Getting log-message "Login authentication failed with target .." during iSCSI login-redirect

2,394 views
Skip to first unread message

KUMAR NITISH

unread,
Jul 30, 2014, 2:41:03 AM7/30/14
to open-...@googlegroups.com
Hi all,

I am using Dell EqualLogic array as target. When I make session with this target, I am getting the logs as given below :

login response status 0101
Login authentication failed with target iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521
..
..
login response status 0000
Login Success: iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521 if=default addr=10.115.178.29:3260 (TPGT:1 ISID:0x1)

Why log "Login authentication failed with target" shows on iSCSI login-redirect..?
I think It's a bug and It should show the proper message.

Regards,
Nitish

Mike Christie

unread,
Jul 31, 2014, 2:19:14 PM7/31/14
to open-...@googlegroups.com, KUMAR NITISH
I am working with Equallogic on this now. Will update this thread when
we root cause it.
> --
> You received this message because you are subscribed to the Google
> Groups "open-iscsi" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to open-iscsi+...@googlegroups.com
> <mailto:open-iscsi+...@googlegroups.com>.
> To post to this group, send email to open-...@googlegroups.com
> <mailto:open-...@googlegroups.com>.
> Visit this group at http://groups.google.com/group/open-iscsi.
> For more options, visit https://groups.google.com/d/optout.

Mike Christie

unread,
Jul 31, 2014, 2:21:50 PM7/31/14
to open-...@googlegroups.com, KUMAR NITISH
On 07/30/2014 01:41 AM, KUMAR NITISH wrote:
> Hi all,
>
> I am using Dell EqualLogic array as target. When I make session with
> this target, I am getting the logs as given below :
>
> login response status 0101
> Login authentication failed with target
> iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521
> ..
> ..
> login response status 0000
> Login Success:
> iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521 if=default
> addr=10.115.178.29:3260 (TPGT:1 ISID:0x1)

Where did this last log message come from?

Mike Christie

unread,
Jul 31, 2014, 2:45:53 PM7/31/14
to open-...@googlegroups.com, KUMAR NITISH
Could you tell me your Equallogic array's firmware version?

KUMAR NITISH

unread,
Aug 1, 2014, 5:19:03 AM8/1/14
to open-...@googlegroups.com, csnit...@gmail.com
Hi Mike,

Dell EqualLogic firmware version is V6.0.5 (R3 16 39152).

Log messages below are coming after running "session add" command only once.


login response status 0101
Login authentication failed with target iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521
..
..
login response status 0000
Login Success: iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521 if=default addr=10.115.178.29:3260 (TPGT:1 ISID:0x1)


Thanks,
Nitish

Mike Christie

unread,
Aug 1, 2014, 12:02:00 PM8/1/14
to open-...@googlegroups.com, KUMAR NITISH
Hey,

I meant that this message does not seem to match any open-iscsi code
that I know of. I was wondering if you modified the code or where did
you get the tools you are using?


On 08/01/2014 04:19 AM, KUMAR NITISH wrote:
> login response status 0000
> Login Success:
> iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521 if=default
> addr=10.115.178.29:3260 <http://10.115.178.29:3260> (TPGT:1 ISID:0x1)
>

Mike Christie

unread,
Aug 1, 2014, 12:40:55 PM8/1/14
to open-...@googlegroups.com, KUMAR NITISH
Could you send the output of

iscsiadm -m node -T
iqn.2001-05.com.equallogic:0-8a0906-964f1f903-d850018d2a253d5f-nitishk521

It might show your passwords and usernames for CHAP, so comment them
out, or send it to me in private.


On 08/01/2014 04:19 AM, KUMAR NITISH wrote:
> addr=10.115.178.29:3260 <http://10.115.178.29:3260> (TPGT:1 ISID:0x1)
>
>
> Thanks,
> Nitish
>

Mike Christie

unread,
Aug 1, 2014, 1:31:35 PM8/1/14
to open-...@googlegroups.com, KUMAR NITISH
Hey Kumar,

Just to make sure you have set things up correctly here is some
additional info:

If you are only setting node.session.auth.username/password then just
setup the initiator side ACL/creds.

If you are trying to do bidi/mutual then on the open-iscsi side you
would set up the node.session.auth.username/password settings then also
setup the node.session.auth.username_in/password_in. So if you are
setting this up, then you would want the target side auth setup like you
can see in this doc
http://en.community.dell.com/dell-groups/dtcmedia/m/equallogic/19909634/download.aspx
on page 7.

Remember that after clearing/setting those values in iscsid.conf you
need to return the isccsiadm discovery command for the iscsid.conf
updates to be propogated to the individual per portal/node settings you
see when you run iscsiadm -m node -T yourtarget.

Thanks to Donald Williams at Dell/Equallogic.

KUMAR NITISH

unread,
Aug 13, 2014, 6:45:11 AM8/13/14
to open-...@googlegroups.com, csnit...@gmail.com
Hi Mike,

 There is no any CHAP parameter set on either side (initiator or target). Finally session is being made successfully (on the login_redirect address), but syslog shows message "Login authentication failed with target" in between.

You may have a look on the links below which is on the similar issue.
https://groups.google.com/forum/#!searchin/open-iscsi/login$20authenticatuon$20failed/open-iscsi/SeDymMdT7Zk/reBF3UPaY00J

https://groups.google.com/forum/#!searchin/open-iscsi/Login$20authentication$20failed$20with$20target/open-iscsi/qaIgnevBE0Q/XqDPNjntUjUJ

Thanks,
Nitish

Mike Christie

unread,
Aug 13, 2014, 12:19:33 PM8/13/14
to open-...@googlegroups.com, KUMAR NITISH
Ah ok. From your initial bug report/complaint, I thought you wanted
something else fixed. So we know now, that the auth error message is not
a incorrect message from getting redirected. It is a error caused by
something unknown.

Are you hitting this problem in the same way those other people are? Can
you initially login, then hit this later? Or are you hitting it in the
initial login sequence?

Can you do what I asked some of the people on those threads? Replicate
the problem and:

1. take a wireshark/tcpdump trace.
2. also run iscsid in debug mode, so we can extra info. Run iscsid by
hand with debugging on:

iscsid -d 8 -f &

Send the trace, iscsid debug info, and all the /var/log/messages.

Also, can you please tell me why your debug messages have info that are
not in the upstream open-iscsi code? Did you modify it yourself, is it
from a distro, etc?

KUMAR NITISH

unread,
Aug 14, 2014, 9:18:23 AM8/14/14
to open-...@googlegroups.com, csnit...@gmail.com

Hi Mike,

I am more interested in warning message "Login authentication failed with target ..". Today I observed that :

Initially (before setting CHAP parameters) when we try to add session then this message is not coming (on login redirect). Finally session is being made successfully.

Once CHAP parameters is set (on both side) and we try to add session then this message is coming (on login redirect). Finally session is being made successfully.

After that, if we disable the CHAP (on both sides) and then try to add session then also this message is coming (on login redirect). Finally session is being made successfully.

I will provide other info later.

Regards,
Nitish

Paul Koning

unread,
Aug 14, 2014, 10:13:21 AM8/14/14
to open-...@googlegroups.com, csnit...@gmail.com
Nitish,

We discussed this a few weeks ago.  The message is misleading, because there is no authentication error here.  I believe it’s just a trace message you should simply ignore.  It would be good for the wording to be fixed because the current wording is misleading.

paul

--
You received this message because you are subscribed to the Google Groups "open-iscsi" group.
To unsubscribe from this group and stop receiving emails from it, send an email to open-iscsi+...@googlegroups.com.
To post to this group, send email to open-...@googlegroups.com.

neilca...@gmail.com

unread,
Dec 9, 2014, 7:28:21 AM12/9/14
to open-...@googlegroups.com
Hi guys,

I am currently getting a simular error
Login to iSCSI target iqn.2001-05.com.equallogic:0-8a0906-ee861180b-5e40001a1484fc4b-xxxx01 on vmhba39 @ vmk4 failed. Target returned login error of: 0101.

These drives used to be fine on this host. 

When looking in static discovery I can see the target. We are getting this for a few volumes too. It is happening to random volumes over random hosts. 

Other hosts are connecting to this LUN with out any issues.

Any help here would be great. 

Paul Koning

unread,
Dec 11, 2014, 10:14:41 AM12/11/14
to open-...@googlegroups.com
EqualLogic arrays always do a redirect, because you connect to the group address and you are redirected by the connection balancer to a specific interface IP address.

The initiator is wrong to call code 0101 a “login error”.  The RFC is perfectly clear that redirect is NOT an error condition.  But it looks like it’s just a confusing message, nothing more.

If you’re seeing actual failures to connect, you should look for other messages that explain that; the redirect isn’t the explanation.  Real connection failures should also come with event messages on the array that report some sort of error, for example an access control reject.

paul

Reply all
Reply to author
Forward
0 new messages