Enabling vSAN iSCSI target service
To enable vSAN file services use following steps
- Login into vCenter
- Ideally distributed switch, dedicated VLAN for iSCSI target service and kernel ports for all ESXi hosts in this iSCSI target VLAN should already be in place.
- Click on cluster and go to Configure -> vSAN -> Services
- Click "Edit" or "Enable" against iSCSI Target services which will open dialog box for enabling iSCSI target services.
- Choose appropriate port-group which has VMkernel IPs which can be reached for iSCSI target service
- After that go to cluster -> configure -> vSAN -> iSCSI target service
- Basically we create a initiator group (Randomly generated target name), Add LUNs and allow a group of initiators (ISCSI Initiator Group) to have access to this iSCSI target
- From initiator ideally use two different IPs, install multipath and add all VMkernel ports as discovery target. This way even if one ESXi host is down, the iSCSI service can be accessed via other hosts.
Changing VMkernel portgroup used by iSCSI Target service
If we want to change the iSCSI target kernel port-group used by iSCSI Target service then we need to use below steps:
- Stop / Disconnect iSCSI initiators from accessing the targets and related LUNs. For this from initiator machines might have to make a disk offline and then disconnect the target using "iSCSI initiator" target tab.
- If we are planning to change the IPs then it also makes sense to remove favorite targets and discovery portals of old IPs
- Then once there is no one referring to the old target IPs we can go to Cluster -> Configure -> vSAN -> Services -> "iSCSI Target service" and click edit. Change kernel port group. If required we can disable/enable the service.
- Then we need to go to Cluster -> Configure -> vSAN -> iSCSI target service and edit all the existing targets and change their kernel port group
- Now we can configure the initiators to connect to the new updated IPs and hopefully the same old LUNs should get mapped again
- PSOD due to same initiator name
- It is important that if we clone any VM using iSCSI target service (instead of using local vSAN disk directly) then we should change initiator name in the cloned VM. By default cloned VM would have same initiatorname and if two VMs from two different IPs contact vSAN ISCSI target service with same initiator name, it will lead to PSOD.
- LUNs are bound to target IQN
- We cannot take a LUN from one target IQN and move/migrate it to another IQN. There is no such option from vSAN iSCSI Target service point of view. Manually we can create a new target and a LUN of similar size and map it to server. Then manually at OS /application level we can migrate data and unmap/delete older LUN. But moving LUN from one target IQN to another is not supported.