Using External RADIUS Servers for Initiator Authentication

Before configuring RADIUS authentication servers in the Group Manager GUI, you must set up accounts on the RADIUS servers as described in Setting Up External RADIUS Authentication Servers.

To use an external RADIUS server for initiator authentication, follow these steps:

  1. Click Group Configuration > iSCSI tab. The Group iSCSI window appears (Figure 13: Group iSCSI ).
  2. In the iSCSI Authentication panel, select Enable RADIUS authentication for iSCSI initiators.
  3. If you want the group to check for a matching local CHAP account before checking the RADIUS server, select Consult locally defined CHAP accounts first.
  4. Specify the RADIUS authentication servers. Click RADIUS settings. The RADIUS Settings dialog box (Figure 9: RADIUS Settings ) appears. Follow the instructions in Setting Up External RADIUS Authentication Servers.
  5. Note: A RADIUS server must be set up and available on the network in order for the group to access it. Be sure that the RADIUS server is highly available. Downtime will disrupt host access for any volume that requires CHAP authentication.

  6. Optionally, to prevent hosts from discovering targets for which they are not authorized, in the iSCSI Discovery panel of the Group iSCSI window, select Prevent unauthorized hosts from discovering targets. Otherwise, initiators that support discovery will attempt to log in to the target, even if they do not have the right access credentials, resulting in a large number of events logged in the group and an inefficient use of resources.

After specifying a RADIUS server, create an access control record for a volume and specify a CHAP user name (already configured on the RADIUS server) in the record. To access the volume, a host must supply the user name and its password. A host must meet all the requirements in one access control record to access the volume. See Managing Access Controls for Volumes and Snapshots for more information.