Creating a cluster peer relationship (ONTAP 9.4 and later)
You can use the cluster peer create command to create a peer relationship between a local and remote cluster. After the peer relationship has been created, you can run cluster peer create on the remote cluster to authenticate it to the local cluster.
Before you begin
You must have created intercluster LIFs on every node in the clusters that are being peered.
The clusters must be running ONTAP 9.4 or later.
About this task
Beginning in ONTAP 9.4, you can use the generate passphrase feature to create a peer relationship with a cluster whose intercluster LIF IP addresses you do not know in advance. This eliminates the need for the initiating cluster to authenticate itself to the remote cluster.
In a typical scenario, the administrator at the data protection destination cluster runs cluster peer create with the -generate-passphrase option, sending a copy of the output to the administrator at the data protection source cluster:
cluster02::> cluster peer create -generate-passphrase -offer-expiration 2days -initial-allowed-vserver-peers vs1,vs2
Passphrase: UCa+6lRVICXeL/gq1WrK7ShR
Expiration Time: 6/7/2020 08:16:10 EST
Initial Allowed Vserver Peers: vs1,vs2
Intercluster LIF IP: 192.140.112.101
Peer Cluster Name: Clus_7ShR (temporary generated)
The source cluster can then use the generated password to authenticate itself to the destination cluster, as long as it does so within the specified expiration period. The passphrase can be used by one cluster only.
Beginning in ONTAP 9.4, you can pre-authorize
peer relationships for multiple SVMs on the initiating cluster by listing the SVMs in the -initial-allowed-vserver option when you create a cluster peer relationship. You can specify *
to pre-authorize all of the SVMs on the initiating cluster.
Beginning in ONTAP 9.6, cluster peering encryption is enabled by default on all newly created cluster peering relationships. Cluster peering encryption must be enabled manually for peering relationships created prior to upgrading to ONTAP 9.6 or later. Cluster peering encryption is not available for clusters running ONTAP 9.5 or earlier, so both clusters in the peering relationship must be running ONTAP 9.6 or later in order to manually enable cluster peering encryption.