Security Lab — NetApp DC/DR storage roadmap

Roadmap for simulating real-world NetApp data center and disaster recovery storage operations.

This roadmap defines a NetApp storage track for real-world DC/DR learning. The goal is to practice operational behavior, not benchmark performance: SVMs, NFS, iSCSI, snapshots, SnapMirror, failover, failback, OpenShift CSI, and DR evidence.

Target Outcomes

OutcomeWhat good looks like
Storage administrationCreate SVMs, volumes, LIFs, export policies, LUNs, igroups, snapshots, and quotas
DC/DR designModel DC1 and DC2 as separate ONTAP clusters
Recovery operationsFail over NFS and iSCSI workloads to DR and document the exact steps
OpenShift integrationUse NetApp Trident as CSI with ONTAP NAS and SAN backends
Replication operationsPractice SnapMirror async, break, resync, reverse resync, and SVM-DR concepts
EvidenceProduce runbooks, validation outputs, screenshots, and change records
SiteComponentsPurpose
DC1ONTAP cluster, client VM, optional OpenShift workersPrimary production storage
DC2ONTAP cluster, client VM, optional OpenShift workersDR target and recovery site
Shared managementDNS, NTP, monitoring, jump host, Git repoCommon enterprise services
Optional securityWazuh, Security Onion, GreenboneManagement telemetry and vulnerability visibility

Suggested networks:

NetworkExampleUse
Management30.30.30.0/24ONTAP management, System Manager, SSH, API
DC1 storage172.31.10.0/24NFS/iSCSI data LIFs and client access
DC2 storage172.31.20.0/24DR-side NFS/iSCSI data LIFs and client access
Replication172.31.30.0/24SnapMirror intercluster LIFs

Platform Choice

OptionUse it forLimits
ONTAP SimulatorCLI, System Manager, SVM, volume, NFS, SMB, iSCSI, snapshot, and SnapMirror learningBest-effort simulator support, no real performance, limited hardware behavior
ONTAP Select 90-day evaluationCloser VM-based ONTAP behavior, HA, SnapMirror synchronous concepts, larger DR workflowsOfficial eval deployment expects VMware/vCenter
Cloud Volumes ONTAP / FSx for ONTAPCloud DR and hybrid replication conceptsCloud cost and account setup
NetApp Labs on DemandMetroCluster and curated advanced labsExternal lab access

Start with ONTAP Simulator if the immediate goal is learning. Use ONTAP Select when the lab needs more realistic VM-based behavior.

Phase Roadmap

PhaseGoalExit criteria
Phase 0 — Design and guardrailsChoose platform, IP plan, naming, custody rules, and runbook structureArchitecture drafted and no vendor artifacts committed
Phase 1 — Single-site foundationsBuild DC1 ONTAP, SVM, NFS, iSCSI, snapshots, Linux host accessNFS and iSCSI work from Linux; snapshot restore documented
Phase 2 — SnapMirror async DRBuild DC2, peer clusters/SVMs, replicate NFS and SAN volumesDC2 can serve recovered data after planned SnapMirror break
Phase 3 — SVM-DR modelPractice SVM-level replication and activationDecision matrix for volume SnapMirror versus SVM-DR
Phase 4 — OpenShift and Trident CSIUse ONTAP as Kubernetes/OpenShift storage backendPVCs dynamically provision from ONTAP NAS and SAN backends
Phase 5 — BFSI DR scenariosRun realistic DR drillsPlanned DR, accidental delete, corruption recovery, and failback evidence exists
Phase 6 — Governance and monitoringAdd access control, logging, scanning, and evidence disciplineStorage management boundaries and monitoring notes are documented
Phase 7 — Advanced topicsSnapMirror sync, MetroCluster theory, BlueXP DR, automationAdvanced designs documented separately from supported lab facts

First Four Weeks

WeekTarget
Week 1Download ONTAP Simulator or ONTAP Select eval, define IP plan, deploy first ONTAP node
Week 2Create SVM, NFS volume, iSCSI LUN, Linux host access, and snapshot restore runbook
Week 3Deploy DC2, configure peering, baseline SnapMirror async
Week 4Run planned DR drill, reverse resync, publish evidence

BFSI DR Scenarios

ScenarioWhat to prove
Planned DR testApplication can run from DC2 without corrupting DC1 replication
Primary volume lossRecover from latest replicated snapshot
Accidental deleteRestore from local snapshot before invoking DR
Ransomware-style corruptionIdentify clean snapshot and recover to isolated volume
Storage maintenanceMigrate workload access without losing documented pathing
DR failbackReverse resync and return production to DC1

Download Rules

  • Download ONTAP Simulator, ONTAP Select, and related tools only from NetApp official sources.
  • Store images under a local ignored path such as /home/ze/Softwares/netapp-images/.
  • Record filenames, checksums, versions, and source page URLs.
  • Do not commit NetApp software, licenses, session cookies, entitlement screenshots, or private download URLs.

Source Notes

  • NetApp ONTAP Simulator download guidance: https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Where_can_the_NetApp_ONTAP_9_Simulator_be_downloaded
  • ONTAP Select 90-day evaluation deployment: https://docs.netapp.com/us-en/ontap-select-9181/deploy-evaluation-ontap-select-ovf-template.html
  • SnapMirror disaster recovery: https://docs.netapp.com/us-en/ontap/concepts/snapmirror-disaster-recovery-data-transfer-concept.html
  • SnapMirror synchronous disaster recovery: https://docs.netapp.com/us-en/ontap/data-protection/snapmirror-synchronous-disaster-recovery-basics-concept.html
  • SnapMirror SVM replication: https://docs.netapp.com/us-en/ontap/data-protection/snapmirror-svm-replication-concept.html
  • ONTAP Select HA: https://docs.netapp.com/us-en/ontap-select/concept_ha_config.html
  • NetApp OpenShift storage options and Trident: https://docs.netapp.com/us-en/netapp-solutions-cloud/openshift/os-solutions-storage-options.html

Private Repo

The detailed tracked roadmap lives in:

/home/ze/codex-security-lab-agent/docs/NETAPP_DC_DR_STORAGE_ROADMAP.md

Last reviewed: 2026-05-13