ISCSI Target Configuration

Revision as of 05:45, 7 October 2026 by Qadmin (talk | contribs) (osn-seo-utilities: docs-iscsi-target-presentation-of-storage-volumes-t @ a4968c7b29ee (approved in the portal))
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

QuantaStor presents each Storage Volume to iSCSI clients as its own target, with its own IQN, on the network ports you allow for iSCSI. This page covers how the target IQN is formed, which addresses a target listens on, how assigning a volume to a host opens the target to that host's initiator, how CHAP is applied, and what the initiator sees once it logs in.

Section Purpose
One target per Storage Volume The target IQN format and why every iSCSI volume is LUN 0
Portals: which network ports serve iSCSI The iSCSI Portal setting on a network port, TCP port 3260, HA VIFs and Portal Groups
Hosts and initiator IQNs Registering a client by its initiator IQN
Assigning a Storage Volume to a host What an assignment programs on the target
Discovery and login What a client needs to find and log in to a target
CHAP authentication Per-volume, per-user and Resource Group CHAP
What the initiator sees Vendor and product strings, device identifiers
iSCSI sessions Viewing and dropping active sessions
Troubleshooting A volume that does not appear on the client
CLI reference The commands used on this page

One target per Storage Volume

QuantaStor uses the SCST iSCSI target. Every Storage Volume gets its own iSCSI target, and assigning the volume to more hosts adds initiators to that same target rather than creating new ones. Because each volume has a unique IQN, the volume is always presented at LUN 0 of its target. The LUN number you can set on a Storage Volume, labelled FC LUN, applies only to Fibre Channel; see Fibre Channel Target Port Management.

A target IQN has three parts after the fixed prefix:

iqn.2009-10.com.osnexus:9c30f734-0d4edacd5d071f74:volume-vmwaretest.001
                        |        |                |
                        |        |                +-- Storage Volume name (underscores become dots)
                        |        +-- first 16 hex digits of the Storage Volume ID
                        +-- first 8 hex digits of the Storage Pool ID

The pool part is what ties a target to its pool. QuantaStor uses it to decide which portals a target is offered on, which is how a volume in an HA pool follows the pool's virtual interface (see below). If a volume is in a namespace, the namespace is inserted before the pool part.

The IQN is shown in the IQN row of the Storage Volume's Properties panel and in the Target IQN/WWN column of the Storage Volumes grid. It is also returned by qs volume-get --volume=<volume>.

The IQN format is controlled by the [iqn] section of /etc/quantastor.conf. Leave it at the defaults: initiators that are already logged in identify the volume by its IQN, so a change affects every existing client.

Portals: which network ports serve iSCSI

A portal is an IP address and TCP port on which a target accepts logins. QuantaStor's iSCSI target listens on TCP port 3260. If a firewall sits between the clients and the appliance, it must allow that port; see Firewall Configuration.

The iSCSI Portal setting on a network port

Navigation: Storage Management → Storage Systems (section) → select a Storage System → Network Ports (tab) → select a port (select + right-click) → Modify Network Port

Each network port has an iSCSI Portal checkbox in the Modify Network Port dialog. The dialog's tooltip describes it: by checking this option this interface becomes an allowed portal for the protocol. A target is offered only on ports that have iSCSI enabled and a valid IP address. Clear the checkbox on management or replication ports to keep block traffic off them. The checkbox is not available on the grid management virtual interface. Network Ports covers the rest of the dialog.

From the CLI, use qs network-port-modify --port=<port> --iscsi-enable=true. The Properties panel for a port shows the current setting in the iSCSI Enabled? row.

If no port on the appliance has iSCSI enabled, QuantaStor binds the targets to the loopback address only, which blocks all external iSCSI access.

HA pools and virtual interfaces

For a volume in a high-availability Storage Pool, QuantaStor offers the target only on the pool's HA virtual interfaces (VIFs), not on the appliance's physical port addresses. The VIF moves with the pool on failover, so a client that logged in through it reconnects to the node that now owns the pool. Point initiators at the VIF address, never at a node's own IP. Configure the VIF in High-availability VIF Management, and enable iSCSI on it when you create it.

Volumes in a scale-out (Ceph) pool are offered on the site cluster VIFs by default; see Cluster VIFs.

Portal Groups

A Portal Group restricts a set of Storage Volumes to a specific set of cluster VIFs and FC ports, for example to keep one group of clients on one storage network. Portal Groups live in the Hosts & Portal Groups section. A Portal Group belongs to one Storage Pool, and a Storage Volume can be in at most one Portal Group. Create one with qs portal-group-create --name=<name> --pool=<pool>, or list the portals a pool can use with qs pool-portals-list --pool=<pool>.

Resource Group network settings narrow the allowed portals further for volumes that belong to a tenant; see Create Resource Group.

Hosts and initiator IQNs

 
The Add Host dialog. Choose iSCSI Initiator (IQN) and paste the client's initiator IQN.
Navigation: Storage Management → Hosts & Portal Groups (section) → Host (toolbar group) → Add (toolbar)

QuantaStor grants access by initiator, so each client must exist as a host with its initiator IQN. Copy the IQN from the client: on Linux it is in /etc/iscsi/initiatorname.iscsi; on VMware ESXi it is shown on the software iSCSI adapter (see VMware Configuration); on Windows it is on the Configuration tab of the iSCSI Initiator.

The Add Host dialog has these fields:

Field Notes
Host Name A name for the host in QuantaStor. It does not have to match the client's hostname. Letters, digits and - _ . only.
Description Optional.
Operating System Type Windows, Mac OS X, Linux, Solaris, AIX, HP-UX, VMware, XenServer or Other. Windows is the default.
Initiator One of iSCSI Initiator (IQN), FC Initiator WWPN or NVMeoF Initiator (NQN). For iSCSI, select the first option and enter the IQN, for example iqn.1991-05.com.example:iscsihost-03fo1500.

The dialog takes one initiator. A client with several initiators, or a cluster node that should be reachable under one host entry, gets the others through Add Initiator on the Host toolbar group, or qs host-initiator-add --host=<host> --iqn=<iqn>. Only entries that begin with iqn. are used for iSCSI access; WWPNs and NQNs are used by the FC and NVMe-oF targets.

To give a group of clients, such as the nodes of a hypervisor cluster, the same volumes, put the hosts in a Host Group and assign volumes to the group. Hosts and Host Groups covers hosts, host groups and their dialogs in full.

The CLI equivalent of the dialog is qs host-add --hostname=<name> --iqn=<iqn> --host-type=linux.

Assigning a Storage Volume to a host

 
The Assign/Unassign Storage Volume dialog. Tick the hosts, or switch to the Host Groups tab, then click OK.
Navigation: Storage Management → Storage Volumes (section) → select a Storage Volume → Assign (toolbar)

The same dialog is on the right-click menu of a Storage Volume as Assign/Unassign Host Access.... To work from the other direction, select a host and use Assign on the Host toolbar group, or Assign Volumes... on its right-click menu, to choose several volumes for one host.

The dialog lists every host and host group. Ticked entries have access to the volume; clearing a tick removes it. The Release/free unused storage volume LUN number(s) checkbox concerns FC LUN numbers only and has no effect on iSCSI, where the LUN is always 0.

When you click OK, QuantaStor updates the volume's target:

  1. The target gets an access list (an SCST initiator group) containing the iSCSI IQNs of every assigned host and every host in an assigned host group. New initiators are added before removed ones are taken out.
  2. The volume's CHAP settings are applied to the target.
  3. The target is enabled, on the allowed portals described above.

A target is enabled only while it has at least one initiator. An unassigned volume, or one assigned only to hosts that have no iSCSI IQN, has no active iSCSI target, and no client can log in to it.

From the CLI: qs volume-assign --volume=<volume> --host-list=<host>, reversed with qs volume-unassign. qs volume-assign-list --host=<host> lists what a host can reach.

Discovery and login

QuantaStor does not configure iSNS. Clients find targets by SendTargets discovery against a portal address:

  • For a volume in a standalone pool, use the IP address of a network port with iSCSI enabled.
  • For a volume in an HA pool, use the pool's HA VIF address.
  • For a volume in a scale-out pool, use a site cluster VIF address.

On a Linux client with open-iscsi, discover and log in like this:

iscsiadm -m discovery -t sendtargets -p 10.0.20.50:3260
iscsiadm -m node -T iqn.2009-10.com.osnexus:9c30f734-0d4edacd5d071f74:vol1 -p 10.0.20.50:3260 --login

A client discovers a target only on the portals that the target is allowed on. To reach a volume over several networks for multipathing, enable iSCSI on a port in each network and log in once per portal; see Multipath Configuration. Client-side setup for Linux and Windows is covered in ISCSI Initiator Setup, and for ESXi in VMware Configuration.

CHAP authentication

Navigation: Storage Management → Storage Volumes (section) → select a Storage Volume → Modify (toolbar) → Security Settings (tab)

CHAP is set per Storage Volume, so it applies to the volume's target and to every host assigned to it. Hosts have no CHAP settings. The Security Settings tab of the Storage Volume Create and Modify dialogs has a CHAP Authentication & Policy Settings group with three options:

Option Credentials used
Use User's default CHAP user/pass if available The default CHAP username and password of the QuantaStor user who owns the volume.
Use Resource Group default CHAP user/pass The CHAP credentials of the volume's Resource Group, for multi-tenant setups.
Use Volume specific CHAP user/pass specified below The CHAP Username and CHAP Password entered in the dialog.

The username may not contain spaces. The password must be 12 to 16 alphanumeric characters. CHAP is disabled by default. Once it is enabled, the client must be configured with the same username and password before it can log in, so set the client first or expect existing sessions to fail at their next login.

From the CLI, use qs volume-modify --volume=<volume> --chap-policy=target --chap-user=<user> --chap-pass=<password>. The other --chap-policy values are user-defaults, cloud-defaults (the Resource Group credentials) and disabled.

QuantaStor configures one-way CHAP, where the target authenticates the initiator. Mutual CHAP is off.

What the initiator sees

After login, the client sees one disk per target at LUN 0, with:

Property Value
SCSI vendor OSNEXUS
SCSI product QUANTASTOR
Device identification An NAA type 6 identifier, 62000000 followed by a descriptor built from the Storage Volume ID and the Storage System ID, plus a T10 vendor ID and a unit serial number built from the same descriptor
Size The Storage Volume's size. A resize is visible after the client rescans the device.

The identifiers come from the Storage Volume's ID rather than its name, and they are the same on every portal the target is offered on. That is what lets a multipath driver recognise the paths through each portal as one device. The Properties panel of a Storage Volume also shows a VMware EUI identifier, which is how VMware Configuration matches a datastore device to its volume.

Per-volume iSCSI tuning, such as burst lengths and queued commands, comes from the volume's IO profile rather than from appliance-wide settings; see Storage Volumes.

iSCSI sessions

Navigation: Storage Management → Storage Volumes (section) → select a Storage Volume → Sessions (tab)

The Sessions tab below the Storage Volumes grid lists the active iSCSI sessions for the selected volume: Storage System, Session, State, Storage Volume, Initiator IQN/WWN, Initiator IP, Target IQN/WWN, Reads, Writes and Created. It is the quickest way to confirm that a client actually logged in, and from which address.

To end a session, right-click it and choose Drop Session; see Session Drop. The CLI help recommends removing the host's assignment instead, because dropping a session does not take away the host's access.

From the CLI: qs volume-session-list --volume=<volume> and qs volume-session-close --volume=<volume> --session-list=<session>.

Troubleshooting

Discovery returns no targets.

  • Check that the volume is assigned to a host, and that the host entry has the client's exact initiator IQN. A typo in the IQN leaves the target with no matching initiator.
  • Check that the address you discover against is on a port with iSCSI Portal enabled, or, for an HA pool, is the pool's VIF.
  • Check that TCP port 3260 is open between the client and the appliance.

Discovery works but login fails.

  • CHAP mismatch: compare the volume's CHAP settings with the client's.
  • The client is using a node IP for a volume in an HA pool. Use the VIF.

The client logs in but sees no disk.

  • Rescan the client's iSCSI adapter. On ESXi, rescan storage after every new assignment.

A volume disappears from a client.

  • Check whether the assignment was removed, the host's initiator IQN changed, or the port's iSCSI Portal setting cleared.

CLI reference

Command Purpose
qs host-add Add a host with its initiator IQN
qs host-initiator-add Add another initiator IQN to a host
qs volume-assign Give hosts access to a Storage Volume
qs volume-unassign Remove access
qs volume-assign-list List volume-to-host assignments
qs volume-modify Set the CHAP policy and credentials
qs network-port-modify Enable or disable iSCSI on a port
qs portal-group-create Restrict volumes to a set of VIFs and FC ports
qs volume-session-list List active iSCSI sessions
qs volume-session-close Close an iSCSI session

Related pages


Verified against QuantaStor 6.9.0.