Start of changeStart of change

Configure IPSec

Note:
Start of change
An iSCSI HBA for iSeries™ with IPSec support is required in order to use IPSec to secure the data flows over the iSCSI network. If the iSCSI HBA hardware does not support IPSec, then a connection security object still needs to be created but you should not define any IP security rules.
End of change

To configure IPSec, or to change IPSec credentials, do the following steps:

  1. This step is required if you haven't already generated the first pre-shared key. You can also perform this step at any time to change the pre-shared key: With the server shut down (NWSD varied off), use the procedure described in Change connection security configuration properties to change the properties of the connection security configuration for the server.
  2. Use the procedure described in Display connection security configuration properties to display the properties of the connection security configuration for the server.
  3. Using iSeries Navigator:
  4. This step is required only if you don't want IPSec enabled on all of the server's NWSD's connections, or if remote interface rules in the server properties have been changed from the Default value.

    Using iSeries Navigator:

  5. This step is required only if the Delivery method in the remote system configuration is Manually configured on remote system or Start of changeDynamically delivered to remote system via CHAPEnd of change: Upon the next server start (NWSD vary on), watch the hosted system's console for a prompt to press CTRL-Q. Immediately on seeing the prompt, press CTRL-Q. In the CTRL-Q utility, select the adapter that is configured to boot the hosted OS. Enter the pre-shared key from the connection security configuration properties into the pre-shared key of the target security configuration panel. See Diskless booting over iSCSI more information about the CTRL-Q utility.
    Note:
    Any non-boot iSCSI HBAs in the hosted system are automatically configured from the i5/OS configuration.
End of changeEnd of change