Page 1 of 1
Starwind 5 access rights
Posted: Mon Nov 16, 2009 12:52 am
by megacc
Hi ,
im trying to filter out unwanted iscsi initiator clients through access rights rules but it didn't work , the initiator client failed to detect the target.
i setup access rights as follow :
-myrule : (source :iqn.1991-05.com.micrososft.com:mail-srv.mydomain.com) , (destination : iqn.2008-08.com.starwindsoftware.com:starwind01.mydomain.com-one),(interface:all interface) <== set to allow
-DefaultAccessPolicy : Denied
is that correct ?
Re: Starwind 5 access rights
Posted: Mon Nov 16, 2009 1:13 pm
by Robert (staff)
Does it connect with no access rights at all?
Also, can you post here a screen shot of your access right inlay?
Thanks
Re: Starwind 5 access rights
Posted: Mon Nov 16, 2009 1:46 pm
by megacc
Hi Robert ,
If I set (DefaultAccessPolicy : set to allow) it will connect , i found strange thing :
on ("-myrule : (source :iqn.1991-05.com.micrososft.com:mail-srv.mydomain.com) , (destination : iqn.2008-08.com.starwindsoftware.com:starwind01.mydomain.com-one),(interface:all interface) <== set to allow") at destination i replace the iqn target name with a device name and it work although in the list there wasn't any device name only iqn target names . im far away from the pc now but i'll try to get a screen shot as soon as possible
thanks
Re: Starwind 5 access rights
Posted: Fri Nov 27, 2009 5:01 am
by Robert (staff)
Any chance we could get that screen shot?
Thanks.
Re: Starwind 5 access rights
Posted: Thu Jan 14, 2010 3:36 pm
by EGarbuzov
Hi!
I have same question.
1. Pic.1 "All allow": all my ESXs (gesx2, vhs211, vhs212, etc...) can see and work with all LUNs (main, backUP, batrachenko). All OK.
2. Pic. 2 "My rules": gesx2 see LUN main, but doesn't see LUN backUP. I try reboot esx and rescan vmhba many times.
I want to connect both LUNs (main and backUP) to gesx2. What should I do whith Access Rights?
PS: sorry for my english

Re: Starwind 5 access rights
Posted: Fri Jan 15, 2010 12:26 pm
by Constantin (staff)
I recommend you to change default policy to block. Then add all required initiators to white list.