Link to home
Start Free TrialLog in
Avatar of snyderkv
snyderkv

asked on

CHAP on storage/ESX hosts

I'm about to set mutual CHAP authentication up on my storage and then my ESXi hosts but was wondering if I can set it up on my storage first for both incoming and outgoing without blocking any new LUNs coming online? We won't be setting CHAP up on the ESXi hosts until later.

My other question was since all our LUNs are already connected, will a temporary disconnect of storage reconnect them using CHAP or does CHAP initiate only for new LUNs?

Thanks
Avatar of Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Flag of United Kingdom of Great Britain and Northern Ireland image

What we would do is ensure

1. No VMs using datastore
2. Remove datastore
3. Remove LUNs from all hosts
4. Enable CHAP
5. Reconfigure ESXi with Chap
6. Reconnect LUNs
7. Recreate datastores

Otherwise LUNs will disconnect datastores will become inassessible and turn into a mess and can cause iSCSI to retry causing host to spin out of control with high CPU polling
ASKER CERTIFIED SOLUTION
Avatar of snyderkv
snyderkv

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial