Work with volume access groups and initiators

Contributors amgrissino ntap-bmegan Download PDF of this page

You can use iSCSI initiators or Fibre Channel initiators to access the volumes defined within volume access groups.

You can create access groups by mapping iSCSI initiator IQNs or Fibre Channel WWPNs in a collection of volumes. Each IQN that you add to an access group can access each volume in the group without requiring CHAP authentication.

There are two types of CHAP authentication methods:

  • Account-level CHAP authentication: You can assign CHAP authentication for the account.

  • Initiator-level CHAP authentication: You can assign unique CHAP target and secrets for specific initiators without being bound to single CHAP across a single account. This CHAP level authentication supersedes account level credentials.

Optionally, with per-initiator CHAP, you can enforce initiator authorization and per-initiator CHAP authentication. These options can be defined on a per-initiator basis and an access group can contain a mix of initiators with different options.

Each WWPN that you add to an access group enables Fibre Channel network access to the volumes in the access group.

Volume access groups have the following limits:
  • A maximum of 64 IQNs or WWPNs are allowed in an access group.

  • An access group can be made up of a maximum of 2000 volumes.

  • An IQN or WWPN can belong to only one access group.

  • A single volume can belong to a maximum of four access groups.