Local Authentication; Restricting Iscsi Initiator Authentication; Mutual Chap Authentication - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

Configuring iSCSI
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Local Authentication

See the
in the local password database for the iSCSI initiator, the iSCSI keyword is mandatory.
To configure iSCSI users for local authentication using Device Manager, follow these steps:
Step 1
Choose Security > iSCSI.
You see the iSCSI Security dialog box shown in
Figure 50-28
Complete the iSCSI User, Password, and Password Confirmation fields.
Step 2
Click Create to save this new user.
Step 3

Restricting iSCSI Initiator Authentication

By default, the iSCSI initiator can use any user name in the RADIUS server or in the local database in
authenticating itself to the IPS module or MPS-14/2 module (the CHAP user name is independent of the
iSCSI initiator name). The IPS module or MPS-14/2 module allows the initiator to log in as long as it
provides a correct response to the CHAP challenge sent by the switch. This can be a problem if one
CHAP user name and password has been compromised.
To restrict an initiator to use a specific user name for CHAP authentication using Fabric Manager, follow
these steps:
Choose End Devices > iSCSI in the Physical Attributes pane.
Step 1
You see the iSCSI tables in the Information pane (see
Right-click the AuthUser field and enter the user name to which you want to restrict the iSCSI initiator.
Step 2
Click the Apply Changes icon to save these changes.
Step 3

Mutual CHAP Authentication

In addition to the IPS module or MPS-14/2 module authentication of the iSCSI initiator, the IPS module
or MPS-14/2 module also supports a mechanism for the iSCSI initiator to authenticate the Cisco MDS
switch's iSCSI target during the iSCSI login phase. This authentication requires the user to configure a
user name and password for the switch to present to the iSCSI initiator. The provided password is used
to calculate a CHAP response to a CHAP challenge sent to the IPS port by the initiator.
Cisco MDS 9000 Family CLI Configuration Guide
50-30
"Configuring Users" section on page 39-12
iSCSI Security Dialog Box
to create the local password database. To create users
Figure
50-28.
Figure
50-5).
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 50
Configuring iSCSI

Advertisement

Table of Contents
loading

Table of Contents