AWS Storage Gateway User Guide
Configuring CHAP Authentication
3. On the
Create Endpoint
page, choose
AWS Services
for
Service category
.
4. For
Service Name
, choose
com.amazonaws.
region
.storagegateway
and then choose
Create
endpoint
.
5. For
VPC
, choose your VPC and note its Availability Zones and subnets.
6. Verify that
Enable Private DNS Name
is selected.
7. For
Security group
, choose the security group that you want to use for your VPC. You can accept the
default security group.
8. Choose
Create endpoint
. The initial state of the endpoint is
pending
. When the endpoint is created,
take note of the ID of the VPC endpoint that you just created.
9. In the navigation pane, choose
Endpoints
and copy your endpoint.
Now that you have a VPC endpoint, you can create your gateway. The following instructions show you
how to create a gateway using a VPC endpoint.
To create a gateway and configure it to use a VPC endpoint
1. Open the AWS Management Console at
http://console.www.amazonaws.cn/storagegateway/home
,
and choose the AWS Region that you want to create your gateway in.
If you have previously created a gateway in this AWS Region, the console shows your gateway.
Otherwise, the service homepage appears.
2. Choose a gateway type.
3. Choose a host platform.
4. Choose a service endpoint.
Note
You can associate a VPC endpoint with one gateway at a time.
5. Use your gateway's IP address to connect to gateway
6. Activate your gateway.
7. Configure local disks.
For step-by-step instructions on how to create a gateway, see the following:
• File gateway—
• Volume gateway—
• Tape gateway—
Configuring CHAP Authentication for Your
Volumes
In AWS Storage Gateway, your iSCSI initiators connect to your volumes as iSCSI targets. Storage
Gateway uses Challenge-Handshake Authentication Protocol (CHAP) to authenticate iSCSI and initiator
connections. CHAP provides protection against playback attacks by requiring authentication to access
storage volume targets. For each volume target, you can define one or more CHAP credentials. You can
view and edit these credentials for the different initiators in the Configure CHAP credentials dialog box.
To configure CHAP credentials
1. In the AWS Storage Gateway Console, choose
Volumes
and select the volume for which you want to
configure CHAP credentials.
API Version 2013-06-30
291