Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 109

Display Local CHAP Accounts, Create a Local CHAP Account, In the Local CHAP Accounts panel, click

Page 109 highlights

Using a RADIUS server to manage CHAP accounts is helpful if you are managing a large number of accounts. However, computer access to targets depends on the availability of the RADIUS server. NOTE: If you use CHAP for initiator authentication, you can also use target authentication for mutual authentication, which provides additional security. Display Local CHAP Accounts To display local CHAP accounts: 1. Click Group → Group Configuration. 2. Click the iSCSI tab. The Local CHAP Accounts panel lists all current CHAP accounts. NOTE: Starting with firmware v9.1.x, the CHAP password is no longer displayed in clear text format. Create a Local CHAP Account CHAP accounts are a method of ensuring that only authorized users can access a PS Series group. You can create local CHAP accounts or you can use a RADIUS server. Before you create an account: • You can decide whether to verify iSCSI initiator credentials against local CHAP accounts first (before verifying external CHAP accounts on a RADIUS server). • You need the following information: - CHAP user name - Password (otherwise known as a CHAP secret). For optimal security, passwords must contain at least 12 characters (preferably random). Individual iSCSI initiators have their own rules and restrictions for length and format. Consult your initiator documentation for details. To create a local CHAP account: 1. Click Group → Group Configuration. 2. Click the iSCSI tab. 3. (Optional) Select Enable local authentication and check local first in the iSCSI Authentication panel. 4. In the Local CHAP Accounts panel, click Add to open the Add CHAP Account dialog box. 5. Type a CHAP user name and, optionally, a password. • The user name can be up to 63 printable characters (any characters except space and colon). NOTE: If the user name contains a pound-sign character, enclose the name in quotation marks (for example, "chap#user"). Otherwise, the system will read the characters after the pound sign as a comment and not include them in the user name. • The password can be up to 255 printable characters (any characters except space and colon). If you do not enter a password, the group automatically generates a password that is 16 characters long). 6. Select whether to enable the account. You must enable an account to use it for initiator authentication. You can modify an account and enable or disable it later. 7. Click OK. 8. Click Save all changes. NOTE: In the iSCSI initiator authentication area, you can select Enable RADIUS authentication for iSCSI initiators, Consult locally defined CHAP accounts first, or both. Make sure that at least one of these choices is selected. If neither option is selected, the PS Series group will lock out all iSCSI initiator logins. After creating the CHAP account, you can: • Create an access control policy and use the CHAP user name in the policy About Volume-Level Security 109

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

Using a RADIUS server to manage CHAP accounts is helpful if you are managing a large number of accounts. However,
computer access to targets depends on the availability of the RADIUS server.
NOTE: If you use CHAP for initiator authentication, you can also use target authentication for mutual authentication,
which provides additional security.
Display Local CHAP Accounts
To display local CHAP accounts:
1.
Click
Group
Group
Configuration
.
2.
Click the
iSCSI
tab.
The Local CHAP Accounts panel lists all current CHAP accounts.
NOTE: Starting with
firmware
v9.1.x, the CHAP password is no longer displayed in clear text format.
Create a Local CHAP Account
CHAP accounts are a method of ensuring that only authorized users can access a PS Series group. You can create local CHAP
accounts or you can use a RADIUS server.
Before you create an account:
You can decide whether to verify iSCSI initiator credentials against local CHAP accounts
first
(before verifying external CHAP
accounts on a RADIUS server).
You need the following information:
CHAP user name
Password (otherwise known as a CHAP
secret
). For optimal security, passwords must contain at least 12 characters
(preferably random). Individual iSCSI initiators have their own rules and restrictions for length and format. Consult your
initiator documentation for details.
To create a local CHAP account:
1.
Click
Group
Group
Configuration
.
2.
Click the
iSCSI
tab.
3.
(Optional) Select
Enable local authentication and check local
first
in the iSCSI Authentication panel.
4.
In the Local CHAP Accounts panel, click
Add
to open the Add CHAP Account dialog box.
5.
Type a CHAP user name and, optionally, a password.
The user name can be up to 63 printable characters (any characters except space and colon).
NOTE: If the user name contains a pound-sign character, enclose the name in quotation marks (for example,
“chap#user”). Otherwise, the system will read the characters after the pound sign as a comment and not
include them in the user name.
The password can be up to 255 printable characters (any characters except space and colon). If you do not enter a
password, the group automatically generates a password that is 16 characters long).
6.
Select whether to enable the account. You must enable an account to use it for initiator authentication. You can modify an
account and enable or disable it later.
7.
Click
OK
.
8.
Click
Save all changes
.
NOTE: In the iSCSI initiator authentication area, you can select Enable RADIUS authentication for iSCSI initiators,
Consult locally
defined
CHAP accounts
first
, or both. Make sure that
at least
one of these choices is selected. If
neither option is selected, the PS Series group will lock out all iSCSI initiator logins.
After creating the CHAP account, you can:
Create an access control policy and use the CHAP user name in the policy
About Volume-Level Security
109