CHAP on storage/ESX hosts

snyderkv
snyderkv used Ask the Experts™
on
I'm about to set mutual CHAP authentication up on my storage and then my ESXi hosts but was wondering if I can set it up on my storage first for both incoming and outgoing without blocking any new LUNs coming online? We won't be setting CHAP up on the ESXi hosts until later.

My other question was since all our LUNs are already connected, will a temporary disconnect of storage reconnect them using CHAP or does CHAP initiate only for new LUNs?

Thanks
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
What we would do is ensure

1. No VMs using datastore
2. Remove datastore
3. Remove LUNs from all hosts
4. Enable CHAP
5. Reconfigure ESXi with Chap
6. Reconnect LUNs
7. Recreate datastores

Otherwise LUNs will disconnect datastores will become inassessible and turn into a mess and can cause iSCSI to retry causing host to spin out of control with high CPU polling
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
thanks for the update.
Commented:
I finished enabling CHAP in our production environment after testing it in my lab and found no issues just enabling it on both ends. Existing iSCSI sessions stay connected until reboot. Obviously put in maintenance mode for the reboot, otherwise no need to move VMs around and delete datastore etc.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial