6.0.1

Table Of Contents
ESXi supports the following CHAP authentication methods:
Unidirectional CHAP
In unidirectional CHAP authentication, the target authenticates the initiator,
but the initiator does not authenticate the target.
Bidirectional CHAP
In bidirectional CHAP authentication, an additional level of security enables
the initiator to authenticate the target. VMware supports this method for
software and dependent hardware iSCSI adapters only.
For software and dependent hardware iSCSI adapters, you can set unidirectional CHAP and bidirectional
CHAP for each adapter or at the target level. Independent hardware iSCSI supports CHAP only at the
adapter level.
When you set the CHAP parameters, specify a security level for CHAP.
N When you specify the CHAP security level, how the storage array responds depends on the array’s
CHAP implementation and is vendor specic. For information on CHAP authentication behavior in
dierent initiator and target congurations, consult the array documentation.
Table 104. CHAP Security Level
CHAP Security Level Description Supported
None The host does not use CHAP authentication. Select this
option to disable authentication if it is currently
enabled.
Software iSCSI
Dependent hardware iSCSI
Independent hardware
iSCSI
Use unidirectional CHAP if
required by target
The host prefers a non-CHAP connection, but can use a
CHAP connection if required by the target.
Software iSCSI
Dependent hardware iSCSI
Use unidirectional CHAP
unless prohibited by target
The host prefers CHAP, but can use non-CHAP
connections if the target does not support CHAP.
Software iSCSI
Dependent hardware iSCSI
Independent hardware
iSCSI
Use unidirectional CHAP The host requires successful CHAP authentication. The
connection fails if CHAP negotiation fails.
Software iSCSI
Dependent hardware iSCSI
Independent hardware
iSCSI
Use bidirectional CHAP The host and the target support bidirectional CHAP. Software iSCSI
Dependent hardware iSCSI
Set Up CHAP for iSCSI Adapter
When you set up CHAP name and secret at the iSCSI adapter level, all targets receive the same parameters
from the adapter. By default, all discovery addresses or static targets inherit CHAP parameters that you set
up at the adapter level.
The CHAP name should not exceed 511 alphanumeric characters and the CHAP secret should not exceed
255 alphanumeric characters. Some adapters, for example the QLogic adapter, might have lower limits, 255
for the CHAP name and 100 for the CHAP secret.
Prerequisites
n
Before seing up CHAP parameters for software or dependent hardware iSCSI, determine whether to
congure unidirectional or bidirectional CHAP. Independent hardware iSCSI adapters do not support
bidirectional CHAP.
n
Verify CHAP parameters congured on the storage side. Parameters that you congure must match the
ones one the storage side.
Chapter 10 Configuring iSCSI Adapters and Storage
VMware, Inc. 99