{"id":2069,"date":"2015-12-12T22:25:09","date_gmt":"2015-12-12T20:25:09","guid":{"rendered":"http:\/\/blog.hosebei.ch\/?p=2069"},"modified":"2015-12-12T22:25:09","modified_gmt":"2015-12-12T20:25:09","slug":"iscsi-over-internet-with-server-2012-r2-and-an-encrypted-bitlocker-volume","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=2069","title":{"rendered":"iSCSI over Internet with Server 2012 R2 and an Encrypted Bitlocker Volume"},"content":{"rendered":"<p>In this blog post I would like to describe an opportunity to use Bitlocker for an easy Backup Solution on a Server, where you may not want to save Data without any encryption. In my case, I have one virtual Machine on a Hoster of my choice (of course, it would be Azure), where I do have a lot of storage unused, but paying for it. Currently more than 80GB is free space and I would be able to use it, and it would be more than I need for the data I want to backup. So lets go on to the virtual Server and install the iSCSI Target Role:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker01.png\" rel=\"attachment wp-att-2070\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker01.png?w=300\" alt=\"Install iSCSI Target Role\" width=\"300\" height=\"213\" class=\"aligncenter size-medium wp-image-2070\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker01.png 798w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker01-300x213.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker01-768x546.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><!--more--><\/p>\n<p>When this is done, I would suggest you that you configure the firewall for the iSCSI Target. To do this, you can open the firewall with advanced security and filter for &#8220;iSCSI Target group&#8221;, and only allow a specific IP Range or a single IP to connect on default Port 3260:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03.png\" rel=\"attachment wp-att-2072\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03.png?w=300\" alt=\"Configure Firewall for iSCSI\" width=\"300\" height=\"224\" class=\"aligncenter size-medium wp-image-2072\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03.png 1061w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03-300x224.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03-1024x765.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker03-768x574.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>When this is done, go ahead in the Server Manager, and create an new iSCSI Target and its corresponding virtual hard disc, first you have to start with the hard disc:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02.png\" rel=\"attachment wp-att-2076\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02.png?w=300\" alt=\"Create Virtual hard disc\" width=\"300\" height=\"79\" class=\"aligncenter size-medium wp-image-2076\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02.png 1200w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02-300x79.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02-1024x271.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker02-768x203.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nThe wizard to create an virtual hard disc appears, I will not annoy you with all the screens of the wizard, but I will point out those, which might be a surprise when not correctly configured. The first is, where the new Virtual hard disc will be store, as Default it uses the &#8220;C:\\iSCSIVirtualDisk&#8221; Path:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker04.png\" rel=\"attachment wp-att-2078\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker04.png?w=300\" alt=\"Create Virtual Disk\" width=\"300\" height=\"228\" class=\"aligncenter size-medium wp-image-2078\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker04.png 851w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker04-300x228.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker04-768x583.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nWhen it comes to select a iSCSI Target, you have to create a new one, and the name you give to the new target does not matter:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker05.png\" rel=\"attachment wp-att-2080\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker05.png?w=300\" alt=\"iSCSI Target Name\" width=\"300\" height=\"228\" class=\"aligncenter size-medium wp-image-2080\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker05.png 852w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker05-300x228.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker05-768x583.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAfterwards you can select, which Initiator can access this iSCSI Target, thus it is easy to fake this, it does also not really matter what you enter in the lower section of the wizard. But to have it configured, you can select an IQN or something else:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker06.png\" rel=\"attachment wp-att-2081\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker06.png?w=300\" alt=\"iSCSI Initiator\" width=\"300\" height=\"213\" class=\"aligncenter size-medium wp-image-2081\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker06.png 908w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker06-300x213.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker06-768x546.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIf you would like to use the IQN as I did, go to the Client\/Server where you would like to connect to the iSCSI Target, and open the iSCSI Initiator and go to the configuration tab, there you can see the Initiator Name (which you also can change if you like):<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker07.png\" rel=\"attachment wp-att-2083\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker07.png?w=206\" alt=\"iSCSI Initiator Name\" width=\"206\" height=\"300\" class=\"aligncenter size-medium wp-image-2083\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker07.png 476w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker07-206x300.png 206w\" sizes=\"auto, (max-width: 206px) 100vw, 206px\" \/><\/a><br \/>\nThus I was already connected, I can use my stored IQN, and can now configure the CHAP and reverse CHAP. You need only configure the CHAP, setting reverse CHAP does not impact the usage through the iSCSI initiator:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker08.png\" rel=\"attachment wp-att-2084\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker08.png?w=300\" alt=\"iSCSI configure Chap\" width=\"300\" height=\"227\" class=\"aligncenter size-medium wp-image-2084\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker08.png 852w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker08-300x227.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker08-768x582.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nBefore you finish the wizard by clicking on &#8220;Create&#8221;, you can review your settings, and if clicked, the process of creating the disk and the iSCSI Target will be started.<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker09.png\" rel=\"attachment wp-att-2087\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker09.png?w=300\" alt=\"Create iSCSI Target finished\" width=\"300\" height=\"228\" class=\"aligncenter size-medium wp-image-2087\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker09.png 850w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker09-300x228.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker09-768x584.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIt is now time to go on to the client or server, where you want to connect the iSCSI Target, open the iSCSI Initiator, and open the Discovery Tab an click on &#8220;Discover Portal &#8230; &#8220;:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker10.png\" rel=\"attachment wp-att-2089\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker10.png?w=210\" alt=\"Discover iSCSI Portal\" width=\"210\" height=\"300\" class=\"aligncenter size-medium wp-image-2089\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker10.png 483w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker10-210x300.png 210w\" sizes=\"auto, (max-width: 210px) 100vw, 210px\" \/><\/a><br \/>\nType in the name of the target, and click on OK, and the Portal should be connected:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker11.png\" rel=\"attachment wp-att-2090\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker11.png?w=300\" alt=\"Discover iSCSI Portal\" width=\"300\" height=\"183\" class=\"aligncenter size-medium wp-image-2090\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker11.png 376w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker11-300x183.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou can now switch back to the target tab and select the iSCSI target that you have created on your server and click on connect:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker12.png\" rel=\"attachment wp-att-2091\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker12.png?w=209\" alt=\"Connect to iSCSI Target\" width=\"209\" height=\"300\" class=\"aligncenter size-medium wp-image-2091\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker12.png 480w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker12-209x300.png 209w\" sizes=\"auto, (max-width: 209px) 100vw, 209px\" \/><\/a><br \/>\nIn the window that will open after your click on connect, click on advanced to configure the CHAP log in:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker13.png\" rel=\"attachment wp-att-2093\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker13.png?w=242\" alt=\"iSCSI CHAP Log on\" width=\"242\" height=\"300\" class=\"aligncenter size-medium wp-image-2093\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker13.png 548w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker13-242x300.png 242w\" sizes=\"auto, (max-width: 242px) 100vw, 242px\" \/><\/a><br \/>\nYou can the close the connect windows by accepting the settings. Afterwards it is time to open the Disk management and initialize your new Disk:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14.png\" rel=\"attachment wp-att-2096\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14.png\" alt=\"Intialize disk\" width=\"700\" height=\"418\" class=\"aligncenter size-full wp-image-2096\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14.png 1066w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14-300x179.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14-1024x611.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker14-768x458.png 768w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><br \/>\nI think your a quite familiar in initializing Disks and format them properly, so I skip those Screenshots. From this point, you will mostly wait until the local System has send and received the correspoinding iSCSI packages, which is depending on your network speed between your localsystem and the iSCSI target which represents a remote target.<br \/>\nAfter the formatting of the Disk is done, you can go on to the Explorer, and select &#8220;Turn on Bitlocker&#8221;:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15.png\" rel=\"attachment wp-att-2098\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15.png?w=300\" alt=\"Turn on Bitlocker\" width=\"300\" height=\"188\" class=\"aligncenter size-medium wp-image-2098\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15.png 1184w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15-300x188.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15-1024x643.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/12\/iscsibitlocker15-768x482.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Also this step is quite self-explaining, thus I don&#8217;t post the screenshots how to enable Bitlocker on a Disk Drive.<br \/>\nBut when the Bitlocker is initialized, it is even possible to create another VHDX on this drive, attach it within the Disk management aswell and you can still turn on bitlocker on this nested hard disc.<\/p>\n<p>Everything works fine, but those two points are unclear for me right now:<br \/>\n1. When I copy data to the Drive, the copy job is immediately done, but I know, that the data can&#8217;t already be copied to the iSCSI target. May a reader can give a point on this, or I will figure it out later.<br \/>\n2. Is this secure in some kind of ways? I don&#8217;t know, it is clear, that the encrypted VHDX on the remote Server is as secure as it can be when Bitlocker is used. Beside the encryption technology, I&#8217;m not sure, when and how the traffic sent through iSCSI (without IPsec) can affect the leakage of the Bitlocker Key or decryption opportunities. May a reader can point out something in the comments, or get in contact with me on twitter to share your knowledge.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog post I would like to describe an opportunity to use Bitlocker for an easy Backup Solution on a Server, where you may not want to save Data without any encryption. In my case, I have one virtual Machine on a Hoster of my choice (of course, it would be Azure), where I [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-2069","post","type-post","status-publish","format-standard","hentry","category-homelab"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2069"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2069\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}