Deployment Guide

Preparing Your Systems for Clustering 59
2
To configure a CHAP secret, select
CHAP
and select
CHAP Secret
.
3
Enter the
Target CHAP secret (
or
Generate Random Secret)
, confirm it
in
Confirm Target CHAP Secret
, and click
OK
.
Although the storage array allows sizes from 12 to 57 characters, many
initiators only support CHAP secret sizes up to 16 characters (128-bit).
NOTE: Once entered, a CHAP secret is not retrievable. Ensure that you record
the secret in an accessible place. If Generate Random Secret is used, copy
and paste the secret into a text file for future reference since the same CHAP
secret is used to authenticate any new host servers you may add to the
storage array. If you forget this CHAP secret, you must disconnect all existing
hosts attached to the storage array and repeat the steps in this chapter to
add them.
4
Click
OK
.
Configuring Mutual CHAP Authentication on the Storage Array
The initiator secret must be unique for each host server that connects to the
storage array
and must not be the same as the target CHAP secret.
1
From MD Storage Manager, click on the
iSCSI
tab, then select
Enter
Mutual Authentication Permissions
.
2
Select an initiator on the host server and click the
CHAP Secret
.
3
Enter the
Initiator CHAP secret
, confirm it in
Confirm initiator CHAP
secret
, and click
OK
.
NOTE: In some cases, an initiator CHAP secret may already be defined in
your configuration. If so, use it here.
4
Click
Close
.
NOTE: To remove a CHAP secret, you must delete the host initiator and add it.
Configuring CHAP Authentication on the Host Server (Optional)
If you configured CHAP authentication in "Configuring Target CHAP
Authentication on the Storage Array" on page 58, complete the following
steps. If not, skip to "Connect to the Target Storage Array From the Host
Server" on page 61.
To optionally configure CHAP authentication on the host server:
1
Click
Start
Programs
Microsoft iSCSI Initiator
.
2
If you are NOT using mutual CHAP authentication
,
skip to step 4.
book.book Page 59 Tuesday, April 15, 2008 12:30 PM