Digi, Digi International, the Digi logo, the Digi Connectware, the Making Device
Networking Easy logo, Digi One, and RealPort are trademarks or registered
trademarks of Digi International, Inc. in the United States and other countries
worldwide. All other trademarks are the property of their respective owners.
Microsoft Windows Server 2003 is a trademark of Microsoft Corporation.
4
Contents
Chapter 1Introduction
Digi CM Model Support....................................................................................9
Solaris Ready...............................................................................................153
Index .................................................................................................................155
8 Contents
Introduction
Chapter 1
Digi CM Model Support
This manual of fers info rmation on Digi CM 8-po rt, 16-po rt, 32-port, an d 48-port
models.
Feature Overview
With Digi CM, administrators can securely monitor and control servers,
routers, switches, and other network devices from anywhere on the corporate
TCP/IP network, over the Internet, or through dial-up modem connections,
even when the server is unavailable through the network.
Digi CM employs SSHv2 encryption, to keep server access passwords safe
from hackers, and supports all popular SSH clients, as well as secure access
from any Java-enabled browser. It is the first console server to provide a
secure graphical u ser int erface for easy ou t-of-ba nd m anage ment of Micro sof t
Windows Server 2003 systems. It connects to serial console ports using
standard CAT5 cables, eliminating the hassles of custom cabling. In addition,
the Digi CM offers a PCMCIA card slot, for adding dialup modems or wireless
network cards. Flash memory cards can be used to save po rt logs and backup
configuration files.
Introduction
Digi CM is available in 8-, 16-, 32- and 48-p ort models, in a 1U rack-mount
form factor.
Feature Summary
CategoryFeature
•SSH v2 server and client
Security
Authentication
•SSL
•IP Filtering
•TACACS+
•RADIUS
•LDAP
•Kerberos
•User access per port
•Local user database
Chapter 19
Feature Summary
CategoryFeature
•Command line
•WEB --HTTP/HTTPS
•SNMP
•Custom applications
Management
Data Capture
Port Access
•Port Triggers and Alerts
•Multi level menus
•Auto-discovery
•Integrated power management and control
•Automatic Device Recognition
•Local port logging
•External logging (syslog, NFS, secure
NFS, PC card)
•Telnet/SSH with custom menu
•Reverse Telnet/SSH
•HTTP/HTTPS
•Raw TCP
•Port escape menu
PC Card Support
Other Features
•CompactFlash memory card
•Wireless LAN adapter (802.11b)
•Ethernet LAN adapter
•PSTN/CDMA modem card
See http://cm.digi.com for more information.
•Solaris Ready
•Multiple users per port
•Flash upgrade able
•SSH sessions simultaneously on all ports
•Secure Clustering - Single IP for multiple
Digi CM devices
•IP addresses per port
•Automated TFTP firmware and
configuration update upon boot
•RSA SecurID® support using RADIUS
10 Chapter 1
User Groups
Introduction
The Digi CM comes with built -in user groups, defined by access levels. The
following table lists user groups, their access rights, and default user names.
GroupAccess Privileges
-----------Ports
Rootyesyesyesyesrootdbps
System Adminyes
Port Adminyesnoyesno-Useryesnonono--
Command
yes
(read only)
Root and Admin Usernames and Passwords
The Digi CM comes with two default users; root and system admin.
The user names of the Digi CM are case sensitive.
User NameDefault Password
rootdbps
Line
Configuration
Privileges
Ports System LoginPassword
yesyesadminadmin
Defaults
Adding Port Administrators and Users
The system administrator and root user can add port administrators and
additional users easily with th e web interface by choosing System
administration > User administration > Add user.
Ways to Configure the Digi CM
This section discusses the three ways to configure the Digi CM using the web
interface, configuration menu, or command line interface.
Web Interface
The web interface provides an easy way to configure the Digi CM. The root
The Digi CM web
interface features
HTTPS for secure
access.
user and system administrator can configure all featu res through the web. Port
administrators can configure ports, including port clustering, but cannot modify
system settings. No other users can use the web interface for configuration.
To access the web interface, enter the Digi CM IP address or host name in a
browser’s URL window. The following page is displayed after login.
adminadmin
Chapter 111
Ways to Configure the Digi CM
Configuration Menu
The root user and system administrator have full access to the configuration
menu from a Telnet or SSH session or a serial connection through the console
port. Functionality is similar to the web interface, with the exception of custom
menus, which can be created only from the web interface. The configuration
menu is presented to system administrators automatically. Root users access
the menu by entering the command configmenu. Port administrators can
access this menu but can mod if y ser i al port configuratio n o nl y. No other users
can access this menu.
Command Line Interface
The command line interface can be accessed from a Telnet or SSH session or
from the console port. The root user always has access to this interface. The
12 Chapter 1
system administrator can be granted read-only permission as well. No other
users can access the command line interface.
Ways of Accessing the Digi CM: Overview
There are four wa ys to access the ports on the Digi CM:
•Web Interface
•Port Access Menu
•Direct Port Access
•Custom Menus
Web Interface Access Menu
The web interface menu provides easy and convenient access to ports. All
users can access the menu by entering the Digi CM IP address or host name
in a web browser’s URL windo w. Y ou will on ly be abl e to see the port s that you
are allowed to access.
To access a port from the web interface, do the following:
1. Access the web interface.
Introduction
2. Click Serial port > Connection.
The P (Power) col umn allo ws you to control power of the attach ed devices, if a
Remote Power Management unit is attached and you have appropriate rights.
The M (Manage) column offers web based management for Windows Server
2003, Remote Power Management units or Rackable Systems Management
Card.
The “# of User” column shows how many users are actually connected to the
port and the username of the read/write user.
Chapter 113
Web Interface Access Menu
If you are conducting a special task through the console port, like BIOS
upgrade and should not be interrupted, you can notify other users by entering
a comment upon connect. This comment is shown here.
3. Select a port by clicking the icon in the C (Console) column.
A Java applet or Telnet window opens with a login prompt.
The web interface can also be configured to call a local Telnet or SSH
application, see "Configuring Host Mode" on page 47.
14 Chapter 1
Port Access Menu
The Port Access Menu provides access to ports. It is accessible to all users
through the web interface, Telnet and SSH sessions, and remote modem
access. The information that follows shows you how to access this menu.
Introduction
Access
Type
Web interface
Telnet/SSH
Command
line
Telnet/SSHAny user
PermissionsProcedure
Any user can use
this method.
Any user can use
this method.
Root
1. Access the web interface
2. Choose Serial port > Connection > Port access
menu connection
3. Log in
1. Telnet to the Digi CM specifying its IP address
and port 7000. (7000 is the default socket port for
both Telnet and SSH) Example:
telnet 192.168.15.7 7000
2. Log in
From the command line, issue the
portaccessmenu command. Examp le :
portaccessmenu
TCP port 23/22
Example: telnet digicm.digi.com
If user’s shell is configured to "Port access
menu", please refer to "Administering Users" on
page 59.
Direct Port Access
You can connect directly to a pr oper ly co nfig ured po rt thro ugh a Teln et or S SH
session. Configuratio n require ment s include set ting the Ho st Mode to C onsole
Server Mode and the Prot ocol to either Telnet or SSH. Ports, by def ault are set
to Console Server Mode and Telnet. Use the following information to make a
Telnet or SSH connection to a port:
Chapter 115
Custom Menus
TypeCommand SyntaxExample: Connection to Port 3
Telnet
SSH
WEB
Custom Menus
telnet ip-addresstcp-port
where ip-address is the Digi CM’s IP address
and tcp-port is the Listening TCP port for a
port
ssh user-name@ip-addresstcp-port
where user-name is a user’s name,
ip-address is the Digi CM’s IP address and
tcp-port is the Listening TCP port for a port
where ip-address is the Di gi CM
IP address or NDS name, port-number is the
number of the serial port and port title is the
name of the port as assigned in serial port,
port title.
Note:The example assumes that the Listening TCP port is 7003, the default for port 3.
telnet 192.168.15.7 7003
(7000 is the default socket port for both
Telnet and SSH)
ssh admin@ 192.168.15.7 -p 7003
(7000 is the default socket port for both
Telnet and SSH)
ssh sunadmin:”p=25”@Digi12
ssh ciscoadmin:”t=Cisco-main”@Digi12
Custom menus are created by either root or the system administrator to limit
your access to specific ports. For m or e infor mati o n, see "M akin g Cu stom
Menus" on page 69.
Port Escape Menu
Port escape is the ability to escape from a port without disconnecting. Port
escape is available in main session s as well as sniff sessions. Every
connection method accommodates port escape. You configure the escape
sequence per por t. Follow the procedure to configure the port escape
sequence.
1. Serial Port > Configuration > Select the port number or All.
2.
3. Click Save to flash and continue with other configurations or click Save & ap ply
Host mode configuration > Port escape sequence - enter a letter for the Port
escape sequence. The default is <ctrl> z.
for the changes to take effect.
16 Chapter 1
Introduction
The port escape menu is automaticall y started if there is one active session to
the port established and a second user tries to connect.
To open a sniff session:
1. Click Serial port > Connection.
2. Select the port you want to access.
3. Log in with your user name and password.
Chapter 117
Port Escape Menu
4. Enter the letter of the port escape sequence.
The following table describes the fi elds and the operations for the port escape
feature. You will only see the fields allowed for your permissions.
Description of Fields
Escape
Sequence
Ctrl+
mtake over main session (read/write)
senter as a slave session (read only)
bsend breaknot functional for sniff users
lshow last 100 lines of log buffermust enable logging for this option
ddisconnect a sniff sessiononly functional to admin
asend message to port user(s)not available to sniff users
rreboot device using power-switch
ppower device on/off
Description of ActionOccurrence
only presented to users with read/
write access upon entering a
session
only presented to users with read/
write access upon entering a
session
only if power management is
available on this port
(show only on or off) only if power
management is ava il abl e on thi s p ort
18 Chapter 1
Escape
Sequence
Ctrl+
xclose current connection to portcloses the current connection
Saving and Applying Changes
In the web interface, you can save and apply configuration changes in two
ways. With the one-step method, you choose “Save & apply” and changes are
saved and applied (take effect) immediately. With the two-step method, you
choose “Save to flash,” which immediately saves changes but the changes do
not take effect until you choose Apply changes. The following topics describe
how to do each of these operations.
One Step: Save and Apply Changes
To save and apply changes immediately, choose the Save & apply button.
Two-Step: Save to Flash and then Apply Changes
To save multiple changes but apply changes once, do the following:
Choose the Save to flash button.
When you finish changing the configuration, choose the Apply changes link
which is located on the left navigation menu (or the Save & apply button at the
bottom of the page.)
Introduction
Description of ActionOccurrence
Automatic Device Recognition
This feature allows the Digi CM to automatically detect and recognize attached
devices. The Digi CM sends down a probe string, “Enter”, by default then
analyzes the response. It then displays the detected OS, device and port
number like:
CISCO.Router.port3
Sun.nemo.port5
To enable Automatic Device Recognition:
1. Serial Port > Configuration > Select the port number or All.
Port title
2.
Automatic Detection
Use detected port title - Enable
Probe String - \x0D (means <Enter>)
Device detection method - Active
Detection initiation - periodically
Detection delay - every 5 minutes
3. Click Save & apply.
For more details about Automatic Device Recognition please refer to chapter
4, Configuring Ports.
- Enable
Chapter 119
Automatic Device Recognition
Port 3 shows a real world example of a detected device.
Automatic Devic e Recognition also monitors each of the configured seri al
ports. This allow s you to recei ve an e- mail or SNM P trap if th ere is a chan ge in
the expected response from the device connected to the serial port. If the
device goes down or is disconnected for any reason, you are notified.
For configuration of this alarm feature please refer to chapter 4, Configuring
Ports.
20 Chapter 1
Getting Started
n
Chapter 2
Introduction
This chapter covers basic configuration topics. Included is information on
assigning IP settings, enabling secure access with the web interface,
accessing the unit through SSH, and adding or removing users.
Note:Initial setup is described in the Quick Start Guide included with the product
packaging. A copy of this document is also available online at http://cm.digi.com.
Assigning IP Settings from the Console Port
The following steps use the console port to assign IP settings.
The default IP
address is
192.168.161.5.
1. Connect the console port on the rear panel of the Digi CM to a serial port
on a workstat io n using the Eth ernet co nsole cabl e an d the appr opria te Digi
console adapter packaged with the Digi CM. The arrow in the following
graphic points to the console port.
Getting Started
console port
CM 32 back panel show
2. Configure a terminal emulation program, such as HyperTerminal, using the
following settings:
•bps=9600
•data bits=8
•parity=none
•stop bits=1
•flow control=none.
3. Establish a connection to the console por t and press Enter to get a
command prompt.
Chapter 221
Configuring HTTP and HTTPS
4. At the login prompt, log in as admin. The default password for admin is
admin.
The Configuration menu appears.
5. Enter the number for Network configuration.
6. Enter the number for IP configuration.
7. Enter the appropriate parameters for the IP settings.
8. Press ESC when done to return to the main configuration menu.
9. Enter the number to exit and apply changes.
Changes are saved and applied immed iately. There is no need to reboot.
Configuring HTTP and HTTPS
By default HTTP and HTTPS are enabled on the Digi CM device. To modify
these settings, do the following:
1. Enter the IP address for the Digi CM in a web browser’s URL.
2. Under the left navigation bar, Network > Web server configuration
3. Select Enabled or Disabled.
4. Set the desired refresh rate for statistics, connection, and power control
data. The default value is 10 second s.
22 Chapter 2
5. Select an authentication method for accessing the web interface. The
6. To save and apply changes, click Save & apply.
Configuring for SSH
Accessing the Digi CM’s command line via SSH is enabled by default
(TCP port 22).
Getting Started
default is local.
The Digi CM
supports Blowf ish
and 3DES
encryption
methods for SSH.
Options
The Port Access Menu and individual ports can be config ured for SSH.
Configuring the Port Access Menu for SSH
1. Access the web interface.
2. Log in as root, admin, or a member of the port administration group. The
default password for root is dbps, and the default password for admin is
admin.
3. Under Serial port > Configuration >
Port access menu configuration.
The Port access configuration menu appears.
Chapter 223
Configuring for SSH
4. Select SSH as the Port access menu protocol.
5. Click Save & apply.
Configuring a Port for SSH
1. Access the web interface.
2. Log in as root, admin, or a member of the port administration group. The
default password for root is dbps, and the default password for admin is
admin.
3. Under Serial port > Configuration.
4. Select All or one individual port you want to configure for SSH.
5. Click Host mode configuration.
6. Specify SSH as the Protocol as shown in the following screenshot.
24 Chapter 2
Getting Started
7. Click Save & apply.
Adding, Editing, and Removing Users
The root user and system administrator can add, remove, or edit users from
the web interface.
Procedure
1. Access the web interface.
2. Log in as root or admin. The default password for root is dbps, and the
default password for admin is admin.
Chapter 225
Adding, Editing, and Removing Users
3. Under the System administration heading click Users administration.
4. Select Add, Edit, Remove or click the username to edit a user.
•Add: Assign a user name, user group, password, and shell.
•Edit: Change user group, password, or their shell
•Remove: Remove a user from the system
5. Click Save & apply.
Note:The root and admin users cannot be removed from the system.
About Shell Options
The shell program selection determines the interface you see when
establishing a Telnet or SSH session or connecting via the console port with
the Digi CM.
User GroupShell Program Options
rootcommand line
system admin
port adminconfiguration menu, port access menu, custom menus
userport access menu, custom menus
command line, configuration menu, port access menu, custom
menus
26 Chapter 2
Installing and Configuring PC Ca rds
n
Chapter 3
Installing and Configuring PC Cards
Introduction
This chapter includes information on adding and configuring PC cards for the
Digi CM. PC card devices that can be added to the Dig i CM include a serial
modem, compact-flash card, wireless LAN c ard, and a network LAN card.
Compatible PC Cards
All compact-flash cards work with the Digi CM, but not all serial modem,
wireless LAN, or regular LAN cards do. To see a list of compatible cards that
have been tested with the Digi CM, visit the Digi support site at
http://cm.digi.com.
Adding a Compact-flash Card
A PC card slot is located on the front panel of the Digi CM. The arrow in the
following graphic indicates the PC card slot.
PC card slot
Digi CM 32 show
To install and configure the compact-flash card on the Digi CM, do the following.
1. Insert the card into the PC card slot.
2. Access the web interface.
3. Under the PC card heading click Configuration.
Chapter 327
Adding a Network Card
4. Click Configure the detected card.
Always select the
Stop card
service button
and Save & apply
before removing
the PC card.
The following fields appea r on the confi gu rati on p ag e.
— ATA/IDE Fixed Disk Card configuration
Total data size to be used
- Enter the am ount of mem ory you wa nt to assig n to
the compact-flash card for configuration files.
Delete all files in ATA/IDE Fixed Disk Card - Select the Delete button to clear the
compact-flash card of all files.
Format ATA/IDE Fixed Disk Card. - The options are EXT2 or FAT formats.
Select the format option and then select the Format button.
Restore previously saved configuration - Click Restore to import the previously
saved configuration.
Restore currently saved configuration - Click Restore to import the most
recently saved configuration.
5. Enter the appropriate parameters on the configuration page.
6. Click Save to flash or Save & apply.
Adding a Network Card
To install and configure a network card on the Digi CM, do the following.
1. Insert the card into the PC slot.
2. Access the web interface.
3. Under the PC card heading, click Configuration.
Note:The card is automatically discovered and a configuration menu is displayed.
28 Chapter 3
Installing and Configuring PC Ca rds
4. Enter the appropriate parameters in the configuration menu.
5. Click Save & apply.
Note:If DHCP is active the IP address will appear after the configuration is saved and
applied.
Adding a Wireless LAN Card
To install and configure a wireless LAN card on the Digi CM, do the following.
1. Insert the card into the PC slot.
2. Access the web interface.
3. Under the PC card heading, click Configuration.
Note:The card is automatically discovered and a configuration menu is displayed.
4. Click Configure the detected card.
5. Enter the appropriate parameters in the configuration menu.
WEP is the acronym for Wired Equivalent Privacy and is a security protocol
for wireless LANs using encryption to protect data transfers. If you are
unsure of the set tings for th e wi rele ss card, see your network administrato r.
Chapter 329
Adding a Serial Modem
SSID - Set Service Identifier and is the name of the wireless LAN n etwork
Use WEP key - Enable or disable the WEP key
WEP mode - Encrypted or unencrypted
WEP key length - The options are 40 or 128 bits if the WEP key is enabled
WEP key string - Refer to the wireless network administrator for the
wireless encryption key string
6. Click Save to flash.
Adding a Serial Modem
The modem must first be inserted and installed on your system before it can
be used. To configure the modem do the following:
1. Access the web interface.
2. From the menu click Configuration under the PC card heading.
Note:The card is automatically discovered and a configuration menu is displayed.
30 Chapter 3
Loading...
+ 128 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.