background image

 

If set to “Force”, the applet tries to make an encrypted connection. 

An error will be reported in case connection establishment fails. 

5.5.4 Certificate 

 

The IKVM-8000 uses the Secure Socket Layer (SSL) protocol for any encrypted 

network traffic between itself and a connected client. During the connection 

establishment the IKVM-8000 has to expose its identity to a client using a 

cryptographic certificate. Upon delivery, this certificate and the underlying secret 

key is the same for all IKVM-8000 ever produced and certainly will not match the 

network configuration that will be applied to the IKVM-8000 by its user. The 

certificate's underlying secret key is also used for securing the SSL handshake. 

Hence, this is a security risk (but far better than no encryption at all). 

However, it is possible to generate and install a new certificate that is unique for a 

particular IKVM-8000. In order to do that, the IKVM-8000 is able to generate a new 

cryptographic key and the associated Certificate Signing Request (CSR) that 

needs to be certified by a certification authority (CA). A certification authority 

verifies that you are the person who you claim you are, and signs and issues a SSL 

certificate to you. 

The following steps are necessary to create and install a SSL certificate for the 

IKVM-8000:  

50 

Summary of Contents for IKVM-8000

Page 1: ...8 Port IP KVM IKVM 8000 User s Guide ...

Page 2: ...sponsibility for any inaccura cies that may be contained in this User s Manual PLANET makes no commitment to update or keep current the information in this User s Manual and reserves the right to make im provements to this User s Manual and or to the products described in this User s Manual at any time without notice If you find information in this manual that is incorrect misleading or incomplete...

Page 3: ...Revision User s Manual for PLANET 8 Port IP KVM Model IKVM 8000 Rev 1 0 October 2005 Part No EM IKVM8000 iii ...

Page 4: ...NITIAL CONFIGURATION 11 3 1 Default Settings 11 3 2 Configuration via Setup Utility 11 3 3 Configuration via Serial Port 13 3 4 Keyboard Mouse and Video Configuration 14 CHAPTER 4 REMOTE USAGE 17 4 1 Prerequisite 17 4 2 Login and Logout 18 4 3 The Remote Console 20 CHAPTER 5 ADVANCED CONFIGURATION 27 5 1 Remote Control 27 5 2 Virtual Media 28 5 3 User Management 37 5 4 KVM Settings 38 5 5 Device S...

Page 5: ......

Page 6: ...nected PCs for Maintenance without Pow ering Down the KVM switch or PCs High Video Quality Resolution Up To 1920X1440 local side 1280 X1024 remote side No Software Required easy PC selection via On Screen Display Menu OSD Push Buttons Hot Keys At local console side Support eight characters password protection and search PC server name At Remove console side Use SSL protocol for any encrypted netwo...

Page 7: ...ole 1920 x 1440 Remote console 1280 x 1024 Client Software Microsoft Java VM Sun Java VM Plug in Netscape Java VM Dimensions L x W x H 41 x 16 4 x 4 6 cm Weight 2Kg Environmental Speci fication Operating temperature 0 50 degree C Storage temperature 20 60 degree C Relative humanity 0 80 non condensing Power Requirement 5V DC 2 5A Electromagnetic Compatibility FCC CE 1 4 Video Modes IKVM 8000 recog...

Page 8: ...er UNIX like Operating Systems In order to access the remote host system using a securely encrypted connection you need a browser that supports the HTTPS protocol Strong security is only assured by using a key length of 128 Bit Some of the old browsers do not have a strong 128 Bit encryption algorithm For using the Remote Console window of your managed host system the browser must come with a Java...

Page 9: ...15 pin Male to Male AT to PS 2 keyboard adapter Optional Din 5 pin Male to Mini Din 6 pin Female PS 2 to DB9 adapter Optional Mini Din 6 pin Female to DB 9 pin Female CAT5 5E 6 Straight Through UTP STP Cable 8P8C 4 ...

Page 10: ...le connector Please plug it into the computer port on the rear of IKVM 8000 The other end has three connectors male type HDDB 15 pin for PC video male type Mini Din 6 pin for keyboard and male type Mini Din 6 pin for mouse Please plug these three connectors into the respective ports of computer If there is many PC need to connected please repeat the same produce to connect all of the PCs 6 Connect...

Page 11: ... 00000000 Please key in eight zero and enter the same value at retype field Note Before you get acquaintance with the operation of OSD manual please don t change the password i e keep default eight zero 00000000 value The Membrane Buttons Pressing the individual button to get PC port you want PC port LED Indication There are two LEDs Power LED The LED is marked by and Link LED The LED is marked by...

Page 12: ... you add a new KVM Switch as a slave bank please use reset button of master KVM Switch to automatically assign a new ID to it You can view this new slave bank through OSD menu Hot Key Commands You can also conveniently switch ports through simple key sequences To send commands to KVM switch the SCROLL LOCK key must be pressed twice within 2 seconds You will hear a beep for confirmation and the key...

Page 13: ...e The default Beeper function is ON and beeper control is only for available for Scan Mode To get out of Auto Scan Mode Press any key or SPACE bar Note Not including password Note Search PC name starting from 1st PC port 8 ...

Page 14: ...on of IKVM 8000 and KVM 800 1600 Note The IKVM 8000 must be master KVM BANK 1 The IKVM 8000 would not work correctly if it were not in BANK 1 Moreover do not cascade more than one IKVM 8000 in the KVM chain That would cause the KVM chain to work incorrectly also 1 Connect Keyboard Mouse and Monitor to the console port Local console block of IKVM 8000 9 ...

Page 15: ... KVM switches from the last BANK to BANK 1 6 When IKVM 8000 is powered on please wait for the IKVM 8000 to finish boot up procedure You will hear a beeper sound after 15 seconds Then you can enter the password default password is 00000000 of IKVM 8000 and start to control this KVM chain 7 You can use the local console on IKVM 8000 to switch to different BANK or port Since IKVM 8000 just has 8 butt...

Page 16: ...ase make sure the corresponding configuration of your DHCP server is com pleted It is recommended to reserve a fixed IP assignment to the MAC address of the IKVM 8000 You can find the MAC address labeled on the bottom side of the metal housing If this initial configuration does not meet your local requirements use the setup tool to adjust the values to your needs The setup tool can be found on the...

Page 17: ...via USB it is classified as an USB device and an appropriate drive letter is chosen for this device 5 On the lower right corner of the window there are two buttons Query Device and Setup Device Press the Query Device button to display the preconfig ured values of the network configuration The values are displayed in the text fields located above If necessary adjust the network settings according t...

Page 18: ...ts set the device settings to factory defaults help print online help reset perform a soft reset When using config command the following interactive options will appear IP auto configuration non dhcp bootp dhcp With this option you can specify whether the IKVM 8000 should get its network settings from a DHCP or BOOTP server For DHCP enter dhcp and for BOOTP enter bootp If you do not specify any of...

Page 19: ...onization algorithm There are two mouse modes available on the IKVM 8000 Auto mouse speed The automatic mouse speed mode tries to detect the speed and acceleration settings of the host system automatically See the section below for a more detailed explanation Fixed mouse speed This mode just translates the mouse movements from the Remote Console in a way that one pixel move will lead to n pixel mo...

Page 20: ...re are the following limitations which may prevent this synchronization from working properly the following limitations do not apply in case of USB and Mouse Type MS Windows 2000 and newer Special Mouse Driver There are mouse drivers that influence the synchronization process and lead to desynchronized mouse pointers If this happens make sure you do not use a special vendor specific mouse driver o...

Page 21: ...l and Server In general we recommend the usage of a mouse via USB Choose USB without Mouse Sync For a PS 2 mouse choose Auto Mouse Speed For XP disable the option enhance pointer precision in the Control Panel SUN Solaris Adjust the mouse settings either via xset m 1 or use the CDE Control Panel to set the mouse to 1 1 no acceleration As an alternative you may also use the Single Mouse Mode MAC OS...

Page 22: ...serial port via a terminal mode The primary interface of the IKVM 8000 is the HTTP interface This is covered extensively in this chapter Other interfaces are addressed in subtopics In order to use the Remote Console window of your managed host system the browser has to come with a Java Runtime Environment version 1 1 or higher If the browser has no Java support such as on a small handheld device y...

Page 23: ...he dialog box presented by the Internet Ex plorer 6 0 Newer web browsers do support strong encryption on default 4 2 Login and Logout 4 2 1 Login Note Your web browser has to accept cookies or else login is not possible Launch your web browser Direct it to the address of your IKVM 8000 which you configured during the initial configuration The address used might be a plain IP address or a host and ...

Page 24: ... into the IKVM 8000 successfully the main page of the IKVM 8000 will appear This page consists of three parts each of them contains specific information The buttons on the upper side allow you to navigate within the front end Return to the main page of the IKVM 8000 Open the IKVM 8000 remote console Exit from the IKVM 8000 front end The lower left frame contains a navigation bar and allows you to ...

Page 25: ...ion This is because today s web proxies are not capable of relaying the RFB protocol In case of problems please consult your network administrator in order to provide an appropriate network environment Once the Remote Console is connected it displays the screen content of your host system The Remote Console will behave exactly in the same way as if you were sitting directly in front of the screen ...

Page 26: ...r you can always resize the Remote Console window in your local window system as usual 4 3 1 Remote Console Control Bar The upper part of the Remote Console window contains a control bar Using its elements you can see the state of the Remote Console and influence the local Remote Console settings A description for each control follows Special button to send the Control Alt Delete key combination t...

Page 27: ...ttings on the host system In general there is no need to change mouse settings on the host Single Double Mouse Mode Switches between the Single Mouse Mode where only the remote mouse pointer is visible and the Double Mouse Mode where remote and local mouse pointers are visible and need to be synchronized Single mouse mode is only available if using SUN JVM 1 3 or higher Click on this button an Opt...

Page 28: ... however the scaling algorithm will not preserve all display details Mouse Handling The submenu for mouse handling offers two options for synchronizing the local and the remote mouse pointer Fast Sync The fast synchronization is used to correct a temporary but fixed skew Intelligent Sync Use this option if the fast sync does not work or the mouse settings have been changed on the host system This ...

Page 29: ...r higher offers the full list Video Settings Opens a panel for changing the IKVM 8000 video settings Brightness Controls the brightness of the picture Contrast Controls the contrast of the picture Clock Defines the horizontal frequency for a video line and depends on the video mode Different video card types may require different values here The default settings in conjuction with the auto adjustm...

Page 30: ...set all Modes Reset all settings to the factory made defaults Save Changes Save changes permanently Undo Changes Restore last settings Soft Keyboard Opens up the Menu for the Soft Keyboard Show Pops up the Soft Keyboard The Soft Keyboard is necessary in case your host system runs a completely different language and country mapping than your administration machine Mapping Used for choosing the acco...

Page 31: ...remote host Select OK to perform the command on the remote host 4 3 2 Remote Console Status Line The Remote Console Status Bar shows both console and the connection state The size of the remote screen is displayed The value in brackets describes the connection to the Remote Console Norm means a standard connection without encryption SSL indicates a secure connection Furthermore both the incoming I...

Page 32: ...as required by the Telnet client for instance in a UNIX shell telnet 192 168 1 1 Replace the IP address by the one that is actually assigned to the IKVM 8000 This will prompt for username and password in order to log into the device The creden tials that need to be entered for authentication are identical to those of the web interface That means the user management of the Telnet interface is entir...

Page 33: ...e steps working on the basis of a certain floppy image can be achieved First the path of the image has to be specified You can do that either by hand or by using the file selection dialog of your web browser To open the file selection dialog click on the button Browse and select the desired image file The maximum image size is limited to 1 44MB To use a larger image mount this image via CD ROM Ima...

Page 34: ...f a floppy to a file You can use the following command dd if dev fd0 of tmp floppy image dd reads the entire disc from the device dev fd0 and saves the output in the specified output file tmp floppy image Adjust both parameters exactly to your needs input device etc MS Windows You can use the tool RawWrite for Windows it is downloadable in http uranus it swin edu au jn linux From the menu select t...

Page 35: ...r the share named before If unspecified and a guest account is activated this guest account information will be used as your login Password optional if necessary specify the password for the given user name To register the specified file image and its location click on the button Set Configure Share Host The specified image file is supposed to be accessible from the IKVM 8000 The information above...

Page 36: ... Windows 2000 XP Open the Explorer navigate to the directory or share and press the right mouse button to open the context menu Select Sharing to open the configuration dialog Adjust the settings for the selected directory Activate the selected directory as a share Select Sharing this folder Choose an appropriate name for the share You may also add a short description for this folder input field C...

Page 37: ... file copy the contents of the CDROM to a file You can use the following command dd if dev cdrom of tmp cdrom image dd reads the entire disc from the device dev cdrom and saves the output in the specified output file tmp cdrom image Adjust both parameters exactly to your needs input device etc MS Windows To create the image file use your favorite CD imaging tool Copy the whole contents of the disc...

Page 38: ...s 2000 and the latter version 2 The Drive Redirection works on a low SCSI level and the SCSI protocol cannot recognize partitions therefore the whole drive selected will be shared instead of any particular partition 3 While connecting to a legacy KVM switch please select PS 2 mouse for Key board Mouse setting from webpage Otherwise you will be not be able to use Hot key Create a New Device in KVM ...

Page 39: ...uses Authentication Port This is a fixed number 443 Username The factory default Username is super Password The factory default Password is pass Connection Mode With this option you can specify whether the connection mode is LAN DSL UMTS ISDN 128k or ISDN Modem V9 0 4 Click Ok the new device will be added as below 34 ...

Page 40: ...elect the local drive you want to share with the remote computer which could be Floppy disc CD ROMs USB Sticks and hard drives The Port is fixed to 443 Then enter the correct username and password in the Device Authentication field The factory default Username is super and the default Password is pass Warning if Allow Write Support is selected all data on the shred media might be destroyed 35 ...

Page 41: ...urrently loaded If unset and no file image will be found it may happen that the host system will hang on boot due to changes in the boot order or the boot manager LILO GRUB This case was reported for some Windows versions 2000 XP other OS might not be fully excluded This behavior depends on the BIOS version used in that machine To set this option press the button Apply 36 ...

Page 42: ...esponding fields select appropriate Role setting for the user There are two Role options Administrator and User Administrator will be granted limited privileges on managing IKVM 8000 User will have less man agement privileges than Administrator After all necessary configurations are done click on Create button to add a new user Modify an existing user Select a user from Existing users list then cl...

Page 43: ...re shown and for which the changes will take effect You may change the settings of other users if you have the necessary access rights Transmission Encoding The Transmission Encoding setting allows changing the image encoding algo rithm that is used to transmit the video data to the Remote Console window It is possible to optimize the speed of the remote screen depending on the number of users wor...

Page 44: ...simultaneously The standard color depth is 16 Bit 65536 colors The other color depths are intended for slower network connections in order to allow a faster transmission of data Therefore compression level 0 no compression uses only 16 Bit color depth At lower bandwidths only 4 Bit 16 colors and 2 Bit 4 gray scales are recommended for typical desktop interfaces Photo like pictures have best result...

Page 45: ... yes The download volume is around 11 Mbytes The advantage of downloading Sun s JVM lays in providing a stable and identical Java Virtual Machine across different platforms The Remote Console software is optimized for this JVM versions and offers wider range of functionality when run in SUN s JVM Miscellaneous Remote Console Settings Start in Monitor Mode Sets the initial value for the monitor mod...

Page 46: ...tionally catching this keystroke already Typical examples are Control Alt Delete on Windows and DOS what is always caught or Control Backspace on Linux for terminating the X Server The syntax to define a new Button Key is as follows confirm keycode keycode confirm requests confirmation by a dialog box before the key strokes will be sent to the remote host keycode is the key to be sent Multiple key...

Page 47: ...se the USB and or PS 2 interface you need a correct cabling between the managed host and the managing device If the managed host has no USB keyboard support in the BIOS and you have connected the USB cable only then you will have no remote keyboard access during the boot process of the host If USB and PS 2 are both connected and you selected Auto as host interface then the card will select USB if ...

Page 48: ... the A key once you may see the screen dislay AA In such condition please enable this function and set to suitable timeout time Then this situation will disappear USB Mouse Type Enables USB mouse type Choose between MS Windows 2000 MacOS X for MS Windows 2000 XP Server 2003 and Mac OS X or Other Operating Systems for MS Windows NT Linux In MS Windows 2000 MacOS X mode the remote mouse is always sy...

Page 49: ...ys all changes instantly but may lead to a constant amount of network traffic even if the display content is not really changing depending on the quality of the video input signal All in all the default setting should be suitable for most situations Force Composite Sync Required for Sun Computers To support signal transmission from a Sun machine enable this option If not enabled the picture of the...

Page 50: ...the settings remotely make sure that all the values are correct and you still have an option to access the IKVM 8000 IP auto configuration With this option you can control if the IKVM 8000 should fetch its network settings from a DHCP or BOOTP server For DHCP select dhcp and for BOOTP select bootp accordingly If you choose none then IP auto configuration is disabled IP address IP address in the us...

Page 51: ...be contacted Remote Console And HTTPS port Port number at which the IKVM 8000 s Remote Console server and HTTPS server are listening If left empty the default value will be used HTTP port Port number at which the IKVM 8000 s HTTP server is listening If left empty the default value will be used Telnet port Port number at which the IKVM 8000 s Telnet server is listening If left empty the default val...

Page 52: ...he interface of connected device please set the options to Auto Detect 5 5 2 Dynamic DNS A freely available Dynamic DNS service dyndns org can be used in the following scenario The IKVM 8000 is reachable via the IP address of the DSL router which is dynamically assigned by the provider Since the administrator does not know the IP 47 ...

Page 53: ...igured Enable Dynamic DNS and change the settings according to your needs Enable Dynamic DNS This enables the Dynamic DNS service This requires a configured DNS server IP address Dynamic DNS server This is the server name where IKVM 8000 registers itself in regular intervals Currently this is a fixed setting since only dyndns org is supported for now DNS System Dyndns org provides Static charged a...

Page 54: ... web front end is only possible using an HTTPS connection The IKVM 8000 will not listen on the HTTP port for incoming connections In case you want to create your own SSL certificate that is used to identify the IKVM 8000 refer to next Certificate section KVM encryption This option controls the encryption of the RFB protocol RFB is used by the Remote Console to transmit both the screen data to the ...

Page 55: ...twork configuration that will be applied to the IKVM 8000 by its user The certificate s underlying secret key is also used for securing the SSL handshake Hence this is a security risk but far better than no encryption at all However it is possible to generate and install a new certificate that is unique for a particular IKVM 8000 In order to do that the IKVM 8000 is able to generate a new cryptogr...

Page 56: ...onal authentication process depending on the CA Upload the certificate to the IKVM 8000 using the Upload button After completing these three steps the IKVM 8000 has its own certificate that is used for identifying the card to its clients Warning if you destroy the CSR on the IKVM 8000 there is no way to get it back In case you deleted it by mistake you have to repeat the three steps as described a...

Page 57: ...he organization is located This is the two letter ISO code e g DE for Germany or US for the USA Challenge Password Some certification authorities require a challenge password to authorize later changes on the certificate e g revocation of the certificate The minimal length of this password is 4 characters Confirm Challenge Password Confirmation of the Challenge Password Email The email address of ...

Page 58: ...dem needs to be connected to the serial interface of the IKVM 8000 Logically connecting to the IKVM 8000 using a telephone line means nothing else than building up a dedicated point to point connection from your console computer to the IKVM 8000 In other words the IKVM 8000 acts as an Internet Service Provider ISP to which you can dial in The connection is established using the Point to Point Prot...

Page 59: ...dem or the modem is connected to a local telephone switch that requires a special dial sequence in order to establish a connection to the public telephone network you can change this setting by giving a new string Refer to the modem s manual about the AT command syntax Modem server IP address This IP address will be assigned to the IKVM 8000 itself during the PPP handshake Since it is a point to p...

Page 60: ...ave the possibility to adjust the clock manually or to use a NTP timeserver Without a timeserver your time setting will not be persistent so you have to adjust it again after IKVM 8000 loses power for more than a few minutes To avoid this you can use a NTP timeserver which sets up the internal clock automatically to the current UTC time Because NTP server time is always UTC there is a setting that...

Page 61: ... 7 Event Log Important events like a login failure or a firmware update are logged to a selection of logging destinations Each of those events belongs to an event group which can be activated separately 56 ...

Page 62: ... 8000 loses power or a hard reset is performed all logging data will be lost To avoid this use one of the following log methods NFS Logging enabled Define a NFS server where a directory or a static link have to be exported to write all logging data to a file that is located there To write logging data from more than one IKVM 8000 devices to only one NFS share you have to define a file name that is...

Page 63: ...with all information about the log event Only authentication and host power events have an own trap class that consists of several fields with detailed information about the occurred event To receive this SNMP traps any SNMP trap listener may be used Warning in contrast to the internal log file on the IKVM 8000 the size of the NFS log file is not limited Every log event will be appended to the end...

Page 64: ... information together with a support request It will help us to locate and solve your reported problem The Connected Users field shows the IP address from which host the user comes from and activity status of the connected users RC means that the Remote Console is open If the Remote Console is opened in exclusive mode the term exclusive mode is added To display the user activity the last column co...

Page 65: ...nts that are logged by the IKVM 8000 5 6 3 Update Firmware The IKVM 8000 is a complete standalone computer The software it runs is called the firmware The firmware of the IKVM 8000 can be updated remotely in order to install new functionality or special features 60 ...

Page 66: ...he currently running firmware and the version number of the uploaded firmware Pressing the button Update will store the new version and substitute the old one completely Warning this process is not reversible and might take some minutes Make sure the IKVM 8000 s power supply will not be interrupted during the update process because this may cause a permanent damage Thirdly after the firmware has b...

Page 67: ...newly updated firmware It will close all current connections to the administration console and to the Remote Console The whole process will take about half a minute Resetting sub devices e g video engine will take some seconds only and does not result in closing connections To reset a certain IKVM 8000 functionality click on the button Reset as displayed above Note Only the super user is allowed t...

Page 68: ... address of IKVM 8000 If not check network hardware Is IKVM 8000 powered on Check whether the IP address of IKVM 8000 and all other IP related settings are correct Also verify that all the IP infrastructure of your LAN like routers etc is correctly configured Without a ping functioning IKVM 8000 can t work either Q 6 Special key combinations e g ALT F2 ALT F3 are intercepted by the console system ...

Page 69: ...Every time I open a dialog box with some buttons the mouse pointers are not synchronous anymore A 10 Please check if you have an option like Automatically move mouse pointer to the default button of dialog boxes enabled in the mouse settings of the operat ing system This option needs to be disabled 64 ...

Page 70: ...A Appendix A Pin Assignments A 1 VGA HD 15 A 2 RJ 45 Connector Ethernet A 3 RJ 45 Connector ISDN 65 ...

Page 71: ...A 4 Serial SUB D 9 Connector 1 A 5 KVM 15 pin connector 66 ...

Page 72: ...ping The layout for this keyboard is shown in Figure B 1 However most modifier keys and other alphanumeric keys used for hotkey purposes in application programs are on an identical position no matter what language mapping you are using Some of the keys have aliases also means they can be named by 2 key codes separated by comma in the table Figure B 1 English US Keyboard Layout used for key codes K...

Page 73: ...SPACE ALTGR ESCAPE ESC F1 F2 F3 F4 F5 F6 F7 F8 F9 F10 F11 F12 PRINTSCREEN SCROLL LOCK BREAK INSERT HOME PAGE UP DELETE END PAGE DOWN UP LEFT DOWN RIGHT NUM LOCK NUMPAD0 NUMPAD1 NUMPAD2 NUMPAD3 NUMPAD4 NUMPAD5 NUMPAD6 NUMPAD7 NUMPAD8 68 ...

Page 74: ...NUMPAD9 NUMPADPLUS NUMPAD PLUS NUMPAD NUMPADMUL NUMPAD MUL NUMPADMINUS NUMPAD MINUS NUMPADENTER WINDOWS MENU Table B 1 Key Names 69 ...

Page 75: ...of these If done so IKVM 8000 may not be able to detect them Resolution x y Refresh Rates Hz 640 x 350 70 85 640 x 400 56 70 85 640 x 480 60 67 72 75 85 90 100 120 720 x 400 70 85 800 x 600 56 60 70 72 75 85 90 100 832 x 624 75 1024 x 768 60 70 72 75 85 90 100 1152 x 864 75 1152 x 870 75 1152 x 900 66 1280 x 960 60 1280 x 1024 60 75 70 ...

Reviews: