This post is more than 5 years old

1 Rookie

 • 

89 Posts

427634

April 21st, 2013 08:00

Error: Initiator tried to bypass the security phase but we cannot

Hi,

I started working on new company and tonight we lost storage for about an hour and errors came:

ERROR event from storage array SAN1
subsystem: MgmtExec
    event: 7.4.3
    time: Sun Apr 21 00:58:18 2013
iSCSI login to target '10.10.10.21:3260, iqn.2001-05.com.equallogic:4-52aed6-cb0bdf198-eee0000000c50212-vss-control' from initiator '10.10.10.22:53396, iqn.1991-05.com.microsoft:sp2-vm-sql2.company.local' failed for the following reason:
Initiator tried to bypass the security phase but we cannot.

On windows this night first errors started:

EventID: 4025
Source: EqualLogic
iSCSI login error 0xefff0009 when connecting to vss-control volume for group 10.10.10.41

EventID: 10
Source: iScsiPrt
Login request failed. The login response packet is given in the dump data.

These errors I see repeating from the past in Windows event log. 

This is hyper-v virtual SQL cluster with iSCI Dell storage connection. 

How to solve this?

thanks

1 Rookie

 • 

89 Posts

April 22nd, 2013 09:00

From windows node I checked "iSCI Initiator Properties" selected one of discovered targets and in the properties I see that - Authentication: None Specified.

So do I understand it right, that on the DELL storage access to LUN or disk is controlled by  IP address ACLs and CHAP authentication enabled by default on the volume. If my Windows server has the correct IP that is configured on ACL's in the storage, but does not have CHAP authentication it will be able to discover connect and work with the volume, just CHAP authentication errors will be generated?

If this is correct, what would be the simplest way to fix this without downtime?

Not sure what is EQL HIT? And how to find if we are using it?

thanks

1 Rookie

 • 

89 Posts

April 22nd, 2013 09:00

could you please guide me a little, is it possible to check from windows side and will it require any down time if configuration will be changed?

1 Rookie

 • 

89 Posts

April 22nd, 2013 12:00

"Re: Errors.  Yes, if a volume only has a CHAP ACL, then any initator can discover the volume, but requires the CHAP username/password in order to allow login.   If the initiator tries to login anyways, you get the error you are seeing."

But in this situation our CHAP ACL is not working from server side and we still can use volumes. Does that mean CHAP is just recommended storage security enhancement in this case?

Yes, we have "Dell EqualLogic MPIO" tab in MS initiator control utility.

"On the server(s) trying to connect to the vss-control, there will be an entry for that volume in the Favorites tab in the MS iSCSI initiator control utility.   If you remove that favorite it won't try logging into that volume on start up."

If I remove the favorites I wont be able to connect automatically to storage after server reboot?

And  is it any simple way to fix this without downtime?

thanks

1 Rookie

 • 

89 Posts

April 22nd, 2013 13:00

and where exactly "Group Configuration" is? thanks

1 Rookie

 • 

89 Posts

April 23rd, 2013 06:00

As I understand EQL GUI is not installed on the windows platform (if it is, then what is the file location to run it). All I could found is IP address on Target Portals section in Discovery tab on iSCI initiators properties. I tried to browse to that IP and it asked me credentials witch I don't have. Is there any other way to solve this problem?

thanks,

1 Rookie

 • 

89 Posts

April 23rd, 2013 09:00

Thank you, and how this will solve the problem? don't I have to disable CHAP ACL on storage instead of adding iSCSI initiators name?

Group Configuration->VDS/VSS tab->Add-->Select Checkbox next to:  Limit ACcess to iSCSI initiator name   Then past in  iqn.1991-05.com.microsoft:sp2-vm-sql2.company.local  

1 Rookie

 • 

89 Posts

April 23rd, 2013 13:00

I am still trying to get password from another team.

But the situation with CHAP ACL is still not clear to me. If I add additional constraint, how it will solve CHAP ACL problem? Storage will still require CHAP and will display the error if windows iSCSI initiator won't be configured with CHAP password?

thanks

1 Rookie

 • 

89 Posts

April 24th, 2013 03:00

Oh, so login  by name will be enough in this case and CHAP authentication wont be required or it won't log the error.

Do I have to enter names of both cluster servers to "Limit ACcess to iSCSI initiator name"?

And how could I test it without the down time?

thanks

1 Rookie

 • 

89 Posts

May 1st, 2013 00:00

Hi,

I checked VDS/VSS properties and I see CHAP user: administrator and IP address and iSCSI initiator is "*".

Should I leave this and only add:

Limit ACcess to iSCSI initiator name   Then past in  iqn.1991-05.com.microsoft:sp2-vm-sql2.company.local  

thanks

No Events found!

Top