Avocent Cyclades ACS4, Cyclades ACS48 Installation/administration/user Manual

Cyclades® ACS
Installation/Administration/User Guide
FCC Warning Statement
The Cyclades ACS advanced console server has been tested and found to comply with the limits for Class A digital devices, pursuant to Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment.
This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the Installation and Service Manual, may cause harmful interference to radio communications.
Operation of this equipment in a residential area is likely to cause harmful interference in which case the user is required to correct the problem at his or her own expense.
Notice about FCC Compliance for All Cyclades ACS Advanced Console Server Models
To comply with FCC standards, the Cyclades ACS advanced console server requires the use of a shielded CAT5 cable for the Ethernet interface. Notice that this cable is not supplied with either of the products and must be provided by the customer.
Canadian DOC Notice
The Cyclades ACS advanced console server does not exceed the Class A limits for radio noise emissions from digital apparatus set out in the Radio Interference Regulations of the Canadian Department of Communications.
L’Cyclades ACS advanced console server n’émete pas de bruits radioélectriques dépassant les limites applicables aux appareils numériques de la classe A prescrites dans le règlement sur le brouillage radioélectrique edicté par le Ministère des Communications du Canada.
Cyclades® ACS Advanced Console Server
Installation, Administration and User
Guide
Avocent, the Avocent logo, The Power of Being There and Cyclades are registered trademarks of Avocent Corporation or its affiliates. All other marks are the property of their respective owners.
© 2006 Avocent Corporation. All rights reserved. 590-660-501A
Instructions
This symbol is intended to alert the user to the presence of important operating and maintenance (servicing) instructions in the literature accompanying the appliance.
Dangerous Voltage
This symbol is intended to alert the user to the presence of uninsulated dangerous voltage within the product’s enclosure that may be of sufficient magnitude to constitute a risk of electric shock to persons.
Power On
This symbol indicates the principal on/off switch is in the on position.
Power Off
This symbol indicates the principal on/off switch is in the of f position.
Protective Grounding Terminal
This symbol indicates a terminal which must be connected to earth ground prior to making any other connections to the equipment.
iii
Table of Contents
List of Figures ................................................................................................................ vii
List of Tables................................................................................................................... xi
Chapter 1: Introduction ................................................................................................... 1
Overview............................................................................................................................................1
Connectors on the ACS Console Server ............................................................................................1
Accessing the ACS Console Server and Connected Devices.............................................................2
Web Manager.....................................................................................................................................2
Prerequisites for Using the Web Manager........................................................................................3
Types of Users....................................................................................................................................3
Security ..............................................................................................................................................3
Authentication....................................................................................................................................5
VPN....................................................................................................................................................6
Packet Filtering .................................................................................................................................6
Structure of IP filtering...............................................................................................................6
Add rule and edit rule options....................................................................................................7
SNMP.................................................................................................................................................8
Notifications, Alarms and Data Buffering .........................................................................................9
Syslog servers .............................................................................................................................9
Managing Users of Connected Devices.............................................................................................9
Configuring access to connected devices.................................................................................10
ACS Console Server and Power Management ................................................................................10
Configuring power management ..............................................................................................10
Options for managing power....................................................................................................11
Chapter 2: Installation ................................................................................................... 13
Supplied with the ACS Console Server............................................................................................13
Important Pre-installation Requirements........................................................................................14
Basic Installation Procedures..........................................................................................................14
Making an Ethernet connection................................................................................................15
Making a direct connection to configure the network parameters...........................................15
Powering up the console server and the connected devices.....................................................16
TABLE OF CONTENTS
iv Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Performing basic network configuration using the wiz command ...........................................16
Adding users and configuring ports using the Web Manager..................................................19
Other Methods of Accessing the Web Manager......................................................... ......................19
Installing PCMCIA Cards ...............................................................................................................20
Connecting PM IPDUs....................................................................................................................20
Chapter 3: Web Manager for Regular Users................................................................ 23
Using the Web Manager ..................................................................................................................23
Features of Regular User Forms.....................................................................................................24
Connect............................................................................................................................................25
Connect to the console server...................................................................................................25
Connect to serial ports .............................................................................................................25
Connection protocols for serial ports.......................................................................................26
IPDU Power Management...............................................................................................................27
Outlets Manager.......................................................................................................................27
View IPDU info.........................................................................................................................28
IPDU Multi-Outlet Ctrl .................................... ...............................................................................29
Security ............................................................................................................................................31
Chapter 4: Web Manager for Administrators............................................................... 33
Common Tasks for ACS Console Server Administrators.................................................................33
Common Features of Administrator Forms.....................................................................................34
Logging Into the Web Manager.......................................................................................................35
Overview of Administrative Modes..................................................................................................36
Wizard mode.............................................................................................................................36
Expert mode..............................................................................................................................37
Chapter 5: Configuring the ACS Console Server in Wizard Mode ............................ 39
Step 1: Security Profile.............................................................................................................39
Step 2: Network Settings...........................................................................................................43
Step 3: Port Profile...................................................................................................................45
Step 4: Access.............................. .............................................................................................47
Step 5: Data Buffering..............................................................................................................49
Step 6: System Log....................................................................................................................52
Chapter 6: Applications................................................................................................. 55
Table of Contents v
Configuring the Console Server in Expert Mode.............................................................................55
Overview of menus and forms...................................................................................................55
Mapping the expert mode menus and forms.............................................................................56
Applications Menu and Forms.........................................................................................................57
Connect.....................................................................................................................................57
IPDU Power Management .......................................................................................................59
IPDU Multi-Outlet Ctrl .............................................. ..............................................................67
IPMI Power Management.........................................................................................................70
Terminal Profile menu........................................ ......................................................................74
Chapter 7: Network Menu and Forms .......................................................................... 77
Host Settings ....................................................................................................................................78
Syslog...............................................................................................................................................81
PCMCIA Management.....................................................................................................................82
VPN Connections.............................................................................................................................91
SNMP...............................................................................................................................................95
Firewall Configuration............... .....................................................................................................99
Host Table......................................................................................................................................108
Static Routes ..................................................................................................................................108
Chapter 8: Security Menu and Forms ........................................................................ 113
Users and Groups..........................................................................................................................113
Active Ports Sessions.....................................................................................................................116
Authentication................................................................................................................................117
Configuring authentication for console server logins............................................................117
Security Profiles................................................... ..........................................................................124
Security certificates ................................................................................................................128
Chapter 9: Ports Menu and Forms ............................................................................. 131
Physical Ports................................................................................................................................131
Virtual Ports ..................................................................................................................................153
Ports Status....................................................................................................................................156
Ports Statistics ...............................................................................................................................157
Chapter 10: Administration Menu and Forms........................................................... 159
System Information ........................................................................................................................159
Notifications...................................................................................................................................160
vi Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Time/Date.......................................................................................................................................164
Boot Configuration ........................................................................................................................166
Backup Configuration....................................................................................................................168
Upgrade Firmware........................................................................................................................170
Reboot............................................................................................................................................171
Online Help....................................................................................................................................171
Appendices................................................................................................................... 175
Appendix A: Technical Specifications ...........................................................................................175
Appendix B: Safety, Regulatory and Compliance Information......................................................176
Appendix C: Technical Support.....................................................................................................183
Index.............................................................................................................................. 185
vii
List of Figures
Figure 1.1: Front of the ACS Console Server with PCMCIA Card Slots (ACS4 shown)...............1
Figure 1.2: Back of the ACS Console Server Showing Connectors (ACS16 shown) .....................1
Figure 1.3: ACS Console Server Connectors................................................................................. 2
Figure 2.1: Placement of Mounting Brackets (Forward Mounting Configuration Shown).........15
Figure 2.2: Configuration Wizard Screen....................................................................................17
Figure 3.1: Regular User Form....................................................................................................24
Figure 3.2: Regular User - IPDU Power Mgmt. Forms ..............................................................27
Figure 3.3: Regular User - View IPDUs Info...............................................................................28
Figure 3.4: Regular User - IPDU Multi-Outlet (no permissions)................................................30
Figure 3.5: Regular User - IPDU Multi-Outlet (with permissions)............................................30
Figure 4.1: Administrator - Web Manager Buttons .....................................................................34
Figure 4.2: Example of Web Manager Form in Wizard Mode .....................................................37
Figure 4.3: Example of Web Manager Form in Expert Mode...................................................... 38
Figure 5.1: Administrator - Physical Ports Factory Settings .......................................................41
Figure 5.2: Wizard - Step 1: Security Profile Form.....................................................................42
Figure 5.3: Custom Security Profile Dialog Box .........................................................................43
Figure 5.4: Wizard - Step 2: Network Settings - DHCP Disabled ...............................................44
Figure 5.5: Wizard - Step 2: Network Settings - DHCP Enabled ................................................44
Figure 5.6: Wizard - Step 3: Port Profile.....................................................................................45
Figure 5.7: Wizard - Step 4: Access.............................................................................................47
Figure 5.8: Wizard - Step 4: Access Add User Dialog Box..........................................................47
Figure 5.9: Wizard - Step 4: Change Password Dialog Box........................................................48
Figure 5.10: Wizard - Step 5: Data Buffering [Local].................................................................50
Figure 5.11: Wizard - Step 5: Data Buffering [Remote]..............................................................50
Figure 5.12: Wizard - Step 6: System Log....................................................................................52
Figure 6.1: Expert Mode Screen Elements...................................................................................55
Figure 6.2: Expert - SSH session Java Applet ..............................................................................58
Figure 6.3: Expert - Applications - IPDU Power Mgmt. - Outlets Manager...............................60
Figure 6.4: IPDU Power Mgmt. - View IPDUs Info....................................................................61
Figure 6.5: IPDU Power Mgmt- Users Manager........................................................................63
Figure 6.6: Expert - IPDU Power Mgmt. - Users Manager - Add User......................................64
LIST OF FIGURES
viii Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Figure 6.7: Example of Adding IPDU Users................................................................................64
Figure 6.8: Expert - Applications - IPDU Power Mgmt. - Configuration .................................. 65
Figure 6.9: Expert - Applications - IPDU Power Mgmt. - Software Upgrade.............................66
Figure 6.10: Expert - Applications - IPDU Multi-Outlet Ctrl.....................................................67
Figure 6.11: Expert - Applications - Multi-Outlet Ctrl [not configured].................................... 67
Figure 6.12: Expert - Applications - Multi-Outlet Control Icons................................................68
Figure 6.13: Expert - IPMI Power Mgmt. Add and Edit IPMI Device Dialog Boxes..................70
Figure 6.14: Expert - IPMI Power Mgmt. Device Entry Example............................................... 70
Figure 6.15: Expert - Serial Port - Power Management - Enable Power Management.............73
Figure 6.16: Expert - Serial Port - Power Management - User Permissions .............................73
Figure 6.17: Expert - Serial Port - Power Management - Enable IPMI..................................... 74
Figure 6.18: Expert - Applications - Terminal Profile Menu.......................................................74
Figure 6.19: Expert - Terminal Profile Menu Example ..............................................................75
Figure 7.1: Expert - Network - Host Settings [DHCP Enabled]..................................................78
Figure 7.2: Expert - Network - Host Settings [DHCP disabled].................................................. 78
Figure 7.3: Expert - Network - Syslog..........................................................................................81
Figure 7.4: Expert - Network - PCMCIA Management................................................................82
Figure 7.5: PCMCIA Card Type by Slot ......................................................................................83
Figure 7.6: Expert - PCMCIA CompactFlash/Hard Disk Configuration Dialog Box................ 88
Figure 7.7: Expert - PCMCIA Wireless LAN Card Configuration Dialog Box.......................... 89
Figure 7.8: Expert - VPN New/Modify Connection Dialog Box .................................................. 92
Figure 7.9: Security Custom Profile Dialog.................................................................................94
Figure 7.10: Expert - Network - SNMP.......................................................................................96
Figure 7.11: Expert - New/Mod SNMP v1 v2 Configuration Dialog Box...................................97
Figure 7.12: Expert - New/Mod SNMP v3 Configuration Dialog Box ................................ ........ 98
Figure 7.13: Expert - Network - Firewall Configuration............................................................ 99
Figure 7.14: Expert - Firewall Configuration Edit Chain Dialog Box.....................................100
Figure 7.15: Firewall Configuration User-defined Chain Message ..........................................100
Figure 7.16: Expert - Firewall Configuration Add Chain Dialog Box ......................................100
Figure 7.17: Firewall Configuration Edit Rules for chain_name Form ...................................101
Figure 7.18: Firewall Configuration Edit Rules for chain_name Buttons.................................101
Figure 7.19: Expert - Firewall Configuration Add Rule and Edit Rule Dialog Boxes ..............101
Figure 7.20: Firewall Configuration TCP Protocol Fields and Menu Options.........................102
Figure 7.21: Firewall Configuration Add Rule and Edit Rule UDP Protocol Fields................103
Figure 7.22: Input/Output Interface Fields and Fragments Menu Options............................... 104
List of Figures ix
Figure 7.23: Firewall Configuration Add Rule and Edit Rule LOG Target Fields ...................104
Figure 7.24: Firewall Configuration Add Rule and Edit Rule REJECT Target Menu Options.105
Figure 7.25: Edit Chain Dialog Box .......................................................................................... 107
Figure 7.26: Expert - Network - Host Tables............................................................................ 108
Figure 7.27: Expert - Network - Static Routes ..........................................................................109
Figure 7.28: Expert - Static Routes Add and Edit Dialog Boxes - Default Route.....................109
Figure 7.29: Expert - Static Routes Add and Edit Dialog Boxes - Network Route ...................110
Figure 7.30: Expert - Static Routes Add and Edit Dialog Boxes - Host Route .........................110
Figure 8.1: Expert - Security - Users and Groups Form............................................................113
Figure 8.2: Expert - Security - Active Ports Sessions.................................................................116
Figure 8.3: Expert - Security - Authentication ...........................................................................117
Figure 8.4: Expert - Security - Authentication - LDAP.............................................................. 121
Figure 8.5: Expert - Administration - Time/Date......................................................................123
Figure 8.6: Expert - Security - Authentication - Kerberos.........................................................123
Figure 8.7: Expert - Security - Authentication - NIS..................................................................124
Figure 8.8: Expert - Security - Security Profile.........................................................................124
Figure 8.9: Expert - Physical Ports Default Factory Settings ................................. .................127
Figure 8.10: Serial Ports Protocol Incompatibility Dialog Box ................................................127
Figure 8.11: Custom Security Profile Dialog Box ....................................................................128
Figure 9.12: Ports - Physical Ports............................................................................................131
Figure 9.13: Ports - Physical Ports - General Form ................................................................. 133
Figure 9.14: Ports - Physical Ports - Data Buffering Enabled ...................................... ............ 143
Figure 9.15: Ports - Physical Ports - Power Management, Enable IPMI Checked................... 147
Figure 9.16: Ports - Physical Ports - Power Management-Allow All Users .............................149
Figure 9.17: Ports - Physical Ports -Power Management -Allow Users and Groups ...............150
Figure 9.18: Ports - Virtual Ports..............................................................................................153
Figure 9.19: Ports - Virtual Ports - New/Modify Port Dialog Box............................................154
Figure 9.20: Ports - Virtual Ports - New/Modify Port Dialog Box............................................155
Figure 9.21: Ports - Virtual Ports - New/Modify - Port Names Dialog box..............................156
Figure 9.22: Ports - Ports Status (Read-Only)...........................................................................156
Figure 9.23: Ports - Port Statistics (Read-Only)........................................................................157
Figure 10.1: Expert - Administration - Time/Date....................................................................164
Figure 10.2: Expert - Administration - Time and Date - NTP Enable...................................... 165
Figure 10.3: Expert - Administration - Time/Date - Edit Custom..............................................166
Figure 10.4: Expert - Administration - Online Help..................................................................172
x Cyclades ACS Advanced Console Server Installation, Administration and User Guide
xi
List of Tables
Table 1.1: Security Profile Availability.............................................................................................4
Table 1.2: Enabled Services to Access the Serial Ports Under Each Profile....................................4
Table 1.3: Enabled Protocols for Each Profile Shown with a Check Mark......................................4
Table 1.4: Authentication Methods Supported ..................................................................................5
Table 1.5: Add Rule and Edit Rule Option Definitions .....................................................................7
Table 1.6: TCP Protocol Option Definitions.....................................................................................8
Table 1.7: Common Administrator Tasks for Configuring Software.............................. .................10
Table 1.8: Power Management Configuration Tasks......................................................................10
Table 1.9: Power Management Options in the Web Manager ........................................................11
Table 2.1: ACS Console Server Shipping Box Contents, Part Numbers and Description ..............1 3
Table 2.2: Additional Information About Configuration and Administration.................................19
Table 2.3: Tasks related to connecting Cyclades IPDUs ................................................................21
Table 3.1: Common Screen Information..........................................................................................24
Table 3.2: Java Applet Buttons for Connecting to the Console Server...........................................25
Table 3.3: Available Serial Port Protocols .....................................................................................26
Table 3.4: Regular User - Outlet Management Buttons..................................................................28
Table 3.5: Power Management Display Information by Configured Port......................................28
Table 4.1: Administrator - Common Administrative Tasks .............................................................33
Table 4.2: Description of Administrator Web Manager Buttons.................................................. ...34
Table 4.3: Administrator - Options for Trying, Saving and Restoring Configuratio n Change.......35
Table 4.4: Administrator - Logout Button and Other Information in the Upper Right...................35
Table 5.1: Wizard - Serial Port Enabled Services for Each Security Profile..................................40
Table 5.2: Wizard - Serial Port Enabled Services for Each Security Profile..................................40
Table 5.3: Wizard - Enabled Protocols for Each Security Profile ..................................................40
Table 5.4: Port Profile Setup Options.............................................................................................45
Table 5.5: Wizard - Add User Dialog: Field Names and Definitions .............................................48
LIST OF TABLES
xii Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Table 5.6: Wizard - Data Buffering Field Names and Definitions..................................................51
Table 5.7: Differences beween remote and local data buffering.....................................................51
Table 6.1: Expert Mode Menu and Forms, Applications, Network and Security............................56
Table 6.2: Expert Mode Menu and Forms, Ports and Administration............................................56
Table 6.3: Expert - Applications Menu............................................................................................57
Table 6.4: Expert - Outlets Manager Icons Description.................................................................60
Table 6.5: Expert - View IPDUs General Information....................................................................62
Table 6.6: Expert - View IPDUs Unit Information..........................................................................62
Table 6.7: Expert - IPDU Multi-Outlet Ctrl Form Icons ................................................................68
Table 6.8: Expert - IPMI Information .............................................................................................71
Table 6.9: Expert - IPMI Power Mgmt. Form Icons .......................................................................71
Table 7.1: Expert - Network Menu Descriptions.............................................................................77
Table 7.2: Network Host Setting Field Defintions...........................................................................79
Table 7.3: Modem Dialog Box Fields..............................................................................................84
Table 7.4: ISDN Dialog Box Fields.................................................................................................85
Table 7.5: GSM Dialog Box Fields ...................................... ...........................................................86
Table 7.6: Ethernet Dialog Box Fields............................................................................................87
Table 7.7: CompactFlash / Hard Drive Dialog Box Fields ............................................................88
Table 7.8: Wireless LAN Dialog Box Fields....................................................................................89
Table 7.9: CDMA Dialog Box Fields ..............................................................................................90
Table 7.10: Field and Menu Options for Configuring a VPN Connection......................................93
Table 7.11: Expert - Fields and Menu Options for SNMP Configuration . .....................................97
Table 7.12: Expert - TCP Options Fields......................................................................................103
Table 7.13: UDP Options..............................................................................................................103
Table 7.14: Expert - Firewall Configuration Input/Output Interface and Fra gments Fields.......104
Table 7.15: Expert - Target LOG Options Selection Fields..........................................................105
Table 7.16: Reply Packet Names and Definitions .........................................................................105
Table 7.17: Routing Type Fields in the New/Modify Route Dialog Box .......................................110
List of Tables xiii
Table 8.1: Expert - Add User Dialog Field Names and Definitions..............................................114
Table 8.2: Expert - Active Ports Sessions Information..................................................................116
Table 8.3: Tasks for Setting up Authentication Servers.................................................................118
Table 8.4: Enabled Services to Access the Console Server Under Each Security Profile ...........125
Table 8.5: Enabled Services to Access the Serial Ports Under Each Security Profile..................125
Table 8.6: Enabled Protocols for Each Security Profile Shown with a Check Mark....................126
Table 9.7: List of Procedures for Serial Port Configuration ........................................................132
Table 9.8: Connections Protocols When Serial Port is Connected to Device Console Port ........134
Table 9.9: Available Connection Protocols When Terminal is Connected to a Serial Port .........134
Table 9.10: Connection Protocols for Modems or IPDUs............................................................136
Table 9.11: Access Form Menu and Fields.................................. .................................................140
Table 9.12: Expert - Authentication Methods and Fallback Mechanisms ....................................141
Table 9.13: List of Authentication Method Procedures.................................................................142
Table 9.14: Data Buffering Form Fields................... ....................................................................143
Table 9.15: Expert - Multi User Form Fields................................................................................145
Table 9.16: Available Options from the Allow Multiple Sessions Pull-down ...............................146
Table 9.17: Expert - Power Management Form Fields.................................................................147
Table 9.18: Other Form Fields......................................................................................................150
Table 9.19: New/Modify Port Dialog Box Fields..........................................................................154
Table 9.20: Expert - Port Status Read-Only Form........................................... .............................157
Table 9.21: Expert - Ports-Port Status Read-Only Form..............................................................157
Table 10.1: System Information Form...........................................................................................159
Table 10.2: Notifications Form Fields ..........................................................................................160
Table 10.3: Email Notifications Dialog Box Fields ......................................................................161
Table 10.4: Pager Notification Add/Edit Dialog Box Fields.........................................................162
Table 10.5: SNMP Trap Notifications Add/Edit Dialog Box Fields..............................................163
Table 10.6: Boot Configuration Form Fields................................................................................167
Table 10.7: Backup Configuration Settings if Using FTP Server .................................................168
Table 10.8: Backup Configuration if Using Storage Device.........................................................169
xiv Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Table 10.9: Expert - Upgrade Firmware Form Fields..................................................................170
Table 1.1: Technical Specifications for the ACS Console Server Hardware................................175
1
CHAPTER
1
Introduction
Overview
Each model in the Cyclades ACS advanced console server family is a 1U appliance serving as a single access point for accessing and administering servers and other devices. The following figure shows the front of the console server with its two PCMCIA card slots
.
Figure 1.1: Front of the ACS Console Server with PCMCIA Card Slots (ACS4 shown)
The following figure shows the back of an ACS16 with its Serial, Ethernet and Console ports.
Figure 1.2: Back of the ACS Console Server Showing Connectors (ACS16 shown)
Connectors on the ACS Console Server
The following figure depicts the connectors on the back of an ACS16.
COL
100
P1 P2
Console
10/100Base-T
LK/ DT
LK/ DT
CP
l
O
100-240V, 50/60Hz 0.3A P1
DT
LK
1 2 3 4 5 6 7 8
9 10 11 12 13 14 15
16
A
C
S
16
2 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Figure 1.3: ACS Console Server Connectors
The number of serial ports and power supplies depends on the model.
Accessing the ACS Console Server and Connected Devices
You can access a console server and the connected servers or devices either locally or remotely using any of the following methods.
Web Manager through LAN/WAN IP networks.
A modem, ISDN, GSM or CDMA optional PCMCIA card.
Using the W eb Manager, you can log in and launch a console session such as T elnet or SSH to
connect to the devices attached to the console server’s serial ports.
Connecting a server running a terminal emulation program enables an administrator to log into
the console server and either enter commands in the console server shell or use the Command
Line Interface (CLI) tool.
NOTE: Only one root or admin user can have an active CLI or Web Manager session. A second root or admin user must abort the session or close the other user’s session.
CAUTION: If there are cron jobs running through automated scripts, a root or admin user login can cause the automated cron jobs to fail.
Web Manager
ACS console server administrators perform most tasks through the Web Manager either locally or from a remote location. The Web Manager runs in a browser and provides a real-time view of all equipment connected to the console server.
The administrator can use the Web Manager to configure users and ports. An authorized user can access connected devices through the Web Manager to troubleshoot, maintain, cycle power and reboot connected devices.
Access the Web Manager using one of the following ways:
The IP Network.
A dial-in or callback connection with one of the following:
COL
100
P1 P2
Console
10/100Base-T
LK/ DT
LK/ DT
CP
l
O
100-240V, 50/60Hz 0.3A P1
DT
LK
1 2 3 4 5 6 7 8
9 10 11 12 13 14 15
16
A
C
S
16
Ethernet Port Console Port
Power Supplies
Serial Ports
Chapter 1: Introduction 3
An optional external modem connected to one of the serial ports.
A modem on an optional PCMCIA modem card.
An optional CDMA, GSM or ISDN card.
Prerequisites for Using the Web Manager
The following conditions must be met prior to accessing the Web Manager.
Basic network parameters must be defined on the console server so the Web Manager can be
launched over the network.
The dynamically-assigned IP address of the console server must be known. This address is
found in one of the following three ways:
Make an inquiry to the DHCP server on the subnet that the console server resides, using the MAC address.
Connect to the console server remotely using Telnet or SSH and use the ifconfig command.
Connect directly to the console server and use the ifconfig command through a terminal emulator application.
A Web Manager user account must be defined. The admin has an account by default, and can add regular user accounts to grant access to the connected servers or devices using the Web Manager.
Types of Users
The ACS console server supports the following user account types:
The root user who can manage the console server and its connected devices. The root user performs the initial network configuration. Access privileges are full read/write and management.
NOTE: It is strongly recommended that you change the default password tslinux before setting up the console server for secure access to the connected servers or devices.
Users who are in an Admin group with administrative privileges.
Regular users who can access the connected devices through the serial ports they are authorized for. Regular users have limited access to the Web Manager features.
Security
The Cyclades ACS advanced console server includes a set of security profiles that consists of predefined parameters to control access to the console server and its serial ports. This feature provides more control over the services that are active at any one time. As an additional security measure, all serial ports are disabled by default, allowing the administrator to enable and assign individual ports to users.
4 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
The following table shows the available security profiles and the active services under each profile. See Security Profiles on page 124 for detailed information and procedures.
NOTE: The Default security profile parameters are the same as Moderate profile.
NOTE: The Default security profile parameters are the Same as Moderate Profile.
Table 1.1: Security Profile Availability
Access to the Console Server Secure Moderate Open Default
Telnet P sshv1 P P P sshv2 PPPP Allow SSH root access P P P HTTP PPP HTTPS PPPP HTTP redirection to HTTPS P P
Table 1.2: Enabled Services to Access the Serial Ports Under Each Profile
Access to Serial Ports Secure Moderate Open Default
Console (Telnet) P P P Console (ssh) PPPP Console (Raw) P P P Serial Port Authentication P Bidirect (Dynamic Mode Support) P P P
Table 1.3: Enabled Protocols for Each Profile Shown with a Check Mark
Other Services Secure Moderate Open Default
SNMP P RPC P ICMP PPP FTP
Chapter 1: Introduction 5
NOTE: The Default security profile parameters are the same as Moderate profile.
Authentication
The ACS console server supports a number of authentication methods to assist the administrator with user management. Authentication can be performed locally or with a remote server, such as RADIUS, TACACS+, LDAP or Kerberos. An authentication security fallback mechanism is also employed should the negotiation process with the authentication server fail. In such situatio ns, the console server follows an alternate defined rule when the authentication server cannot authenticate the user.
The following table lists the supported authentication methods.
IPSec
Table 1.3: Enabled Protocols for Each Profile Shown with a Check Mark (Continued)
Other Services Secure Moderate Open Default
Table 1.4: Authentication Methods Supported
Authentication Type Definition
None No authentication. Kerberos Authentication is performed using a Kerberos server. Kerberos/Local Kerberos authentication is tried first, switching to Local if unsuccessful. KerberosDownLocal Local authentication is performed only when the Kerberos server is down. LDAP Authentication is performed against an LDAP database using an LDAP server. LDAP/Local LDAP authentication is tried first, switching to Local if unsuccessful. LDAPDownLocal Local authentication is performed only when the LDAP server is down. Local Authentication is performed locally. For example using the /etc/passwd file. Local/Radius Authentication is performed locally first, switching to Radius if unsuccessful. Local/TACACS+ Authentication is performed locally first, switching to TACACS+ if unsuccessful. Local/NIS Authentication is performed locally first, switching to NIS if unsuccessful. NIS NIS authentication is performed. NIS/Local NIS authentication is tried first, switching to Local if unsuccessful. NISDownLocal Local authentication is performed only when the NIS server is down. OTP Uses the one time password (OTP) authentication method.
6 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
VPN
The console server administrator can set up VPN connections to establish an encrypted communication between the console server and a host on a remote network. The encryption creates a security tunnel for dedicated communications.
You can use the VPN features on the console server to create a secure connection between the console server every machine on the subnet at the remote location or between the console server and a single remote host.
To set up a security gateway, install IPSec on any machine performing networking over IP, including routers, firewall machines, application servers and end-user machines.
The ESP and AH authentication protocols are supported. RSA Public Keys and Shared Secret are supported.
For detailed information and procedures to configure a VPN connection, see VPN Connections on page 91.
Packet Filtering
The administrator can configure the device to filter packets like a firewall. IP filtering is controlled by chains and rules.
Structure of IP filtering
The Firewall Configuration form in the Web Manager is structured on two levels:
The view table of the Firewall Configuration form containing a list of chains.
The chains which contain the rules controlling filtering.
OTP/Local Uses the local password if the OTP password fails. Radius Authentication is performed using a Radius authentication server. Radius/Local Radius authentication is tried first, switching to Local if unsuccessful. RadiusDownLocal Local authentication is performed only when the Radius server is down. TACACS+ Authentication is performed using a TACACS+ authentication server. TACACS+/Local TACACS+ authentication is tried first, switching to Local if unsuccessful. TACACS+DownLocal Local authentication is tried only when the TACACS+ server is down.
Table 1.4: Authentication Methods Supported (Continued)
Authentication Type Definition
Chapter 1: Introduction 7
Chain
A chain is a named profile that includes one or more rules defining either a set of characteristics to look for in a packet or what to do with any packet having all the defined characteristics.
The console server filter table contains a number of built-in chains, each referenced according to the packet type they handle. As defined in the rules for the default chains, all input and output packets and packets being forwarded are accepted.
Rule
Each chain can have one or more rules that define either the packet characteristics being filtered or what to do when the packet matches the rule.
Each filtered packet characteristic is compared against the rules. All defined characteristics must match. If no rules are found then the default action for that chain is applied.
Administrators can:
Add a new chain and specify rules for that chain
Add new rules to existing chains
Edit a built-in chain or delete the built-in chain rules
Add rule and edit rule options
When you add or edit a rule, you can define any of the options described in the following table.
Flag any of the above elements with Inverted to perform target action on packets not matching any criteria specified in that line. For example, if you select DROP as the target action, specify Inverted for a source IP address and do not specify any other criteria in the rule, any packets arriving from any other source IP address than the one specified are dropped.
Table 1.5: Add Rule and Edit Rule Option Definitions
Filter Options Description
Source IP and Mask Destination IP and Mask
With source IP, incoming packets are filtered for the specified IP address. With destination IP, outgoing packets are filtered. If you fill in a source or destination mask, all packets are filtered for IP addresses
from the subnetwork in the specified netmask. Protocol Select protocol options for filtering from ALL, Numeric, TCP, UDP and ICMP. Input Interface The input interface (ethN) used by the incoming packet. Output Interface The output interface (ethN) used by the outgoing packet. Fragments The types of packets to be filtered are All packets, 2nd, 3rd... fragmented packets,
non-fragmented and 1st fragmented packets.
8 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Numeric protocol options
If you select Numeric as the protocol when specifying a rule, you need to specify the desired number.
TCP protocol options
If you select TCP as the protocol when specifying a rule, you can define the following options.
UDP protocol options
Select UDP options by selecting UDP as the protocol when selecting a rule. Choose either the Source or Destination Port from the field, as defined above.
ICMP protocol options
When you select ICMP as a protocol when specifying a rule, you can select the ICMP options available on the display.
Target actions
The Target is the action to be performed on an IP packet that matches all the criteria specified in a rule.
NOTE: If the LOG and REJECT targets are selected, additional options are available.
For detailed information on LOG target options, see LOG target on page 104. For detailed information on REJECT target options, see REJECT target on page 105.
SNMP
The administrator can activate the Simple Network Management Protocol (SNMP) agent that resides on the console server so that the SNMP agent sends notifications about significant events or traps to an SNMP management application. The console server SNMP agent supports SNMP v1/v2 and v3.
See To configure SNMP: on page 98 for more information.
Table 1.6: TCP Protocol Option Definitions
Field/Menu option Definition
Source or Destination Port Specify a source or destination port number for filtering. Specify a range to
filter TCP packets for any port number within the range.
TCP Flags Specify any of the flags: SYN (synchronize), ACK (acknowledge), FIN
(finish), RST (reset), URG (urgent), PSH (push) and one of the Any, Set, or Unset conditions to filter TCP packets for the specified flag and selected condition.
Chapter 1: Introduction 9
Notifications, Alarms and Data Buffering
The administrator can set up logging, notifications and alarms to alert administrators of problems. System generated messages on the console server and the connected servers or devices can be sent to syslog servers for handling. The administrator can also configure data buffering to store data from communication on serial ports for monitoring.
Data from communication with serial-connected consoles can be stored locally in the console server’s flash memory or remotely either on an NFS server or a syslog server.
Syslog servers
Messages about the console server and connected servers or devices can be sent to central logging servers, called syslog servers. Console data from devices connected to serial ports can be stored in data buffer files on syslog servers. By default, logging and data buffering are not done.
Prerequisites for logging to syslog servers
Before configuring syslogging, ensure that syslog server is pre-configured with a public IP address and is accessible from the console server. The system administrator must obtain both the IP address of the syslog server from the syslog server’s administrator and the facility number for messages from the console server. Facility numbers are used on the syslog server for handling messages generated by multiple devices.
Facility numbers for syslog messages
Each syslog server has seven local facility numbers available for its administrator to assign to different devices or groups of devices, at different locations. The available facility numbers are Local0 through Local7.
Example of using facility numbers
The syslog system administrator sets up a server called syslogger to handle log messages from two console servers. One console server is located in São Paulo, Brazil and the other in Fremont, California. The syslog server’s administrator wishes to aggregate messages from the São Paulo console server into the local1
facility and to aggregate messages from Fremont console server into
the local2
facility.
On syslogger the system administrator has configured the system logging utility to write m essages from the
local1 facility to the /var/log/saopaulo-config file and the messages from the local2
facility to the
/var/log/fremont-config file. If you were in Fremont and identifying the syslog server
using the Web Manager, according to this example, you would select the facility number local2 from the Facility Number pull-down menu on the Syslog form.
Managing Users of Connected Devices
This section provides a list of tasks that a Cyclades ACS advanced console s erver administrator can perform to enable access to connected devices.
10 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Configuring access to connected devices
During hardware installation of the console server, the installer connects the servers, devices and any IPDUs to the serial ports. During software configuration, the console server administrator performs the common tasks listed in the following table.
ACS Console Server and Power Management
The ACS console server enables users who have power management permissions to power up, power down and reboot devices. The console server offers the following power management options:
Remote power management of servers that have Intelligent Platform Management Interface (IPMI) controllers. The console server's implementation of the IPMI protocol lets authorized users manage power for servers that have embedded IPMI controllers. IPMI servers do not need to be connected to the console server because their IPMI controllers respond to out-of­band IPMI commands. Authorized users can also perform IPMI power management of serially-connected devices. The console server uses IPMI V1.5.
Remote power management of devices plugged into a Cyclades IPDU connected to the console server.
The IPDU can be connected to any serial port. Up to 128 IPDU outlets can be daisy-chained.
Configuring power management
Administrators commonly perform power management through the Web Manager to assign power management permissions to users, configure IPMI devices and configure ports for power management. The following table list the tasks for power management and where they are described.
Table 1.7: Common Administrator Tasks for Configuring Software
Task Where Documented
To Configure a Serial Port Connection Protocol for a Console Connection Page 136 To Configure User Access to Serial Ports. Page 141 To Configure a Serial Port for IPDU or IPMI Power Management Page 72 To Configure a User for IPDU Power Management Page 73
Table 1.8: Power Management Configuration Tasks
Task Where documented
Configure users to manage power on IPDUs To configure a user for IPDU power management while
connected to a serial port: on page 73
Chapter 1: Introduction 11
Configuring ports for power management by authorized users
Administrators of connected devices who have power management permissions can do power management while connected by using a hotkey that brings up a power management screen.
For IPMI power management the default hotkey is
Ctrl+p. For IPDU power management, the
default hotkey is
Ctrl+Shift+I.
Configuring ports for power management using the CLI
ACS console server administrators can use the CLI command with the config ipmi options to manage power on IPMI devices while logged into the console server with administrative rights. The ipmitool command is documented in the Cyclades ACS Advanced Console Server Command Reference Guide.
Options for managing power
Authorized users can perform power management through the console server by using forms in the web manager, from a power management screen while logged into a device or from the command line while logged into the console server.
An authorized user with administrative privileges can perform IPDU and IPMI power management. A regular user with permissions to the connected devices can perform IPDU power management.
Power management through the Web Manager
Users with power management permissions can perform power management through the Web Manager. The Web Manager menu includes the two power management options listed in the following table.
Identify servers for IPMI power management To delete, add or edit an IPMI device to enable or disable IPMI
power management: on page 72
Configure ports for power management by authorized users
To configure a serial port for IPDU power management: on page 148.
Table 1.8: Power Management Configuration Tasks (Continued)
Task Where documented
Table 1.9: Power Management Options in the Web Manager
Form Name Where Documented
IPDU Power Mgmt IPDU Power Management on page 59
To view status, lock, unlock, rename or cycle power outlets: on page 60
IPMI Power Mgmt IPMI Power Management on page 70
To delete, add or edit an IPMI device to enable or disable IPMI power management: on page 72 To manage power on an IPMI device: on page 72
12 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Power management from the console server command line
ACS console server administrators can use the ipmitool command to manage power on IPMI devices while logged into the console server with administrative rights. The ipmitool command is documented in the Cyclades ACS Advanced Console Server Command Reference Guide.
13
CHAPTER
2
Installation
Supplied with the ACS Console Server
The shipping box contains the console server along with the items shown in and Table 2.1 for ACS4 through ACS48. Use the part numbers from this table to reorder any of the parts.
Table 2.1: ACS Console Server Shipping Box Contents, Part Numbers and Description
P/N Description Purpose
PAC0199 ACS console server QuickStart Guide Basic installation guide in printed format. N/A Power cable.
One cable is included with the AC single power supply products. Two cables are included with the AC dual power supply products. No cables are included with any DC power supply products.
To connect the console server to a power source. The destination country is used to determine which type of cord is shipped based on the country’s standard power outlet. Talk with an Avocent sales representative if you have special requirements.
CAB0010 NEMA5--15P. Flat blades with round
grounding pin.
United States and Canada
CAB0037 Schuko. Round pin attachment plug. Continental Europe CAB0055 Oblique flat blades with ground. Australia and New Zealand CAB0056/
CAB0104
Rectangular blade plug. UK and Ireland
CAB0278 Flat blades with round grounding pin. Japan ADB0017 RJ45 to DB25F crossover adaptor To connect the console port to a server with a DB-25
male connector.
ADB0025 RJ45 to DB25M crossover adaptor To connect the console port to a server that has a
DB-25 female connector.
ADB0036 RJ45 to DB9F crossover adaptor To connect the console port to a server that has a
DB-9 connector.
14 Cyclades ACS Advanced Console Server Installation, Administration and User Guide
Important Pre-installation Requirements
Before installing and configuring the console server, ensure that you have the following:
Root Access on your local UNIX machine to use the serial ports.
An appropriate terminal application for your operating system.
IP address, DNS, Netwoprk Mask and Gateway addresses of your server or terminal, the console server and the machine to which the console server is connected.
A web browser that supports the console server Web Manager, such as Netscape, Internet Explorer, Firefox or Mozilla.
Java 2 Runtime Environment (JRE) version 1.4.2 or later . If a more recent version is available, go to http://java.com to locate and download the latest version of J2RE.
Basic Installation Procedures
Mounting the console server
You can mount the ACS console server on a wall, rack or cabinet or place it on a desktop or other flat surface. Two brackets are supplied with six hex screws for attaching the brackets to the console server for mounting.
ADB0039 Sun/Netra crossover adaptor To connect the console port to a Sun Netra server,
or other devices with the same pinout configuration.
CAB0018 RJ45 to RJ45 7ft. CAT5 cable Use for the following:
To connect a device or an IPDU to a serial port. To connect an Ethernet port to the LAN.
To connect a terminal to a console port. CAB0025 RJ45 to DB25M straight-thru cable Use for modems and other DCE devices. CON0071 DB25F Loopback Use to test and diagnose serial ports. HAR0220 2 - Mounting brackets with
8 - screws (2 spares)
Use to mount the console server to a rack or
cabinet. To mount on a wall, order the brackets
under part number: HAR0220.
Table 2.1: ACS Console Server Shipping Box Contents, Part Numbers and Description (Continued)
P/N Description Purpose
Loading...
+ 182 hidden pages