Phoenix G2 IDU User Manual
WEB GUI
SAF Tehnika JSC
59
b)
SSH
– this option will add automatic NAT record for accessing the remote IDU’s
SSH. The default values are as follows (the IP portion is only an example and
depends on actual running IP configuration):
1022 192.168.3.91:22
Remote IDU’s GUI accessible on local port 1022
2022 192.168.3.92:22
Second remote (in 505 1+0 dual mode with two
separate remotes) or direct FO neighbor (in Split
Protection mode) IDU’s GUI accessible on local port
2022
3022 192.168.3.93:22
Indirect Remote FO neighbor (ergo 'cross-corner' in split
protection mode) device’s GUI accessible on local port
3022
Example:
The local device has IP address of 192.168.3.90 and remote 192.168.3.91, the NAT
records of local device for accessing the remote will be these:
1443 192.168.3.91:443
1022 192.168.3.91:22
To access the remote device’s GUI, it is required to open a new page in WEB browser
and navigate to address 192.168.3.90:1443. Note this is the address of the local device
plus port which is then redirected according to the appropriate NAT record to the
remote side. The SSH access is realized in the same manner.
The advantage of such option is following:
Separate management channel for local and remote device access. The whole
system capacity is available for data traffic
The disadvantage of such option is following:
The management traffic uses dedicated slower channel; therefore,
management responses are little longer in comparison to the In-Band
management scheme
2)
Management in a Separate Channel:
Out-Band management configuration in a separate channel is a preferred scheme
when more links in series are managed, and the management access is originated
from any device in such link or from provider’s management node. The
communication with the remote side is ensured by means of a configurable separated
traffic channel. Management and data traffic are separated at provider side, and they
are then kept separated by a reserved standalone channel through radio links.
Management access is available also from opposite side (customer side) by a similar
configuration of the channel separation.
This configuration can be achieved on the section
user have to put the MNG, the dedicated management LAN3 port and one WAN
channel into the same group. Simultaneously user needs to put the remaining WAN
port, and user data LAN port into a different group than the management ports are in.
Finally, on the section
, user has to configure the speed limit for
both management and data. It is recommended to assign 2Mbits for the management
channel. The management channel should have the highest priority. Note that the port
priority is falling from left to right.
The advantages of such option are following:
Easy configuration
Allows ICMP packet transfer (ping)
The disadvantages of such option are following:
One whole traffic channel has to be dedicated to such management
The management and data have to be separated in the switch before the
device
A network loop risk when link operates within a single network