Brocade Fabric OS Administrator's Guide Supporting Fabric OS v6.3.0 (53-1001336-02, November 2009)

262 Fabric OS Administrator’s Guide
53-1001336-02
iSCSI gateway service overview
12
FIGURE 35 Discovery domain set configuration example
Switch-to-iSCSI initiator authentication
iSCSI sessions are authenticated using CHAP (Challenge Handshake Authentication Protocol). The
iSCSI gateway service supports the following three strategies for CHAP authentication:
One-way—Only the iSCSI VT authenticates the session.
Mutual—Both the iSCSI initiator and the iSCSI VT authenticate the session.
Binding user names - Specific user names can be bound to an iSCSI VT. Only those user names
can be used for authentication during iSCSI login.
NOTE
iSCSI gateway service does not support IPSec.
Load balancing through connection redirection
Connection redirection allows iSCSI sessions to be evenly distributed across ports on the same
blade. Before the maximum number of connections is reached for any given port, logins are
redirected to the next available port, resulting in an even distribution of sessions. This distribution
occurs only during the first login phase. Existing connections are not redistributed when iSCSI ports
change state from disabled to enabled or offline to online.
Connection redirection does not need to be committed as a configuration parameter. It is
independently enabled and disabled.
IP network
iS C S I gateway s ervic e
iS CS I v irtual targe ts (V Ts )
iS CS I in itia tor A
iS CS I in itia tor B
VT 1
VT 2
VT 3
DD1
DD2
DDS et 1