Administrator Guide

Table Of Contents
Congure CHAP for Initiator Authentication on Existing Volumes
To congure CHAP for an existing volume:
1. Click Volumes
2. Expand Volumes and then select the volume that you want to congure.
3. In the Activities panel, click Add basic access point to open the New Basic Access Point dialog box.
4. In the dialog box, type a description for the volume and a CHAP account name.
Names can be up to 63 ASCII characters.
5. Enter a CHAP acount name, an iSCSI initiator name, or an IP address.
6. Select whether the access point applies to volumes and snapshots, volumes only, or snapshots only.
7. Click OK.
Congure CHAP for Initiator Authentication on New Volumes
To congure CHAP for a new volume:
1. Click Volumes.
2. In the Activities panel, click Create volume to open the Create Volume dialog box.
3. In the dialog box, type the general and space information for the volume.
4. For the iSCSI access information, select Dene one or more basic access points.
5. Click Add to open the New Basic Access Point dialog box.
6. In the dialog box, type a description for the volume and a CHAP account name.
Names can be up to 63 ASCII characters.
7. Select whether the access point applies to volumes and snapshots, volumes only, or snapshots only.
8. Click OK and nish typing the information for the volume.
Congure CHAP Accounts on a RADIUS Authentication Server
To use a CHAP account on an external RADIUS authentication server for iSCSI initiator authentication:
1. Set up the RADIUS server and CHAP accounts. (The RADIUS server must be accessible to all the group members.)
2. Click GroupGroup Conguration.
3. Click the iSCSI tab.
4. In the iSCSI Authentication panel, select Enable RADIUS authentication for iSCSI initiators.
5. (Optional) Select Enable local authentication and check local rst.
6. Click RADIUS settings to congure the group to use a RADIUS server (if you have not already done so).
7. Add at least one RADIUS server by clicking the RADIUS settings button and adding the IP address of the RADIUS
authentication server.
8. Click OK to save the changes.
After creating the CHAP account, create an access control policy for a volume and specify the CHAP user name in the policy.
NOTE: In the iSCSI Authentication panel, you can select either Enable RADIUS authentication for iSCSI initiators, Enable
local authentication and check local rst, or both. Make sure that
at least
one of these options is selected. If neither
option is selected, the PS Series group will lock out all CHAP logins.
Congure Target Authentication
If you congure initiator authentication though a local CHAP account or a CHAP account on a RADIUS authentication server, you
can also allow the iSCSI initiator to authenticate iSCSI targets in a PS Series group. The combination of initiator and target
authentication is called mutual authentication and provides additional security.
About Volume-Level Security
119