7065Admin_iSCSI.fm
Figure 12-1 DS3000 Storage Manager - iSCSI
12.1 Authentication
Settings that affect the security of iSCSI connections can be done here. We discussed iSCSI
security in 1.3.3, "iSCSI security considerations" on page 11.
12.1.1 Change Target Authentication
Target authentication is used to allow only configured HBAs to access the storage subsystem.
When target authentication is enabled, the target needs to authenticate itself against the
initiator that attempts to access the storage subsystem. When using a QLogic iSCSI HBA,
target authentication is called bidirectional authentication and can only be configured on the
HBA when the initiator itself authenticates against the storage subsystem. If this is required,
you have to also configure an initiator CHAP secret on the DS3300 by following the steps in
12.1.2, "Enter Mutual Authentication Permissions" on page 272.
To configure target authentication,
1. On the iSCSI tab (Figure 12-1) click Change Target Authentication.
2. A new dialog opens (Figure 12-2 on page 271) that provides two options.
– None
– CHAP
This setting affects the connection between an iSCSI initiator and a DS3300 iSCSI port.
Option None allows any iSCSI initiator to establish an iSCSI connection to this target.
When option CHAP is selected an initiator is required to provide a CHAP password to get
a session established. CHAP needs to be enabled if mutual authentication is required by
an iSCSI initiator. Both options (None and CHAP) can be enabled together - in this case,
initiators with and without a target secret can access the storage subsystem.
270
IBM System Storage DS3000: Introduction and Implementation Guide
Draft Document for Review August 30, 2007 12:59 am