HP P4000 9.0 HP StorageWorks P4000 SAN Solution User Guide - Page 301

Requirements for configuring CHAP, Differentiating types of CHAP

Page 301 highlights

• No CHAP-Authorized initiators can log in to the volume without proving their identity. The target does not challenge the server. • 1-way CHAP-Initiators must log in with a target secret to access the volume. This secret proves the identity of the initiator to the target. • 2-way CHAP-Initiators must log in with a target secret to access the volume as in 1-way CHAP. In addition, the target must prove its identity to the initiator using the initiator secret. This second step prevents target spoofing. Figure 121 Differentiating types of CHAP . CHAP is optional. However, if you configure 1-way or 2-way CHAP, you must remember to configure both the server and the iSCSI initiator with the appropriate characteristics. Table 66 on page 301 lists the requirements for configuring CHAP. Requirements for configuring CHAP Table 66 Configuring iSCSI CHAP CHAP Level CHAP not required 1-way CHAP What to Configure for the Server in the SAN/iQ Software What to Configure in the iSCSI Initiator Initiator node name only No configuration requirements • CHAP name* • Target secret Enter the target secret (12-character minimum) when logging on to available target. 2-way CHAP • CHAP name* • Target secret • Initiator secret • Enter the initiator secret (12-character minimum). • Enter the target secret (12-character minimum). * If using CHAP with a single node only, use the initiator node name as the CHAP name. P4000 SAN Solution user guide 301

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350

No CHAP
Authorized initiators can log in to the volume without proving their identity. The target
does not challenge the server.
1-way CHAP
Initiators must log in with a target secret to access the volume. This secret proves
the identity of the initiator to the target.
2-way CHAP
Initiators must log in with a target secret to access the volume as in 1-way CHAP.
In addition, the target must prove its identity to the initiator using the initiator secret. This second
step prevents target spoofing.
Figure 121 Differentiating types of CHAP
.
CHAP is optional. However, if you configure 1-way or 2-way CHAP, you must remember to configure
both the server and the iSCSI initiator with the appropriate characteristics.
Table 66
on page 301 lists
the requirements for configuring CHAP.
Requirements for configuring CHAP
Table 66 Configuring iSCSI CHAP
What to Configure in the iSCSI Initiator
What to Configure for the Server
in the SAN/iQ Software
CHAP Level
No configuration requirements
Initiator node name only
CHAP not required
Enter the target secret (12-character minimum)
when logging on to available target.
CHAP name*
Target secret
1-way CHAP
Enter the initiator secret (12-character
minimum).
Enter the target secret (12-character min-
imum).
CHAP name*
Target secret
Initiator secret
2-way CHAP
* If using CHAP with a single node only, use the initiator node name as the CHAP name.
P4000 SAN Solution user guide
301