7-28 SANRAD V-Switch CLI User ManualConnecting an Identity and TargetIf you are working ina V-Switch cluster,each Identity must beconnected to thetarget(s) on both V-Switches.All CLI names andaliases are casesensitiveOnce created, an identity must be connected to a target to provide it withaccess control. An identity specifies which access rights the iSCSIinitiators within the Identity have to the target.When an identity is connected to a target, it is also given a position. Theposition of the identity determines its place in the V-Switch access rightsevaluation. An identity with the position 0 (default identity) is the lastidentity evaluated when an initiator tries to access a volume. If theinitiator meets the profile of the identity, it is granted that identity ‘s accessrights. If not, the V-Switch continues to position 1. The V-Switch does notscan all identities to determine which most specifically fits the host.Therefore, identities must be positioned in decreasing specificity tofunction correctly. The V-Switch scans for the first fit and not the best fit.An identity can be connected to more than one target to provide the sameconditions for each target. Use the CLI command acl add to connect anidentity to a target.acl addYou need to define four parameters to connect an identity to a target:SWITCH PARAMETER D EFINITION STATUS E XAMPLE-ta TARGET ALIAS ALIAS OF TARGETTO ATTACH TOMANDATORY finance-id IDENTITY NAME OF ACLIDENTITYMANDATORY accounting-acc ACCESS ACCESS RIGHTS TOTARGET:DEFAULT = RWRW = READ -WRITERO = READ- ONLYNA = NOTACCESSIBLEOPTIONALDEFAULT = RWrw-pos POSITION ACL RANK INACCESS RIGHTEVALUATION SCANOPTIONALASSIGNED LASTPOSITION IFNOT SPECIFIED1