ONTAP 9.19.1 release notes: what’s new, ASA r2 changes, and upgrade guide
One canonical administrator’s view of ONTAP 9.19.1 features, ASA r2 changes, upgrade preparation, advisories and authoritative release notes.
What’s new in ONTAP 9.19.1
Data Protection
- SnapMirror active sync for NAS — Adds SVM-level NFS and SMB protection on supported 2-node AFF and 4-node AFX configurations; read-write access remains primary-only. Official source.
- Tamperproof locking and scheduled snapshots for SnapMirror synchronous — Synchronous relationships can lock snapshots and replicate scheduled snapshots to the destination. Official source.
Networking
- Direct-attached FC hosts — Permits direct FC and FC-NVMe host attachment to supported AFF, ASA and FAS adapter ports without FC switches. Official source.
- Broader NAS LIF failover targets — The system-defined policy can select available ports across the broadcast domain instead of being limited to one other node. Official source.
Security
- NFS over TLS 1.3 — Encrypts NFS traffic in transit and can use mutual TLS authentication and export-policy enforcement. Official source.
S3/Object
- Conditional S3 writes and deletes — Helps clients prevent unintended object overwrite and deletion. Official source.
- Two access keys per S3 user — Allows access-key rotation without interrupting a client that still uses the original key. Official source.
Arp/Ai
- ARP/AI support with synchronous replication — Protects active read-write primary volumes in supported SnapMirror synchronous and active sync relationships; ARP snapshots are not replicated. Official source.
Performance
- Small-directory listing enhancement — Assigns more CPU to highly concurrent listing of NAS directories up to about 2 MB or 25,000 files; no configuration is required. Official source.
- Configurable automatic QoS ceiling behavior — Makes the defaults controlling temporary QoS throughput-ceiling increases configurable. Official source.
ASA r2 changes in 9.19.1
- AIX with SnapMirror active sync — Transparent Application Failover for AIX is supported in symmetric active/active configurations. ASA r2 release notes.
- FLI with iSCSI backend connectivity — Foreign LUN Import adds iSCSI as a backend connectivity protocol. ASA r2 release notes.
- Direct-attached FC — FC and FC-NVMe hosts can attach directly to ASA r2 FC adapter ports without an FC switch. ASA r2 release notes.
- ARP/AI with SnapMirror active sync — ARP/AI protects primary read-write storage units; detection and ARP snapshots remain on the active primary. ASA r2 release notes.
- TLS hardware offload — Supported Ethernet cards can offload TLS encryption and decryption to reduce CPU overhead. ASA r2 release notes.
Upgrade information
NetApp’s path table documents direct upgrades into 9.19.1 from 9.16.1, 9.17.1, 9.18.1. “Direct” does not waive hardware, host, switch or minimum-patch checks.
Pre-flight commands
cluster image show
system node image show
system health alert show
storage failover show
network interface show -fields home-node,home-port,curr-node,curr-port,status-oper
cluster peer health show
snapmirror show -fields status,healthy,lag-timeRun the automated pre-checks through System Manager or the documented cluster image validate workflow for your image and resolve errors before scheduling the upgrade.
Known post-upgrade gotchas
- 9.16.1, 9.17.1 and 9.18.1 have documented direct upgrade paths to 9.19.1; verify the live path table for the exact source patch and platform.
- Upgrade the source train to its latest patch release first, then validate Hardware Universe and the Interoperability Matrix.
- Automated pre-upgrade checks separate errors from warnings in 9.19.1; errors must be resolved before proceeding.
- A pre-update warning is expected where ARP/AI default enablement had been suppressed by synchronous replication; 9.19.1 can restore it automatically.
Release notes and primary sources
The public “What’s new” pages describe features. NetApp’s detailed Release Notes require a NetApp account and remain authoritative for known issues, limitations and cautions.
ONTAP 9.19.1 vs 9.18.1
| Capability | What changed in 9.19.1 | Why an admin cares |
|---|---|---|
| Synchronous protection | NAS active sync, AIX transparent failover, snapshot locking and scheduled-snapshot replication additions. | More workloads qualify, but topology and primary-write restrictions need design review. |
| NFS security | NFS over TLS 1.3 with optional mutual TLS. | Plan certificates, LIF policy and client compatibility. |
| SAN connectivity | Direct-attached FC and wider automatic SAN LIF failover support. | Revalidate host multipathing and failover behavior. |
| S3 | Conditional writes/deletes and a second user access key. | Safer concurrency and non-disruptive credential rotation. |
| ARP/AI | Coverage expands to supported synchronous relationships and suppressed defaults can be restored during upgrade. | Review the pre-update warning and alerting runbook. |
| Performance | Small-directory listing improvement and configurable QoS ceiling behavior. | Retest directory-listing workarounds and automation around QoS. |
Admin impact: what changes operationally
- May break assumptions: NAS LIFs can fail over more broadly; SAN path behavior and new NFS-service defaults deserve regression testing.
- New command surface: WebAuthn adds
-rp-domains;volume show-spaceoutput gains directory context, so check parsers. - Needs planning: NFS TLS certificates, direct FC topology, synchronous-protection constraints, S3 key rotation and ARP/AI enablement.
Security & advisories affecting the ONTAP 9.19 train
- NTAP-20260722-0001: CVE-2026-22049 WebAuthn MFA Bypass Vulnerability in ONTAP 9 Final
- NTAP-20260610-0001: June 2026 Apache HTTP Server Vulnerabilities in NetApp Products Interim
- NTAP-20260529-0002: CVE-2026-5946 ISC BIND Vulnerability in NetApp Products Interim
- NTAP-20260501-0006: CVE-2026-42512 FreeBSD Vulnerability in NetApp Products Final
- NTAP-20260501-0005: CVE-2026-42511 FreeBSD Vulnerability in NetApp Products Final
- NTAP-20260501-0002: CVE-2026-35547 FreeBSD Vulnerability in NetApp Products Final
- NTAP-20260327-0004: CVE-2026-3783 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20260327-0003: CVE-2026-3784 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20260327-0002: CVE-2026-1965 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20260327-0001: CVE-2026-3805 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20260313-0014: Intel SA-01171 Ethernet Controller Vulnerabilities in NetApp Products Interim
- NTAP-20260220-0013: CVE-2026-0990 Libxml2 Vulnerability in NetApp Products Interim
- NTAP-20260213-0015: CVE-2025-14524 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20260204-0012: CVE-2025-11187 OpenSSL Vulnerability in NetApp Products Interim
- NTAP-20260204-0006: CVE-2025-69420 OpenSSL Vulnerability in NetApp Products Interim
- NTAP-20260204-0005: CVE-2026-22795 OpenSSL Vulnerability in NetApp Products Interim
- NTAP-20260116-0019: CVE-2024-25062 Libxml2 Vulnerability in NetApp Products Interim
- NTAP-20260109-0004: CVE-2025-24296 Intel Ethernet Controller Vulnerability in NetApp Products Interim
- NTAP-20251031-0007: CVE-2025-9086 Libcurl Vulnerability in NetApp Products Interim
- NTAP-20250718-0013: July 2025 Apache HTTP Server Vulnerabilities in NetApp Products Final
- NTAP-20250711-0004: CVE-2025-4516 Python Vulnerability in NetApp Products Final
- NTAP-20250425-0006: CVE-2024-9287 Python Vulnerability in NetApp Products Final
- NTAP-20250411-0005: CVE-2024-0450 Python Vulnerability in NetApp Products Interim
Scope note: included only when the archive contains an ONTAP remediation link for the 9.19 train. Confirm vulnerable and fixed patch levels in each advisory.
Related Black Box pages
- ONTAP release and upgrade guide
- 9.19.1 admin field guide
- ONTAP upgrade runbook
- Upgrade troubleshooting
- ONTAP 9.19.1: data protection, networking, security, S3, ARP/AI updates — docs.netapp.com dated 2026-07-28: SnapMirror active sync adds transparent failover for AIX on 2-node clusters (symmetric active/active, zero RPO) and supports NAS SVM-level failover on AFF (2-node) and AFX (4-node); SnapMirror cloud raises to 100 S3 buckets per relationship; SnapMirror synchronou…
- ONTAP documentation hub now maps releases through 9.19.1 — NetApp's release hub covers trains through ONTAP 9.19.1. Recent highlights include SAN-focused ARP/AI, NVMe support for SnapMirror active sync, ONTAP Cloud Mediator, stronger identity controls, and S3 bucket restore.
- CVE-2026-55200 Libssh2 Vulnerability in NetApp Products — CVE-2026-55200 — Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Cloud Volumes ONTAP Mediator: Affected versions 9.17.1P4 through 9.17.1P9, 9.18.1P1 through 9.18.1P5 and 9.19.1GA through 9.
- ONTAP release upgrade guide: 9.16.1 through 9.19.1 — Plan ONTAP upgrades from 9.16.1, 9.17.1 and 9.18.1 to 9.19.1 with path selection, pre-flight checks and validation steps.
- ONTAP S3 access-key rotation — A safe, command-backed ONTAP S3 access-key rotation runbook, including expiring keys and dual-key zero-downtime rotation in ONTAP 9.19.1.
- ONTAP 9.19.1 admin impact and validation guide — Operational validation checklist for ONTAP 9.19.1: LIF failover, SAN paths, ARP/AI, NFS TLS, automation and post-upgrade checks.
ONTAP 9.19.1 FAQ
ONTAP 9.19.1 release notes?
NetApp’s detailed, account-gated Release Notes are linked above; the public What’s New page is the authoritative feature list. This hub adds operational context but does not replace either source.
What’s new in ONTAP 9.19.1?
Highlights include broader synchronous protection, NFS over TLS 1.3, direct-attached FC, S3 conditional operations and dual keys, expanded ARP/AI coverage, and performance and QoS changes. The grouped list above links every claim to NetApp documentation.
What’s new in ONTAP 9.19.1 for ASA r2?
NetApp documents AIX active-sync support, iSCSI-backed FLI, direct-attached FC, ARP/AI on active-sync primaries and TLS hardware offload. Availability still depends on the exact ASA r2 platform and configuration.