Skip to main content

New Page

There are two options to configure and use iSCSI CHAP authentication Uni-directional and bi-directional also referred as mutual authentication

Appliance (Target) configuration

Uni-directional authentication

Configure the Host for CHAP authentication on the appliance GUI/CLI

Host 🡪 Chap Secret

embedded-image-jd6u1ndg.png

Bi-directional (mutual) authentication

Bi-directional CHAP adds another level of authentication. To use Bi-directional authentication first Uni-directional authentication is required.

To enable bi-directional (mutual) authentication, add CHAP secret also to the appliance on the GUI / CLI

    1. Nodes 🡪 CHAP

embedded-image-zstsaynf.png

    1. Chap name, Chap Secret

embedded-image-5fnqk5to.png

Windows initiator configuration

Uni-directional authentication

Configure on the Windows iSCSI initiator

  1. Connect iSCSI Target

embedded-image-w0nlyaox.png

  1. Use advanced dialogue

embedded-image-28ojvbqn.png

  1. Enable CHAP log on
  2. Enter the Host Chap-name (initiator iqn) and Chap-secret

embedded-image-kfi4oqwx.png

The Target Secret should be the same as configured in the GUI/CLI Host dialogue

    1. Perform this operation for both HA nodes

Bi-directional (mutual) authentication

Configure on the Windows initiator

    1. Open iSCSI initiator properties, choose CHAP

embedded-image-0bu7imew.png

    1. Configure the initiator CHAP secret using the same secret as configured on the appliance GUI/CLI Node 🡪 CHAP dialogue

embedded-image-u6ub5w5l.png

    1. Connect iSCSI Target

embedded-image-m7uy1xaf.png

    1. Use advanced dialogue

embedded-image-r0eq09eg.png

    1. Enable CHAP log on
    2. Enter the Host Chap-name (initiator iqn) and Chap-secret
    3. Choose the CHAP option - “Perform mutual authentication”

embedded-image-naim5arh.png

    1. Perform this operation for both HA appliance nodes

ESXi initiator configuration using VCenter

Uni-directional authentication

  1. Configure on the ESXi iSCSI initiator

Choose ESX-Host 🡪Configure 🡪 Storage Adapters 🡪 iSCSI Software Adapter

Use Dynamic Discovery 🡪 ADD

On the Add Send Target Server pop-up windows, un-check the inherit authentication

embedded-image-bn22k0tg.png

  1. Enter the following in the detailed authentication pop-up windows

Choose the Authentication Method – Use unidirectional CHAP

Tick the use initiator name to fill the ESXi-host iqn and enter the secret as defined on the appliance GUI/CLI Host 🡪 Chap secret dialogue

embedded-image-daynm7py.png

  1. Perform this operation for both HA appliance nodes

Bi-directional (mutual) authentication

  1. Configure on the ESXi iSCSI initiator

Choose ESX-Host 🡪Configure 🡪 Storage Adapters 🡪 iSCSI Software Adapter

Use Dynamic Discovery 🡪 ADD

On the Add Send Target Server pop-up windows, un-check the inherit authentication

embedded-image-nyqwfep0.png

  1. Enter the following in the detailed authentication pop-up windows

Choose the Authentication Method – Use bidirectional CHAP

Tick the use initiator name to fill the ESXi-host iqn and enter the secret as defined on the appliance GUI/CLI Host 🡪 Chap secret dialogue

embedded-image-mm9ncxb7.png

  1. On the Incoming CHAP Credentials section,

Name and Secret - use the name configured on the appliance Node 🡪 CHAP dialogue

embedded-image-mkwodt10.png

  1. Perform this operation for both HA appliance nodes