Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 108

Manage Access Controls for VDS/VSS Access, Authenticate Initiators with CHAP

Page 108 highlights

5. Select the checkbox next to each group policy name that you want to associate with the selected volume and click OK. Manage Access Controls for VDS/VSS Access To allow VDS and VSS access to the group, you must create at least one VDS/VSS access control policy that matches the access control credentials you configure on the computer by using Remote Setup Wizard or Auto-Snapshot Manager/Microsoft Edition. The same access control constructs (access policies, access policy groups, and basic access points) are available for defining VDS/VSS access. 1. Click Group → Group Configuration. 2. Click the VDS/VSS tab. 3. Take the appropriate action in the VDS/VSS Access Control List panel to either add, modify, or remove access. Add, Modify, or Remove an Access Policy Group: • To add an access policy group for VDS/VSS access, click Add. Select the checkbox next to the additional policy groups that you want to assign and click OK. • To make changes to the access policies within an access policy group, select a group policy and click Modify to open the Edit Access Policy Group dialog box. You can add, modify, or remove the access policies within this group. • To remove an entire policy group from VDS/VSS access, select that policy group name and click Delete. When prompted to confirm the decision, click Yes. Add, Modify, or Remove an Access Policy: • To add an additional access policy for VDS/VSS access, click Add. Select the checkbox next to the additional access policies that you want to assign and click OK. • To make changes to the access points within an access policy, select a policy and click Modify to open the Edit Access Policy dialog box. You can create new access points, edit existing access points, or remove access points that belong to this policy. • To remove an access policy from VDS/VSS access, select the policy name and click Delete. When prompted to confirm the decision, click Yes. Add, Modify, or Remove a Basic Access Point: • To create an additional access point for VDS/VSS access, click New to open the New Basic Access Point dialog box. You can then define an additional access point. • To change the parameters of an existing access point (CHAP name, iSCSI name, or IP address), select the access point that you want to edit and click Modify. • To remove a basic access point from VDS/VSS access, select the access point name and click Delete. When prompted to confirm the decision, click Yes. Authenticate Initiators with CHAP CHAP (Challenge Handshake Authentication Protocol) is a network login protocol that uses a challenge-response mechanism. You can use CHAP to authenticate iSCSI initiators by specifying a CHAP user name in an access control policy. To meet this condition, a computer must supply the user name and its password (or "secret") in the iSCSI initiator configuration interface when logging in to the target. Using CHAP for iSCSI authentication can help you manage access controls more efficiently because it restricts target access by using user names and passwords, instead of unique IP addresses or iSCSI initiator names. Before you can use CHAP for initiator authentication, you must set up the CHAP accounts consisting of a user name and password (or "secret"). Two options are available for accounts; you can use both options simultaneously in a group: • CHAP accounts in the group Local CHAP accounts do not rely on any external system. You can create up to 100 local CHAP accounts. • CHAP accounts on an external RADIUS authentication server 108 About Volume-Level Security

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

5.
Select the checkbox next to each group policy name that you want to associate with the selected volume and click
OK
.
Manage Access Controls for VDS/VSS Access
To allow VDS and VSS access to the group, you must create at least one VDS/VSS access control policy that matches the access
control credentials you
configure
on the computer by using Remote Setup Wizard or Auto-Snapshot Manager/Microsoft Edition.
The same access control constructs (access policies, access policy groups, and basic access points) are available for
defining
VDS/VSS access.
1.
Click
Group
Group
Configuration
.
2.
Click the
VDS/VSS
tab.
3.
Take the appropriate action in the
VDS/VSS Access Control List
panel to either add, modify, or remove access.
Add, Modify, or Remove an Access Policy Group:
To add an access policy group for VDS/VSS access, click
Add
. Select the checkbox next to the additional policy groups
that you want to assign and click
OK
.
To make changes to the access policies within an access policy group, select a group policy and click
Modify
to open the
Edit Access Policy Group dialog box. You can add, modify, or remove the access policies within this group.
To remove an entire policy group from VDS/VSS access, select that policy group name and click
Delete
. When prompted to
confirm
the decision, click
Yes
.
Add, Modify, or Remove an Access Policy:
To add an additional access policy for VDS/VSS access, click
Add
. Select the checkbox next to the additional access
policies that you want to assign and click
OK
.
To make changes to the access points within an access policy, select a policy and click
Modify
to open the Edit Access
Policy dialog box. You can create new access points, edit existing access points, or remove access points that belong to this
policy.
To remove an access policy from VDS/VSS access, select the policy name and click
Delete
. When prompted to
confirm
the
decision, click
Yes
.
Add, Modify, or Remove a Basic Access Point:
To create an additional access point for VDS/VSS access, click
New
to open the New Basic Access Point dialog box. You
can then
define
an additional access point.
To change the parameters of an existing access point (CHAP name, iSCSI name, or IP address), select the access point
that you want to edit and click
Modify
.
To remove a basic access point from VDS/VSS access, select the access point name and click
Delete
. When prompted to
confirm
the decision, click
Yes
.
Authenticate Initiators with CHAP
CHAP (Challenge Handshake Authentication Protocol) is a network login protocol that uses a challenge-response mechanism. You
can use CHAP to authenticate iSCSI initiators by specifying a CHAP user name in an access control policy. To meet this condition, a
computer must supply the user name and its password (or “secret”) in the iSCSI initiator
configuration
interface when logging in to
the target.
Using CHAP for iSCSI authentication can help you manage access controls more
efficiently
because it restricts target access by
using user names and passwords, instead of unique IP addresses or iSCSI initiator names.
Before you can use CHAP for initiator authentication, you must set up the CHAP accounts consisting of a user name and password
(or “secret”). Two options are available for accounts; you can use both options simultaneously in a group:
CHAP accounts in the group
Local CHAP accounts do not rely on any external system. You can create up to 100 local CHAP accounts.
CHAP accounts on an external RADIUS authentication server
108
About Volume-Level Security