Page 1 of 1

Starwind 5 access rights

Posted: Mon Nov 16, 2009 12:52 am
by megacc
Hi ,

im trying to filter out unwanted iscsi initiator clients through access rights rules but it didn't work , the initiator client failed to detect the target.
i setup access rights as follow :

-myrule : (source :iqn.1991-05.com.micrososft.com:mail-srv.mydomain.com) , (destination : iqn.2008-08.com.starwindsoftware.com:starwind01.mydomain.com-one),(interface:all interface) <== set to allow
-DefaultAccessPolicy : Denied

is that correct ?

Re: Starwind 5 access rights

Posted: Mon Nov 16, 2009 1:13 pm
by Robert (staff)
Does it connect with no access rights at all?
Also, can you post here a screen shot of your access right inlay?

Thanks

Re: Starwind 5 access rights

Posted: Mon Nov 16, 2009 1:46 pm
by megacc
Hi Robert ,
If I set (DefaultAccessPolicy : set to allow) it will connect , i found strange thing :
on ("-myrule : (source :iqn.1991-05.com.micrososft.com:mail-srv.mydomain.com) , (destination : iqn.2008-08.com.starwindsoftware.com:starwind01.mydomain.com-one),(interface:all interface) <== set to allow") at destination i replace the iqn target name with a device name and it work although in the list there wasn't any device name only iqn target names . im far away from the pc now but i'll try to get a screen shot as soon as possible

thanks

Re: Starwind 5 access rights

Posted: Fri Nov 27, 2009 5:01 am
by Robert (staff)
Any chance we could get that screen shot?

Thanks.

Re: Starwind 5 access rights

Posted: Thu Jan 14, 2010 3:36 pm
by EGarbuzov
Hi!

I have same question.
1. Pic.1 "All allow": all my ESXs (gesx2, vhs211, vhs212, etc...) can see and work with all LUNs (main, backUP, batrachenko). All OK.
2. Pic. 2 "My rules": gesx2 see LUN main, but doesn't see LUN backUP. I try reboot esx and rescan vmhba many times.

I want to connect both LUNs (main and backUP) to gesx2. What should I do whith Access Rights?

PS: sorry for my english :)

Re: Starwind 5 access rights

Posted: Fri Jan 15, 2010 12:26 pm
by Constantin (staff)
I recommend you to change default policy to block. Then add all required initiators to white list.