SANRAD V-Switch manual Assigning Identity Credentials

Models: V-Switch

1 300
Download 300 pages 15.92 Kb
Page 131
Image 131

If you are working in a V-Switch cluster, the identity authentication method(s) must be added on both V- Switches.

In the event of a failover, if each identity does not require authentication on both V-Switches, each attached identity will have free access to the target’s underlying volumes.

Assigning Identity Credentials

You can require initiator authentication before allowing access to a target and its underlying volume(s). The V-Switch supports CHAP and SRP authentication methods. Microsoft and Cisco initiators support CHAP. Use the CLI command acl identity add chap/srp to assign a login authentication method(s) to initiators in an identity.

An assigned authentication method encrypts the host login name and password. The authentication method does not encrypt the virtual volume data transferred. The host login and password do not have to relate to the iSCSI initiator WWUI. They can be any selected character strings.

If you are working with a Microsoft initiator and configuring target authentication, note that the V-Switch exchanges the final character in the password with a zero. Therefore, do not configure initiator passwords with a zero as the final character. CHAP passwords must be between twelve to sixteen characters in length.

acl identity add chap

You need to define four parameters to assign the CHAP/SRP authentication method to an identity:

SWITCH

PARAMETER

DEFINITION

STATUS

EXAMPLE

 

 

 

 

 

-id

IDENTITY

ALIAS OF IDENTITY

MANDATORY

accounting

-us

USER NAME

INITIATOR USER

MANDATORY

steven

 

 

NAME

 

 

-pw

USER PASSWORD

INITIATOR

MANDATORY

oneveryhot

 

 

PASSWORD

UNLESS A

dude

 

 

 

RADIUS

 

 

 

 

SERVER IS USED

 

 

 

 

12-16 CHAR

 

 

 

 

STRING

 

-radius

RADIUS

RADIUS SERVER

OPTIONAL

No parameter

 

 

 

DEFAULT: NO

required

 

 

 

 

 

 

 

 

 

Chapter 7: Volume Exposure and Security

125

Page 131
Image 131
SANRAD V-Switch manual Assigning Identity Credentials