Serve an iSCSI LUN from lin-srv and connect to it from win-srv

short · 50 min · Objective 1.2

Task

Turn lin-srv into an iSCSI target serving one LUN, connect win-srv to it with the built-in iSCSI initiator, and bring the LUN online as a local disk. Record the target and initiator names, because iSCSI access control is built on them, and see for yourself that the initiator treats network storage as a block device it formats and owns.

Steps

  1. On lin-srv, create a 1 GB backing file and, in targetcli, create a fileio backstore from it, an iSCSI target, a LUN mapped to the backstore, and a portal on the host-only address -- delete the 0.0.0.0:3260 portal targetcli creates by default first, or the new one cannot bind.
  2. On win-srv, find its initiator name with Get-InitiatorPort (or in the iSCSI Initiator control panel) and add it to the target's ACL in targetcli. Save the targetcli ls output to lab/iscsi/target.txt.
  3. On win-srv, connect with New-IscsiTargetPortal and Connect-IscsiTarget, or the iSCSI Initiator GUI. Save Get-IscsiSession | Format-List to lab/iscsi/session.txt.
  4. Bring the new disk online, initialise it, create an NTFS volume and copy a file to it. Save Get-Disk | Format-List to lab/iscsi/disk.txt.
  5. Remove win-srv's initiator from the ACL, reconnect, and record in lab/iscsi/acl-test.txt whether the connection succeeded.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Ec 'iqn.[0-9]{4}-[0-9]{2}' lab/iscsi/target.txt
grep -Eic 'IsConnected.*True' lab/iscsi/session.txt
grep -Eic 'BusType.*iSCSI' lab/iscsi/disk.txt
grep -Eic 'fail|denied|refused|unable|could not' lab/iscsi/acl-test.txt

The target listing contains at least two IQNs (the target's and the allowed initiator's), the session is connected, and Windows reports the disk's bus type as iSCSI. After the ACL entry was removed the connection must fail -- if it still succeeded, the target is open to any initiator on the network.

Notes

Two initiators writing to the same LUN with an ordinary file system will corrupt it. Shared LUNs need a cluster-aware file system, which is exactly what failover clusters provide, as the clustering lesson describes.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.