AWS Security ChangesHomeSearch

AWS fsx: Clarify failover transparency for iSCSI and NVMe/TCP clients

Service: fsx · 2026-09-27 · Documentation low

File: fsx/latest/ONTAPGuide/managing-throughput-capacity.md

Summary

Adds NVMe/TCP to the list of protocols with transparent failover and adds a note explaining that iSCSI and NVMe/TCP failover transparency depends on client-side multipathing that must be installed and configured.

Security assessment

The change is about availability/failover behavior and client multipathing configuration, not about authentication, encryption, or any security weakness.

Evidence

+Failover transparency is achieved differently depending on the protocol. For NFS and SMB clients, failovers are transparent because the endpoint IP address that clients use to access your data remains the same. For the iSCSI and NVMe/TCP block storage protocols, failover transparency instead depends on client-side multipathing, which you must install and configure on the client so that it automatically fails over between your file servers.

Diff

diff --git a/fsx/latest/ONTAPGuide/managing-throughput-capacity.md b/fsx/latest/ONTAPGuide/managing-throughput-capacity.md
index 5240e4d38..9b73157b2 100644
--- a//fsx/latest/ONTAPGuide/managing-throughput-capacity.md
+++ b//fsx/latest/ONTAPGuide/managing-throughput-capacity.md
@@ -15 +15,5 @@ Throughput capacity is one factor that determines the speed at which the file se
-When you modify your file system's throughput capacity, Amazon FSx switches out the file server that's powering your file system. Both Single-AZ and Multi-AZ file systems experience an automatic failover and failback during this process, which typically takes a few minutes to complete. The failover and failback processes are transparent to NFS (Network File Sharing), SMB (Server Message Block), and iSCSI (Internet Small Computer Systems Interface) clients, allowing your workloads to continue running without interruption or manual intervention. You are billed for the new amount of throughput capacity once it's available to your file system.
+When you modify your file system's throughput capacity, Amazon FSx switches out the file server that's powering your file system. Both Single-AZ and Multi-AZ file systems experience an automatic failover and failback during this process, which typically takes a few minutes to complete. The failover and failback processes are transparent to NFS (Network File Sharing), SMB (Server Message Block), iSCSI (Internet Small Computer Systems Interface), and NVMe/TCP (Non-Volatile Memory Express over TCP) clients, allowing your workloads to continue running without interruption or manual intervention. You are billed for the new amount of throughput capacity once it's available to your file system.
+
+###### Note
+
+Failover transparency is achieved differently depending on the protocol. For NFS and SMB clients, failovers are transparent because the endpoint IP address that clients use to access your data remains the same. For the iSCSI and NVMe/TCP block storage protocols, failover transparency instead depends on client-side multipathing, which you must install and configure on the client so that it automatically fails over between your file servers. For more information, see [Provisioning iSCSI for Linux](./mount-iscsi-luns-linux.html) and [Provisioning NVMe/TCP for Linux](./provision-nvme-linux.html).