Appendix B. Deploying iSCSI host interface controllers on the IBM System Storage DS5000 series
523
The iSNS server listening port is the TCP port number that the controller tries to connect to a
server. This process lets the iSNS server register the storage subsystem with the iSCSI target
and the iSCSI portals so that the host initiators can find the storage subsystem. The default
value for this listening port is 3205.
Challenge Handshake Authentication Protocol
The Challenge Handshake Authentication Protocol (CHAP) provides an additional security
layer within the iSCSI SAN on the DS5000 storage subsystems When CHAP is enabled, the
initiator sends the target a random value and an ID value. Both the initiator and the target
share a predefined “secret,” or password. The peer then concatenates the random value, the
ID, and the secret to calculate a one-way hash using the MD5 hash function. This hash value
is then sent back to the initiator, which in turn builds the same string, calculates the MD5 sum,
and compares the result with the value received by the target. If the values match, then the
iSCSI session is considered established and future communication proceeds with
subsequent increases of the ID value to prevent possible replay attacks. By default, CHAP is
not enabled nor enforced on the DS5000 storage subsystem and this method is highly
recommended for enhanced security. Figure B-6 shows the CHAP setup in the iSCSI settings
window.
Figure B-6 Configuring CHAP and secret
The CHAP secret must be between 12 characters and 57 characters. The CHAP secret must
use ASCII code characters with a decimal value between 32 and 126. In Figure B-6, the utility
is used to generate a “secret”.
Содержание System Storage DS4000
Страница 2: ......
Страница 18: ...xvi IBM Midrange System Storage Hardware Guide...
Страница 40: ...22 IBM Midrange System Storage Hardware Guide...
Страница 302: ...284 IBM Midrange System Storage Hardware Guide...
Страница 344: ...326 IBM Midrange System Storage Hardware Guide...
Страница 372: ...354 IBM Midrange System Storage Hardware Guide Figure 7 25 Drive firmware Incompatible...
Страница 490: ...472 IBM Midrange System Storage Hardware Guide...
Страница 522: ...504 IBM Midrange System Storage Hardware Guide...
Страница 544: ...526 IBM Midrange System Storage Hardware Guide...
Страница 561: ...Index 543 Z zoning 129 130...
Страница 562: ...544 IBM Midrange System Storage Hardware Guide...
Страница 564: ...IBM Midrange System Storage Hardware Guide IBM Midrange System Storage Hardware Guide...
Страница 565: ......