Iscsi Transparent Mode Initiator - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

iSCSI Authentication Setup Guidelines and Scenarios
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
c.
d.
e.
f.
Set up the authentication verification for the iSCSI protocol to go to the RADIUS server.
Step 4
a.
b.
c.
d.
Set up the iSCSI authentication method to require CHAP for all iSCSI clients.
Step 5
a.
b.
c.
Step 6
In Fabric Manager, choose End Devices > iSCSI in the Physical Attributes pane.
Step 7
Click the Globals tab in the Information pane to verify that the global iSCSI authentication setup is for
CHAP.
Step 8
In Fabric Manager, choose Switches > Security > AAA in the Physical Attributes pane.
Step 9
Click the Applications tab in the Information pane to verify the AAA authentication information for
iSCSI.
To configure an iSCSI RADIUS server, follow these steps:
Configure the RADIUS server to allow access from the Cisco MDS switch's management Ethernet IP
Step 1
address.
Configure the shared secret for the RADIUS server to authenticate the Cisco MDS switch.
Step 2
Configure the iSCSI users and passwords on the RADIUS server.
Step 3

iSCSI Transparent Mode Initiator

This scenario assumes the following configuration (see
Cisco MDS 9000 Family CLI Configuration Guide
50-58
Set the Index field to a unique number.I
Set the Protocol radio button to radius.
Set the Name field to the server group name.
Set the ServerIDList to the index value of the RADIUS server (as created in
Create.
In Fabric Manager, choose Switches > Security > AAA in the Physical Attributes pane.
Click the Applications tab in the Information pane.
Right-click on the iSCSI row in the Type, SubType, Function column.
Set the ServerGroup IDList to the index value of the Server Group (as created in
Create.
In Fabric Manager, choose End Devices > iSCSI in the Physical Attributes pane.
Select chap from the AuthMethod drop-down menu.
Click the Apply Changes icon.
No LUN mapping or LUN masking or any other access control for hosts on the target device
No iSCSI login authentication (that is, login authentication set to none)
The topology is as follows:
iSCSI interface 7/1 is configured to identify initiators by IP address.
iSCSI interface 7/5 is configured to identify initiators by node name.
Chapter 50
Step 2
Figure
50-42):
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Configuring iSCSI
c.) and click
Step 3
c) and click

Advertisement

Table of Contents
loading

Table of Contents