<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: iSCSI on Solaris 10 x86</title>
	<atom:link href="http://blog.scottlowe.org/2006/12/05/iscsi-on-solaris-10-x86/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2006/12/05/iscsi-on-solaris-10-x86/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:13:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Michael</title>
		<link>http://blog.scottlowe.org/2006/12/05/iscsi-on-solaris-10-x86/comment-page-1/#comment-43548</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 05 Feb 2009 21:55:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=379#comment-43548</guid>
		<description>The bulk of the security settings / permissions is handled at the target side.  That is where Ernie is directing you to.  Depending on your storage solution, the manner in which you do it may differ, but basically you configure the target to say, &quot;These are the specific initiators that are allowed to connect to this resource.&quot;   Then it doesn&#039;t matter as much if someone can see the different targets since they won&#039;t be able to authenticate.

Also for the sake of best practices you should always configure mutual CHAP authentication.  It makes a little bit more work, but adds an important piece of security.</description>
		<content:encoded><![CDATA[<p>The bulk of the security settings / permissions is handled at the target side.  That is where Ernie is directing you to.  Depending on your storage solution, the manner in which you do it may differ, but basically you configure the target to say, &#8220;These are the specific initiators that are allowed to connect to this resource.&#8221;   Then it doesn&#8217;t matter as much if someone can see the different targets since they won&#8217;t be able to authenticate.</p>
<p>Also for the sake of best practices you should always configure mutual CHAP authentication.  It makes a little bit more work, but adds an important piece of security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ernie Oporto</title>
		<link>http://blog.scottlowe.org/2006/12/05/iscsi-on-solaris-10-x86/comment-page-1/#comment-41937</link>
		<dc:creator>Ernie Oporto</dc:creator>
		<pubDate>Tue, 14 Oct 2008 14:32:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=379#comment-41937</guid>
		<description>You want to use /etc/initiators.allow to define which target LUNs can be seen with from the initiator.  This allow you to use discovery and &quot;iscsiadm list target&quot;.  Combine this with the CHAP authentication for some nice security.  Both should probably be used as a best practice.</description>
		<content:encoded><![CDATA[<p>You want to use /etc/initiators.allow to define which target LUNs can be seen with from the initiator.  This allow you to use discovery and &#8220;iscsiadm list target&#8221;.  Combine this with the CHAP authentication for some nice security.  Both should probably be used as a best practice.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

