Dominion® SX
User Guide
Release 3.1
Copyright © 2007 Raritan, Inc.
DSX-0M-E
April 2007
255-60-2000-00
This page intentionally left blank.
Copyright and Trademark Information
This document contains proprietary information that is protected by copyright. All rights reserved.
No part of this document may be photocopied, reproduced, or translated into another language
without express prior written consent of Raritan, Inc.
© Copyright 2007 Raritan, CommandCenter, RaritanConsole, Dominion, and the Raritan
company logo are trademarks or registered trademarks of Raritan, Inc. All rights reserved. Java is
a registered trademark of Sun Microsystems, Inc. Internet Explorer is a registered trademark of
Microsoft Corporation. Netscape and Netscape Navigator are registered trademarks of Netscape
Communication Corporation. All other marks are the property of their respective owners.
FCC Information
This equipment has been tested and found to comply with the limits for a Class A digital device,
pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection
against harmful interference in a commercial installation. This equipment generates, uses, and can
radiate radio frequency energy and if not installed and used in accordance with the instructions,
may cause harmful interference to radio communications. Operation of this equipment in a
residential environment may cause harmful interference.
VCCI Information (Japan)
Raritan is not responsible for damage to this product resulting from accident, disaster, misuse,
abuse, non-Raritan modification of the product, or other events outside of Raritan’s reasonable
control or not arising under normal operating conditions.
U
C
LI STED
1F61
US
L
I.T.E.
For assistance in North or South America, please contact the Raritan Technical Support Team
by telephone (732) 764-8886, by fax (732) 764-8887, or by e-mail
tech@raritan.com
Ask for Technical Support – Monday through Friday, 8:00am to 8:00pm, Eastern.
For assistance around the world, please see the last page of this guide for
regional Raritan office contact information.
Safety Guidelines
To avoid potentially fatal shock hazard and possible damage to Raritan equipment:
• Do not use a 2-wire power cord in any product configuration.
• Test AC outlets at your computer and monitor for proper polarity and grounding.
• Use only with grounded outlets at both the computer and monitor.
• When using a backup UPS, power the computer, monitor and appliance off the supply.
Rack Mount Safety Guidelines
In Raritan products that require rack mounting, follow these precautions:
• Operation temperature in a closed rack environment may be greater than room
temperature. Do not exceed the rated maximum ambient temperature of the appliances
(See Appendix A: Specifications ).
• Ensure sufficient airflow through the rack environment.
• Mount equipment in the rack carefully to avoid uneven mechanical loading.
• Connect equipment to the supply circuit carefully to avoid overloading circuits.
• Ground all equipment properly, especially supply connections, such as power strips
(other than direct connections), to the branch circuit.
CONTENTS i
Contents
Preface.............................................................................................................................. xii
Audience ....................................................................................................................xii
Conventions ...............................................................................................................xii
Acronyms ...................................................................................................................xii
Notices ......................................................................................................................xiii
Chapter 1: Introduction....................................................................................................1
Dominion SX Overview ............................................................................................... 1
Product Features......................................................................................................... 2
Comprehensive Console Management..............................................................................................2
Strong Security and User-Authentication...........................................................................................2
Reliable Connectivity .........................................................................................................................2
Simplified User Experience................................................................................................................2
Package Contents....................................................................................................... 3
Chapter 2: Installation ......................................................................................................5
Pre-Installation ............................................................................................................ 5
Client Configuration ...........................................................................................................................5
Hardware Installation .................................................................................................. 6
Physical Installation of Dominion SX for Initial Configuration.............................................................6
LED State ..........................................................................................................................................6
Initial Configuration Using the Graphical User Interface (GUI) ..........................................................7
Initial Configuration Using the Command Line Interface....................................................................9
Chapter 3: Initial Software Configuration....................................................................11
Dominion SX Initial Software Configuration .............................................................. 11
Date / Time Configuration................................................................................................................12
Network Configuration .....................................................................................................................13
Deployment ...............................................................................................................14
LAN Connection...............................................................................................................................14
Modem Connection (Optional).........................................................................................................14
Chapter 4: Network Settings and Services....................................................................15
Configuring the Basic Network Settings.................................................................... 15
Give the DSX a Name .....................................................................................................................15
Configure the DSX’s Network Settings ............................................................................................15
Change the Discovery Ports ............................................................................................................16
Configuring the Network Service Settings................................................................. 16
To change any of these network service settings: ...........................................................................17
Configuring Modem Access ......................................................................................18
Configuring IP Forwarding and Static Routes ........................................................... 18
Enable IP Forwarding ......................................................................................................................18
Add a New Static Route...................................................................................................................19
Delete a Static Route.......................................................................................................................20
Chapter 5: User Profiles and Groups.............................................................................21
Managing User Profiles............................................................................................. 21
Display a List of User Profiles..........................................................................................................21
Create a User Profile .......................................................................................................................21
Modify a User Profile .......................................................................................................................23
Delete a User Profile........................................................................................................................23
Managing User Groups ............................................................................................. 23
Display a List of User Groups ..........................................................................................................24
Create a User Group .......................................................................................................................24
Modify a User Group........................................................................................................................25
Delete a User Group........................................................................................................................25
Chapter 6: Remote Authentication................................................................................27
Configuring RADIUS ................................................................................................. 27
Configuring LDAP ..................................................................................................... 28
Configuring TACACS+ .............................................................................................. 29
ii DOMINION SX USER GUIDE
Chapter 7: Port Configuration and Port Access Application......................................31
Port Keywords........................................................................................................... 31
Port Configuration ..................................................................................................... 32
Direct Port Access..................................................................................................... 34
Anonymous Port Access ...........................................................................................35
Raritan Serial Console .............................................................................................. 35
Raritan Serial Client Requirements for Java ............................................................. 36
Java Runtime Environment (JRE)....................................................................................................36
Java Applets and Memory Considerations ......................................................................................36
Raritan Serial Client Interface ................................................................................... 38
Emulator ..........................................................................................................................................39
Edit ..................................................................................................................................................45
Tools................................................................................................................................................46
Chat .................................................................................................................................................48
Help .................................................................................................................................................49
Standalone Raritan Serial Console Installation......................................................... 50
Standalone Raritan Serial Client Requirements........................................................ 50
Setting Windows OS Variables........................................................................................................51
Setting Linux OS Variables..............................................................................................................54
Setting UNIX OS Variables..............................................................................................................54
Installing Standalone RSC for Windows ................................................................... 55
Launching RSC on Windows Systems...................................................................... 56
Installing RSC for Sun Solaris................................................................................... 57
Launching RSC on Sun Solaris................................................................................. 58
Chapter 8: Security..........................................................................................................59
Security Settings ....................................................................................................... 59
Login Settings ........................................................................................................... 60
Local Authentication ........................................................................................................................60
Login Handling.................................................................................................................................60
Strong Password Settings......................................................................................... 61
Configure Kerberos ...................................................................................................61
Certificates ................................................................................................................ 61
Generate a Certificate Signing Request ..........................................................................................62
Install a User Key.............................................................................................................................63
Install a User Certificate...................................................................................................................63
SSL Client Certificate ................................................................................................64
Enabling Client Certificate Authentication:.......................................................................................66
Installing a New Trusted Certificate Authority ..................................................................................66
Removing a User-Added Certificate Authority .................................................................................66
Viewing a Certificate Authority.........................................................................................................66
Managing the Client Certificate Revocation List (CRL)....................................................................66
Adding a New Certificate Revocation List to the DSX......................................................................66
Deleting a Certificate Revocation List from the DSX........................................................................66
Viewing a Certificate Revocation List...............................................................................................67
Banner....................................................................................................................... 67
Security Profiles ........................................................................................................ 68
About Security Profiles ....................................................................................................................68
Select a Security Profile...................................................................................................................68
Edit the Custom Profile ....................................................................................................................68
Firewall...................................................................................................................... 70
Enable the Firewall ..........................................................................................................................70
Add an IPTables Rule......................................................................................................................70
Chapter 9: Logging..........................................................................................................71
Configuring Local Event Logging .............................................................................. 71
Enable the Event Log File................................................................................................................71
Enable System Logging...................................................................................................................71
Enable Port Logging ........................................................................................................................72
Configure Input Port Logging...........................................................................................................74
Configuring Encryption ....................................................................................................................74
Configuring SMTP Logging ....................................................................................... 75
Enable SMTP Logging.....................................................................................................................75
Select a New SMTP Event ..............................................................................................................75
CONTENTS iii
Test the SMTP Logging ...................................................................................................................76
Configuring NFS Logging.......................................................................................... 76
Configuring SNMP Logging....................................................................................... 78
Enable SNMP Logging ....................................................................................................................78
Create a New SNMP Destination ....................................................................................................78
Chapter 10: Maintenance................................................................................................79
Managing the Local Event Log.................................................................................. 79
Display the Local Event Log ............................................................................................................79
Clear the Event Log .........................................................................................................................79
Send the Event Log .........................................................................................................................80
Displaying a Configuration Report ............................................................................ 80
Backing Up and Restoring the DSX .......................................................................... 81
Backing Up the DSX ........................................................................................................................81
Restoring the DSX ...........................................................................................................................82
Upgrading the DSX Firmware ................................................................................... 82
Display the Current Firmware Version.............................................................................................83
Upgrade the Firmware .....................................................................................................................83
Display a Firmware Upgrade History ...............................................................................................84
Performing a Factory Reset on the DSX................................................................... 85
Rebooting the DSX ................................................................................................... 85
Chapter 11: Diagnostics ..................................................................................................87
Network Infrastructure Tools ..................................................................................... 87
Status of Active Network Interfaces.................................................................................................87
Network Statistics ............................................................................................................................88
Ping Host .........................................................................................................................................89
Trace Route to Host.........................................................................................................................89
Administrator Tools ─ Process Status....................................................................... 90
Chapter 12: Command Line Interface...........................................................................91
Command Line Interface Overview........................................................................... 91
Accessing the Dominion SX Using CLI ..................................................................... 94
SSH Connection to the Dominion SX........................................................................ 94
SSH Access from a Windows PC ....................................................................................................94
SSH Access from a UNIX Workstation ............................................................................................94
Telnet Connection to the Dominion SX ..................................................................... 95
Enabling Telnet................................................................................................................................95
Telnet Access from a Windows PC..................................................................................................95
Local Port Connection to the Dominion SX............................................................... 96
Port Settings ....................................................................................................................................96
Connection ......................................................................................................................................96
To Change the Local Port Parameters: ...........................................................................................96
Login .........................................................................................................................96
Navigation of the CLI................................................................................................. 98
Completion of Command .................................................................................................................98
CLI Syntax –Tips and Shortcuts ......................................................................................................98
Common Commands for all Command Line Interface Levels..........................................................99
Show Command ..............................................................................................................................99
Initial Configuration ...................................................................................................99
Setting Parameters ........................................................................................................................100
Date and Time Configuration.........................................................................................................100
Setting Network Parameters..........................................................................................................100
CLI Prompts ............................................................................................................ 101
CLI Commands ....................................................................................................... 101
Security Issues ..............................................................................................................................102
Configuring Users and Groups ......................................................................................................103
Command Language Interface Permissions..................................................................................103
Target Connections and the CLI ............................................................................. 103
Set Emulation on Target ................................................................................................................103
Set Escape Sequence ...................................................................................................................104
Port Sharing Using CLI ..................................................................................................................104
Administering the Dominion SX Console Server..................................................... 104
Configuration Commands ....................................................................................... 104
Configuring Authorization and Authentication (AA) Services.....................................................
iv DOMINION SX USER GUIDE
Remote Services ...........................................................................................................................105
LDAP Configuration Menu .............................................................................................................106
RADIUS Command........................................................................................................................107
TACACSPLUS Command .............................................................................................................107
Configuring Events.................................................................................................. 107
Configuring Log....................................................................................................... 107
Cleareventlog Command ...............................................................................................................108
Eventlogfile Command...................................................................................................................108
Eventsyslog Command..................................................................................................................108
nfsget Command ...........................................................................................................................109
nfssetkey Command......................................................................................................................109
Portlog Command..........................................................................................................................110
Sendeventlog Command ...............................................................................................................111
Vieweventlog Command................................................................................................................111
Configuring Modem................................................................................................. 111
Configuring Network................................................................................................ 114
Ethernetfailover Command ............................................................................................................114
Interface Command ......................................................................................................................114
IPForwarding Command...............................................................................................................115
Name Command...........................................................................................................................115
Ports Command............................................................................................................................115
Route Command............................................................................................................................116
Routeadd Command......................................................................................................................116
Routedelete Command..................................................................................................................116
Configuring NFS...................................................................................................... 117
Configuring Ports .................................................................................................... 118
Ports Configuration Menu ..............................................................................................................118
Ports Config Command .................................................................................................................118
Ports Keywordadd Command........................................................................................................120
Ports Keyworddelete Command ....................................................................................................120
Configuring Services ............................................................................................... 120
dpa Command ...............................................................................................................................121
Encryption Command ....................................................................................................................123
HTTP Command............................................................................................................................123
HTTPS Command .........................................................................................................................124
Logout Command ..........................................................................................................................124
LPA Command ..............................................................................................................................124
SSH Command..............................................................................................................................125
Telnet Command ...........................................................................................................................125
Configuring SNMP .................................................................................................. 126
SMNP Add Command ...................................................................................................................126
SNMP Delete Command ...............................................................................................................126
SNMP Command...........................................................................................................................127
Configuring Time..................................................................................................... 127
Clock Command ............................................................................................................................127
NTP Command ..............................................................................................................................128
Timezonelist Command .................................................................................................................128
Configuring Users ................................................................................................... 128
Addgroup Command......................................................................................................................129
Adduser Command........................................................................................................................129
Deletegroup Command..................................................................................................................130
Deleteuser Command....................................................................................................................130
Editgroup Command......................................................................................................................130
Edituser Command ........................................................................................................................131
Groups Command .........................................................................................................................131
Users Command............................................................................................................................131
Connect Commands ............................................................................................... 132
Diagnostics Commands ..........................................................................................132
IPMI Commands ..................................................................................................... 132
IPMIDISCOVER.............................................................................................................................133
IPMITOOL .....................................................................................................................................134
Listports Command........................................................................................................................136
Maintenance Commands ........................................................................................ 136
Backup Command .........................................................................................................................137
Cleareventlog Command ...............................................................................................................137
Factoryreset Command .................................................................................................................137
Firmware Command ......................................................................................................................138
CONTENTS v
Logoff Command ...........................................................................................................................138
Password Command .....................................................................................................................138
Reboot Command..........................................................................................................................139
Restore Command.........................................................................................................................139
Sendeventlog Command ...............................................................................................................140
Upgrade Command .......................................................................................................................140
Upgradehistory Command.............................................................................................................141
Userlist Command .........................................................................................................................141
Vieweventlog Command................................................................................................................141
Security Commands................................................................................................ 141
Banner Command..........................................................................................................................142
ftpgetbanner Command .................................................................................................................142
Certificate Command Menu ...........................................................................................................143
Firewall Command.........................................................................................................................144
IPtables Command ........................................................................................................................144
Kerberos Command.......................................................................................................................146
Loginsettings Commands ..............................................................................................................147
idletimeout Command....................................................................................................................147
Inactiveloginexpiry Command........................................................................................................148
Invalidloginretries Command ........................................................................................................148
Localauth Command......................................................................................................................148
Lockoutperiod Command .............................................................................................................148
Singleloginperuser Command ......................................................................................................149
Strongpassword Command ...........................................................................................................149
Unauthorizedportaccess Command...............................................................................................150
Securityprofiles Commands...........................................................................................................151
Profiledata Command ....................................................................................................................151
Chapter 13: Intelligent Platform Management Interface..........................................153
Discover IPMI Devices ............................................................................................ 153
IPMI Configuration .................................................................................................. 154
Chapter 14: Power Control...........................................................................................157
Port Power Associations ......................................................................................... 157
Create a Port Power Association...................................................................................................157
Delete a Port Power Association ...................................................................................................158
Power Strip Configuration ....................................................................................... 158
Power Association Groups...................................................................................... 159
Power Control ......................................................................................................... 159
Associations Power Control .................................................................................... 160
Power Strip Power Control...................................................................................... 161
Power Strip Status .................................................................................................. 162
Chapter 15: Top-10 Use Cases......................................................................................163
Case 1. Upgrading DSX Firmware via Web Browser.............................................. 163
Case 2. Configuring and Using Direct Port Access via SSH................................... 163
Case 3. Using Exclusive Write Access via RSC .....................................................163
Case 4. Configuring LDAP ...................................................................................... 164
Case 5. Creating Power Association Group............................................................ 164
Case 6. Performing Factory Reset on DSX ............................................................ 164
Case 7. Managing User Profiles on DSX ................................................................ 165
Case 8. Accessing Port Access on DSX via RSC................................................... 165
Case 9. Port Configuration...................................................................................... 165
Case 10. CLI / SSH Connection to SX Port ............................................................ 166
Appendix A: Specifications...........................................................................................167
Dominion SX Models and Specifications ................................................................ 167
Requirements.......................................................................................................... 169
Browser Requirements – Supported ....................................................................... 169
Connectivity............................................................................................................. 170
Dominion SX Serial RJ-45 Pinouts ......................................................................... 171
DB9F Nulling Serial Adapter Pinouts .............................................................................................171
DB9M Nulling Serial Adapter Pinouts ............................................................................................172
DB25F Nulling Serial Adapter Pinouts ...........................................................................................172
vi DOMINION SX USER GUIDE
DB25M Nulling Serial Adapter Pinouts ..........................................................................................172
Dominion SX Terminal Ports................................................................................... 172
Dominion SX16 and SX32 Terminal Ports .............................................................. 174
Appendix B: System Defaults .......................................................................................175
Appendix C: Certificates...............................................................................................177
Default SX Certificate Authority Settings................................................................. 177
Install CA Root for IE Browsers............................................................................... 177
Accept a Certificate (Session-Based) ............................................................................................177
Install the Dominion SX Server Certificate In Internet Explorer .....................................................179
Remove an Accepted Certificate In Internet Explorer....................................................................180
Install Dominion SX Server Certificate for Netscape Navigator ..............................180
Accept a Certificate (Session-Based) ............................................................................................181
Install the Dominion SX Server Certificate In Netscape Navigator.................................................181
Remove an Accepted Certificate ...................................................................................................181
Install a Third-Party Root Certificate ....................................................................... 182
Installing a Third-Party Root Certificate to Internet Explorer..........................................................182
Installing a Third-Party Root Certificate to Netscape Navigator.....................................................183
Generate a CSR for a Third Party CA to sign. ...............................................................................183
Install Third Party Certificate to SX. ...............................................................................................183
Install Client Root Certificate into the SX. ......................................................................................184
Install Client Certificate into Internet Explorer................................................................................184
Appendix D: Server Configuration..............................................................................187
Microsoft IAS RADIUS Server................................................................................. 187
Configure the Dominion SX to Use an IAS RADIUS Server ..........................................................187
Create an IAS Policy......................................................................................................................188
Cisco ACS RADIUS Server..................................................................................... 189
Configure the Dominion SX to use a Cisco ACS Server................................................................ 189
Configure the Cisco ACS Server ...................................................................................................189
TACACS+ Server Configuration.............................................................................. 191
CiscoSecure ACS ................................................................................................... 191
Active Directory .......................................................................................................193
Appendix E: Modem Configuration.............................................................................195
Client Dial-Up Networking Configuration................................................................. 195
Windows NT Dial-Up Networking Configuration...................................................... 195
Windows 2000 Dial-Up Networking Configuration .................................................. 197
Windows XP Dial-Up Networking Configuration ..................................................... 200
Appendix F: Troubleshooting.......................................................................................203
Page Access ........................................................................................................... 203
Firewall.................................................................................................................... 204
Login .......................................................................................................................205
Port Access .............................................................................................................205
Upgrade .................................................................................................................. 206
Modem .................................................................................................................... 206
FIGURES VII
Figures
Figure 1 Dominion SX16 Unit....................................................................................................................... 1
Figure 2 Rear Panel of the DSXA-32 ........................................................................................................... 6
Figure 5 Certificate Information.................................................................................................................... 7
Figure 6 DSX Login Screen .........................................................................................................................8
Figure 7 Restricted Service Agreement Screen ........................................................................................... 8
Figure 8 Change Password Screen ............................................................................................................. 8
Figure 9 Dominion SX Port Access Screen for Operators/ Observers ....................................................... 11
Figure 10 Dominion SX Port Access Screen for Administrators................................................................. 11
Figure 11 Setup Screen .............................................................................................................................11
Figure 12 Date / Time Configuration Screen.............................................................................................. 12
Figure 13 Network Configuration Screen ...................................................................................................13
Figure 14 Network Basic Settings and Ports Screen ................................................................................ 15
Figure 15 Network Service Settings.......................................................................................................... 17
Figure 16 Modem Settings Screen............................................................................................................ 18
Figure 17 IP Forwarding Panel ..................................................................................................................18
Figure 18 Static Routes List ....................................................................................................................... 19
Figure 19 Static Route Screen .................................................................................................................. 19
Figure 20 User List Screen ....................................................................................................................... 21
Figure 21 New User Screen...................................................................................................................... 22
Figure 22 Group List Screen ..................................................................................................................... 24
Figure 23 New Group Screen ................................................................................................................... 24
Figure 24 RADIUS Panel .......................................................................................................................... 27
Figure 25 LDAP Panel ..............................................................................................................................28
Figure 26 TACACS+ Panel ....................................................................................................................... 29
Figure 27 Port Keywords Screen ...............................................................................................................31
Figure 28 Port Configuration Screen.......................................................................................................... 32
Figure 29 Edit Port Screen........................................................................................................................ 33
Figure 30 Direct Port Access Mode Field................................................................................................... 34
Figure 31 Port Access Screen ................................................................................................................... 35
Figure 34 Java Runtime Settings ............................................................................................................... 36
Figure 35 Raritan Serial Client Window .....................................................................................................38
Figure 36 Emulator Drop-Down Menu ....................................................................................................... 39
Figure 37 Connection Terminated Warning ...............................................................................................39
Figure 38 General Settings Window .......................................................................................................... 40
Figure 39 Display Settings Window ...........................................................................................................41
Figure 40 Display Settings: GUI Font Properties .......................................................................................42
Figure 43 Connected Users Window ......................................................................................................... 44
Figure 45 Edit Commands - Copy, Paste, and Select All Text................................................................... 45
Figure 46 Tools Menu ................................................................................................................................ 46
Figure 47 Start Logging Command Window .............................................................................................. 47
Figure 48 Send Keystroke.......................................................................................................................... 48
Figure 50 SecureChat Command and User Chat Window......................................................................... 49
Figure 52 Sample of the About Raritan Serial Console Window ................................................................ 50
Figure 53 Windows OS: System Properties............................................................................................... 51
Figure 54 Windows OS: New System Variable.......................................................................................... 52
Figure 55 Windows OS: Edit System Variable........................................................................................... 53
Figure 56 Windows OS: CLASSPATH Variable......................................................................................... 53
Figure 57 Check JRE Version in Sun Solaris............................................................................................. 54
Figure 60 RSC Windows Install Progress Screen...................................................................................... 55
Figure 61 RSC Windows Shortcut Screen ................................................................................................. 56
viii DOMINION SX USER GUIDE
Figure 63 Standalone RSC Login Screen ..................................................................................................56
Figure 64 Standalone RSC Connected to Port Window............................................................................. 57
Figure 67 Security Settings Screen............................................................................................................ 59
Figure 68 Login Settings Screen................................................................................................................ 60
Figure 69 Kerberos Settings ......................................................................................................................61
Figure 70 Certificate Signing Request ....................................................................................................... 62
Figure 71 Install User Key.......................................................................................................................... 63
Figure 72 Install User Certificate................................................................................................................ 63
Figure 73 SSL Client Certificate Screen .................................................................................................... 65
Figure 74 Banner Screen........................................................................................................................... 67
Figure 75 Security Profiles......................................................................................................................... 68
Figure 76 Edit Custom Security Profile Screen .......................................................................................... 69
Figure 77 Firewall Screen ..........................................................................................................................70
Figure 78 Event Log Panel........................................................................................................................ 71
Figure 79 System Logging Panel .............................................................................................................. 71
Figure 80 Port Logging Panel ...................................................................................................................72
Figure 81 Sample Output File ...................................................................................................................73
Figure 82 Input Port Logging Panel ........................................................................................................... 74
Figure 83 Encryption Panel....................................................................................................................... 74
Figure 84 SMTP Settings Panel................................................................................................................ 75
Figure 85 New SMTP Event Panel ...........................................................................................................75
Figure 86 NFS Settings Screen ................................................................................................................77
Figure 87 SNMP Settings Panel ................................................................................................................78
Figure 88 SNMP Destination Panel .......................................................................................................... 78
Figure 89 Event Log.................................................................................................................................. 79
Figure 90 Send Event Log Screen ............................................................................................................ 80
Figure 91 Backup Screen.......................................................................................................................... 81
Figure 92 Restore Screen ......................................................................................................................... 82
Figure 93 Firmware Version...................................................................................................................... 83
Figure 94 Firmware Upgrade Screen......................................................................................................... 84
Figure 95 Firmware Upgrade History Screen............................................................................................. 84
Figure 96 Diagnostics Screen .................................................................................................................... 87
Figure 97 Active Network Interface Status ................................................................................................. 87
Figure 98 Network Statistics ......................................................................................................................88
Figure 99 Ping Host ................................................................................................................................... 89
Figure 100 Trace Route to Host................................................................................................................. 89
Figure 101 Process Status......................................................................................................................... 90
Figure 102 Sample Administrator Login..................................................................................................... 97
Figure 103 Sample Operator or Observer Login ........................................................................................ 97
Figure 104 IPMI Screen ...........................................................................................................................153
Figure 105 Discover IPMI Devices Screen............................................................................................... 153
Figure 106 IPMI Configuration ................................................................................................................. 154
Figure 107 Port Power Association Screen.............................................................................................. 157
Figure 108 Power Strip Configuration Screen.......................................................................................... 158
Figure 109 Power Association Group Screen ......................................................................................... 159
Figure 110 Power Control ........................................................................................................................159
Figure 111 Associations Power Control ...................................................................................................160
Figure 112 Power Strip Power Control..................................................................................................... 161
Figure 113 Power Strip Status ................................................................................................................. 162
Figure 114 Cisco ACS AAA Client for TACACS+ .................................................................................... 191
Figure 115 Cisco ACS Interface Configuration ........................................................................................192
Figure 116 TACACS+ Properties ............................................................................................................. 192
Figure 117 Dial-Up Networking Display ................................................................................................... 195
FIGURES IX
Figure 118 New Phone Entry Display ...................................................................................................... 196
Figure 119 Dial-Up Security Display ........................................................................................................ 197
Figure 120 Windows 2000 Network and Dial-Up Connections................................................................. 197
Figure 122 Network Connection Type...................................................................................................... 198
Figure 123 Device Selection .................................................................................................................... 198
Figure 124 Phone Number to Dial............................................................................................................ 199
Figure 125 Connection Availability........................................................................................................... 199
Figure 128 Network Connection Type...................................................................................................... 200
Figure 129 Device Selection .................................................................................................................... 200
Figure 130 Internet Connection................................................................................................................ 201
Figure 131 Connection Name .................................................................................................................. 201
Figure 132 Phone Number to Dial............................................................................................................ 202
Figure 133 Internet Account Information.................................................................................................. 202
x DOMINION SX USER GUIDE
Tables
Table 1 Factory Default Network Settings.................................................................................................... 5
Table 2 Java Runtime Parameters............................................................................................................. 37
Table 3 Commands Common to All CLI Levels ......................................................................................... 99
Table 4 Available CLI Commands............................................................................................................ 101
Table 5 Configuration: Authentication Commands: ldap .......................................................................... 105
Table 6 LDAP Command .........................................................................................................................106
Table 7 Configuration: Events Commands............................................................................................... 107
Table 8 Eventlogfile Command ................................................................................................................ 108
Table 9 Eventsyslog Command ............................................................................................................... 108
Table 10 nfsget Command....................................................................................................................... 109
Table 11 nfssetkey Command ................................................................................................................ 109
Table 12 Portlog Command ..................................................................................................................... 110
Table 13 Sendeventlog Command........................................................................................................... 111
Table 14 Configuration: Modem Commands............................................................................................ 111
Table 15 Configuration: Network Commands .......................................................................................... 114
Table 16 Interface Command................................................................................................................... 114
Table 17 Ipforwarding Command............................................................................................................. 115
Table 18 name Command........................................................................................................................ 115
Table 19 ports Command......................................................................................................................... 115
Table 20 Route Command ....................................................................................................................... 116
Table 21 Routeadd Command ................................................................................................................. 116
Table 22 Routedelete Command ............................................................................................................. 116
Table 23 NFS Command .........................................................................................................................117
Table 24 Port Configuration Command.................................................................................................... 118
Table 25 Port Keywordadd Command ..................................................................................................... 120
Table 26 Port Keyworddelete Command .................................................................................................120
Table 27 dpa Command .......................................................................................................................... 121
Table 28 Encryption Command................................................................................................................ 123
Table 29 HTTP Command ....................................................................................................................... 123
Table 30 Lpa Command .......................................................................................................................... 124
Table 31 SSH Command .........................................................................................................................125
Table 32 Telnet Command....................................................................................................................... 125
Table 33 SNMP Add Command............................................................................................................... 126
Table 34 SNMP Delete Command........................................................................................................... 126
Table 35 SNMP Command ......................................................................................................................127
Table 36 Clock Command........................................................................................................................ 127
Table 37 ntp Command ........................................................................................................................... 128
Table 38 Addgroup Command ................................................................................................................. 129
Table 39 Adduser Command ................................................................................................................... 129
Table 40 Deletegroup Command ............................................................................................................. 130
Table 41 Deleteuser Command ............................................................................................................... 130
Table 42 Editgroup Command ................................................................................................................. 130
Table 43 Edituser Command ................................................................................................................... 131
Table 44 Connect Commands ................................................................................................................. 132
Table 45 Diagnostics Commands ............................................................................................................ 132
Table 46 IPMIDiscover Command ........................................................................................................... 133
Table 47 IPMITool Command .................................................................................................................. 134
Table 48 Listports Command ................................................................................................................... 136
Table 49 Backup Command..................................................................................................................... 137
Table 50 Logoff Command....................................................................................................................... 138
Table 51 Password Command................................................................................................................. 138
TABLES XI
Table 52 Restore Command .................................................................................................................... 139
Table 53 Sendeventlog Command........................................................................................................... 140
Table 54 Upgrade Command................................................................................................................... 140
Table 55 Banner Command ..................................................................................................................... 142
Table 56 ftpgetbanner Command ............................................................................................................ 142
Table 57 Certificate Client Commands .................................................................................................... 143
Table 58 Certificate Server Commands ................................................................................................... 143
Table 59 Firewall Command ................................................................................................................... 144
Table 60 iptables Command .................................................................................................................... 144
Table 61 Kerberos Commands ................................................................................................................ 146
Table 62 Loginsettings Commands.......................................................................................................... 147
Table 63 Inactiveloginexpiry Command ................................................................................................... 148
Table 64 Invalidloginretries Command..................................................................................................... 148
Table 65 Lockoutperiod Command .......................................................................................................... 149
Table 66 Singleloginperuser Command................................................................................................... 149
Table 67 Strongpassword Command....................................................................................................... 150
Table 68 unauthorizedportaccess Command........................................................................................... 150
Table 69 Securityprofiles Commands ...................................................................................................... 151
Table 70 Profiledata Command ............................................................................................................... 151
Table 71 Dominion SX Specifications ...................................................................................................... 167
Table 72 Dominion SX Dimensions and Weight ...................................................................................... 168
Table 73 Dominion SX Requirements...................................................................................................... 169
Table 74 Browser Requirements.............................................................................................................. 169
Table 75 Connectivity .............................................................................................................................. 170
Table 76 Dominion SX RJ-45 Serial Pinouts and Signals ........................................................................ 171
Table 77 DB9F Nulling Serial Adapter Pinouts ........................................................................................ 171
Table 78 DB9M Nulling Serial Adapter Pinouts........................................................................................ 172
Table 79 DB25F Nulling Serial Adapter Pinouts ...................................................................................... 172
Table 80 DB25M Nulling Serial Adapter Pinouts...................................................................................... 172
Table 81 Dominion SX Terminal Port Pinouts-First Port ..........................................................................173
Table 82 Dominion SX Terminal Port Pinouts-Second Port ..................................................................... 173
Table 83 Dominion SX16 and SX32 Terminal Port Pinouts ..................................................................... 174
Table 84 Dominion SX System Defaults .................................................................................................. 175
Table 85 Initiating Port Access................................................................................................................. 176
Table 86 Troubleshooting Page Access .................................................................................................. 203
Table 87 Troubleshooting Firewall ...........................................................................................................204
Table 88 Troubleshooting Login............................................................................................................... 205
Table 89 Troubleshooting Port Access .................................................................................................... 205
Table 90 Troubleshooting Upgrade.......................................................................................................... 206
Table 91 Troubleshooting Modem ........................................................................................................... 206
xii DOMINION SX USER GUIDE
Preface
The Dominion SX User Guide provides the information needed to install, set up and configure,
access devices such as routers, servers, switches, VPNs, and power strips, manage users and
security, and maintain and diagnose the Dominion SX secure console server.
Audience
The primary audiences for this guide are infrastructure administrators and installers who are
responsible for installing and setting up devices such as secure console servers. Other interested
audiences are operators and observers who use the Dominion SX to reach other devices.
Conventions
This guide uses the following conventions:
EXAMPLE DESCRIPTION
/usr/local/java
Enter
<ip address>
Monospaced text indicates file names, paths, directories, or screen text.
Menu items, Key words and Keyboard keys are bolded.
Monospaced, italicized text indicate where the user would substitute a
value in a command.
Acronyms
This guide uses the following acronyms:
ACRONYM MEANING
AD Active Directory
CC Command Center
CLI Command Line Interface
CSC Common Socket Connection
DPA Direct Port Access
HTTP Hypertext Transfer protocol
HTTPS HTTP Secure (over SSL)
LAN Local Area Network
LDAP Lightweight Directory Access Protocol
LDAP/S Lightweight Directory Access Protocol/Secure
NFS Network File System
NTP Network Time Protocol
PPP Point to Point Protocol
RADIUS Remote Authentication Dial In User Service
RSC Raritan Serial Console
SMTP Simple Mail Transfer Protocol
SSH Secure Shell
SSL Secure Sockets Layer Protocol
SNMP Simple Network Management Protocol
TACACS+ Terminal Access Controller Access Control System (PLUS)
TLS Transport Layer Security
UTC Universal Time Coordinated
VLAN Virtual Local Area Network
PREFACE XIII
ACRONYM MEANING
VPN Virtual Private Network
Notices
Important: cautionary information that warns of possible affects on the users,
corruption risks, and actions that may affect warranty and service coverage.
Note: general information that is supplemental to the text.
This page intentionally left blank.
CHAPTER 1: INTRODUCTION 1
Chapter 1: Introduction
Dominion SX Overview
The Dominion SX Series of Serial over IP Console Servers offers convenient and secure, remote
access and control through LAN/WAN, Internet, or Dial-up modem to all networking devices.
The Dominion SX:
• Provides a non-intrusive solution for managing network elements and does not require any
installation of software agents on the target device.
• Connects to any networking device (servers, firewalls, load balancer, and so forth) through
the serial port and provides the ability to remotely and securely manage the device using a
Web browser.
Dominion SX is a fully configured stand-alone product in a standard 1U high 19” rack mount
chassis.
Figure 1 Dominion SX16 Unit
2 DOMINION SX USER GUIDE
Product Features
Comprehensive Console Management
• Remote Management: Access, monitor, administer, and troubleshoot up to 48 target devices
(depending on the model) via Secure Socket Shell (SSH), Telnet, Local Port or Web browser
with only one IP address.
• Direct Port Access via TCP/IP address per port; or one IP address and TCP Port numbers.
• Notification: Create notification messages by email alerts.
• Collaborative Management and Training: Access ports simultaneously; up to 10 users per
port at any time.
• SecureChat™: “Instant message” and other Secure Sockets Layer (SSL) users can securely
collaborate on device management, troubleshooting, and training activities.
• Get History: Get up to 256 KB (64KB on units with 64MB SDRAM; 256KB on units with
128MB SDRAM) of recent console history to assist with debugging.
• Supports VT100, VT220, VT 320, and ANSI terminal emulation.
• Up to a 5,000 line copy-paste buffer.
• Local port access.
• SNMP traps.
• SYSLOG.
• Logging to Network File System (NFS) Server.
• Comprehensive SNMP traps.
• Port alerts with keyword triggers.
• Three Levels of User Access:
o Administrator: Has read and write access to the console window; can modify the
configuration of unit.
o Operator: Has read and write access to the console window; cannot modify the
configuration of unit (except own password).
o Observer: Has read-only access to the console window; cannot modify the configuration
of unit (except own password).
Strong Security and User-Authentication
• SSHv2 Support
• Encryption Security: 128-bit SSL handshake protocol and RC4 encryption.
• User Authentication Security: local database, remote authentication
• Supports RADIUS, TACACS+, LDAP, LDAP(S), Microsoft Active Directory, and NTP.
• Supports user-defined and installable security Certificates.
Reliable Connectivity
• Optional Modem Connectivity: For emergency remote access if the network has failed.
• Target Device Connectivity: Simplified RJ45-based CAT 5 cable scheme; serial port adapters
are available from Raritan.
• Local Access for “crash-cart” applications.
Simplified User Experience
• Telnet
• SSH
• Browser-based Interface: The new GUI provides intuitive access to target devices (click on
the appropriate button to select the desired target device).
• Upgrades: Built-in firmware upgrade capability through FTP and integrated with Command
Center (CC) and SSH.
CHAPTER 1: INTRODUCTION 3
Package Contents
Each Dominion SX ships with the following:
• (1) Dominion SX unit with mounting kit (Rack-mount kit is optional on some units)
• (1) Raritan Dominion SX User Guide CD-ROM, which contains the installation and
operations information for the Dominion SX
• (1) Printed Dominion SX Quick Setup Guide
• (1) Power cord
• (1) Release Notes
• (1) Packing List page
• (1) RJ45 serial loop-back plug
• A DB9 Factory Reset Adapter for some units (Other units have a reset switch and do not
require an adapter).
4 DOMINION SX USER GUIDE
This page intentionally left blank.
CHAPTER 2: INSTALLATION 5
Chapter 2: Installation
There are two ways of completing the initial network installation of the Dominion SX:
• Using a serial cable with a VT100/equivalent, such as a PC with HyperTerminal.
• Using Ethernet (with an installation computer).
This section describes the steps necessary to configure Dominion SX for use on a local area
network (LAN). The following table describes the factory default network settings that come with
the Dominion SX. After units are connected to the network, these factory default settings allow
you to configure the Dominion SX for normal use.
Table 1 Factory Default Network Settings
DEFAULT NETWORK SETTINGS
Internet Address (IP) 192.168.0.192
Gateway Address 192.168.0.192
Subnet Mask 255.255.255.0
CSC Port Address 5000
Port Address for CC Discovery 5000
Username admin (all lowercase)
Password raritan (all lowercase)
Pre-Installation
Ensure that you have the correct cabling ready to connect to the serial consoles of the target
server (s) or other serially managed devices that provide a console port.
The following sections describe information that you must supply to complete the configuration
of the Dominion SX. Obtain all required configuration information prior to performing the
configuration steps. If you are uncertain of any information, contact your system administrator for
assistance.
Client Configuration
1. Disable Proxies in the installation computer Web browser.
Use “no Proxies” or temporarily add 192.168.0.192 to the list of URLs for which no proxy is
configured.
2. Enable Java Applet Execution in the installation computer Web browser for the console
client application (RSC).
3. Access the unit through your installation computer Web browser on the same subnet by
typing the URL https://192.168.0.192 into the address/location field.
6 DOMINION SX USER GUIDE
Hardware Installation
Figure 2 Rear Panel of the DSXA-32
Physical Installation of Dominion SX for Initial Configuration
1. Use a computer with a network card and crossover network cable. This computer will be
referred to as the ‘installation computer.’
2. Physically mount the unit in an ergonomically sound manner. The unit is designed to be
easily rack-mounted, and rack mounting is recommended.
3. Connect the crossover network LAN cable to the primary LAN connection (LAN 1 on
models with two Ethernet interfaces) on the back of the chassis.
4. Connect the other end of the network LAN cable to the network card in the installation
computer.
5. Connect the female end of the external power cord to the back of the chassis.
6. Connect the male end of the external power cord to the power supply outlet.
7. Power ON the Dominion SX unit.
Note: The unit will perform a hardware and firmware self-test then start the software boot
sequence, which takes a short time and is complete when the light turns on and remains
on.
After completion of the hardware and firmware self-test and the software boot sequence, perform
the initial configuration tasks using the Graphical User Interface (GUI) or the Command
Language Interface (CLI) as described in the following sections.
LED State
On the front panel of the Dominion SX unit, there exists a LED indicator right next to the model
name label. The LED indicator will blink blue in the following three cases:
1. Ethernet packets are received or transmitted.
2. Serial data are received or transmitted.
3. When watchdog timer is reset to 0. The LED blinks on a periodic basis as the watchdog
timer reaches a certain value, and then is reset to 0.
CHAPTER 2: INSTALLATION 7
Initial Configuration Using the Graphical User Interface (GUI)
To initially configure the Dominion SX unit from the Graphical User Interface, follow the steps
below.
Network Access
1. Ensure that the installation computer has the route for 192.168.0.192 and that it can
communicate with IP address 192.168.0.192.
2. To check the route table in Windows, type the command route print in a Command
window on the installation computer. If 192.168.0.192 is on the gateway list, proceed to step
3. Otherwise, add 192.168.0.192 to the gateway list using the appropriate DOS or UNIX CLI
command:
• Windows 98/2000/NT system: route add 192.168.0.192
<INSTALLATION COMPUTER IP ADDRESS> .
[Example: route add 192.168.0.192 15.128.122.12
• UNIX (including Sun Solaris) system:
route add 192.168.0.192 <CLIENT_HOST IP ADDRESS> -interface .
[Example: route add 192.168.0.192 15.128.122.12 –interface ]
3. Type ping 192.168.0.192 . Go to step 4 if you receive a successful reply from the
Dominion SX unit. If an error occurs, verify that the default IP address is entered correctly
and that a route to that IP address exists.
4. Use the installation computer to connect to the unit by launching a browser and typing the
factory default IP address 192.168.0.192 in the Web browser’s address box.
5. The computer displays the security screens before you can log in.
6. If you click View Certificate on the Security Alert-Certificate screen a Certificate screen
appears.
Figure 3 Certificate Information
See Chapter 8: Security and Appendix C: Certificates for information about installing
certificates.
8 DOMINION SX USER GUIDE
The login screen appears after you finish viewing the security alerts and the Certification
Information screen.
Figure 4 DSX Login Screen
7. Log in with the default username admin and password raritan. Use all lowercase letters. A
Restricted Service Agreement Screen appears:
Figure 5 Restricted Service Agreement Screen
Note: Once you click Accept after login, the Dominion SX prompts you to change the
default password.
A Change Password screen appears:
Figure 6 Change Password Screen
8. Type a new secure password then retype it (Remember the new password).
9. Click OK.
10. Click Exit .
11. Log in again using your new password.
The Dominion SX Port Access Screen appears. (See
Chapter 3: Initial Software
Configuration)
CHAPTER 2: INSTALLATION 9
Initial Configuration Using the Command Line Interface
To initially configure the Dominion SX unit from the Command Line Interface, follow the steps
below.
1. Connect the serial port of your Installation Computer to the Terminal serial port on your
Dominion SX. This port is a DB9-Male port on most models, except ALL dual-power dualLAN models, including DSXA-48, which have an RJ45 connector for a terminal port.
2. Open a terminal emulation program, such as HyperTerminal, to connect to the Dominion SX
unit. The serial communication parameters are 9600 bps, No parity, 8 data bits, 1 stop bit and
None flow control.
3. Power ON the Dominion SX.
4. Log in using the default username admin and the default password raritan when prompted.
Once logged in a prompt to change the password appears.
5. Type a new password, and then retype it (Remember this password).
A display will appear showing the Dominion SX unit’s status and serial channel ports.
Note: If the password entered does not follow the password rules, an error message will
appear as a warning. The user will then be logged out and need to start over again for
password setting.
Network Access
1. Ensure that the installation computer has the route for 192.168.0.192 and that it can
communicate with IP address 192.168.0.192.
2. To check the route table in Windows, type the command route print in a Command
window on the installation computer. If 192.168.0.192 is on the gateway list, proceed to step
3. Otherwise, add 192.168.0.192 to the gateway list using the appropriate DOS or UNIX CLI
command:
• Windows 98/2000/NT system: route add 192.168.0.192
<INSTALLATION COMPUTER IP ADDRESS> .
[Example: route add 192.168.0.192 15.128.122.12
• UNIX (including Sun Solaris) system:
route add 192.168.0.192 <CLIENT_HOST IP ADDRESS> -interface .
[Example: route add 192.168.0.192 15.128.122.12 –interface ]
3. Type ping 192.168.0.192 . Go to step 4 if you receive a successful reply from the
Dominion SX unit. If an error occurs, verify that the default IP address is entered correctly
and that a route to that IP address exists.
4. Use the installation computer to connect to the unit by launching a browser and typing the
factory default IP address 192.168.0.192 in the Web browser’s address box.
Set Date and Time
1. Type Configuration to change the unit’s configuration.
2. Type Time to select the Date / Time configuration.
3. Type Timezonelist and find the number code that corresponds to your time zone.
4. Type clock [tz timezone] [datetime datetime-string] . The following is an
example:
admin > Config > Time > clock tz 9 datetime “2007-02-05
09:22:33”
In this example, 9 is the time zone code (Step 3) and “2007-02-05 09:22:33” the
date/time string in the format “YYYY-MM-DD HH:MM:SS” (quotes required).
Network Configuration
10 DOMINION SX USER GUIDE
1. Type Configuration to change the unit’s configuration.
2. Type Network to select the network configuration.
3. Type:
admin > Config > Network > interface enable true if lan1 ip
192.16.151.12 mask 255.255.255 gw 192.168.51.12
.Upon successfully entering the data, a report will display the new network configuration and you
will be prompted to reboot the unit.
4. Type yes to reboot the Dominion SX.
5. You can now remove the serial cable.
6. Reconnect from the installation computer browser to the Dominion SX using the new IP
address and password and proceed.
User Configuration
1. Type Configuration to change the unit’s configuration.
2. Type Users to select the user configuration.
To add a user group
Type
addgroup name <group name> class <class type> ports <n1,n2,n3...>
where <group name> is the name of the group and <class type> is
• Op for operator
• Ob for observer.
<n1,n2,n3...> is a list of port numbers this group has access to, separated by comas and no
spaces. You could configure port ranges using the same parameters as well, or use the wildcard
asterisk (*). For example:
• “config port 3-7 exitstring #0”(this disables exit strings for ports
3,4,5,6,7)
• config port * bps 115200 (this sets all ports to a communications speed of
115200 bps)
To add a user
1. Type
adduser user <user name> fullname <full name> group <group name>
password <password> info <information> dialback <dialback number>
active <status>
...
where <user name> is user’s login name,
<full name> is a user’s descriptive name (no spaces),
<group name> is the user’s assigned group,
<password> is the user’s password,
<information> is extra information (optional, no spaces),
<dialback number> is the user’s phone number (optional),
<status> is true or false, allowing the user to login or not.
2. Type top to return to the top level of the CLI menu.
CHAPTER 3: INITIAL SOFTWARE CONFIGURATION 11
Chapter 3: Initial Software Configuration
After the hardware installation, perform the initial software configuration. Do this by logging
onto the Dominion SX from either a browser or through a Command Line Interface (See Chapter
12: Command Line Interface for CLI information.)
Dominion SX Initial Software Configuration
1. Log on to the Dominion SX using your new password. A Port Access screen appears
according to your user type:
Figure 7 Dominion SX Port Access Screen for Operators/ Observers
Figure 8 Dominion SX Port Access Screen for Administrators.
2. Click the Setup tab. The Setup screen appears. It contains links to the Configuration and
Logging screens.
Figure 9 Setup Screen
12 DOMINION SX USER GUIDE
Important: After you complete each configuration task, you must return to the Setup tab to
perform the next configuration task.
Date / Time Configuration
1. Click the Date / Time in the Configuration section of the Setup Screen. The Date / Time
Configuration screen appears.
Figure 10 Date / Time Configuration Screen
2. Select the correct time zone from the UTC Offset drop-down menu.
3. Choose one of the following:
• User Specified Time – Click this radio button and enter the date and time manually
in the corresponding fields.
• Synchronize with NTP Server – Click this radio button and enter the IP address of a
Network Time Protocol (NTP) server in the Primary Time Server . If you have a
backup NTP server, enter its IP address in the Secondary Time Server field.
4. Type the Interface Name in the Interface field.
5. Click OK .
Note: Features such as certificate generation depend on the correct Timestamp, used to
check the validity period of the certificate. In addition, the Syslog and NFS logging
features also use the system time for time-stamping log entries.
After you click OK, the system displays one of the following screens:
• A confirmation screen, which contains the settings you chose and a confirmation message
at the top of the screen.
Date / Time Settings successfully applied.
• An error screen, which contains the original Date / Time screen and the error message.
ERROR: Date / Time Settings NOT successfully applied.