EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts P/N 300 003 807, Revision A06 May 30, 2008 This document describes how to configure iscsi initiator ports and how to set up iscsi security on a server connected to the iscsi data ports on CX4 series, CX3 UltraScale TM series, CX series, AX4 5 series, and AX150 series storage systems. We recommend that you use this guide in conjunction with one of the followingguides,whichareavailableonthepowerlink website: thestorage-systemsetupguide(ax4 5serieswithNavisphereExpress, CX4 series, CX3 series, or CX series storage systems) the storage-system getting started guide (AX150 series storage systems with Navisphere Express) the installation roadmap (P/N 069001166) (AX4 5 series or AX150 series with Navisphere Manager, CX4 series, CX3 series, or CX series storage systems) IMPORTANT For more information on supported operating system revisions, driver types, or features, refer to the E-Lab Interoperability Navigator on the Powerlink website for CX4 series, CX3 series, or CX series storage systems, and the Support Matrix link on the Install page of the storage-system support website for AX4-5 series or AX series storage systems. Topics include: Before you start... 3 iscsi server setup process overview... 6 Assigning an IP address to a NIC or iscsi HBA... 7 Enabling services and agents in the initiator firewall (ESX Server 3.x)... 10 1
Configuring an ESX Server 3i or 3.x host for software or hardware iscsi initiators... 11 Preparing for CHAP security... 14 Configuring CHAP on the iscsi initiators... 15 Modifying CHAP credentials on the server... 17 2 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Before you start Before you use this guide to set up iscsi initiator ports on the server or to set up iscsi security (Challenge Handshake Authentication Protocol CHAP),youmust: configure the storage-system iscsi ports as described in the storage-system setup guide, the storage-system getting started guide, or the installation roadmap (storage systems with Navisphere Manager only). complete the worksheets in the storage system configuration planning guide that either shipped with your storage system or that you generated from the customized storage-system support website. For AX4-5 series or AX150 series, you can generate a planning guide using the Plan link on the Install page of the storage-system support website. For CX4 series, CX3 series or CX series, you can generate a planning guide using the Plan link on the storage-system support website. For more information on CHAP security, refer to the CHAP security overview, page 4. Otherwise,refertotheiSCSI server setup process overview, page 6. For information on how VMware ESX Server uses CHAP, refer to the Virtual Infrastructure Server Configuration Guide. Terms used in this guide The table below lists the storage system terms used in this guide. Table 1 Storage system models Storage system term Refers to CX4 series CX4-120, CX4-240, CX4-480, and CX4-960 storage systems CX3 series CX3 model 10 systems, CX3 model 20 systems, CX3 model 40 systems, and CX3 model 80 storage systems CX series AX4-5 series CX200, CX300 series, CX400, CX500 series, CX600, and CX700 storage systems AX4-5SC, AX4-5SCi, AX4-5, AX4-5i storage systems EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 3
Storage system term AX series Refers to AX150 series systems, which include the AX150SC, AX150SCi, AX150, and AX150i storage systems CHAP security overview Challenge Handshake Authentication Protocol (CHAP) is a method of authenticating iscsi users. The iscsi storage system can use CHAP to authenticate initiators and initiators can likewise authenticate targets such as the storage system.! CAUTION If you do not configure CHAP security for the storage system, any host connected to the same IP network as the storage-system iscsi portscanreadfromandwritetothestoragesystem. Ifthestorage system is on a private network, you can choose not to use CHAP security. If the storage system is on a public network, we strongly recommend that you use CHAP security. If you want to use CHAP security, you must set up and enable it on both the server and storage system before preparing LUNs or virtual disks to receive data. If you prepare disks to receive data before you set up and enable CHAP security, you lose access to the LUNs or virtual disks. While you are setting up and enabling CHAP, you may temporarily loose connectivity between the server and the storage system. CHAP has the following two variants: Initiator CHAP - Sets up accounts that iscsi initiators use to connect to targets. The target authenticates the initiator. Initiator CHAP is the primary CHAP authentication method. Navisphere Express provides Basic and Advanced initiator CHAP options. Basic CHAP specifies one secret (password) for all initiators thatlogintoagiventarget. TheAdvanced option allows you to specify a different secret for each initiator, and also allows you to set up mutual CHAP. 4 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Mutual CHAP - Applied in addition to initiator CHAP, mutual CHAP sets up an account that a target uses to connect to an initiator. The initiator authenticates the target. Mutual CHAP is not currently supported. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 5
iscsi server setup process overview The following overview describes the steps required for configuring iscsi initiator ports and setting up iscsi security. Configuring iscsi initiator ports Assign an IP address for the NICs or iscsi HBAs as described in Assigning an IP address to a NIC or iscsi HBA, page 7. Enable services and agents in the initiator firewall as described in Enabling services and agents in the initiator firewall (ESX Server 3.x), page10. Configure ESX Server 3.x for iscsi software initiators (NICs) or hardware initiators (iscsi HBAs) asdescribed inconfiguring an ESX Server 3i or 3.x host for software or hardware iscsi initiators, page 11. Setting up iscsi security Prepare for setting up CHAP on the server as described in Preparing for CHAP security, page14. Configure initiator CHAP on each NIC or iscsi HBA initiator as described in Configuring CHAP on the iscsi initiators, page15. 6 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Assigning an IP address to a NIC or iscsi HBA Assign an IP address to each NIC or iscsi HBA in the server that will be connected to the storagesystem. For the NIC or iscsi HBA IP addresses, refer to the iscsi target and initiator port network information worksheet, which you should have completed when you planned your configuration using the Administration Worksheet and the configuration and planning guide. Configuring an ESX Server 3i or 3.x host for a NIC To configure an ESX Server 3i or 3.x host for a NIC, you use the VMkernel to: Create a virtual switch (Vswitch) if you do not have one. Assign the NIC to the virtual switch. For failover to work between multiple NICs, make sure that the NICs areonthesamevirtualswitchsotheyareonthesamenicteam using the same IP address. For detailed information on configuring the VMkernel for software-initiated iscsi storage, see the document, Virtual Infrastructure Server Configuration Guide. IfthemanagementportandVMkernelarenotonthesamesubnetonan ESXServer3.xhost,thencreateaserviceconsole2inthesamevSwitch as the VMkernel. Service console 2 must be on the same subnet as the VMkernel;itcannotusethesameIPaddressastheserviceconsole. 1. Login to the VMware VI client as administrator. 2. From the inventory panel. select the server with the iscsi initiator to add to a virtual switch. 3. Click the Configuration tab and click Networking. 4. Click Add Networking. 5. In Connection Type, select VMkernel and click Next. The Network Access page appears. 6. Either select a virtual switch (Vswitch) or click Create a virtual switch to create a new virtual switch. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 7
7. Check the box next to each adapter that you want to connect to the virtual switch. The adapters that you select appear in the Preview pane. You can either create a new virtual switch without a network adapter or select a network adapter used by an existing virtual switch. The selected adapter, if currently used by another virtual switch, is removed from that virtualswitchandaddedtotheonethatyouarecreating. 8. Click Next. 9. Under Port Group Properties, select or enter a network label and a VLAN ID. The Network Label identifies the port group. The VLAN ID identifies the VLAN that the port group uses. 10. Under IP Settings, enter the adapter IP address and subnet mask for the VMkernel. 11. If necessary, you can set the VMkernel Default Gateway address as follows: a. Click Edit. b. Enter the VMkernel Default Gateway address. c. Click OK. 12. Click Next. 13. Review the summary, and if all of the settings are correct, click Finish. Assigning an IP address to an iscsi HBA in an ESX Server 3i or 3.x host 1. Login to the VMware VI client as administrator. 2. From the inventory panel, select the server with the iscsi HBA to which you want to assign an IP address. 3. Click the Configuration tab, and click Storage Adapters. 4. Select the iscsi HBA initiator whose IP address you want to assign, and click Properties. 5. Click Configure. 8 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
6. In iscsi Alias, enter the user-friendly name that you use to identify the iscsi hardware initiator. 7. Under Hardware Initiator Properties, choose one of the IP settings options. 8. Click OK. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 9
Enabling services and agents in the initiator firewall (ESX Server 3.x) Configure the service console firewall to accept services and installed management agents, enabling the services and agents to access the ESX Server 3.x host, as follows: 1. Login to the VMware VI client as administrator. 2. From the inventory panel, select the server. 3. Click the Configuration tab and then click Security Profile. 4. Click Properties to open the Firewall Properties dialog box. This dialog box lists services and management agents. 5. For software iscsi initiators, selectsoftware iscsi Client. 6. For hardware iscsi initiators, deselect Software iscsi Client. 7. Enable any other services and agents as needed by checking the corresponding boxes. 8. Click OK. 10 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Configuring an ESX Server 3i or 3.x host for software or hardware iscsi initiators Configure ESX Server 3i or 3.x for each software iscsi initiator (NIC) or hardware iscsi initiator (iscsi HBA). Configuring an ESX Server 3i or 3.x host for software iscsi initiators To configure software iscsi initiators (NICs) on a virtual machine, refer to the iscsi Server Setup Guide of the guest operating system for your virtual machine. For each software iscsi initiator (NIC port) on the ESX Server: 1. Log into VMware VI Client as administrator. 2. From the inventory panel, select the server with the initiator that you want to configure. 3. Click the Configuration tab, and click Storage Adapters. 4. Select the iscsi initiator that you want to configure, and click Properties. 5. In the iscsi Initiator Properties page, click the General tab and then click Configure. 6. Select Enabled. 7. Under iscsi Properties, you can enter an iscsi name and iscsi Alias for the software iscsi initiator, and then click OK. 8. Add target addresses for the software iscsi initiator: a. Click the Dynamic Discovery tab and then click Add. b. Enter the send targets server information and click OK to add target information from a selected storage system. c. Click Close to close the iscsi Initiator Properties page. 9. Rescan for the new NIC: a. From the inventory panel, select the server, and click the Configuration tab. b. Under Hardware, clickstorage Adapters. c. Under iscsi Software Adapters in the list of adapters, select the adapter (NIC), and then click Rescan. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 11
d. In the Rescan dialog box, select both Scan for New Storage Devices and Scan for New VMFS Volumes, andclickok. 10. Review the summary, and if all of the settings are correct, click Finish. Configuring an ESX Server 3i or 3.x host for hardware iscsi initiators For each hardware iscsi initiator (iscsi HBA port): 1. Log into VMware VI Client as administrator. 2. From the inventory panel, select the server with the initiator that you want to configure. 3. Click the Configuration tab, and click Storage Adapters. 4. Select the iscsi HBA initiator that you want to configure, and click Properties. 5. If you have not already assigned an IP address to the hardware iscsi initiator: a. Click Configure. b. In iscsi Alias, enter a user-friendly name to identify the hardware iscsi initiator. c. Under Hardware Initiator Properties, choose one of the IP settings options. d. Click OK. 6. Add target addresses for the hardware iscsi initiator: a. Click the Dynamic Discovery tab, and then click Add. b. Enter the send targets server information and click OK to add target information from a selected storage system. c. Click Close to close the iscsi Initiator Properties page. 7. Rescan for the new iscsi HBA: a. From the inventory panel, select the server, and click the Configuration tab. b. Under Hardware, clickstorage Adapters. c. In the list of adapters, select the adapter (iscsi HBA), and then click Rescan. d. In the Rescan dialog box, select both Scan for New Storage Devices and Scan for New VMFS Volumes, andclickok. 12 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
8. Review the summary, and if all of the settings are correct, click Finish. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 13
Preparing for CHAP security To prepare for using CHAP security, you must have done the following: Completed the CHAP worksheets in the chapter on iscsi configuration in the appropriate configuration and planning guide that either shipped with your storage system or that you generated from the customized storage-system support website. 14 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Configuring CHAP on the iscsi initiators Before configuring CHAP security on iscsi initiators, verify that you have completed the steps listed in the previous section, Preparing for CHAP security. Navisphere Express refers to initiator CHAP as basic CHAP. Configuring initiator CHAP for iscsi initiators in an ESX Server 3i or 3.x host ForadditionalinformationonCHAPsecurity,seethedocument,Virtual Infrastructure Server Configuration Guide.! CAUTION You must enable CHAP security for the NIC or iscsi HBA before you can configure CHAP on the storage system. While you are setting up and enabling CHAP, you may temporarily loose connectivity between the server and the storage system. Use the VMware VI Client to configure CHAP parameters for the iscsi initiators on the server: 1. Login to the VMware VI client as administrator. 2. In the inventory panel, select the server with the initiator that you want to configure. 3. Click the Configuration tab and then click Storage Adapters. 4. Select the iscsi initiator that you want to configure, and click Properties. 5. In the iscsi Initiator Properties dialog box, click the CHAP Authentication tab. 6. Click Configure. 7. Select Use the following CHAP credentials. 8. To use the initiator name as the CHAP name, select Use Initiator name. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 15
If you are using iscsi qualified names (iqn names), the initiator name format is: iqn.<year-month>.com.<naming_authority>:<unique_name> If you are using IEEE qualified names (eui names), the initiator name format is: eui:<16_character_value_assigned_by_ieee> If you want to assign a new CHAP name, deselect Use initiator name and enter the new name. 9. In the CHAP Secret box, enter the same secret that you entered on the storage system. 10. Click OK to save the changes.! CAUTION If you disable CHAP, all sessions that require CHAP authentication will terminate immediately. 11. Rescan the iscsi adapters: a. Click the Configuration tab, and then click Storage Adapters. b. Click Rescan above the storage adapters panel. c. In the Rescan dialog box, select Scan for New Storage Devices. 16 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Modifying CHAP credentials on the server Before modifying thechapsecretontheserver,youmust modify it on the storage system first. For information on modifying CHAP credentials on the storage system, refer to the Navisphere Manager or Navisphere Express online help. Modifying the CHAP secret for iscsi initiators in an ESX Server 3i or 3.x host ForadditionalinformationonCHAPsecurity,seethedocument,Virtual Infrastructure Server Configuration Guide. Use the VMware VI Client to configure CHAP parameters for the NICs (software initiators) on the server. 1. If not already connected, login to the VMware VI client as administrator. 2. In the VI Client, under Hosts & Clusters, clicktheesxserver. 3. Click the Configuration tab and then click Storage Adapters. 4. Under Storage Adapters, click the iscsi adapter. 5. In the Details pane, click Properties for the NIC. 6. In the iscsi Initiator Properties dialog box, click the CHAP Authentication tab. 7. Click Configure to enter or change CHAP parameters. 8. In the CHAP Authentication window, if you want to keep CHAP enabled, select Use the following CHAP credentials. 9. To use the initiator name as the CHAP name, select the box, Use Initiator name. If you are using iscsi qualified names (iqn names), the initiator name format is: iqn.<year-month>.com.<naming_authority>:<unique_name> If you are using IEEE qualified names (eui names), the initiator name format is: eui:<16_character_value_assigned_by_ieee> EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 17
If you want to assign a new CHAP name, deselect Use initiator name and enter the new name. 10. In the CHAP Secret box, enter the same secret that you entered on the storage system. 11. Click OK to save the changes.! CAUTION If you disable CHAP, all sessions that require CHAP authentication will terminate immediately. 18 EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts
Copyright 2006 2008 EMC Corporation. All Rights Reserved. EMC believes the information in this publication is accurate as of its publication date. The information is subject to change without notice. THE INFORMATION IN THIS PUBLICATION IS PROVIDED "AS IS." EMC CORPORATION MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Use, copying, and distribution of any EMC software described in this publication requires an applicable software license. For the most up-to-date listing of EMC product names, see EMC Corporation Trademarks on EMC.com. All other trademarks mentioned herein are the property of their respective owners. EMC CLARiiON iscsi Server Setup Guide for VMware ESX Server 3i and 3.x Hosts 19