Send documentation comments to mdsfeedback-doc@cisco.com
50-57
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 50 Configuring iSCSI
iSCSI Authentication Setup Guidelines and Scenarios
CHAP with Local Password Database
To configure authentication using the CHAP option with the local password database, follow these steps:
Step 1 Set the AAA authentication to use the local password database for the iSCSI protocol:
a. In Fabric Manager, choose Switches > Security > AAA in the Physical Attributes pane.
b. Click the Applications tab in the Information pane.
c. Check the Local check box for the iSCSI row and click Apply Changes.
Step 2 Set the iSCSI authentication method to require CHAP for all iSCSI clients.:
a. In Fabric Manager, choose End Devices > iSCSI in the Physical Attributes pane.
b. Click the Globals tab in the Information pane.
c. Set the AuthMethod drop-down menu to chap and click Apply Changes.
Step 3 Configure the user names and passwords for iSCSI users:
a. In Device Manager, choose Security > iSCSI.
b. Set the Username, Password and Confirm Password fields.
c. Click Create to save these changes.
Step 4 Verify the global iSCSI authentication setup:
a. In Fabric Manager, choose End Devices > iSCSI in the Physical Attributes pane.
b. Click the Globals tab in the Information pane.
CHAP with External RADIUS Server
To configure authentication using the CHAP option with an external RADIUS server, follow these steps:
Step 1 :Configure the password for the Cisco MDS switch as RADIUS client to the RADIUS server:
a. In Fabric Manager, choose Switches > Security > AAA > RADIUS in the Physical Attributes pane.
b. Click the Default tab in the Information pane.
c. Set the AuthKey field to the default password and click the Apply Changes icon.
Step 2 Configure the RADIUS server IP address:
a. In Fabric Manager, choose Switches > Security > AAA > RADIUS in the Physical Attributes pane.
b. Click the Server tab in the Information pane and click Create Row.
c. Set the Index field to a unique number.
d. Set the IP Type radio button to ipv4 or ipv6.
e. Set the Name or IP Address field to the IP address of the RADIUS server and click Create.
Step 3 Create a RADIUS server group and add the RADIUS server to the group:
a. In Fabric Manager, choose Switches > Security > AAA in the Physical Attributes pane.
b. Select the Server Groups tab in the Information pane and click Create Row.