Authentication Overview - HP StorageWorks SR2122 User Manual

Ip storage router
Hide thumbs Also See for StorageWorks SR2122:
Table of Contents

Advertisement

Software Overview

Authentication Overview

Authentication is a software service that is available in each SR2122-2. It provides
a method of identifying users (including login and password dialog, challenge and
response, and messaging support) prior to receiving access to the requested object,
function, or network service. The SR2122-2 supports three types of
authentication:
Authentication is provided by an AAA (authentication, authorization, and
accounting) subsystem configured in each SR2122-2. AAA is an architectural
framework for configuring a set of three independent security functions in a
consistent and modular manner: authentication, authorization, and accounting.
The SR2122-2 Storage Router software implements the authentication function.
AAA authentication is configured by defining a list of authentication services.
iSCSI authentication, which uses a AAA authentication services list, can be
enabled for specific SCSI routing instances in an SR2122-2.
When iSCSI authentication is enabled, IP hosts (with iSCSI drivers) must provide
user name and password information each time an iSCSI TCP connection is
established. With two-way authentication, the SCSI routing instance to which an
iSCSI target has been assigned responds to the authentication request with an
assigned username and password. iSCSI authentication uses the iSCSI CHAP
(Challenge Handshake Authentication Protocol) authentication method.
See
configuring authentication services.
78
maintenance interface is lost and if the secondary maintenance interface
connection is assigned and connected, the IP address moves to the secondary
Gigabit Ethernet interface, which then allows management access.
iSCSI authentication—provides an authentication mechanism to authenticate
IP hosts that request access to storage. An IP host, acting as an iSCSI initiator,
can also verify the identity of an iSCSI target assigned to a SCSI routing
instance, which responds to the request, resulting in a two-way authentication.
Enable authentication—provides a mechanism to authenticate users
requesting Administrator mode access to an SR2122-2 management session
via the CLI enable command or an FTP session.
Login authentication—provides a mechanism to authenticate users requesting
access to the SR2122-2 in Monitor mode via the login process from a Telnet
session, SSH session or the SR2122-2 console.
Chapter 10, "Configuring Authentication"
for more information about
IP Storage Router SR2122-2 User Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Storageworks sr2122-2

Table of Contents