DOCS ONTAP 9.19.1 RELEASE Jul 28, 2026
docs.netapp.com dated 2026-07-28: SnapMirror active sync adds transparent failover for AIX on 2-node clusters (symmetric active/active, zero RPO) and supports NAS SVM-level failover on AFF (2-node) and AFX (4-node); SnapMirror cloud raises to 100 S3 buckets per relationship; SnapMirror synchronous gains tamperproof snapshot locking plus scheduled-snapshot replication to the destination volume. NFSv4.2 support is now managed per-SVM (independent of NFSv4.1) and is on by default for new NFS services. The system-defined failover group policy for NAS data LIFs expands failover targets to any available node (was: only one other node, which could strand LIFs if that node failed). TCP performance improvements integrate PRR (default-on) and RACK (opt-in, recommended for ~25 Gbps congested WANs) loss-recovery into the ONTAP TCP stack for lossy/high-latency WAN links. NAS small-directory listings (<25K files, <2MB) get more CPU, removing the FlexCache workaround for high-client-count directory enumerations. Direct-attached FC without switches is supported on AFF/ASA/FAS adapter ports. S3 gains conditional writes/deletes with enforcement and dual S3 user access keys for access-key rotation. Security: TLS offload for NFS-over-TLS leverages NIC resources; NFS-over-TLS 1.3 with optional per-LIF mutual TLS host authentication; ARP/AI now protects SnapMirror synchronous (NAS+SAN, FAS/AFF/AFX) and SnapMirror active sync SAN (AFF/ASA r2); WebAuthn `-rp-domains` locks down the FIDO2 relying-party domain for System Manager MFA. ARP "surge" presentation removed from System Manager UI (CLI/API still surface it) since surge was frequently misread as ransomware.
The admin lesson: if you run MetroCluster IP, AFF A-series, ASA, FAS, or AFX on 9.16+, plan an upgrade soon: 9.19.1 adds active sync for AIX and NAS workloads, ARP/AI coverage for sync-replicated volumes, and LIF failover improvements that fix the "out-of-quorum stuck node" failure mode. Re-tune NFSv4.2 + NFS-over-TLS to align with your encryption posture, and re-baseline ARP alerts off CLI/API rather than the System Manager dashboard.