately reflect size of archive stored for most deployments and reduce unnecessary alarm notifications.

—————————————————

T15638 Daily Eyeglass Backup may not run

In some environments the daily Eyeglass backup may not run as per schedule.

Resolution: Daily restore backup is now created.

—————————————————–




Enhancements and Fixes in 2.5.6-20069

Failover

T14913 Eyeglass API enhanced to accept list of policies for SyncIQ or DFS failover

 Eyeglass REST API will now accept a list of policies to group multiple targets into a single failover job for SyncIQ policy or DFS failover.  More information is available .

—————————————————

T15036 Failover Readiness Warning or Error emails not sent in some cases

Under some conditions if you are using zone or pool failover, zone/pool/policy/dfs readiness emails for readiness warning or error are not sent.

Resolution: Change of Readiness status from Ok, Info or Error to Warning now sends email notification. Change of Readiness status from OK, Info, Warning to Error also now sends email notification. No alarm or email when status changes to OK or Info.

—————————————————

T15469 Access Zone Readiness may take a long time with cluster unreachable

When you have an unreachable cluster, Access Zone Readiness may take a long time.

Resolution: If cluster is unreachable when Access Zone Readiness job starts no attempt is made to retrieve information from unreachable cluster to reduce time for the job to complete.

————————————

T15502 Configuration Replication may take a long time with cluster unreachable

When you have an unreachable cluster, Configuration Replication may take a long time.

Resolution: Policy Readiness steps that are run as a part of Configuration Replication no longer attemtp to retrieve information from unreachable clutster to reduce the time for the job to complete.

————————————

Fixed in 2.5.6-20063

Failover

T12905 Failover Pre and Post Script "target" variable empty for SyncIQ and DFS failover

The Failover pre and post failover scripting engine "target" variable will be empty for SyncIQ and DFS failover types. It is populated for Access Zone failover type.

Resolution: Target is populated for SyncIQ and DFS failover.

—————————————————–

T15403 SPN Validation Error - Zone does not have any registered SPNs

Access Zone and Pool Failover Readiness may incorrectly display error for SPN validation that "Zone does not have any registered SPNs" when in fact it does.

Resolution: Readiness validation now correctly identifies the SPNs that are present.

—————————————————–

T15404 DR Dashboard Access Zone appears in Zone Readiness tab even though Pool Failover is configured, Pool Failover Configuration blocked

In some cases, an Access Zone that was configured for Pool Failover was displayed in the Zone Readiness tab of DR Dashboard. In this case configuration of Pool Failover for that Zone was also blocked.

Resolution: Access Zone configured for Pool failover now appears in Pool Readiness tab and functionality to configure Pool Failover is available.

—————————————————–

General

T15229 Eyeglass Archive creation does not complete due to stale NFS mount

If you have configured Eyeglass appliance for Warm Standby with NFS mount to store backup on the PowerScale, creating an Eyeglass archive will get stuck and not complete if there is an issue with the NFS mount which prevents a command that collects disk space information on the Eyeglass appliance from completing.

Resolution: NFS mount issue no longer blocks backup.

—————————————————–


Enhancements / Fixed in 2.5.6-20056

Failover

T5808:  Inconsistent Zone Readiness Status between DR Dashboard and Eyeglass API

The Eyeglass web UI DR Dashboard shows Zone Readiness in Info state and the Eyeglass API explorer incorrectly shows zone readiness in error state.

Resolution

: Readiness now matched between DR Dashboard and Eyeglass API.  

—————————————————–

T7881, T7893:  Missing Validations for SPN readiness

Zone Readiness and Pool Readiness SPN validations do not check for the conditions below.

IMPACT: These conditions will cause SPN delete/create to fail during a failover:

1) SPN has been created in AD with lower case host (example: host/SPN_name) instead of uppercase HOST (example: HOST/SPN_name)

2) SPN has been created in AD where SPN_name has different case than associated SmartConnect Zone name (example: for SmartConnectZone prod.example.com SPN is configured as HOST/Prod.Example.com)

Resolution: Zone and Pool SPN Readiness validation now include check for service class (HOST) case mismatch and SPN name vs Smartconnect Zone name case mismatch

—————————————————–

T10479 Limit on number of Parallel Failovers

If the number of concurrent (parallel) failovers including some quota failover steps exceeds 10, a deadlock occurs and failovers will not complete.

Resolution: Default concurrent failovers allowed is 5. If a higher number of concurrent failovers is required please contact support.superna.net for assistance.

—————————————————–

T11585 DR Dashboard incorrectly displays SSIP when IP Pool Smartconnect Subnet is not in same subnet as pool

When the Smartconnect Subnet on a IP pool is different that the subnet the IP pool was created in the DR Dashboard displays the incorrect SSIP.

Resolution: DR Dashboard now displays the correct SSIP.

—————————————————–

T11697 API call corner case may affect failover for Ransomware Defender and Easy Auditor customers

There is a small probability for Ransomware Defender and Easy Auditor customers that a corner case condition could affect a critical API call during failover that does not have a retry.

Resolution: Corner case has been addressed.

—————————————————–


Configuration Replication

T14142 SMB Encryption enable/disable not synced

Smb3 Encryption Enabled setting for shares on source cluster is not replicated to target cluster for OneFS 8.2.

Resolution: Smb3 Encryption Enabled setting for shares is now synced.

—————————————————–

General

T11083 Restore from backup does not preserve failover scripts

If you have configured pre or post failover scripts, the restore from backup does not restore the scripts to the new appliance.

Resolution: Failover pre/post scripts now restored from backup.


T15457 HTML 5 vmware vcenter bug on OVA deployment

 Some versions of vmware vcenter HTML user interface have a known issue with OVA properties being read correctly post power on, leading to first boot issues.


Workaround: use the Flash client as a work around.


—————————————————–

Technical Advisories

Technical Advisories for all products are available here.

Known Issues

Failover 


2666/2723: Problems for Controlled Failover when Source becomes unreachable during failover

In a Controlled Failover where requirement is that Source cluster is reachable, should the Source cluster become unreachable during the failover an error will occur on the failover job but it is possible that no failover log will be generated.  

If the Source becomes unreachable after Failover Wizard validation but before the Failover starts, a log is generated with 1 line that states success.  The Running Jobs window has no details

Workaround: None available

—————————————————–


2278: Zone Readiness lists Access Zone after all related SyncIQ Policies are deleted

For the case where an Access Zone which initially had associated SyncIQ Policies and then all SyncIQ Policies are deleted, the Access Zone will incorrectly appear in the Zone Readiness view with a Status of UNKNOWN.

Workaround: None required.  This entry can be ignored.

—————————————————–


2919: Eyeglass Configuration Replication Jobs may not display in the Zone Readiness Eyeglass Configuration Replication Readiness list

If an Eyeglass Configuration Replication Job has no associated shares, exports, alias or quotas, the Job will not be displayed under Eyeglass Configuration Replication Readiness if the SyncIQ OneFS Readiness is WARNING.

Workaround: None Required.  Failover will run all logic and policies as expected.

—————————————————–


3010: Unexpected results for failover where total number of objects exceeds the published limit

Running an Eyeglass assisted failover where the total number of objects exceeds the published maximum limit will lead to unexpected results.

Workaround: Review published limits and do not use Eyeglass assisted failover if your system exceeds the published limit.

Please refer to the Eyeglass Admin Guide for published limits here.

—————————————————–


3029: Zone Readiness not calculated correctly for SyncIQ subnet pool with a mapping hint

The subnet:pool which are provisioned against SyncIQ Policies for the Restrict Source Nodes option require an igls-ignore hint for Access Zone Failover to prevent the networking in the pool from becoming failed over during an Access Zone Failover.  If there is an Eyeglass igls- mapping hint assigned to these subnet:pool which could result in the networking being failed over Zone Readiness either does not show an error OR it may show the error that mapping is incomplete.

Workaround: Only configure igls-ignore hint on subnet:pool that is provisioned against SyncIQ policy for the Restrict Source Nodes option.

—————————————————–


3031: Zone Readiness Policy Path Containment Check results in extra errors

Zone Readiness for an Access Zone which does not meet SyncIQ Policy path requirement “SyncIQ Policy(s) source root directory must be at or below the Access Zone Base Directory” may in errors for every validation category, with the message "Cannot calculate Access Zone Failover Readiness for a zone with no pools".

Workaround: To resolve the error, ensure that the Policy Path Containment Requirement is met.

Eyeglass Assisted Access Zone Failover Requirements are documented in the Access Zone Failover Guide here.

—————————————————–

3077: Zone Readiness does not catch pool mapping hint misconfiguration for partial string match

Zone Readiness: Smartconnect Zone Failover Mapping Readiness validation does not detect a pool mapping error when there is a partial string match.  For example:

cluster A Smartconnect Zone Mapping Hint = igls-pool

cluster B Smartconnect Zone Mapping Hint = igls-pool1

Readiness check from A to B does not detect the error.  Readiness check from B to A shows an error that no mapping is available.

Workaround:

  • Ensure that your Smartconnect Zone Mapping Hints are identical for mapped pools

—————————————————–

T477: No Policy Hot/Hot Validation Error for policy with no share/export

Zone Readiness incorrectly shows Policy Hot/Hot Validation as OK in an environment where there are one or more policies in the Access Zone which do not have any file sharing objects (shares or exports).

Workaround: Add a file sharing object under the SyncIQ Policy path.

—————————————————–

T482: Zone Readiness shows OK for multiple Smartconnect Zone Mapping errors

In the case where Smartconnect Zone Mapping contains many errors such as multiple hints or combination of hint and igls-ignore on both clusters, the mapping error may only show for one of the clusters instead of both clusters.

Workaround: Provision Smartconnect Zone Mapping according to requirements documented here.

—————————————————–

T654: Zone Readiness incorrectly includes SyncIQ Policy in System Access Zone

For the case where a SyncIQ Policy source path corresponds to a non-System Access Zone path (path is at or below the Access Zone path) but there is a share protected by that policy in the System Access Zone, the SyncIQ Policy incorrectly is evaluated for Zone Readiness in the System Access Zone.

Workaround: None required.  This policy can be ignored in the System Access Zone as in this configuration the System Access Zone cannot be failed over.

—————————————————–


T1712:  Zone Readiness missing Zone when pool has no SmartConnect Zone - OneFS 7

In OneFS 7 When a subnet pool is associated with an Access Zone and does not have a Smartconnect Zone, the Access Zone is not displayed in Eyeglass Zone Readiness window.  With OneFS 8 there is an entry in Zone Readiness with appropriate error.

Workaround: Create SmartConnect Zone for the pools associated with the Access Zone that you want to failover.

—————————————————–

T1716:  Eyeglass Runbook Robot NFS mount not functioning for RHEL and Centos deployments

If Eyeglass is deployed on a Redhat or Centos operating system the Eyeglass Runbook Robot pre and post failover check for file system read/write by making an NFS mount does not work.

Workaround: Disable the Runbook Robot mount step by setting to false following the instructions here:

Manually check read/write status of filesystem.

—————————————————––

T1482:  Zone Readiness SyncIQ Readiness not updated after Access Zone associated to a pool

For the case where initially an Access Zone with a policy is not associated with a pool, the policy appears in Zone Readiness/SyncIQ Readiness under the System Access Zone.  Once the Access Zone is associated with the pool the Policy remains associated with the System Access Zone.

Workaround: None Available.  This is a display issue and the policy will failover if the access zone it is a member of is failed over.  

—————————————————–

T3742:  No Policy Hostname Validation error if SyncIQ Policy Target Host is fully qualified and uses short name on target cluster pool that has a Superna Eyeglass mapping hint applied

If the pool on the target cluster which contains the SmartConnect Zone which is configured on the source cluster as the SyncIQ policy target host is configured as “short” name instead of fully qualified name AND that pool has a Superna Eyeglass mapping hint defined instead of the required igls-ignore hint, Zone Readiness INCORRECTLY does not show an error.

Workaround: Use fully qualified domain name for SyncIQ Policy target host and in the pool SmartConnect Zone name.  

—————————————————–

T3848:  SPNs not updated during failover for OneFS8 non-default groupnet AD provider

For the case where OneFS 8 is configured with multiple groupnet and different AD provider between groupnets, the SPN update during failover does not succeed for non-default groupnet AD providers.  SPN are not deleted for source cluster and are not created for the target cluster. The failover log indicates success. This is due to a OneFS8 defect with multiple AD providers and isi commands.

SPN delete / create for the AD provider defined in groupnet0 is successful.

Workaround: Manually delete and create the SPN for the Smartconnect Zones that were moved from AD ADSI Edit interface.  

—————————————————–

T4009:  SPNs creation case sensitive to AD provider name

If you have domain name in lowercase but smartconnect zone name has upper case domain name then in that case Eyeglass does not add the SPN Host automatically .

Workaround: AD provider name and AD provider in SmartConnect Zone name should have same case.  

—————————————————–



T4320:  Access Zone not assigned to any Subnet Pools results in many Zone Readiness Errors

Zone Readiness error for an Access Zone that is not assigned to any Subnet Pool has multiple rows displayed in the DR Dashboard - 1 per Subnet Pool on the PowerScale Cluster.

Workaround: Associate the Access Zone with at least 1 Subnet pool.  

—————————————————–

T4316:  Runbook Robot Policy Job does not display SyncIQ Job Reports

Runbook Robot job creates 2 failover history records - one for policy failover or access zone failover and one for for Runbook Robot.  The Runbook Robot SyncIQ Reports log incorrectly repeats the Failover log information instead of showing the associated SyncIQ Job reports.

Workaround: View the associated Policy or Access Zone Failover results to retrieve the SyncIQ Job Reports.  

—————————————————–

T4857:  Failed SmartConnect Zone Rename step is not displayed in Failover Log

Access Zone Failover which fails at the SmartConnect Zone rename step shows a Major Error in the “Networking updates during failover Job” section of the Failover Log but does not show the actual rename step which failed.

INFO Raised alarm: MAJOR Access Zone Failover Job failed.

ERROR ****************** Networking updates during failover Job FAILED *************


Workaround: Contact Support to assist in determining the rename operation which caused the error.  

—————————————————–

T4878:  Pool Failover - Non Runbook Robot SyncIQ policies can be mapped to Robot pool

Pool failover is not supported for Runbook Robot but pool readiness SyncIQ policy mapping does not block user from mapping a non-Runbook Robot policy to the Runbook Robot pool.  This configuration will cause an error during the Runbook Robot job.

Workaround: Do not configure Pool Failover for the Eyeglass Runbook Robot Access Zone.  

—————————————————–

T4968:  Zone missing from DR Dashboard Zone Readiness tab if a SyncIQ Policy has a target host that cannot be resolved

When an Access Zone contains a SyncIQ Policy which has a Target Host configured which cannot be resolved by Eyeglass, the Access Zone does not appear in the DR Dashboard Zone Readiness tab.

Workaround: Ensure that all SyncIQ Policy Target Host can be resolved by Eyeglass.  To verify, ssh to the Eyeglass appliance and test with nslookup <target host> to confirm that it can be resolved.  

—————————————————–

T5092, T4490:  Access Zone Pre and Post Failover Scripting Issues

  • There is no specific option to create Pre or Post Failover scripts for a Pool Failover.  If there are existing Pre or Post Failover scripts for Access Zone failover those same scripts will be run during pool failover.

  • In a multi-pool setup, the failover log may report an error related to executing the post failover script even though the script succeeds.

  • Running the Test run script, for Access Zone Failover, Test Run script only shows "loading" status

Workaround: Ensure that any Access zone failover scripts also apply to pool failover if both are configured. Verify manually whether a script has succeeded.

—————————————————–

T5473:  Zone/Pool Readiness Pool Mapping Hint Matching Issue

Readiness logic to determine whether 2 pools are mapped for Access Zone or Pool failover will map based on partial match instead of an exact match.  For example a pool with the mapping hint “igls-8” on the source will match any mapping hint on the target that begins with “igls-8” - for example, “igls-8a”, “igls-8b”, “igls-8c” etc.  This may cause an issue if there are multiple pools on target side which match. It will also cause an issue after failover as the target hint (for example “igls-8a”) will not match the source hint (for example “igls-8”).

Workaround: When provisioning pool mapping hints, use unique string that do not overlap between pools - for example, igls-1, igls-2, igls-3 instead of igls-1, igls-1a, igls-1b.  

—————————————————–

T5961:  Failover Log shows Incorrect Final Steps

The Failover log always contains following Final steps even when not required:

  1. Networking Rollback Steps are incorrectly displayed at end of failover for a failover where Networking Client Redirection steps were not executed.

  2. Transfer pool mapping step are incorrectly displayed for non-pool based failovers.

Workaround: In the above conditions these messages can be ignored as they do not apply.  

—————————————————–

T5897:  Post Failover Inventory step may fail during multiple concurrent failovers

When multiple failovers are initiated in parallel and running concurrently the Post Failover Inventory step may fail if the same step is running for one of the concurrent failovers.  This leaves the failover in a Failed state.

Workaround: None Required. This step will be completed successfully on a subsequent failover or during regular Configuration Replication to bring the Eyeglass up to date on the latest state of the PowerScale environment.  The Failover log must be consulted to determine state of other failover steps such as Client Redirection, Make Writeable and Preparation for Failback.

—————————————————–

T5941:  Pool Failover Failover Log Summary incorrectly displayed Client Redirection step not run

For Pool Failover, the Failover Log Summary displays the Client Redirection step as not having run:

Client Redirect : This step did not run

When the step in fact did run.

Workaround: Check this section in the Failover Log to determine the status of the Client Redirection steps:

INFO *************** Networking updates during failover Job STARTED ***************

—————————————————–

T5967:  Failover where Quota Sync is disabled has extra lines in Failover Log

The Failover Log for a failover where Quota Sync is disabled displays the following line multiple times instead of just once:

PLEASE RUN QUOTA FAILOVER JOBS MANUALLY

Workaround: None Required.

—————————————————–

T5934:  Access Zone Readiness shows OK for DFS only failed over Access Zone

Zone Readiness status for Access Zone which only has DFS policies will show OK as the overall status for the failed over direction instead of Failed Over status.

Workaround: Check which cluster has enabled SyncIQ Policies and then verify that other cluster is read-only to confirm which failover direction is active.

—————————————————–

T6289:  SyncIQ policy with no shares or exports is associated with the System Access Zone for failover

A SyncIQ policy which does not have any associated shares or exports at or underneath the policy path will be associated with the System Access Zone for Access Zone or Pool Failover instead of the Access Zone that the SyncIQ policy falls at or under.

Workaround: Create a file sharing object at or underneath the SyncIQ Policy path and in the Access Zone under which the SyncIQ Policy falls.

—————————————————–

T6311:  Selecting the DR Failover Status link on the DR Assistant Summary page may result in an Error

Selecting the DR Failover Status link on the DR Assistant may result in following error:  No policy data has been provided, cannot execute request.

This error does not block the failover from proceeding.

Workaround: Open the DR Dashboard and review the DR Failover Status here.  

—————————————————–

T6402:  Access Zone Failover Post Failover Inventory step runs multiple times

When an Access Zone contains multiple SyncIQ Policies and those policies have been configured in Eyeglass for different Job types (DFS or AUTOSKIPCONFIG), the failover Post Failover Inventory runs for each Eyeglass Job type in the Access Zone instead of just once.

Workaround: None Required.  While this increases the failover time to include completion of multiple post failover inventories, the critical failover steps for client redirection, make writeable and preparation for failback are completed prior to this step.  These steps are required to complete in order to place a new mirror policy into the corresponding DFS or AUTOSKIPCONFIG state.

—————————————————–

T6842:  Zone Readiness: Zone does not display Failover Over state for Access Zones where custom SmartConnect Zone prefix is being used

For Eyeglass deployments where the SmartConnect Zone prefix used to disable SmartConnect Zones on failover has been customized to not use the default igls-original prefix the DR Dashboard does not display Failed Over status for the inactive Access Zone failover direction.

Workaround: None Required.  

  1. This is a display issue only and does not block failover.

  2. This issue does not affect SmartConnect Zone rename during failover.

  3. While the DR Assistant allows you to select a failover in the wrong direction (inactive -> active) it is blocked further along in the Failover Wizard due to no enabled policies.

—————————————————–

T7184:  Pool Readiness: Pool to SyncIQ Policy Mapping is not displayed in DR Dashboard until Readiness task is run

Pool to SyncIQ Policy mapping is not displayed in DR Dashboard Pool Readiness view until a Zone / Pool Failover Readiness task has been run.  

Workaround: None Required.  This is a display issue only - the mapping is successfully saved and displayed after the next readiness task has run.

—————————————————–

T8824:  User Quota creation fails on failover for multiple disjointed AD Domain environment

In an PowerScale environment that is configured to use multiple AD Domains and those Domains are not joined, user quota creation for the quotas related to the non-default AD Domain will fail with the error:

Requested persona was not of user or group type

Workaround: None available with Eyeglass.

—————————————————–

T10363 Overlapping Access Zone Failover blocked for System Access Zone

For the case where there are multiple access zones overlapping wtih System Access Zone on /ifs path, DR Assistant will show an error during navigation indicating an invalid configuration and block completion of failover.

Workaround: SyncIQ Policy failover with manual client redirection.

—————————————————–

T10912 Quota Sync fails for quotas where quota container property set to true

Smartquotas in OneFS configured with the container property set to true fail to be created by quota sync.

Workaround: None available. Quota must be created manually.

—————————————————–

T10935 Pool failover "failovertarget" must be "zone id"

The "failovertarget" field must be "zone id" even though description indicates "ID of the access zone OR syncIQ policy to failover".

Workaround: Enter "zone id" for "failovertarget" when initiating pool failover.

—————————————————–

T7622 Eyeglass will not add custom SPNs if PowerScale Cluster does not return any missing SPN during SPN check (as of 2.5.6)

As of 2.5.6 Eyeglass can manage custom SPN creation based on Eyeglass configuration - additional information available . If PowerScale does not identify any missing SPNs Eyeglass Configuration Replication will not insert custom SPNs. If PowerScale identifies any missing SPN, Eyeglass will insert all custom SPN even if PowerScale does not identify it as missing.

Workaround: SPNs to be added manually if required. For failover, no additional steps - failover will manage all SPN updates based on custom SPN definition.

—————————————————–

T13360 Failover Readiness Validation for Corrupt Failover Snapshots does not check for missing snapshot

There must be one failover snapshot on the target cluster per SyncIQ policy being failed over. The Corrupt Failover Snapshots validation does not check whether that snapshot is missing. Impact: Allow Writes step of failover will fail.

Workaround: Verify presence of snapshot manually on target cluster

isi snapshot snapshots list | grep <SyncIQ Policy Name>

Replacing SyncIQ Policy Name iwth your our SyncIQ Policy Name

example for expected configuration

isi snapshot snapshots list | grep policy1

12345 SIQ-Failover-policy1-2020-05025_21-33-37 /ifs/data/policy1

—————————————————–

T12434 Concurrent Access Zone or Pool Failover with DFS configured policies may fail DFS share rename step

When doing concurrent Access Zone or Pool Failover where the Access Zone or Pool have associated jobs in Eyeglass DFS mode the share renaming step may happen in parallel and depending on the OneFS release an PowerScale OneFS API defect may incorrectly handle the request causing the share rename to be in error.

Workaround: Verify with Dell EMC support whether your OneFS version has this issue. For any shares where share renaming fails they will have to renamed manually - the failover log will indicate which failed and which succeed.

—————————————————–

T13701 Failover option "Disable SyncIQ Jobs on Failover Target" does not reapply schedule

When the failover option Disable SyncIQ Jobs on Failover Target" is selected the synciq policy schedule is not reapplied to the active synciq policy on the target cluster.

Workaround: The original SyncIQ policy schedule is captured in the failover log. Reapply the schedule to the policy manually on the PowerScale. 

—————————————————–

T13726 Pool Failover error mapping policy to pool on target cluster for disabled job

If Pool Failover is initiated and there is an associated Eyeglass Configuration Replication job that is disabled, the failover correctly skips failover of the associated synciq policy / data but incorrectly attempts to associate the mirror policy to a pool on the target cluster resulting in an error for the step "Transfer pool mapping" with mesage "Could not find policy ....".

Workaround: None required failover has been completed successfully for policies which were enabled. No impact to failback.

————————————

T13881 Cannot failover overlapping Access Zones - rel 2.5.6

In Release 2.5.6 overlapping Access Zones cannot be failed over. The network updates that are done durinig failover are rolled back.

Workaround: Use Release 2.5.5 to failover overlapping access zones

————————————

T14398 Zone/Pool Failover Readiness FQDN Alias validation incorrectly reports OK when pool does not have an ignore hint

For case where PowerScale cluster has been provisioned in Eyeglass using FQDN, that FQDN should not be failed over during Zone or Pool failover - it needs to remain associated with its current cluster. This is achieved by configuring the associated IP pool to be "ignored" during failover. The validation that checks whether this configuration is in place incorrectly indicates OK when the "ignore" is not configured.

Note that as of Eyeglass 2.5.3 and higher clusters no longer being added to Eyeglass using FQDN due to PowerScale CSRF not compatible with Smartconnect and API services.

Workaround : If cluster still added to Eyeglass using FQDN modify to be added using IP. Please following Technical Advisory #17 and Technical Advisory #22.

————————————

T14931 Policies configured for Pool failover allowed to do DFS or SyncIQ failover until next configuration replication runs

Policies configured for pool failover are blocked from being failed over in DFS or SyncIQ mode except for period of time between when pool to policy mapping for Pool Failover has been completed and next Configuration Replication cycle has completed.

Workaround: None required - Do not initiate DFS or SyncIQ mode failover for policies configured for pool failover. Next schedule Configuration Replication job will rectify and after that point the DFS and SyncIQ failover mode will not be available for policies configured for Pool Failover.

—————————————————

T14948 Failover log for Uncontrolled Access Zone incorrectly logs status of final readiness job and changes to pool aliases

The failover log for an uncontrolled Access Zone failover will incorrectly report the status of the final failover readiness step as SUCCESS instead of error and will incorrectly summarize the Pool aliases on source after failover and Pool aliases on destination after failover at the end of the log.

Workaround: None required, this is a logging issue only. The failover correctly logs client redirection steps in the Networking updates section of the log which records the changes as they are being executed. The failover readiness status can be viewed on the DR Dashboard / Zone Readiness.

—————————————————

T14965 Failover readinessSyncIQ File Pattern Validation has WARNING state instead of ERROR

Failover readiness SyncIQ File Pattern Validation which detects that SyncIQ policy has file patterns should be ERROR instead of WARNING as PowerScale OneFS Resync Prep function that prepares you for failback will fail when SyncIQ is configured this way.

Workaround: This setting should not be used for DR purposes.

—————————————————

T14971 DR Assistant validation check screen incorrectly requests acknowledgement of readiness warnings

For case where DR Failover status is OK or Info, the DR Assistant Failover wizard validation check step requests acknowledgement that warnings have been reviewed even though DR failover status has no warning status.

Workaround: Close the DR Assistant window and open the DR Dashboard window and confirm that indeed failover status has no Warning states. If so, start the failover again and now select the "I have reviewed the warning status" check box and continue with the failover.

—————————————————

T14974 Access Zone Failover with error on DFS share renaming will abort for all policies

For the case where an Access Zone hss both DFS and non-DFS configured jobs in Eyeglass, if share renaming fails for all shares associated with a DFS policy Client redirection will be considered an error for non-DFS policies as well and failover will be aborted instead of continuing for non-DFS configured jobs.

Workaround: Share renaming issue should be resolved before re-attempting the failover.

—————————————————

T14988 Eyeglass GUI incorrectly allows pool failover configuration for a policy that is active in failover rehearsal mode

From the Eyeglass DR Dashboard you are allowed to map a policy for pool failover when it is in active rehearsal mode even though you cannot initiate a failover when it is in this state.

Workaround: Review policy status and confirm not in rehearsal mode before configuring pool failover.

—————————————————

T15000 DR Rehearsal status lost if fingerprint file deleted

A fingerprint file is used to persist DR Rehearsal status. If the fingerprint file is deleted or otherwise removed while rehearsal mode is active, rehearsal status is lost and there is no way to revert rehearsal mode.

Workaround: Please contact support at support.superna.net to recover from this state.

—————————————————

T15042 REST API policy readiness is missing output for Target Reachability check

The SyncIQ policy readiness retrieved using REST API is missing the output for the Target Reachability check. If the Target Reachability validation fails, the overall Failover Status is correctly in ERROR and failover cannot be initiated

Workaround:

  • To assess target reachability:
    • Target reachability alarms related to Inventory or Configuration replication would have been sent.
    • From the Eyeglass web interface, Eyeglass / PowerScale reachability can be viewed from the Continuous Operation Dashboard.
  • All failover readiness criteria can be viewed from the Eyeglass web interface DR Dashboard.

—————————————————

T15010 DR Rehearsal Revert not blocked for Pool Failover mode when in REHEARSAL_ERROR

If after enabling DR Rehearsal mode for Pool Failover the DR failover status is REHEARSAL_ERROR the failover wizard incorrectly allows you to initiate a revert for rehearsal mode.

Workaround: To recover from this REHEARSAL_ERROR open a support ticket at support.superna.net for assistance. 

————————————

T15609 Alarm time not upated for repeated policy/dfs/zone/ pool readiness alarms

If a policy, dfs, zone or pool readiness alarm occurs multiple times, the Alarm time will not be updated with each occurrence. It will display only the first time the alarm is raised. Email notification also only sent on initial occurence of the alarm. Subsequent occurences will not send an email.

Workaround: Open the DR Dashboard to see the current state of the validations as of the last time the Zone/Pool Readiness job has run.

—————————————————

T15191 Failover Log may show 2 summaries when Rehearsal Mode enabled

When Rehearsal Mode is enabled for an Access which has DFS policies or enabled with multiple pools which also have DFS, the failover log summary shows an interim summary after data access steps and a final summary at end.

Workaround: None required - summary has required information.

————————————

T15192 Rehearsal Mode not disabled for Access Zone assoicated with Pool Failover

From the DR Dashboard, the Access Zone associated with a Pool Failover already active in Rehearsal Mode can be selected for enabling Access zone Rehearsal Mode again even though this is not a valid configuration for Rehearsal Mode.

Workaround: None Required, the next window in DR Assistant identifies the invalid configuration and correctly blocks Rehearsal Mode enabling for the Access Zone.

————————————

T15248 Error in DFS failover does not rollback share renaming when failover job includes multiple policies

A DFS failover which contains multiple policies will not rollback share renaming for a policy that encounters an error if the remaining policies succeed.

Workaround: Use PowerScale interface to remove and add igls-dfs prefix for affected shares.

————————————

T15260 DFS Failover share renaming rollback not done when all share rename fails on source cluster

If client redirection step of failover which adds igls-dfs prefix to shares on the source cluster fails for all of the shares associated with the source cluster the failover stops but the share renaming that completed successfully for the target cluster is not rolled back.

Workaround: Use PowerScale interface to add igls-dfs prefix to shares on the target cluster.

————————————

T15271 Zone/Pool Failover error in SMB Data Integrity step or run policy step incorrectly attempts to roll back networking

If the inital share lockout for SMB Data Integrity step fails or run policy step fails, the failover is aborted as expected but then steps are executed to roll back networking changes even though none were made. There is no impact other than error in failover log as these commands fail as they are attempting to update to configuration that already exists on the cluster.

Workaround: None required - the commands executed do not result in any changes on the PowerScale cluster.

————————————

T15278 Pool Failover job with multiple pools stops failover steps for all pools on DFS share renaming error

If an error which will abort failover occurs for DFS share renaming on one pool where the failover job contains multiple pools, failover will be aborted for all pools instead of continuing for pool which has no error.

Workaround: When failing over multiple pools, execute concurrent failover with 1 pool per failover job.

————————————

T15290 Pool Failover job with multiple pools does not rollback client redirection when allow writes step fails

If an error occurs on allow writes for one pool in a failover job that contains multiple pools there is no rollback for networking for failed pool.

Workaround: Networking can be failed back manually using PowerScale interface and using Failover log as as a guide. Also can failover multiple pools concurrently with 1 pool at a time.

————————————

T15298 Quota job run manually after failover may delete quotas on source cluster

Even if quota failover steps fail on failover from cluster A to cluster B such that no quotas are created on cluster B and all quotas exist on cluster A, the quota failover job from cluster B -> A is created and enabled. If this Quota job is run manually it will delete all related quotas on the source (cluster A) leaving you without related quotas on source or target.

Workaround: Do not run quota jobs manually. Contact support.superna.net for assistance to failover quotas that failed during failover.

————————————

T15530 Policy or DFS Readiness may incorrectly evaluate Policy Hostname validation in error

DR Dashboard / DR Assistant Policy Readiness or DFS Readiness may incorrectly evaluate Policy Hostname validation in Error state placing overall failover status in Error. This validation should only be being assessed for Access Zone or Pool failover.

Workaround: Follow steps for Access zone failover configuration to ignore failover for the pool that has the Target Host. Steps to do this are on the target cluster apply "igsl-ignore" hint on the pool which has the SyncIQ Policy Target Host. Ignore hints are simply an alias with the name of "igls-ignore". Note it is best practise to ensure unique hints by using a naming format that uses cluster name - for example: igls-ignore-<clustername>. Documentation reference can be found - see section on ignore hints.

Once configured run the Eyeglass Configuration Replication Job to update DR Dashboard / DR Assistant.

————————————

T15547 Failover Readiness Domain Mark Validation fails for path with spaces or special characters

The Failover Readiness Domain Mark Validation returns an error for SyncIQ policy source path that has a space or contains special characters.

Workaround: Manually confirm presence of domain mark by running command on PowerScale: isi_classic domain list . DR Failover Status of Warning does not block failover. For additional information on readiness validations in Warning state please refer to our documentation or contact support.superna.net.

————————————

T15610 Policy Readiness Pool Mapping Validation alarm and email indicate Warning severity instead of Error

For the cases where an Access Zone is configured for Pool Failover and there are policies which are not mapped to pools the Un-Mapped Policy SmartConnect/IP Pool Status alarm and email incorrectly indicate that this is a Warning level issue. The DR Dashboard correctly identifies the issue as an Error which would block initiating a failover.

Workaround: Review readiness from the DR Dashboard directly.

————————————

T15613 DR Rehearsal Readiness - no alarm or email when DR Rehearsal status changes from OK to Warning or Error

No Alarm is raised or email sent when DR Rehearsal readiness status changes from OK to Warning or Error status.

Workaround: Login to the Eyeglass GUI and open the DR Dashboard to review readiness.

————————————

T15623 REST API - Pool Failover API does not support multiple pool selection

From Eyeglass DR Assistant a Pool failover can be initiated for multiple pools but this is not supported from the API.

Workaround: Run concurrent failover for multiple pools.

————————————

T15624 REST API - Failover API does not block controlled failover when source cluster unreachable

Failover API does not validate source cluster reachability and will allow a controlled failover to start even if source cluster unreachable. Controlled failover in this case is expected to fail as it will attempt steps against the source cluster. When source cluster is not reachable uncontrolled failover should be used.

Workaround: Use manual process to verify source cluster reachability and initiate the appropriate controlled or uncontrolled failover.

————————————

T15769 DNS Dual Delegation Validation does not work where NS Record does not resolve directly to an SSIP

If DNS Dual Delegation is configured with NS Records that resolve to a name (for example configured as CNAME) the DNS Dual Delegation Validation will not work as it is expecting an IP address on resolution of the NS Record.

Workaround: To avoid this warning DNS Dual Delegation validation can be disabled. Please contact support.superna.net for assistance.

————————————

T16154 DR Rehearsal mode has invalid readiness validation for Corrupt Failover Snapshots

For case where SyncIQ Policy involved in DR Rehearsal mode enabled has different source and target paths or space in SyncIQ Policy path or a special character in SyncIQ Policy path, after DR Rehearsal mode enable the DR Failover Status incorrectly shows an Error for Corrupt Failover Snapshots for that policy. This error blocks reverting DR Rehearsal mode.

Workaround: Do not use DR Rehearsal mode for policies which have different source and target paths, spaces in paths or special characters in paths. Regular failover is unaffected by this issue and is available. To recover from this REHEARSAL_ERROR open a support ticket at support.superna.net for assistance. 

————————————

T17136 Zone Readiness incorrectly shows Error when Access Zone Name, Smartconnect Zone Name and IP Pool name are exactly the same

DR Dashboard Zone Readiness incorrectly shows Policy Readiness Status, SmartConnect/IP Pool Settings and Mappings Readiness and Eyeglass Failover Mapping Hints in error when the Access Zone, SmartConnect Zone Name, IP Pool all have exactly the same name.

Workaround: This issue can be resolved by renaming the Access Zone to be different. This change should be assessed for impact in your environment before making this change.

————————————

T17401 Pool Readiness not displayed with no configured/reachable DNS

If both Eyeglass and Isilon DNS are not available, the DR Dashboard pool readiness is not displayed.

Workaround: Provide reachable Eyeglass or Isilon DNS.

————————————

T17477 DFS share suffix not applied for failover or configuration replication

If a custom suffix is configured for DFS share name on target cluster, suffix is not applied either during configuration replication or during share renaming step of failover.

Workaround: None available.

————————————

T17428 REST API - Policy Readiness returns incorrect Access Zone

Failover API to retrieve Policy Readiness information returns the incorrect Access Zone for environments with multiple Access Zones.

Workaround: None required. Access Zone does not affect Policy Failover and Access Zone Readiness and Failover correctly assign policy to correct Access Zone.

————————————

T17447 OneFS 9.0 and 9.1 Readiness Validation for Policy Source Nodes Restriction always shows INFO

For OneFS 9.0 and 9.1 even if the Policy Source Nodes Restriction is configured, the Readiness Validation always shows INFO,

Workaround: Verify on PowerScale the source nodes restriction settings. DR Status of INFO does not affect / block ability to failover.

————————————

T17522 Failover Scripting Engine SOURCE and TARGET variables expose password

The Failover Scripting Engine SOURCE and TARGET environment variable information includes the password of the account used to connect from Eyeglass to PowerScale in plain text.

Workaround: Do not use these variables in scripting.

————————————

T17555 Blank display for Zone or Pool Readiness

In some instances where Zone and Pool failover is configured the Zone or Pool readiness window may be blank when both the DR Assistant and DR Dashboard are open.

Workaround: Reload the tab or only have one window open at a time.

————————————

T17731 Policies missing in DR Assistant for Zone or Pool failover

DR Assistant missing policies in an Access Zone for Zone or Pool failover where there are no SMB shares or NFS exports configured at or below the SyncIQ policy source path. Impact is that failover steps are not executed against these policies and they remain active on the source cluster.

Workaround: In advance of failover, configure a temporary share with restricted permissions at the SyncIQ policy source path. If you have failed and only then determine the issue, policies can be failed over using Policy failover if the failover was an Access Zone failover. If the failover was a Pool failover manual steps must be used to failover the remaining policies.

————————————

T17732 Multiple Zone Readiness Jobs

Under some circumstances multiple Zone Readiness jobs will be running at the same time without any completing. DR Dashboard not updated when in this state. If this occurs during Access Zone failover it does not block failover.

Workaround: Eyeglass sca service restart will address this issue but recommend to contact support.superna.net for assistance and evaluation of the issue.

————————————

T18127 DNS Dual Delegation uses wrong SSIP when IP Pool Service Subnet different from the pool subnet

The IP Pool Service Subnet setting that is different than the parent subnet of the IP Pool is not taken into account for the DNS Dual Delegation validation. This could result in incorrect assessment of the DNS delegation configuration or if no SSIP configured in the parente subnet can result in the error "This IP address does not reference valid cluster".

Workaround: Manual inspection of DNS NS Record delegation should be done to confirm that it has been configured correctly.

————————————

T18253 DR Rehearsal Mode Enable / Revert Error when multiple policies selected

A DR Rehearsal Mode Enable / Revert where more than 3 SyncIQ policies are involved either selected for SyncIQ or DFS mode or an Access Zone with more than 3 SyncIQ policies, the final step which updates Eyeglass with the rehearsal status fails with a lock conflict error..

Workaround: For SyncIQ or DFS Mode Rehearsal Enable or Revert do not select more than 3 policies at a time. For Access Zone Rehearsal mode where Access Zone has more than 3 SyncIQ policies run the Rehearsal exercise as a SyncIQ policy Rehearsal selecting a maximum of 3 policies at a time.

————————————

T18779 Overlapping Powerscale cluster and SyncIQ Policy names can result in incorrect Failover Readiness assessment

For the case where source and target Powerscale cluster have overlapping names (for example "cluster1" and "cluster1dr" ) and there are SyncIQ policies on both cluster with the same name, failover readiness for source cluster may take into account the SyncIQ policy state on the target cluster resulting in an incorrect state for source cluster. For example a SyncIQ policy disabled on the target cluster incorrectly results in Policy Enabling Readiness Warning for the SyncIQ policy on the source cluster.

Workaround: Rename the SyncIQ policy on the target cluster to make it unique between both clusters. For example pre-pend the SyncIQ policy name with the target cluster name.

Configuration Replication


1683: Export sync where source  is 7.1.1.x and target 8.x.x.x

Description: Syncing exports does not function between these releases.  

Resolution:  None unsupported sync, upgrade to 7.2.x.x

————————————————--


649: Export sync where source and target path on each cluster is different is deleted and recreated in each config cycle (affects onefs 7 to 8 or 8 to 7 replication)

Description: When the path on source cluster and target of the SyncIQ policy are different, exports will be deleted on target and then recreated again  within the same replication job. No error is seen on the config sync job. May affect other releases as well.

Resolution:  None, export is created correctly after config sync job completes.

————————————————--

1462 - Export max_file_size cannot be replicated

Updated export max_file_size parameter is not replicated and replication Job fails.

———————————-


1355: Edit Job configuration to include share/export deselected from another Job causes share/export to be reselected.

Description: When you edit a Job B configuration to include share/export that had already been deselected from Job A, this causes this share/export to be reselected for Job A as well.  

Workaround: None available.  Should the share/export subsequently be deselected from Job B it should then also be manually deselected again from Job A.

—————————————————–


1580: Delete and Create export within same replication cycle orphans deleted export on the target with OneFS 7.1.1.x

With OneFS 7.1.1.x, a delete and create export operation which occurs within the same replication cycle will replicate the export that was created on the next replication cycle but the export deleted on the source will not be deleted on the target.  

Workaround: Manually remove the deleted export from the target using PowerScale OneFS.

—————————————————–


1625: Custom QUOTA Jobs require extra replication cycle to be deleted

In the Eyeglass Jobs window, when you delete a CUSTOM Job and then the associated QUOTA Job is not immediately deleted.  It is deleted on the next replication cycle.

Workaround: None required.

—————————————————–


1639: Able to manually Run Now disabled Custom Job

Eyeglass Jobs window allows you to Run Now on a Custom Job which has been disabled.  A message is displayed indicating that the Job has been queued but the share/export configuration replication Job is not run and the associated QUOTA Job is run and quotas are replicated.

Workaround: Do not Run Now for Custom Job that has been Disabled.

—————————————————–


1641: Custom Job does not include shares/export when source or destination path configured with a trailing /

If you enter source or destination path for Eyeglass Custom Job with a trailing / (for example /ifs/data/test/ ), the Custom Job will not pick up the related shares and exports.

Workaround: Source and destination paths must be entered without the trailing / - for example /ifs/data/test.

—————————————————–




1788: Delete of unlinked user quota on source may not delete matching quota on the target

Attempting a quota replication after deleting an unlinked user quota may fail to delete the quota on the target with a Job status of success but an Audit failure.

Workaround: Deleted quota manually deleted on the target.

—————————————————–


1789: Able to select shares/exports/quotas outside job path after deselected

After a share/export/quota has been deselected from an Eyeglass Job, it can be re-selected for a different Job even if it is outside the Job path.  As a result, the Job may have an error for these share/export/quota due to path not found error.

Workaround: Do not customize Eyeglass configuration replication Job and select share/export/quota that are outside the Job path.

—————————————————–


1887, T3727: Multiple SyncIQ policies associated with same Zone will result in transient error on Eyeglass Zone replication creation

Where there are multiple SyncIQ policies which are associated to the same zone and Eyeglass configuration replication is being used to create the zone on the target, the first Zone replication job will succeed, but subsequent Zone replication jobs for the same Zone will fail with the message “Zone ‘<zone name>’ already exists”.

Workaround: None required for OneFS 7.2 - 7.2 or 8 - 8 replication.  Error will be cleared on subsequent configuration replication cycle.

For OneFS 7.2 - 8 replication, Zone Replication Readiness always has warning status and alarm is raised for failed audit on zone job.  Manually inspect that Access Zones are identical and that Zone Readiness Warning is related to this issue.

—————————————————–



1924: Quotas on excluded SyncIQ directory are selected for replication

Eyeglass quota job includes quotas related to excluded SyncIQ directories.  If quota job is run, it will typically fail due to path not found.

Workaround: Customize Quota Job and deselect quotas for excluded directories.

—————————————————–


1998: Custom Eyeglass configuration replication Job does not have an associated Zone replication Job

When you create a new custom Eyeglass Job, an associated Zone replication Job is not created.

Workaround: Zone must be created manually or already exist on the target cluster in order for Eyeglass configuration replication to succeed.

—————————————————–


2004: Custom Quota Job is incorrectly listed in the Failover: Quota Failover (RUN MANUALLY) section in the Jobs window

When you create a new custom Eyeglass Job, the associated Quota replication Job is created and incorrectly listed under Failover: Quota Failover (RUN MANUALLY) section in the Jobs window.  Custom Quota Jobs do not need to be run manually, they are run automatically each time the customer Eyeglass configuration replication Job is run.

Workaround: None required.  Custom Quota Jobs do not need to be run manually, they are run automatically each time the customer Eyeglass configuration replication Job is run.

—————————————————–


2007: Job error after deleting quota

After running Quota Job and successfully replicating quota to target, if quota is deleted and Quota Job is run again the Quota is successfully deleted from the target but the Quota Job has Error status.

Workaround: None required - quota is deleted.

—————————————————–


2038: Create alias results in temporary error

When an nfs alias is replicated to the target, the initial create leaves Job in Error state with  related alarm " Alias <alias name> already exists on this zone"

Workaround: None required.  Next replication cycle clears the error.

—————————————————–


2043: Configuration replication job has error after zone is deleted

For the case where Zone related to a Configuration Replication Job is deleted on the source, the Zone and associated configuration items are successfully deleted on the target, but the Configuration Replication job remains in Error state.

Workaround: None required.  Shares and exports are deleted as expected.

—————————————————–


2045: Edit Configuration for Custom Job has multiple source cluster selected where Eyeglass is managing more than 2 clusters

For the case where Eyeglass is managing more than 2 clusters, it may occur that the Edit Configuration view incorrect.

Workaround: None required.  Shares and exports are replicated as expected.

—————————————————–


2046: Job Edit Configuration view has the wrong parent selected

For the case where a configuration replication job contained a configuration items and the last configuration item is deleted - after the configuration item is deleted, the parent in the Edit Configuration view continues to be selected for the Job even though when you expand the tree there are correctly no children selected.

Workaround: None required.

—————————————————–


2049: Delete Zone does not delete associated configuration items on target for custom Jobs and auto jobs with disabled zone Job

When a non System zone is deleted on the Source, the Eyeglass Configuration Replication Custom Job or Auto job with disabled Zone Job does not remove the associated configuration items from target related to the deleted Zone.

Workaround: Manually delete the Zone and associated configuration items on the target using OneFS.

—————————————————–


2235: Eyeglass replication Job does not complete when source cluster becomes unreachable after Job has started

If the source cluster becomes unreachable after the Eyeglass configuration replication Job has started, the Job does not complete.

Workaround: None required.  The Job will eventually complete after all communications timeouts have occurred.  This may take an hour.

—————————————————–


2060: Access Zone Replication Error - Error on creation of shared resource

Error on Replication for Access Zone which shows Error on creation of shared resource.

Workaround: None required.  Once SyncIQ Job has run again in OneFS, the next time configuration replication runs the Access Zone is replicated.

—————————————————–


2488: Inconsistent behaviour in Run Now for Disabled Jobs

When Run Now is selected for an Eyeglass Job which is disabled, the handling is different depending on Job Type and state:

For Job which is “Policy Disabled” - Run Now is blocked for all Jobs

For Job which is “User Disabled” - Run Now not blocked and all enabled Jobs run

For Robot Job which is disabled - Run Now not blocked, Job is initiated and then fails.

Workaround: Only select enabled Jobs for Run Now.  

—————————————————–

1938: Issues with Eyeglass Configuration Replication Jobs after the Access Zone is deleted

When you delete an Access Zone in OneFS, the following issues occur in Eyeglass:

  • corresponding Eyeglass Zone Configuration Replication Job is not deleted

Workaround: None Required.  Job is empty.

—————————————————–


2308: In EyeGlass, NFS alias health is always 'unknown'

Eyeglass Inventory, NFS Alias audit and Cluster Configuration Report always have the NFS alias health property set to unknown.

Workaround: Determine the NFS Alias healt from the OneFS command line using isi command..

—————————————————–


2804: Disabled SyncIQ Policy is not initially displayed as Policy Disabled in Eyeglass

When the Eyeglass system setting for INITIALSTATE is set to Disabled for Configuration Replication Jobs (Type = AUTO), the Jobs window State for the Eyeglass Configuration Replication Job where the corresponding SyncIQ Policy is disabled displays as “User Disabled” instead of “Policy Disabled”.  In this state the Eyeglass GUI allows you to Enable this Job, but in fact after the next Configuration Replication Job the Job is correctly displayed with the Policy Disabled state.

Workaround: None Required.

—————————————————–

T676: Eyeglass Zone replication Job does not replicate all authentication providers for OneFS 8.0

For OneFS 8.0, if an Access Zone has multiple authentication providers not all providers will be replicated for the Access Zone on the target cluster.

Workaround: Manually edit the Access Zone on the target cluster and add the required authentication providers.

—————————————————–


T723: Job shows OK when there is an Access Eyeglass Zone Replication Error

The Jobs window for an Access Zone replication Job which had a replication error or audit error shows as OK even though an Alarm was issued for the Error.

Workaround: Monitor email for Access Zone replication errors.  Address the replication issues.

—————————————————–

T771: Edit Configuration does not show parent node selected

If a change is made to a Configuration Replication Job to deselect a file sharing object from the job, the parent node where there still are selected objects is no longer selected in the Edit Configuration window.

Workaround: Expand the Inventory View tree for SMB and NFS to see which objects are contained in the Job.

—————————————————–

T805: Eyeglass Configuration Replication Jobs not updated when IP address changed on Source Cluster

An IP address change on the Source Cluster of an Eyeglass Configuration Replication job does not get picked up and the job continues to reference the old IP address resulting in a configuration replication error.

Workaround: Reset Eyeglass to pick up IP address changes for Jobs on the new active cluster

  1. Make a record of the state of all Configuration Replication Jobs in the Eyeglass Jobs window - these states will NOT be preserved on the reset:

    1. Jobs which are Configuration Replication type

    2. Jobs that are DFS enabled

    3. Jobs that are User Disabled

  2. SSH to Eyeglass appliance using admin: sudo -s enter (must use root)  then use admin password (default password: 3y3gl4ss)

  3. set the initial state for all Eyeglass Job types to User disabled

    1. http://documentation.superna.net/eyeglass-PowerScale-edition/Eyeglass-PowerScale-Edition#TOC-igls-adv-initialstate

  4. cd /opt/superna/sbin

  5. ./reset.sh

  6. Once reset completes, go to the chrome browser and refresh the browser and login with the credentials

  7. Now, you need to add both of the cluster using Management subnet SSIP.

  8. Once it is added, open the Job window - now you will see all the Eyeglass configuration replication jobs are in “user disabled” state

  9. .Enable all the Eyeglass configuration Job to DFS Mode if configured

IMPORTANT: You must enable DFS mode before enabling the Job to prevent creation of active shares on target cluster.

  1. Enable all configuration replication job (except ones that were previously User Disabled) and run it


—————————————————–

T593: Eyeglass errors for multiple exports with the same path

If an Eyeglass Configuration Replication Job contains more than one Export with the same path, this may result in an AUDITFAILED state or configuration replication error  for the associated Eyeglass Configuration Replication Job in the DR Dashboard or a configuration replication error.

Workaround: The following workaround is available to address this issue:

  1. Modify exports on the source to add a second path which is a sub-folder of the existing path.  This way Eyeglass will identify each Export uniquely. Example

           Initial State:

            export 1: /ifs/data/folder

            export 2: /ifs/data/folder

           Updated State:

            export 1: /ifs/data/folder

                             /ifs/data/folder/sub-folder

            export 2: /ifs/data/folder


          2) Exports must have different Clients.

—————————————————–


T1792: Eyeglass does not auto-detect PowerScale version changes and may use incorrect API version for Configuration Replication

You may see Inventory errors after upgrading the PowerScale cluster version or adding a cluster to be managed by Eyeglass which has a different OneFS version than clusters already managed due to wrong version of API being used to connect to the cluster.

Workaround: Restart the Eyeglass sca service as per instructions here for sca service:

http://documentation.superna.net/eyeglass-PowerScale-edition/Eyeglass-PowerScale-Edition#TOC-Eyeglass-Processes

—————————————————–

T1851: Eyeglass Configuration Replication Jobs not removed when there is no SyncIQ privilege for the eyeglass service account

If the eyeglass service account has the SyncIQ privilege removed the Eyeglass Jobs are not updated to removed even though the associated SyncIQ policy cannot be retrieved.  The Jobs run successfully with the message “The job has no data to replicate; skipping it.”

Workaround: eyeglass service account must have the SyncIQ privilege as documented in minimum permissions document here:  http://documentation.superna.net/eyeglass-PowerScale-edition/tech-notes/PowerScale-cluster-user-minimum-privileges-for-eyeglass

—————————————————–

T2193 - Export max_file_size setting not replicated correctly

A large export max_file_size parameter is not replicated exactly to target as it is configured on the source which results in an Audit failure during Eyeglass Configuration Replication.  For example:

Source 4611686018427388000

Target: 4611686018427387904

Workaround:  None available. For smaller values such as 1024 or 1048576 this error does not occur.

———————————-

T2757:  Access Zone is not replicated from OneFS 8 to OneFS 7.2

Access Zone is not replicated from OneFS 8 to OneFS 7.2.

Workaround: Create Access Zone and make updates manually.

—————————————————


T1976 - Eyeglass Jobs Window Edit Configuration does not show related Snapshot Schedules

If a Snapshot Schedule Replication Job is selected in the Jobs window, the Edit Configuration option does not mark the Snapshot Schedules which are included in the Job..

Workaround:  Expand the Snapshot Schedule Job in the Jobs window to see the Source Path.  Manually review Snapshot schedule paths. Any Snapshot Schedule where the path is at or below the Job source path will be included in the Job.

———————————-

T2920:  Access Zone Authentication Provider is not replicated to the target cluster

Eyeglass Configuration Replication does not sync the Access Zone Authentication Provider to the target cluster.

Workaround: Add Authentication Provider to the Access Zone manually.

—————————————————

T3629:  Renamed Snapshot Schedule leaves original Snapshot Schedule on the target

After renaming a Snapshot Schedule, the next Configuration Replication cycle creates the new Snapshot schedule on the target but does not remove the Snapshot schedule with the original name such that on the target they both exist.

Workaround: Manually remove the extra Snapshot Schedule from the target.

—————————————————

T14803 Set Job Type AUTOSKIPCONFIG does not create associated jobs until configuration replication runs

When setting job type for an unconfigured job to type SKIPCONFIG the other relaed jobs for snapshot schedule, zone, quota are not created until the next Configuration Replication cycle has completed.

Workaround: None required - next scheduled Configuration Replication job will rectify and create the jobs.

—————————————————

T15258 Unable to create Custom Job

After creating a Custom Job, it is removed from the Job list after the next Configuration Replication cycle runs.

Workaround: None Available

—————————————————

T15321 DFS share name custom suffix may be doubled

If you have configured a custom DFS suffix, if the source share name already has the suffix it may be added again to target share on replication instead of being skipped.

Workaround: It is not expected for source share name to have the DFS suffix. Please contact support.superna.net for assistance.

—————————————————

T15884 Some scenarios in networking API failures during Configuration Replication may not block deletes

Some scenarios remain after resolution in 2.5.5 T12773 where when Eyeglass has an imcomplete view of PowerScale configuration due to a PowerScale API networking API call failure there is a risk of deleting and readding Eyeglass Configuration Replication jobs and losing their settings such as DFS mode or AutoSkipConfing mode or risk of deleting meta data such as SMB shares or NFS exports.

Workaround: In 2.5.6 all new Eyeglass configuration replication jobs will be in unconfigured state. When activating ensure that you are activating in the correct mode: AUTO, DFS or AUTOSKIPCONFIG.

—————————————————

T16888 Configuration Replication fails if SyncIQ Policy source and target path are different and SyncIQ policy path contains special character

For the case where a SyncIQ Policy path contains a special character and the SyncIQ Policy source and target path are different, configuration replication fails for the associated Eyeglass job with the AEC code AEC_NOT_FOUND.

Workaround: Configuration objects such as SMB shares and NFS exports must be kept in sync on the DR cluster manually. To avoid the replication error on each cycle and keep the SyncIQ policy available for failover the Eyeglass Configuration Replication job can be set to AUTOSKIPCONFIG as per instructions .

—————————————————

T16965 Audit does not consider differences on source and target for SMB share property inheritable_path_acl

For the case where an SMB share has been manually created on the target cluster with a different setting for the SMB share property inheritable_path_acl, the Supena Eyeglass compare of the source and target share does not identify the difference and therefore does not update the target share to match the source share.

Workaround: One OneFS manually change the setting for this property, or if the share on the target cluster is not in use delete it and allow Eyeglass to recreate it.

—————————————————

T17618 SPN repair during Configuration Replication Job does not create missing SPNs

The SPN repair component of the Eyeglass Configuration Job does not create missing SPNs.

Impact: This only impacts creation of SPNs for new SmartConnect zones added in Powerscale. This does not affect SPN create/delete during failover.

Workaround: Create required SPNs for new SmartConnect zones in AD manually.

—————————————————

T18812 Error replicating SMB Share Run as Root permission with local user

In some cases where an SMB share permission is configured with run as root and local users the run as root permissions are replicated to the target as regular permissions and also subsequent attempts to update results in a duplicate permission error.

Workaround: To skip replication of share permissions and properties you can follow the steps here to view the shares and exports that are part of the Configuration Replication Job. To skip replication on a share, uncheck it. Once skipped, manual process will be required to keep share properties and permissions up to date on target cluster.

—————————————————

T19177 NFS modify properties which are not client list fails with unresolvable host

If an NFS export property is modified where the property is not an NSF export client and the client list contains unresolvable hosts, the Eyeglass replication job will fail to update the NFS export on the target with an unresolvable host error even if in Eyeglass the ignoreunresolvablehosts setting is set to true. Note that this is not an issue if an NFS export client list is modified as this results in a delete and create of the export since the client list is part of how we uniquely identify the export.

Workaround: Manually update the export on the target cluster to update for new setting.


Features


1138: Eyeglass UI does not block configuration of duplicate remote logging service

Description: If you configure the same remote logging service twice in Eyeglass, the forwarding of logs to the logging service will fail

Workaround: Only configure 1 instance of a remote logging service.

—————————————————–


2224: Eyeglass Cluster Configuration Report runs when Cluster is unreachable

Eyeglass attempts to run the Cluster Configuration Report for Cluster that is not reachable.  The Job is started but does not complete.

Workaround: None available.  Report will run successfully once cluster is reachable.

—————————————————–


2061: Access Zone name for Directory Migration is case sensitive

Check for Access Zone exists on target cluster for Directory migration fails is case sensitive and will fail if Access Zone exists with same name but different case.

Workaround: Access Zone name and case must be identical between source and target for Directory Migration.

—————————————————–

2882: Phone Home Email Disabled

Phone home feature is changing and will be disabled . A new web direct option will be used in a future release.

Workaround: Use the Eyeglass Backup Full Archive function to collect Eyeglass configuration and logs.  Procedure is described in the document

—————————————————–


3037: Configure Remote Logging Services in Eyeglass requires manual steps

After configuring the Remote Log  Consumer in Eyeglass, additional manual steps are required on the Eyeglass appliance to update syslog-ng.conf to enable the service.

Workaround: Please refer to Eyeglass Tech Note Eyeglass PowerScale Remote Logging Service Tech Note section “Setup Eyeglass remote logging manually for log Analysis”.

—————————————————–

T1515:  Eyeglass Shell feature not functioning for RHEL and Centos deployments

If Eyeglass is deployed on a Redhat or Centos operating system the Eyeglass Shell feature does not work.

Workaround: ssh to the Eyeglass server using other tools such as putty.

—————————————————

T3119:  Access Zone Migration Preview does not always display Configuration information

The Access Zone Migration Preview window does not display the shares, exports and quotas that will be migrated if the source path selected for migration does not have an associated SyncIQ policy.

Workaround: Review shares/exports/quota paths manually to determine which configuration data will be migrated for the selected source path.

—————————————————


T3170:  Quota Requests History shows Status of Error for processed requests after failover

After failover, the Quota Requests History will show state for all processed quota requests as error instead of showing the status of the request as it was when the request was processed.

Workaround: Verify from OneFS that the quota settings are as expected.

—————————————————


T4280:  User Storage View may show all quotas instead of only the User Quotas

It may occur that the User Storage View shows all quotas configured instead of just the quotas related to the logged in User.

Workaround: Logout and refresh browser and then log back in and reopen window may clear this condition.  If not, the quota path may be used to determine which quota apply to the logged in user.

—————————————————


T4329:  DR Test Status does not open

When DR Test Job has first been created, the DR Test Status window does not open and shows the error “Readiness data not found.  Please run configuration replication.” even though Configuration Replication has run.

Workaround: DR Status window will open once DR Test Mode has been Enabled.

—————————————————

T4432:  DR Test Mode action on multiple policies do not display in Running Jobs

When multiple DR Test Jobs are selected in the DR Assistant to enable or disable DR Test mode, the Running Jobs window only shows 1 Job even though action is being applied to all selected Jobs.

Workaround: None required - display issue only.  Action completed against all selected jobs.

—————————————————

T4968:  SyncIQ Job Report Troubleshooting section missing information when report is generated on demand

When a SyncIQ Job Report is generated from the Reports on Demand window, the Troubleshooting section may not be populated.

Workaround: Use the scheduled daily report for Troubleshooting information.

—————————————————

T5173:  Quota Modification Request window does not close after Submit

After a Quota Modification Request is submitted, the window does not close and remains in a loading state.

Workaround: None required - display issue only.  Action was completed and the request can be seen in the Pending Requests window.

—————————————————

T6389:  Built-In AD Groups cannot be used with the Cluster Storage Monitor Active Directory Managed Quota feature

When configuring Cluster Storage Monitor AD Group Mode Templates for automated quota creation, AD built-in groups such as "domain users" cannot be used as the users in the group will not be correctly identified.

Workaround: Create new AD Group for quota assignment and add this group to related shares in PowerScale. For additional information on use of AD groups for share security vs quota creation please read.

—————————————————

T8716:  Upgrade issues for Cluster Storage Monitor Quota or Data Recovery requests

After upgrade to new release see following issues for Quota or Data Recovery requests:

1) Data Recovery does not show any pending requests or history

2) Quota Request shows history but with incorrect status

Workaround: None available for history. For Data Recovery pending request, re-issue the request.

—————————————————

T8834:  Storage Monitor Report missing user information when friendly name cannot be resolved

User quotas created for users who are not in the default AD Domain, a friendly name cannot be resolved and quota itself is associated with user SID but in the Storage Monitor Report the user is reported as "user" instead of showing user SID.

Workaround: None available.

—————————————————

T9561:  Unlock my files incorrectly displays directories

Unlock My Files window incorrectly includes directories in the display instead of just files. If a directory is inadvertently "unlocked" it may disconnect clients or have other unexpected results.

Workaround: Do not use unlock for directories.

—————————————————

T11807 Alarm for quota synchronization error does not contain error details

For case where quota synchronization fails (example advisory threshold configured to be greater than hard threshold), an Eyeglass alarm is raised but the alarm does not contain any details of the error.

Workaround: In Eyelgass Jobs / Running Jobs window tree view under "Group Quota Synchronization Steps" navigate down the tree and find the step with an error. The Info link should contain error details if available.

—————————————————

T9652 Unlock My Files inconsistent handling for unreachable PowerScale cluster

For the case where Eyeglass is managing multiple clusters and one or more clusters are unreachable, the Unlock My Files sometimes displays the error "Failed ot search:","Communication failure or timeout searching for open files. Please try again later or try to be more specific in your query.". without displaying results for reachable cluster or may provide results for reachable clusters without providing the error.

Workaround: Resolve PowerScale cluster reachability issue.

—————————————————

T12307 Cluster Storage Usage may be incomplete

When the API request for cluster storage usage is returned from PowerScale with information missing for one or more nodes, the Eyeglass Cluster Storage Usage window may not display all information for the nodes where information was returned. For example for a 4 node cluster if the API response only contains information for nodes 1, 3 and 4 the Cluster Storage Usage window may only display information for node 1 even though node 3 and node 4 information is available.

Workaround: Use PowerScale tools to determine storage usage.

—————————————————

T13390 DR Testing (Disaster Recovery Testing) Job initially always in User Disabled state

When an Eyeglass Job first becomes type Disaster Recover Testing it is always in User Disabled state no matter what state it was in as an AUTO job.

Workaround: Select the checkbox for the Disaster Recovery Testing job and then Select a bulk action / Enable/Disable to enable it.

—————————————————

T14956 No Recovery when DR Test Mode in Entering DR Testing or Exiting DR Testing

If DR Test Mode Make Target Writeable/ Make Target Read-Only does not complete and is left in the Entering DR Testing or Exiting DR Testing state there is no way to revert or retry the operation.

Workaround: To assist in recovery from this state please open a support case at support.superna.net .

—————————————————

T14962 DR Test Mode Configuration Replication step does not run configuration replication for the DR Test mode job itelf

If Configuration Replication option is selected for Make Target Writeable, the DR Test mode job itself is not included and any changes to SMB shares or NFS exports that had not been previously synced will not be present on shares / exports used for the DR Test.

Workaround: Let scheduled configuration replication job run or manually initiate configuration replication to sync SMB shares and NFS exports to the DR Test mode shares / exports prior to initiating Make Target Writeable.

—————————————————

T15215 Data Config (Zone) Migration Job can not be created where Migration or Destination Path contains special characters

A Data Config Migration Job will fail to be created if the Migration or Destination Path contains special characters (example & or ').

Workaround: None Available

—————————————————

T15311 Data Config (Zone) Migration Job fails for existing policy when "Migrate only configuration" is checked

A Data Config Migration Job will fail when there is an existing SyncIQ policy on the migration path and "Migrate only configuration: is not checked.

Workaround: Select "Migrate only configuration" option to sync the configuration items and separately manage SynciQ from PowerScale interface to manage data replication.

—————————————————

T17535 Quota Search - Display of quota count on modify may not be correct

The count of quotas modified displayed on the GUI may not be accurate.

Workaround: Verify via OneFS interface that requested changes have all been made.

—————————————————

T17739 Cannot create quota template for less than 1 GB

Quota template creation for Active Directory Managed Quotas (igls csm template add) does not allow creation of a quota limit of less than 1 GB either by entering less than 1024 MB or a decimal in GB.

Workaround: None available - minimum quota size available is 1 GB.


General


924: Inventory View shows + beside component when there are no more children

Description: In the Inventory View, components for which there are no children still show a “+” in the inventory tree. When you select the “+”, it changes to a “-” but there are no children displayed.

Workaround: None Required.

—————————————–

T17694:   api token download of CMDB file is blocked by desktop login

Description: The API token download access to the servicenow.xml file is blocked by the web server desktop authentication service.

Workaround: Login to the desktop and enter the url https://isilon-eyeglass/servicenow/servicenow.xml to view download the file. API token access requires future release to bypass web server desktop login. 

—————————————–



943: Inventory View not auto-refreshed

Description: Inventory View is not auto-refreshed and if open when a change occurs does not reflect the change.

Workaround: Use the Refresh Now button or close and reopen the Inventory View.

————————————————–

1612,T11989: Some alarms not cleared

Alarms other than the “Replication job failed to run “ are not cleared automatically once the error condition has been resolved. Example, DR Readiness alarm not cleared once readiness is green.

Workaround: Clear the alarm manually from the Eyeglass UI.

—————————————————–


2155: Access Zone Networking info does not display in Inventory View

To see the Networking info for an Access Zone in the Inventory View:

  • the Failover Readiness job has to have run

  • the Access Zone must have an associated SyncIQ Policy

Workaround: Enable Failover Readiness job.

—————————————————–


2628/T15193: Job Definitions window does not sort properly

Click on column headings in Jobs window to sort listings does not sort properly and sometimes lists jobs outside of the category groupings.  

Workaround: None available

—————————————————–


2895: Inventory SPN View is truncated

The Eyeglass Inventory view may be truncated and not display all SPNs stored in the database.

Workaround: Use isi command directly on cluster to determine all SPN.

—————————————————–


2366: EyeGlass does not support special characters in email recipient address

Email addresses in Eyeglass do not support special characters.

Workaround: Do not provision email recipients or Email Server user with email address that has special characters.

—————————————————–


2385: Refresh Now does not refresh the Failover History window

The Failover History window is not updated by the Eyeglass Refresh Now functionality.

Workaround: Close and reopen the Failover History window to see updates.

—————————————————–


2744: Failed to Retrieve Inventory Alarm missing information

For the case where Inventory does not run because another instance of the Inventory Task was already running, the alarm that is raised does not provide this additional information

Workaround: Review the Eyeglass logs at the time that the inventory alarm occurred and search for the string “Another instance of Inventory Task is still running. Not starting”.

—————————————————–


2978: Syslog Log Viewer freezes Eyeglass web page

Opening the Eyeglass Syslog Log Viewer window may cause the Eyeglass web page to freeze.

Workaround: Refresh the Eyeglass web page or Fetch the Eyeglass Main Log first and then Fetch the Eyeglass Syslog.

—————————————————–

T971: Eyeglass End User Interface Tree View Expanders do not collapse

The Eyeglass End User Interface DR Dashboard tree display ‘+’ can be used to expand the tree but then the ‘-’ does not collapse the tree again.

Workaround: Close and reopen the window

—————————————————–

T1514:  Eyeglass Archive cannot be downloaded when Eyeglass is deployed on Redhat or Centos

Eyeglass Backup Archive file cannot be downloaded from the Eyeglass web page if Eyeglass is deployed on a Redhat or Centos operating system.

Workaround: The Eyeglass Backup Archive files are stored here on the Eyeglass server: /srv/www/htdocs/archive/  and can be copied from this location with a tool such as WinSCP.

—————————————————–

T3137 - Eyeglass daily backup not working for RHEL/CentOS Deployments

The scheduled daily backup for Eyeglass is not working for RHEL/CentOS deployments.

Workaround:  Manually create backup file from the Eyeglass GUI:  About/Contact -> Backup -> Create Full Backup

———————————

T4596: Log Viewer cannot fetch logs

Under certain conditions the Log View may not be able to Fetch logs.  

Workaround: Use the About/Contact -> Backup to create a Backup Archive and then download to your local system to review logs.  

The Log View feature will be deprecated in a future release.

—————————————————–

T12370 Network Visualization does not display Pool Readiness

The Network Visualization window Info Tab does not have a section for Pool Readiness. If you have Pool Failover configured you may see the related Access Zone in the Zone Readiness tab or related policies in the Policy Readiness tab. If you select status for that object it will open the DR Dashboard to the selected section not the Pool Readiness sectiion.

Workaround: For assessing Pool Failover readiness open the DR Dashboard and select Pool Readiness.

—————————————————–

T15310 REST API / Widgets creates empty html file

Unable to create web widget for DR Readiness.

Workaound: Use Eyeglass API to retrieve DR Readiness information. Plan to deprecate web widget in 2.5.7.

—————————————————–

T15493 Extraneous Post Failover placeholder scripts

There are extraneous postfailover script provided that are not runnable: script1.sh, script2.py, script3.js .

Workaround: None required. These scripts should be ignored as they contain no examples. The environment_example scripts should be used as a reference.

—————————————————–


T15511 Historical failover logs may lose formatting after a backup & restore

Failover logs retrieved from the Failover History may not have formatting after backup & restore.

Workaround: None required.

—————————————————–

T15647 igls app report issues

The igls app report command to create a dr health summary file does not exit on completion of execution. The report is available for review but the command itself is not exited.

Workaround: Use CtrlC to exit the command.

The igls app report command may report below error and not start.

Starting a log parser service...
sh: /opt/superna/java/jre1.8.0_05/bin/java: No such file or directory

Workaround: Run the report using command below. Once run this way the correct java version should be available to igls app report command as well.

java -jar /opt/superna/bin/LogParserSca-0.0.1-SNAPSHOT-jar-with-dependencies.jar

—————————————————–

T17530 Backup and Restore does not properly set location/permission for Eyeglass log files

After restoring Eyeglass backup , the Eyeglass log files location and/or permission is not properly set.

Workaround - 2.5.6-20258: Follow the steps below after the restore to correctly set log location:

1. SSH to Eyeglass VM (user: admin, default password: 3y3gl4ss)

2. sudo su (enter admin password)

3. execute below command

cd /opt/superna/sca && mkdir -p /opt/data/superna/sca/logs && cp -af logs/* /opt/data/superna/sca/logs && rm -rf logs && ln -s /opt/data/superna/sca/logs && chown -R sca:users /opt/superna/sca/logs

4. Done

Workaround - 2.5.6-20263: Follow the steps below after the restore to correctly set log location:

1. SSH to Eyeglass VM (user: admin, default password: 3y3gl4ss)

2. sudo su (enter admin password)

3. execute below command

cd /opt/superna/sca && chown -h -R -L sca:users /opt/superna/sca/logs

4. Done

—————————————————–

T17408 Role Based Access Control doesn't handle user names with special characters

RBAC can be setup with users that have special characters or language specific characters or groups where users have special or language characters, but on login the name is not resolved properly and the proper role is not assigned. User gets read only desktop view.

Workaround: None available

—————————————————–

T19208 Too many open files

If Eyeglass is also managing Ransomware Defender, Easy Auditor or Performance Auditor, under some circumstances when the ECA is unhealthy over a period the heartbeat loop results in condition where Eyeglass is in an error state related to too many open files. Impact once file limit is reached is that application no longer functions properly and eventually will restart.

Workaround: Contact support.superna.net for assistance.


Superna Eyeglass Known Limitations

Known Limitations for PowerScale OneFS 8.0.0.x with Eyeglass


T507 Cluster Report for OneFS 8.0 missing information

The Eyeglass Cluster Configuration Report for OneFS 8.0 is missing following information:

  • DNS and Subnet information

  • File System Explorer

  • Protocols - new HDFS, FTP, HTTP settings




Known Limitations for Eyeglass Failover

T939  Eyeglass Access Zone Replication Job in Error after failover

The Access Zone Replication Job associated with the SyncIQ mirror policy configuration replication Job has the following error when the SyncIQ policy source and target path are not identical.

Workaround:  Create and update Access Zones manually on source and target cluster and disable Eyeglass Access Zone replication Jobs.  With the Eyeglass Access Zone replication Jobs disabled, the Zone Configuration Replication Readiness Jobs will have a status of Unknown.  This does not block failover.

T1785  Cannot set ignore flag on subnet pool after failback

It is not supported to apply an igls-ignore flag on a subnet pool that has been failed over and failed back such that the SmartConnect Zone has an igls-original prefix due to the fact that on a subsequent failover the igls-original prefix will not be removed and will leave the Access Zone in a state where both directions are failed over.

Workaround:  Manually edit SmartConnect Zone on active cluster to remove the igls-original prefix.  Run Configuration Replication and then run the Failover Readiness job to update Zone Readiness.


T2479: Access Zone Failover fails between OneFS 7.2 clusters if Eyeglass also managing OneFS 7.1

For the case where Eyeglass is managing OneFS 7.2 and OneFS 7.1 clusters, an Access Zone failover between OneFS 7.2 clusters will fail as OneFS7.1 linmap command is attempted and fails.

Workaround: Access Zone failover in this Configuration is unsupported as for Eyeglass Inter-version management, it is expected to apply capabilities of lower versions to all versions being managed and Access Zone failover for OneFS 7.1 is not supported. No workaround required.

T3258: Cannot start failover while Eyeglass initial inventory is running

For the case where Eyeglass has been restarted and the initial inventory is running for initial discovery, while the initial inventory is running a failover cannot be started.  A “Failover configuration is not valid” message will be displayed in the GUI followed by a message that the target cluster is not managed by Eyeglass.

Workaround: Wait for initial inventory to completed before initiating a failover.   Check running jobs windows for the initial inventory job to show completed.

T3774: Failover relies on policy naming: <policy name> and <policy name_mirror>

The Superna Eyeglass failover relies on following naming conventions:

  1. First failover A to B- policy name = <policy name>.

The first failover name cannot be <policy name>_mirror.

  1. Second failover B to A - policy name = <policy name>_mirror.

Workaround: Manual process on naming the convention above must be followed.

T4808: SPNs not updated for new authentication providers after Access Zone settings changed to “Use all authentication providers” (OneFS 7.2)

If an Access Zone is modified from manually defining the authentication providers to using the “Use all authentication providers” setting in OneFS 7.2, Eyeglass will not update SPNs for any new authentication providers that where not previously provisioned.

Workaround: Manual process required to create these SPNs.

T6229: Existing Failover Logs cannot be reviewed after upgrade to Eyeglass R2.0

Failover logs which were generated from previous releases cannot be viewed from the Eyeglass DR Assistant Failover History view after upgrade to Eyeglass R2.0

Workaround: Generate an Eyeglass Backup and download to your local machine.  The Failover logs are contained in the backup archive in the folder failover_logs.

T14321 Zone/Pool Failover Readiness for AD Delegation validation, SPN Readiness validation not supported for Multi-Site failover configuration

For multi-site failover configuration the AD Delegation validation is not supported as it runs in parallel for both the A -> B and A->C resulting in conflicts and errors for both the self and cross AD delegation testing.

For multi-site failover configuration SPN Readiness validation is not supported as there are 2 pools on the B and C clusters with the same igls-original.... SmartConnectZone name and this cannot provisioned in AD as it does not support duplicate SPNs.

Workaround: For multi-site failover manual verification for AD delegation can be done as documented .

SPN Readiness validation warning cannot be disabled and after manual verification that correct SPNs are present can be ignored.

T15611 Pool Readiness Alarms are reported per Zone

Instead of reporting Pool Readiness alarms per Pool they are reported against the Access Zone that is configured for Pool Failover.

Workaround: None required.

DNS Dual Delegation Failover Readiness Validation Supported DNS servers

DNS Dual Delegation Failover Readiness validation is only supported by design for Microsoft DNS server. This validation must be disabled if any other DNS server is being used. This can be done from the Eyeglass command line using the command: igls adv readinessvalidation set --dualdelegation=false 

T17254 Failover does not take into account Powerscale job retries

In some cases Powerscale will retry a job after it fails and eventually if it succeeds the overall status of the job remains in Needs Attention. Failover logic takes the success / fail status from the first attempt only.


T18556 User Quota Replication requires System Access Zone AD Provider

The API used for creating user quotas requires System Access Zone to be configured with an AD provider to be able to resolve the user SID. If the user SID cannot be resolved the quota creation will fail with the error AEC_BAD_REQUEST "Requested persona was not of user or group type".

Workaround: Add an AD provider to the System Access Zone that has a trust relationship with the other domains in other Access Zones in order for SIDs to be resolved.


Known Limitations for Eyeglass Configuration Replication

Multi-Path Exports

T1359  Update NFS Multi-Path Export path(s) may cause transient Configuration Replication Error

Eyeglass uniquely identifies an NFS Export based on its path.  When the path is changed this results in a Create and Delete operation in Eyeglass.  It may occur that the create is attempted before the Delete is executed. In this case a Configuration Replication error occurs.  This is automatically resolved in the subsequent replication cycle when the new export is successfully created.

Export cannot have multiple paths that span multiple Eyeglass Jobs

Export with multiple paths that are protected by different SyncIQ policies is not supported.  This export configuration is not supported for DR as it would not allow per policy failover and is an unsupported configuration for Eyeglass.

The solution for this is to split the single export into multiple exports each with paths that correspond to a single SyncIQ policy.


T1359  Update NFS Multi-Path Export path(s) may cause transient Configuration Replication Error

Eyeglass uniquely identifies an NFS Export based on its path.  When the path is changed this results in a Create and Delete operation in Eyeglass.  It may occur that the create is attempted before the Delete is executed. In this case a Configuration Replication error occurs.  This is automatically resolved in the subsequent replication cycle when the new export is successfully created.

T1743  Multiple export with same path and same client do not show Configuration Replication Error

Multiple exports with the same path are required to have different clients in order to be replicated as per PowerScale default behaviour.  In the case where they have been provisioned with same client, Eyeglass Configuration Replication will only show error for this condition on the second configuration replication cycle.

T1847  OneFS 8 Overlapping Access Zone Replication has error

In OneFS 8 where there are Access Zones have identical paths, Eyeglass Access Zone Replication will fail with the following error from the PowerScale cluster:  AEC_CONFLICT “field” “path” “message” “access zone base path \*/ifs\* overlaps with base path \*/ifs/data/zone\* in Access Zone Use the force overlap option to override. In this case disable Eyeglass Configuration Replication Jobs for Access Zones and manually create the Access Zone on the target cluster.

T1972  Snapshot schedule replicated with offset

Snapshot schedule expiration offset has OneFS API bug that adds extra time to snapshot expiration when the snapshot schedule is created.  This results in an expiration on the DR cluster, that can be greater than entered on the source cluster. example expire in 20 days will be 22 days on the target cluster.  Different units of off set all result in a value greater than entered. After failover the DR (target cluster) value will be synced back to the source (Prod cluster). Thereby losing the original expiry offset  and extending the expire time by a new offset from the API error. This has been raised with EMC as SR to resolve.

  1. Work around:  Before failover ensure a cluster report has been generated (cluster reports icon), or an existing emailed cluster report exists.   Post Failover re-enter the original values on the DR snapshot schedules using the cluster report values from the source cluster as a reference.

  2. Another option is disable Snapshot Sync jobs in the jobs window if the above workaround does not meet your needs to preserve expiry of snapshot settings.

UPDATE: Resolution for this OneFS issue is available in OneFS 8.0.0.3

T2046  Access Zone Replication limitation when all user mapping rules are deleted

Access Zone Replication successfully creates and updates user mapping rules and also successfully deletes user mapping rules except when all user mapping rules are removed from the source.  In the case where all user mapping rules are deleted from the source, the Access Zone configuration replication job will not delete all on the target - the user mapping rules remain on the target.

T2241  Incorrect missing SPN alarm issued when PowerScale cluster joined to multiple Domains

In an environment where the PowerScale cluster is joined to multiple Domains, the OneFS SPN check command for a specified domain returns list of SPNs from other domains and lists them as missing.  In this case Eyeglass issues an SPN alarm for missing SPNs based on the list returned even if there are no missing SPNs in the domain specified in the check command.


T2779 - Eyeglass Configuration Replication “Full Sync Mode” always updates when Default Settings on Source and Target cluster are not the same

If on the Source and Target cluster for an Eyeglass Configuration Replication Job the “Default Settings” say for SMB are not the same, each replication cycle will perform an update operation even though the shares are already synced and identical.  Making the Default Settings the same for both clusters will eliminate this behaviour and return to expected behaviour to not perform the update when shares are determined to already be identical.

T2780  Same host moved to different NFS Export Client list not updated on target

For the cases where:

  • same host is provisioned on multiple client list and then one host is removed

  • Same host is moved from one client list to another

The change in NFS client list is not replicated to the target cluster.  Target cluster client list must be updated manually.

T2908  New Eyeglass Configuration Replication Job cannot recover state and mode from the Eyeglass Fingerprint file.

When a SyncIQ Policy is renamed, Eyeglass considers it to be a new SyncIQ Policy and therefore creates a new Eyeglass Configuration Replication Job with the new name.  The Eyeglass Fingerprint file which holds Eyeglass Configuration Replication Job Mode and State for recovery does not link the original Job name with the new name and can therefore not be used to recover these properties for the new Eyeglass Job.


T4289  Delete Share or Export may result in temporary Audit error

After a share or export is deleted as part of Eyeglass Configuration Replication Job, the next Eyeglass Configuration Replication Job Audit task may incorrectly expect that the object is not deleted resulting in a alarm such as “ Replication job audit failed" - "objects not found on source or target cluster, hence audit fails” .  The error is cleared on the next Eyeglass Configuration Replication Job where the Audit task correctly does not try to audit the deleted object.


T5972  No Error Message for Duplicate NFS Export on OneFS 7.2 Configuration Replication Failed

Duplicate NFS Export on OneFS 7.2 Configuration Replication failure is expected, however in this case there is no specific Info associated with failed step to identify the issue.


T14936 Short SPN not created during Configuration Replication

Eyeglass Configuration Replication will only create full version of SPN, no short version is created. Note that Access Zone and Pool Failover update both short and full version of SPN. If short version is required it can be manually added using AD tools.


T17097 Eyeglass Configuration Replication direction follows Enable/Disable state of SyncIQ policies

Eyeglass Configuration Replication source cluster is the cluster of the enabled SyncIQ policy. If there is a mirror policy and both SyncIQ policies are enabled Eyeglass enters a defensive state showing Policy Disabled for both and no Configuration Replication is done. If a SyncIQ policy is mistakenly enabled on the read only cluster Eyeglass does not evaluate the read/write state and will use the read only cluster as the source cluster for its Configuration Replication job.


Known Limitations for Eyeglass Features

T2350:  Quota Self Serve Portal: Local Group Quotas not displayed when logged in with Local Group User

Quotas associated with a Local Group (for example wheel) are not displayed in the Quota self serve portal when logged in as a Local Group User for that group.


T1962: Default Role incorrectly shows Delete option

Eyeglass User Roles Default Roles incorrectly provide the option to be deleted when in fact they cannot be deleted.

Workaround: None Required.  If the Delete option is selected the Default Role is not deleted.

T7980: Cluster Storage Monitor AD Group Template Quota Creation does not created group quota for nested AD Groups

If an AD Group has sub-groups (nested groups) is configured as a Template for automated group quota creation, no group quotas will be created for sub-groups.

Workaround: Each group that requires automated group quota creation must be explicitly added to the relevant share permissions.

T8362: Cluster Storage Monitor AD Group Template Quota Creation does not respect highest quota settting user quota in nested AD Groups

If an AD Group has sub-groups (nested groups) is configured as a Template for automated user quota creation, user quota creation follows explicitly the quota limit for the sub-group when the user already has a quota for a higher limit. In this case, what should have happened is that template setting is ignored if there is already an existing user quota with a higher limit.

Workaround: Avoid use of nested AD groups for automated user quota creation.



T8193: special charaters in Cluster storage monitor AD managed quota templates is not supported

If an AD Group templates, if the AD group name has special characters in the AD group name the quotas will not be applied.

Workaround: Avoid use of special characters when creating AD groups for AD managed quotas.

T9622: Unlock My Files! does not indicate error when PowerScale node is not reachable

If an PowerScale node is unreachable when Eyeglass is searching for open files there is no error message for the unreachable PowerScale nodes.

Workaround: None available.No open files displayed for unreachable nodes.

T15139 Data Config Migration Concurrent Jobs Limitation

When 2 Data Config Migration Jobs are started concurrently, each runs a separate Configuration Replication Job and the Configuration Replication Job cannot run concurrently. First one must complete before the second one can start.

Workaround: Recommend to run 1 Data Config Migration job at a time.


Known Limitations for Eyeglass General

T2289  Backup Archive Job is not always displayed in the Running Jobs window

In some cases after a Backup Archive job is initiated it will not appear as a running task in the Jobs / Running Jobs window.  Archive is still created and available for download on completion.

T2908  Renamed SyncIQ Policy does not link to RPO Reports from original SyncIQ Policy Name

When a SyncIQ Policy is renamed, Eyeglass considers it to be a new SyncIQ Policy.  Therefore RPO Reporting for the original SyncIQ Policy name will not be linked to RPO reporting for the new SyncIQ Policy name.


T3170 Pending Quota Requests are not preserved on failover

If a failover is done while there are Quota Pending Requests, the Pending Requests are lost as the quota to which the request was originally made no longer exists on the original cluster after failover.  The pending quota request will appear in the Quota Requests History in Error state.


T4579 Upgrade from 1.5.4 to 1.9 and greater Failover History retrieves Failover Log for SyncIQ Job Reports

After an upgrade from 1.5.4 to 1.9 or greater, in the DR Assistant -> Failover History list the link to open SyncIQ Job Reports opens the Failover Log due to fact that prior to this release Failover Log and SyncIQ Job Report log were combined.  In this case you are able to see the SyncIQ Job Reports related to failover at the bottom of the Failover Log.

T6300 After an Eyeglass restore with the -anyrelease option the print screen functionality for SyncIQ Job Reports and Eyeglass backups may be in error

After an Eyeglass restore to a new appliance using the --anyrelease option, print screen functionality may no longer be working due to a incorrect permission setting.  This impacts SyncIQ Job Reports which will be missing the charts and generating an Eyeglass backup with print screens.

To workaround this issue:

1) ssh to the eyeglass appliance and login with the admin account (default password 3y3gl4ss)

2) assume root user by typing

sudo su -

And entering the admin password

3) vi /opt/superna/sca/data/Screenshots.json and write "<placeholder>" as a value in the "plain_text" field and then save it.
4) Copy and paste the following commands:

str=$(sudo cat /dev/urandom | tr -dc 'a-zA-Z' | fold -w 12 | head -n 1)

echo -e "$str\n$str" | passwd screenshots

sed -i "s/<placeholder>/$str/" /opt/superna/sca/data/Screenshots.json

  5) Start a backup with print screens and follow in Running Jobs to verify the backup completes successfully.


T12034 Eyeglass appliance rediscover does not preserve Eyeglass Job state unless Configuration Replication has run

If a change is made to an Eyeglass Job state or Job type and then there is an appliance rediscover before configuration job has been run the changed Job state / type will be lost.


T16137 Anyrelease restore does not restore all Ransomware Defender and Easy Auditor settings

There is no restore of settings from release 2.5.4 and earlier. For release 2.5.4 and earlier continue to capture all Ransomware settings (False Positive, Ignore List, Allowed Extensions, Security Guard) and Easy Auditor settings (Active Auditor Trigger settings, RoboAudit). Post restore verify settings and update where required before cluster up on ECA.

In all cases, restoring an Eyeglass backup using the --anyrelease option will not restore following Ransomware Defender and Easy Auditor settings:

Ransomware Defender: Event History, Threats Detected

Easy Auditor: Finished Reports, Scheduled Reports, Saved Queries

T16729 Role Based Access Control (RBAC) Known Limitations

- Isilon local users are not supported (Eyeglass local users are supported)

- Eyeglass doesn't resolve AD groups with @ & or ' in the name

© Superna Inc