08.12.2012 Views

SAN Boot Implementation and Best Practices Guide ... - IBM Redbooks

SAN Boot Implementation and Best Practices Guide ... - IBM Redbooks

SAN Boot Implementation and Best Practices Guide ... - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Draft Document for Review June 27, 2012 9:05 am SG247958-iSCSI_DS5000-CL.fm<br />

Note: All iSCSI HBAs <strong>and</strong> software initiators configured on the same machine must share<br />

the same IQN name.<br />

Figure 6-2 shows the example of a qlogic iSCSI HBA (initiator).<br />

Figure 6-2 iSCSI Initiator<br />

Security<br />

Unlike FC <strong>SAN</strong>s or direct SAS connection, Ethernet networks can be more open, so in order<br />

to provide additional security, you can configure the following additional authentication<br />

protocols on the DS5000 storage subsystems:<br />

► The Internet Storage Name Service (iSNS) protocol allows for automated discovery,<br />

management, <strong>and</strong> configuration of iSCSI devices on a TCP/IP network. iSNS servers offer<br />

additional security services through explicitly defined initiator-to-target mappings <strong>and</strong><br />

simplified asset locators, similar to that provided by DNS <strong>and</strong> WINS for IP address lookup<br />

facilities<br />

► Currently, <strong>IBM</strong> DS Storage Manager 10 has only one iSCSI authentication method called<br />

Challenge H<strong>and</strong>shake Authentication Protocol (CHAP). CHAP is an authentication<br />

scheme, used by several types of servers, to validate the identity of remote clients. This<br />

authentication occurs when you establish the initial link. The authentication is based on a<br />

shared secret <strong>and</strong> is bi-directional.<br />

CHAP: An initiator-target authentication protocol that uses a challenge to verify that<br />

systems have access to each other, either one way or both ways. CHAP happens<br />

constantly without user interaction.<br />

Chapter 6. iSCSI <strong>SAN</strong> <strong>Boot</strong> <strong>Implementation</strong> with <strong>IBM</strong> system Storage DS5000 395

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!