Error: Initiator has tried to get around the security phase, but we cannot

Hello

I started working on the new company and tonight we lost storage for about an hour and mistakes came:

SAN1 storage array error event
subsystem: MgmtExec
event: 7.4.3
time: Sun Apr 21 00:58:18 2013
"connection iSCSI to target '10.10.10.21:3260, iqn.2001-05.com.equallogic:4-52aed6-cb0bdf198-eee0000000c50212-vss-control' initiator ' 10.10.10.22:53396, iqn.1991 - 05.com.microsoft:sp2 - vm - sql2.company.local' failed for the following reason:
Initiator has tried to circumvent the security phase, but we cannot.

On windows this evening first errors began:

EventID: 4025
Source: EqualLogic
connection error iSCSI 0xefff0009 connecting to the vss-control for the 10.10.10.41 group volume

Event ID: 10
Source: iScsiPrt
Logon request failed. The login response packet is given in the dump data.

These errors I see repetition of the past in the Windows event log.

It is hyper-v virtual SQL cluster with iSCI Dell storage connection.

How to solve this problem?

Thank you

Hello

Vss control volume, which is used my MS Volume Shadow service to access the clichés of material, there's a GUY configured username. However, the initiator does not send a name of user and password c...

If you use the EQL TYPING kit, then you should allow these servers access to this volume.  Or change the ACL on this volume to allow that the servers that need to access.

Alternatively, you can remove it from the Favorites tab, so that he tries to log in the next time the server starts.

Finally, you can enable the discovery of prevnet filter this of is re - produce.

Here is a KB from the Equallogic Web site.

Solution title error: "initiator wanted to ignore the security phase but we can not." or "initiator has tried to circumvent the security phase but we cannot."

Symptom of solution of details: event on the web interface of PS log table shows a connection error for a volume that says: "initiator wanted to ignore the security phase but we cannot." This error can be repeated continuously every few seconds.

Question: by default, volumes that have enabled CHAP authentication will be shown during the process of iSCSI discovery even if the initiator does not have the authentication information c. Discovery is controlled by its address IP ACL, so if a machine matches the IP address of the ACL scope, we will see the volume. Note that multiple initiators such as those that are unix based as the initiator of the Cisco software that uses VMWare will continue to attempt to connect to the target (often, every two seconds), even if each connection attempt fails. This can fill the paper and the performance of the server can have an impact.

Solution: Limit the discovery of volumes CHAP authenticated by IP address and ensure that only servers with appropriate credentials CHAP can observe the volume at all.

The most common volume to see this error on is the special volume named "vss control." This volume is for communication with Microsoft's VSS service, using EqualLogic host integration tools. If it is configured for unlimited access, or is configured for the CHAP only, then each initiator on the SAN will be able to find out and may attempt to use it. Set ACL "vss-admin" to enter an IP address for each machine that needs to access, to ensure that no one else does.

For firmware version 2.2.3 and, before going to the volume named 'vss-control', select the Access tab and change the entries here in a proper way.

For the later version 2.3.2 (including all versions 3.X) firmware, go to the Configuration Group box and select the VSS/VDS. It's the ACL for the vss-control volume, which you should change as appropriate.

It may be necessary to restart servers that try to access this volume after changing the ACLs, however. Some initiators do not release a target once they have discovered, even though the table indicates that the target does not exist. An example of this are ESX servers, using the software initiator.

A second scenario may be a volume that is configured to be seen from in a VMWare server VM Windows using CHAP credentials and also install on the table to use a single connection Cap. Even if the credentials CHAP is setup correctly on each side if the ESX Server uses the software initiator that ESX will attempt to connect to the volume permanently every minutes or seconds depending on factors both. With configuration to several volumes in this way, it can be a drain on performance on ESX.

To troubleshoot this scenario make sure to activate the iSCSI discovery of the IUG table of PS filter. This is done from the Group/iSCSI Configuration tab. check the box off and save the configuration using the Green disk icon in the upper right of the graphical interface. This makes the servers with the initiators that are correctly setup to see a volume with CHAP will see and try to connect to these volumes. Note: once an ESX Server has seen a volume to continue to try to connect with the software initiator until the ESX Server is restarted after this option is turned on.

Note that, since the version of the firmware 3.0.5 and later, you can require authentication for CHAP-enabled volumes during discovery, by issuing the command in the CLI:

GroupName > enable discovery-use-chap grpparams

Kind regards

Tags: Dell Products

Similar Questions

Maybe you are looking for

  • What is best: Firefox or Chrome

    I'm trying to decide what browser should I use as my main browser. I know most of the people here will tell Firefox, but I would like to hear a more detailed explanation of the reason. Thank you!

  • Satellite Pro 480cdt: how to replace the power supply and memory?

    I broke the tip of the power where it goes to the back of the computer. The two pins came away from the cable. What is the size of the plug round I am looking for as a replacement? Assume that there is a standard fitting of Toshiba. The right size to

  • Design practice nor 6008 USB DAQ

    Hello I have a few question, I'd like to introduce. I need some sort of indication on how to better perform a timed cycle of acquisition driven by WSF.I'll send my VI (conceptual, not one currently working one) and ask for explanations.The goal I nee

  • Blue error screen of Windows 7 Ultimate BSOD netio.sys

    I installed Windows 7 ultimate long ago and a few days ago, he started to show me the blue screen with the error in netio.sys every hour or two exactly! It says DRIVER_IRQL_NOT_LESS_OR_EQUAL I can't understand the problem! Here's the minidump file: h

  • How can I change my annual monthly payment

    I got my subscription for a year and it is just up for renewal, but changed in price by adding more than 70 books, but I'm on a student. How this cancel or change to pay monthly? don't want to pay an extra £80!