Administrator Guide

Table Of Contents
2. Click GroupGroup Conguration.
3. Click the iSCSI tab.
4. In the iSCSI Authentication panel, select Enable RADIUS authentication for iSCSI initiators.
5. (Optional) Select Enable local authentication and check local rst.
6. Click RADIUS settings to congure the group to use a RADIUS server (if you have not already done so).
7. Add at least one RADIUS server by clicking the RADIUS settings button and adding the IP address of the RADIUS
authentication server.
8. Click OK to save the changes.
After creating the CHAP account, create an access control policy for a volume and specify the CHAP user name in the policy.
NOTE: In the iSCSI Authentication panel, you can select either Enable RADIUS authentication for iSCSI initiators, Enable
local authentication and check local rst, or both. Make sure that
at least
one of these options is selected. If neither
option is selected, the PS Series group will lock out all CHAP logins.
Congure Target Authentication
If you congure initiator authentication though a local CHAP account or a CHAP account on a RADIUS authentication server, you
can also allow the iSCSI initiator to authenticate iSCSI targets in a PS Series group. The combination of initiator and target
authentication is called mutual authentication and provides additional security.
With target authentication, when the initiator tries to connect to a target, the target supplies a user name and password to the
initiator. The initiator compares the user name and password to mutual authentication credentials that you congure in the initiator
conguration interface. The iSCSI connection succeeds only if the information matches.
A group automatically enables target authentication using a default user name and password, which you can change. Whether the
initiator requires target authentication depends on the initiator conguration settings.
To display the current target authentication user name and password:
1. Click GroupGroup Conguration.
2. Click the iSCSI tab.
3. In the iSCSI Authentication panel, click Modify. The Modify Target CHAP Account dialog box opens.
4. In the dialog box, type the target authentication user name and password.
5. Click OK to save the changes.
About iSNS Servers
In a shared storage environment, you must control computer access to iSCSI targets (volumes and snapshots), because multiple
computers writing to a target in an uncoordinated manner might result in volume corruption.
When an initiator tries to log in to a target, the group uses access control policies to determine if access should be authorized.
However, access control policies do not prevent multiple initiators, either on the same computer or dierent computers, from
accessing the same target.
Therefore, by default, the group disables multihost (shared) access to a target. Only one iSCSI qualied name (IQN) can connect to
a target at one time.
If all group members are not running PS Series rmware version 5.0 or later, the group allows multihost access to targets.
An iSNS (Internet Storage Name Service) server can facilitate iSCSI initiator discovery of iSCSI targets in a SAN.
About Volume-Level Security
111