iSCSI CHAP authentication
For additional security, iSCSI supports authentication using the Challenge Handshake Authentication Protocol (CHAP). There are two optionsvariations to configure and useof iSCSI CHAP authenticationauthentication: Uni-uni-directional and bi-directionaldirectional, also referred to as mutual authentication.
Appliance (Target)StorONE configuration
Uni-directional authentication
Configure the Host for CHAP authentication on the appliance GUI/CLI
Host 🡪 Chap Secret
Bi-directional (mutual) authentication
Bi-directional CHAP adds another level of authentication. To use Bi-directional authentication first Uni-directional authentication is required.
To enable bi-directional (mutual) authentication, add CHAP secret also to the appliance on the GUI / CLI
-
- Nodes 🡪 CHAP
- Nodes 🡪 CHAP
- Chap name, Chap Secret
- Chap name, Chap Secret
Windows initiator configuration
Uni-directional authentication
Configure onIn the Windows iSCSI initiator properties dialog:
- Select the StorONE target and click Connect
- In the Connect
iSCSITo Target dialog, select Advanced...
Use advanced dialogue
- Enable CHAP log on
Enterbox, and enter theHosthostChap-name (initiatoriqn)IQN) andChap-secretthe
secret:
The Target Secretsecret should be the same assecret you configured inon the GUI/CLIStorONE Host dialogue
- system.
- your
PerformStorONEthissystemoperationis a dual-node high availability (HA) system, repeat these steps forboththeHAothernodescontroller node target.
Bi-directional (mutual) authentication
Configure onIn the Windows initiatoriSCSI Initiator Properties dialog:
-
- Open iSCSI initiator properties, choose CHAP
- Open iSCSI initiator properties, choose CHAP
- Configure the initiator CHAP secret using the same secret as configured on the appliance GUI/CLI Node 🡪 CHAP dialogue
- Configure the initiator CHAP secret using the same secret as configured on the appliance GUI/CLI Node 🡪 CHAP dialogue
- Connect iSCSI Target
- Connect iSCSI Target
- Use advanced dialogue
- Use advanced dialogue
- Enable CHAP log on
Enterand enter the Host Chap-name (initiator iqn) and Chap-secretsecret. ChooseCheck theCHAP option - “Perform mutualauthentication”authentication box.
- Perform this operation for both HA appliance nodes
ESXi initiator configuration using VCenterVMware vCenter
Uni-directional authentication
ConfigureGoon the ESXi iSCSI initiator
Chooseto ESX-Host 🡪 Configure 🡪 Storage Adapters 🡪 iSCSI Software Adapter
- Choose the Authentication Method – Use unidirectional CHAP
- Check the
useUse initiator name checkbox to auto-fill theESXi-ESXi hostiqnIQN, and enter thesecretSecretasyoudefinedconfigured on theapplianceStorONEGUI/CLIsystem.
Tick
- Perform this operation for both HA appliance
nodesnode targets.
Bi-directional (mutual) authentication
Configure on the ESXi iSCSI initiator
Choose ESX-Host 🡪Configure 🡪 Storage Adapters 🡪 iSCSI Software Adapter
- Choose the Authentication Method – Use bidirectional CHAP
- Check the
useUse initiator name checkbox to auto-fill theESXi-ESXi hostiqnIQN, and enter thesecretSecretas defined on the appliance GUI/CLI Host 🡪 Chap secret dialogueOn the Incoming CHAP Credentials section,
Name and Secret - use the nameyou configured on theapplianceStorONENodesystem.
Tick
section, specify the Name and Secret you configured on the StorONE system.