Solved

CHAP for iscsi

Posted on 2016-11-07
4
35 Views
Last Modified: 2016-11-22
I need your opinion on configuring CAHP authentication on iScSI. As far as I know it is tightening the security, but do we need it?. Client has VNX, Equallogic,NetApp. None of them are configured for CHAP authentication. Client is thinking of implementing that solution.
Experts out there might have configured CHAP authentication.  What the advantages and disadvantages of using it ?
0
Comment
Question by:sara2000
  • 3
4 Comments
 
LVL 118
ID: 41877533
It really comes down to your clients security and governance, and accessing the Risk of another iSCSi Client accessing data on these LUNs, and what other access and restrictions exist on these LUNs, e.g. access granted by IQN? is this a secure storage network? how can you obtain access to this LAN, where is the LAN etc

50% of our clients use it, 50% of our clients dont!
0
 

Author Comment

by:sara2000
ID: 41877704
Thanks Andrew,
How difficult is to administrator iscsi with CAHP in vmware esxi environment?
Is it one time configuration? Will it reconnect if Esxi reboot without administrator interference?
0
 
LVL 118

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE) earned 500 total points
ID: 41877843
It's a one time configuration, at adding the passphrase when you setup the iSCSI software initiator.

Very simple, tick box, and the passphrase is hashed and stored.

So no issues, at server host restarts.
0
 
LVL 118
ID: 41896656
do you require any more additional help to close this question?
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

This article is an update and follow-up of my previous article:   Storage 101: common concepts in the IT enterprise storage This time, I expand on more frequently used storage concepts.
When we have a dead host and we lose all connections to the ESXi, and we need to find a way to move all VMs from that dead ESXi host.
Teach the user how to use create log bundles for vCenter Server or ESXi hosts Open vSphere Web Client: Generate vCenter Server and ESXi host log bundle:  Open vCenter Server Appliance Web Management interface and generate log bundle: Open vCenter Se…
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now