background image

AlterPath

 Manager E2000, 2500, and 

5000 Installation, Configuration, and 

User’s Guide

Software Version 1.4.0

Cyclades Corporation

3541 Gateway Boulevard
Fremont, CA 94538 USA
1.888.CYCLADES (292.5233)
1.510.771.6100
1.510.771.6200 (fax)

http://www.cyclades.com

Release Date: December 2005
Part Number: PAC0380

Summary of Contents for AlterPath Manager 2500

Page 1: ...ion Configuration and User s Guide Software Version 1 4 0 Cyclades Corporation 3541 Gateway Boulevard Fremont CA 94538 USA 1 888 CYCLADES 292 5233 1 510 771 6100 1 510 771 6200 fax http www cyclades com Release Date December 2005 Part Number PAC0380 ...

Page 2: ...is a registered trademark of the FreeBSD Foundation HP UX is a registered trademark of the Hewlett Packard Corporation Linux is a registered trademark of Linus Torvalds in the United States and other countries Mozilla and Mozilla Firefox are trademarks of the Mozilla Foundation Sun Sun Microsystems Java J2SE Solaris are trademarks or registered trademarks of Sun Microsystems Inc in the United Stat...

Page 3: ...Key Features 3 Single Point Security Gateway 5 Centralized Authentication 5 Consolidated Views and Console Access 6 Access Control List ACL for Devices 6 Centralized Data Logging System 6 Log File Compression and Rotation 7 Prioritized Triggers Alarms 7 Other Alarm Features 8 Modem Support for Remote Sites 8 Dial Back Support for ACS 8 One Time Password support for ACS 8 Multiport Ethernet 9 Enhan...

Page 4: ...rability Integration and Compatibility 15 APM E2000 2500 and 5000 Database Compatibility 15 Interoperability with Routers and Ethernet Switches 15 Interoperability with Cyclades Devices 16 Interoperability and Compatibility with Modem Vendors 16 Power Management Support 16 KVM net Support 17 Typical Configuration of AlterPath Manager and KVM 17 AlterPath Manager Features Unsupported by KVM net 18 ...

Page 5: ... 47 Search and Filter Functions 47 Online Help 47 Alarms 48 Alarm Logs 48 Alarms List Form 49 Web Access for Users 53 Consoles Devices 53 Consoles 55 Multiple Users and Read Write Access 58 Viewing an IBM Blade Center Blade or Switch 58 Consoles Detail Form 58 KVM net Plus Web Control Page 62 IPMI 66 Logs 67 Access Logs 69 Event Logs 70 Data Buffer 71 Power Management 72 User s Profile 75 Viewing ...

Page 6: ...s of the Web Management Interface 101 Relocating Online Help 102 Sorting Filtering and Saving a List Form 102 Using the Form Input Fields 103 Verifying Error Messages 104 Devices 105 Device List Form 107 Supported Devices 109 Proxies 115 Proxy Types 115 Disabling the Proxy 118 Direct Access 118 Configuring Ports to be Proxied 118 Dial Up and Dial Back 118 Other Requirements for Dial Out Dial Back ...

Page 7: ...ing 160 Using the Logical AND in the Alarm Trigger Expression 161 How Health Monitoring Works 163 User Notification 163 Profiles 163 Consoles 166 Changing the Number of Consoles per Page 169 Console Type KVM 173 Deleting a Console Group 180 Configuring Outlets 180 Log Rotate Now 181 Users 183 User List form 184 Deleting a User Group 192 Local Password 192 Groups 193 Firmware 197 Firmware List Form...

Page 8: ...ault Tolerant APMs 241 WMI Configuration of Fault Tolerant APMs 242 Configuration of the Primary APM 248 Configuration of the Redundant APM 250 Chapter 5 Advanced Configuration 255 Working from a CLI 256 CLI Commands 258 Copying and Pasting Text within the Console Applet Window 259 Connecting Directly to Ports 259 Sample Command Line Interface 261 Console Session Hot Keys 263 Set Commands 264 seta...

Page 9: ...al Card Configuration 283 How to Detect Modems Connected to the Ports 283 Checking Your Modems 284 Viewing the Latest Status of Each Modem 284 Configuring Dial Out and Dial Back 285 For ACS Devices 285 Modem Dial Back for ACS 286 Required CLI configuration 286 Optional CLI Configuration 286 For external modems 287 For PCMCIA modem 287 Changing the Ports to be Proxied 288 NIS Configuration 288 NIS ...

Page 10: ...300 Restoring Your Configuration 301 More About Importing Certificates 305 Appendix A Technical Specifications 307 Hardware Specifications 307 Software Specifications 308 Appendix B ACS Modem Configuration 309 Appendix C DLS Activation 315 Data Logging Session Activation 315 Additional DLS at Time of Purchase 315 DLS Activation Conversion 317 Obtaining Expanded DLS Activation 318 Verifying Your Cu...

Page 11: ...ptions Selected 34 Figure 2 5 Netscape 8 Options Window 35 Figure 2 6 Site Controls Option Selection 36 Figure 2 7 Location of Shield Icon and URL Entry Field 37 Figure 2 8 Trust Settings Dialog Box 38 Figure 2 9 Feature Window 39 Figure 3 1 APM Login Screen 45 Figure 3 2 Console Devices Menu 46 Figure 3 3 Alarms List Form 49 Figure 3 4 Alarms Detail or Ticket Info Form 51 Figure 3 5 Logs Form 52 ...

Page 12: ... 80 Figure 3 26 User s Profile Groups Form 81 Figure 3 27 User s Profile Security Form 82 Figure 4 1 AlterPath Manager Configuration Process Flow 87 Figure 4 2 Admin Menu Bar Selections 99 Figure 4 3 Logging in as Admin 100 Figure 4 4 Basic Functional Fields of a Typical Form 101 Figure 4 5 Console List Form Sorted by Console 103 Figure 4 6 Device Configuration Error Message 104 Figure 4 7 Form in...

Page 13: ...Figure 4 29 Device Firmware Upload 149 Figure 4 30 KVM Device Details Form 151 Figure 4 31 KVM Device Viewer Form 151 Figure 4 32 Device Cascade List Form 154 Figure 4 33 Device Cascade Detail Form 155 Figure 4 34 Alarm Trigger List Form 158 Figure 4 35 Alarm Trigger Detail Form 159 Figure 4 36 Health Monitor User Entry Field 161 Figure 4 37 Health Monitoring Alarm Trigger Detail Form 162 Figure 4...

Page 14: ...ail List 206 Figure 4 62 Selecting Blade_Center from Devices List 211 Figure 4 63 Blade Device Details Form 211 Figure 4 64 Blade Device Groups Form 214 Figure 4 65 Blade Device Switch 1 Form 215 Figure 4 66 Blade Wizard Warning Message 218 Figure 4 67 Blade Wizard Connection Method Form 219 Figure 4 68 Blade Wizard User Access Notification Form 219 Figure 4 69 Blade Wizard Console Switch Selectio...

Page 15: ...9 Figure 4 82 Connecting 2 APMs in a Redundant Configuration 241 Figure 4 83 APM Heartbeat Configuration Form 242 Figure 4 84 Detailed View APM Heartbeat Form for Primary 243 Figure 4 85 Detailed View APM Heartbeat Form for Redundant 243 Figure 4 86 APM Synchronization Form 247 Figure 5 1 PuTTY Configuration of APM as a Security Proxy 260 Figure C 1 Feature Window full content scrolled 320 ...

Page 16: ...xiv AlterPath Manager Installation Configuration and User s Guide ...

Page 17: ...ble 3 9 Event Logs Form 71 Table 3 10 IPDU Viewer Details 72 Table 3 11 User s Profile Details Form 76 Table 3 12 User s Profile Consoles Form 79 Table 3 13 User s Profile Devices Form 80 Table 3 14 User s Profile Groups Form 81 Table 3 15 User s Profile Security Form 82 Table 4 1 Summary of Devices Forms 105 Table 4 2 Device List Form 107 Table 4 3 Devices Detail Form 111 Table 4 4 Types of Web P...

Page 18: ...Table 4 22 Profiles Detail Form 165 Table 4 23 Summary of Console Forms 166 Table 4 24 Consoles Details Form 171 Table 4 25 KVM net and KVM net Plus Console RDP Connection Fields 173 Table 4 26 Summary of User Forms 183 Table 4 27 Users Detail Form 185 Table 4 28 Firmware Detail Form 200 Table 4 29 APM Data Types 202 Table 4 30 Info Reporting List Form 205 Table 4 31 Summary of Blade Module Forms ...

Page 19: ...nization Form Fields and Meanings 247 Table 5 1 CLI Specific Commands 258 Table 5 2 Console Applet Window Menu Options 259 Table 5 3 Console Applet Ec Command Set 263 Table 5 4 Data Types You Can Backup and Restore 296 Table 5 5 Default Configuration Values from the apm properties File 301 Table 5 6 Information for the openssl Command 303 Table C 1 DLS Activations Available at Initial Purchase 316...

Page 20: ...xviii AlterPath Manager Installation Configuration and User s Guide ...

Page 21: ...or Console Logs 52 To Assign or Re assign a Ticket to a User 52 To Access Consoles or Devices 53 To View the Consoles List 56 To Connect to a Console 57 To View the Consoles Notify Form 61 To View the Consoles Groups Form 62 To Access the Web Control Page 62 To View IPMI Sensors 66 To View the Logs 68 To View PM Device Parameters 74 To Change Your Password 78 To Use the First Time Configuration Wi...

Page 22: ...covery Wizard 143 To Connect to a Device 146 To Delete a Device 147 To Delete a Device from a Group 147 To Upload Firmware to a Console Device 148 To Configure Escape Sequences and Idle Timeout 150 To Cascade a Secondary KVM to a Primary KVM 153 To View the Alarm Trigger List Form 157 To Create an Alarm Trigger 158 To Delete an Alarm Trigger 160 To Configure the Health Monitoring Alarm Trigger 162...

Page 23: ...93 To Add Members to a Group 195 To Delete a Group 195 To Assign a Security Rule to a User Group 195 To Add Firmware 198 To Delete Firmware 199 To Upload Firmware to Console Devices 199 To View and Access Firmware Information 201 To Upgrade the AlterPath Manager Firmware 201 To Respond to the Warning Message 204 To Activate the Blade Module 207 To Add or Edit the Chassis 210 To Select a Group to A...

Page 24: ...Change the Session Timeout 275 To Change the Number of Consoles per Page 275 To Enable Telnet 275 To Change the ACS TS Admin Name 277 To Exclude Modems from the Modem Pool 282 To Define Different Scripts for Each tty Device 285 To Configure Active Directory 292 To Configure Open LDAP 293 To Disable HTTP to Use Only HTTPS 294 To Add Firmware 294 To Upgrade the APM Firmware 295 To Recover a Root Pas...

Page 25: ...terPath Manager or as APM If a reference is being made to a specific model of AlterPath Manager references such as AlterPath Manager E2000 and AlterPath Manager 2500 or AlterPath Manager 5000 are used Audience This document is designed for system administrators and regular users of the AlterPath Manager E2000 2500 and 5000 Users are expected to have basic knowledge of using a graphical user interf...

Page 26: ... various fault management procedures such as connecting to a console responding to an alert and more Configuration settings include user access alarm triggers device management firmware control as well as running the configuration wizards 5 Advanced Configuration Covers first time configuration Explains the serial console interface Linux shell and the command line interface CLI functionality as we...

Page 27: ...Edit the pslave conf file User input What you type in an example compared to what the computer displays APM ifconfig eth0 Table P 2 Other Terms and Conventions Term or Convention Meaning Examples Hot keys When hot keys are shown a plus appears between two keys that must be pressed at the same time and a space appears between two keys that must be pressed sequentially Ctrl k p entered while the use...

Page 28: ...tains the user selection or input fields for each selected item in the menu Form Names The form names of the application s GUI do not necessarily appear on the actual window Because some forms do not have titles these names are used to distinguish each form as well as to reflect the form function The most commonly used form names are List forms and Detail forms The configuration forms of the Alter...

Page 29: ...hell Syntax Typeface Meaning Example Brackets Indicate that the parameter inside them is optional The command will still be accepted if the parameter is not defined When the text inside the brackets starts with a dash and or indicates a list of characters the parameter can be one of the letters listed within the brackets iptables ADC chain rule specification options Ellipses Indicate that the late...

Page 30: ...ease visit our website at www cyclades com training call us at 1 888 292 5233 or send an email to training cyclades com text Text enclosed in greater than or less than symbols or angle brackets is variable text that is to be substituted in a specific command line add user username Spacing and Separators Lists will not normally have spaces between the items but will have commas hyphens or semicolon...

Page 31: ...le free of charge to current Cyclades customers Visit http www cyclades com support downloads php to download the latest firmware See To Upgrade the APM Firmware on page 295 for instructions on upgrading the firmware on your AlterPath Manager Cyclades Technical Support Cyclades offers free technical support To find out how to contact the support center in your region go to http www cyclades com su...

Page 32: ...AdditionalResources xxx APM Installation Configuration and User s Guide ...

Page 33: ...PM and all its users from a single location without having to work directly on a target device or server console Note Anyone who uses the APM application in Access mode is referred to as a user regardless of whether that user is a system administrator or not An administrator is anyone who has the exclusive authority to configure and administer the APM and its users Connectivity and Capacity The E2...

Page 34: ...lso available with additional DLS connection capacity at the time of initial purchase For details about DLS capacity refer to Appendix C DLS Activation The LCD control panel power on reset and power off buttons are shown in Figure 1 3 Figure 1 3 APM 2500 Front View The port connections power switch and power connector of the APM 2500 are shown in Figure 1 4 Expansion slots Eth1 Eth0 USB port 2 USB...

Page 35: ...ath Manager E2000 2500 and 5000 are Single Point Security Gateway Page 5 Centralized Authentication Page 5 Fan connector AC USB Eth0 Eth1 Console Press and hold for 1 second to power on the system Press and hold for 4 seconds to reset the system LCD panel Press and hold for 10 seconds to shut down the system USB Console Eth0 Eth1 Redundant AC connectors Fans ...

Page 36: ...s Page 8 Dial Back Support for ACS Page 8 One Time Password support for ACS Page 8 Multiport Ethernet Page 9 Enhanced Ethernet Port Configuration Page 9 Ethernet Bonding Page 10 DHCP Option for APM Network Setup Page 10 Health Monitoring Page 10 Console Wizard Page 11 Device Discovery Page 11 Support for KVM net Page 11 Support for KVM net Plus Page 11 KVM net FW Upgrade Support Page 12 Support fo...

Page 37: ...ion saves you or the administrator from using a password for each device e g TS ACS KVM net and thereby maintain a secure password You need only use your password once upon logging onto the AlterPath Manager For all users who access the console ports the AlterPath Manager provides the following authentication methods local database RADIUS TACACS LDAP Kerberos NIS and Active Directory Blade Module ...

Page 38: ...as well as to one or more consoles if that user has been granted such access by the admin in the user s access control list The regular user will never have admin mode access An admin profile user a regular user granted administrative profile rights can have access regular user mode access or admin access to one or more devices as well as to one or more consoles if that user has been granted such ...

Page 39: ...u or any user connects to a DLS enabled port the APM adds a timestamp to the log file The user identification timestamp is recorded in the data buffer and logged separately on the APM access log database Log File Compression and Rotation The system logger automatically saves the current log file after a certain point in time and then creates a new file to collect a new set of console data The file...

Page 40: ...mote console server devices Moreover users have the choice to use PPP as the primary mode of connection or only as a backup connection in the event that the network fails Note Modems are not supported on the APM 2500 or the APM 5000 Dial Back Support for ACS The AlterPath Manager E2000 provides options for integrated modems to automatically dial to remote locations when the network fails In the ab...

Page 41: ... not supported on the APM 2500 or the APM 5000 The Ethernet cards are detected by the configuration wizard during boot time The Ethernet hardware has commands to control the link speed and duplexing supported on each interface Enhanced Ethernet Port Configuration There is a script called setethernet that is invoked automatically along with the other initial APM configuration the first time the APM...

Page 42: ...ough the CLI setnetwork command you now have the option to use DHCP Dynamic Host Configuration Protocol to configure Eth0 DHCP allows the APM to obtain its own IP address from the DNS server If there is no DNS server or if the DNS server cannot be accessed the default IP address of 192 168 1 20 will be assigned to Eth0 Eth0 is the only Ethernet port that can be configured to use DHCP Of course as ...

Page 43: ...e consuming task of re defining each console port manually Support for KVM net Among other console types the AlterPath Manager supports viewing of Keyboard Video Mouse based consoles through the use of an AlterPath KVM net installed in the network The user connects through a client software over an IP connection and the KVM net switch routes the application to one of its ports to connect the user ...

Page 44: ...ts like a KVM net The AlterPath Manager supports viewing of ACS based consoles as well as Keyboard Video Mouse based consoles through the use of an AlterPath OnSite installed in the network Support for IPMI The AlterPath Manager supports servers that are based on IPMI Intelligent Platform Management Interface the open standard for machine health and control including remote control IPMI defines co...

Page 45: ... Blade Module once enabled supports the number of chassis equal to the number of DLS activations installed on your APM up to 2048 chassis and up to 32768 blades switches just like any device or console Using the Blade Wizard an admin user can create 14 blades and 4 switches All blades provide authorized users with CLI KVM IP virtual media and power options For security Blade users are controlled b...

Page 46: ...up a fault tolerant APM configuration A fault tolerant configuration has the ability to automatically back up and restore an APM 2500 or APM 5000 system with little or no downtime in the event of a failure of a primary APM By using the heartbeat protocol in conjunction with network RAID or RSYNC a redundant APM automatically takes over control of the managed devices in the event of a failure of th...

Page 47: ...ion and system recovery procedures Interoperability Integration and Compatibility APM E2000 2500 and 5000 Database Compatibility Each AlterPath Manager model can migrate backup and restore its database to or from any other AlterPath Manager model Interoperability with Routers and Ethernet Switches The built in Ethernet ports on the AlterPath 2500 and AlterPath 5000 fully compatible with the follow...

Page 48: ...thin the modem setup process Hayes Motorola US Robotics The AlterPath Manager supports dial out and dial back capability through the following PCI modem built in serial card required to connect external modems supporting encryption Note The APM 2500 and the APM 5000 do not have AUX ports and they currently do not support any modems Power Management Support The AlterPath Manager supports AlterPath ...

Page 49: ...n of AlterPath Manager and KVM The configuration below shows the AlterPath Manager managing four KVM switches Two KVM net switches are accessed directly through IP The other two are physically cascaded to KVM net 2 KVM analog switches as well as KVM Expanders are normally used as cascaded units since they cost less than KVM net switches Figure 1 7 Configuration Example of APM and KVM net Each seco...

Page 50: ...s Unsupported by KVM net When using the KVM net logs are available only for access to KVM consoles The Logs form defaults to Access Logs and Event Logs Data Buffering is inactive Alarms are generated only for KVM net Health Monitoring events The Alarm list form is the same as for serial console alarms but without the data buffer link OnSite Support The AlterPath Manager supports the AlterPath OnSi...

Page 51: ...agram shows an example of an APM connected to an OnSite with KVM servers and console servers One server can be accessed through both types of connection Figure 1 8 Example of an OnSite accessed by an APM AlterPath Manager OnSite Server Server Server Server Server Server Server KVM Ports Serial Ports Ethernet ...

Page 52: ...OnSite Support 20 APM Installation Configuration and User s Guide ...

Page 53: ... 2500 or 5000 is shipped with the components as described by the following table Product Installation Checklist Page 21 Rack Mounting the AlterPath Manager Page 23 Deploying the AlterPath Manager Page 25 Safety Considerations When Rack Mounting Page 28 Pre Configuration Requirements Page 30 IPMI and Blade Module Options Page 38 Check Item Part Number Description Purpose PAC0266 Documentation CD CD...

Page 54: ... away See below for country specific part numbers Power cable Main power cable for AlterPath Manager E2000 2500 and 5000 CAB0010 Power cable USA CAB0037 Power cable Europe CAB0056 Power cable UK CAB0055 Power cable Australia CAB0278 Power cable Japan CAB0036 Cable crossover DB 9 female to RJ 45 6 ft Can be used with AUX port ACS and TS serial ports Check Item Part Number Description Purpose ...

Page 55: ...018 Mounting rail kit Mounting brackets screws for APM 2500 Hardware for rack mounting the AlterPath Manager 2500 Note The APM 2500 is furnished with the mounting brackets ears already attached to it Mounting Kit Mounting brackets with rails screws for APM 5000 Hardware for rack mounting the AlterPath Manager 5000 CAB0041 Cable 4 foot DB 9 female to DB 9 female null modem cable for APM E2000 Cable...

Page 56: ...When the inner rails are correctly positioned the tabs will be to the rear of the APM and the front three holes in the inner rails will line up with the holes in the sides of the APM 3 Attach the outer rails to the rack using the end brackets Be sure the open end of each outer rail is located towards the front of the rack a The shorter end brackets mount onto the front of the outer rails Use the t...

Page 57: ... if not already installed Note See To Configure the COM Port Connection and Log In on page 31 You can obtain the latest update to HyperTerminal from http www hilgraeve com htpe download html 3 Connect Switch or Hub to PC and the AlterPath Manager Your workstation and AlterPath Manager must be on the same physical LAN Connect one RJ 45 cable from the Ethernet 1 or 2 port of the AlterPath Manager to...

Page 58: ...ingle network topology the AlterPath Manager is connected to only one network and the AlterPath Manager management functions are contained in the same network While it may appear that the workstation has direct access to the TS and ACS boxes if users attempt to access them they will be denied because the AlterPath Manager is already controlling access to the ports In a single network configuration...

Page 59: ...ay be set up in a private network structure Figure 2 1 Private Network Diagram Eth0 Eth1 Ethernet Ethernet cable AlterPath Manager KVM net KVM ports ACS or TS RS 232 Ethernet OnSite KVM ports Serial ports Workstation Public LAN Private LAN RS 232 RS 232 Cat 5 cable RS 232 RS 232 Serial ports Local KVM user Cat 5 Cat 5 Cat 5 Web User Interface ...

Page 60: ...ty Considerations When Rack Mounting When rack mounting the AlterPath Manager consider the following Operating temperature The manufacturer s recommended operating temperature for the AlterPath Manager is 50 to 95 F 10 C to 35 C Workstation Web User Interface Eth0 AlterPath Manager Public LAN Ethernet KVM net ACS or TS OnSite KVM ports Serial ports KVM ports Serial ports Ethernet cable Local KVM u...

Page 61: ...at the amount of airflow required for safe operation is not compromised Mechanical loading Ensure that the equipment is mounted or loaded evenly to prevent a potentially hazardous condition Circuit loading Ensure that the connection of the equipment to the supply circuit and the effect that overloading of circuits might have on overcurrent protection and supply wiring Check the equipment nameplate...

Page 62: ...ed the configuration procedures discussed in Chapter 4 Requirement Description HyperTerminal Kermit or Minicom If you are using a PC ensure that HyperTerminal is installed on your Windows operating system If you are using the UNIX operating system use Kermit or Minicom NOTE You must have root access on your local UNIX machine in order to use the serial port IP Addresses Have the IP Mask addresses ...

Page 63: ...anager connectivity and system settings is also set up during First Time Configuration Configuration through the web interface is discussed in the chapter Configuration and Administration Before using the terminal make sure it is configured as follows 1 Select an available COM port In HyperTerminal Start Program Accessories Communications Hyper Terminal select File Properties and click the Connect...

Page 64: ...ave ActiveX enabled by default If you update Internet Explorer or if you implement a new installation of Internet Explorer you must be sure to enable ActiveX Caution Browsers other than Internet Explorer are known to have a limitation with logins by more than one user from a single workstation After the initial login session has started a subsequent login by a different user will force the previou...

Page 65: ...ons shown as enabled in Figure 2 3 Options to Enable for ActiveX Figure 2 3 Options to Enable for ActiveX T To Enable ActiveX on Netscape 7 x Note This applies to Netscape 7 x where x 1 1 Go to the following path using Windows Explorer C Program Files Netscape Netscape defaults pref ...

Page 66: ...ex js and edit it 3 In the editor change the following line from to 4 Save the file and exit the editor 5 Restart Netscape 7 x T To Enable ActiveX on Netscape 8 x 1 Open the Netscape 8 x Browser 2 On the pull down menu bar go to the Tools Options Figure 2 4 Tools Pull down menu with Options Selected 3 Click on Options pref security classID allowByDefault false pref security classID allowByDefault ...

Page 67: ...ration Requirements Installation 35 An Options window appears Figure 2 5 Netscape 8 Options Window 4 Click on Site Controls in the left column of the window The window that appears has the button to enable ActiveX ...

Page 68: ...ols Option Selection 5 Select Internet Explorer in the Rendering Engine box in the lower right of the window 6 Select Enable ActiveX in the Web Features box 7 Click the OK button 8 Enter the IP address of your APM in the URL entry field of your Netscape browser Notice the shield icon shown in Figure 2 7 ...

Page 69: ...Pre Configuration Requirements Installation 37 Figure 2 7 Location of Shield Icon and URL Entry Field 9 Click on the Shield Icon A Trust Settings dialog box appears Shield icon URL entry field ...

Page 70: ...e Options The AlterPath Manager can optionally provide the following paid for features IPMI Blade Module You can purchase the IPMI and Blade Module options from your Cyclades sales team or Cyclades partners Cyclades customer service will need the MAC Ethernet hardware address of Eth0 the first Ethernet controller in your APM to generate the license file which will activate your new features To fin...

Page 71: ...out link in the upper left corner of the display A window that shows IPMI blade and any other licenses and their status appears Figure 2 9 Feature Window You can also log on to the CLI on the serial console port as root or as admin and run the following command sysinfo Valid licenses end with the string VALID true An example screen display follows ...

Page 72: ...DEMODULE Name APM_B_IBMBLADEMODULE version 1 0 1 type null feature IBMBLADEMODULE dev ice APM owner paulo customer_id gregg expiry_date 2005 12 28 expiry_time 00 00 info null VALID true FEATURE IPMI Name APM_B_IPMI version 1 0 1 type null feature IPMI device APM owner paulo customer_id gregg expiry_date 2005 12 28 expiry_time 00 00 info null VALID true FEATURE DLS Name APM_B_DLS_256 version 1 0 1 ...

Page 73: ...ame 133 TX packets 5726282 errors 0 dropped 0 overruns 0 carrier 0 collisions 1038728 txqueuelen 1000 RX bytes 685270715 653 5 Mb TX bytes 548308906 522 9 Mb Interrupt 10 Base address 0xc000 Memory e5020000 e5020038 eth1 Link encap Ethernet HWaddr 00 90 FB 01 8C D7 inet addr 10 10 10 2 Bcast 10 10 255 255 Mask 255 255 0 0 UP BROADCAST RUNNING MULTICAST MTU 1500 Metric 1 RX packets 632 errors 0 dro...

Page 74: ...Pre Configuration Requirements 42 APM Installation Configuration and User s Guide ...

Page 75: ...trator refer to Chapter 4 Configuration and Administration User Interface Overview The AlterPath Manager user interface provides you with four main menu options Note With browsers other than Internet Explorer there are limitations with multiple users accessing the AlterPath Manager via the Web Management Interface on a single workstation If you plan to have more than one user simultaneously open A...

Page 76: ...From the list click on the device you wish to access For IPMI and Blade Module users the Consoles List form provides access to the IPMI as a device as well as the chassis blades and switches Consoles Devices select CONSOLE from the Filter by pull down selector List form to view a list of consoles assigned to you From the list click on the console you wish to access For IPMI and Blade Module users ...

Page 77: ...ly HTTPS on page 294 Chapter 5 for the procedure on how to configure the encrypted version 2 When the Login screen appears enter your user name and password as provided by your system administrator Figure 3 1 APM Login Screen 3 Select the Login button Upon successful login the Alarms List form appears Note When the AlterPath Manager launches your application screens for the first time the process ...

Page 78: ...t you see when you log in as a regular user Figure 3 2 Console Devices Menu The menu bar highlights the currently selected menu option Your user name and IP address appears on the upper right hand corner of the screen Access tab indicates that user interface is for regular users Logout tab Menu bar showing Consoles Devices User view or data input form Firmware version info Panel to manage list as ...

Page 79: ...hat the list is alphanumerically arranged in ascending order an upward arrowhead in descending order You can change the sort order by clicking on the heading or the arrow Search and Filter Functions When available you will find the Filter By and Search For fields at the bottom of a list form This allows you to search through a list form by selecting the search category i e Console group from the d...

Page 80: ...each alarm in a database but also maintains a log for each alarm There are two ways in which you can view alarm logs From the Alarms List form From the Logs form Logs select console Event Logs T To Respond to an alarm Since no two issues are exactly the same you have several ways to respond to an alarm depending on its nature and severity A typical procedure for responding to an alarm is as follow...

Page 81: ...ms to connect to a console and to view console logs To re assign the current ticket change the ticket status and add notes or comments use the Alarms Detail or Ticket Info Form on page 51 Figure 3 3 Alarms List Form Table 3 2 Alarms List Form Element Definition Ticket Ticket number assigned to an alarm The symbol above the ticket number indicates the severity level of the alarm Select the number t...

Page 82: ... console session according to the type of configured device and console For example a serial console will establish a text based session a KVM console will launch the KVM viewer and an IPMI console will launch the SSH applet and connect to the IPMI SOL console Console Config Console configuration Select this to view the Console Detail form which includes the secondary form Console Notify Console A...

Page 83: ...ser to assign or re assign ticket to another individual user Status Dropdown box to select the status of the ticket Messages The system generated message s pertaining to the alarm Notes Text entry box for entering notes or comments about the current ticket or alarm Back Button to return to the Alarms List form Save Button to save your entries Reset Button to reset the form to its original or defau...

Page 84: ...onding view link for the console log you wish to view The system displays the Logs form Figure 3 5 Logs Form T To Assign or Re assign a Ticket to a User To assign or re assign a ticket follow these steps 1 From the Alarms List form select an alarm or ticket to open the Alarm Detail or Ticket Information form The system opens the Alarms Detail form 2 From the Ticket Information form select a user f...

Page 85: ...orts on the ACS TS and the OnSite KVM ports on the KVM net and OnSite T To Access Consoles or Devices 1 Log onto the WMI 2 Select Consoles Devices from the main menu You will see a list of consoles in the first column if you have been granted permission to access any consoles At the bottom of the form the filter by pull down menu shows CONSOLE 3 Select DEVICE from the filter by pull down menu You ...

Page 86: ... s Guide Figure 3 6 Selecting a Device View or CLI a Select the VIEW button and you will see a read only view of the Device Detail or Console Detail form which is the default of a series of tabbed forms Figure 3 7 Access Device Detail Form The tabs include Details ...

Page 87: ...re read only forms b Select the CLI button and a CLI viewer will be launched Figure 3 8 Device CLI Viewer Consoles Selecting Consoles from the menu brings up the Consoles List form which allows you to View detailed information about the consoles assigned to you Connect to your target console ...

Page 88: ...net or OnSite Optional Features For the following paid for options the Consoles menu also allows you to Connect to an IPMI Serial Over Lan SOL console View individual blades and switches of the chassis as part of the Blade Module T To View the Consoles List The Consoles List form allows you to view the consoles to which you have authorized access To view the Consoles List form follow this step 1 F...

Page 89: ...ht delay before connecting to a console The system normally connects you to a console through Secure Shell SSH In KVM net the listed console names are the KVM net ports Clicking on the console name launches the ActiveX application and connects to the port If the console name is an IPMI console clicking on the console name launches an SSH session and connects to the IPMI CLI Command Line Interface ...

Page 90: ... mouse cursor on the device name or the blade switch name and then left click the mouse to display the list of connect options Like all other consoles as a regular user you can only view those blade servers to which you have access You may also view your user profile with regards to blade access from the User s Profile option of the menu Security form Consoles Detail Form Use the Consoles Detail f...

Page 91: ...ay the Console Detail form Notify Tab to tell you if you are on the notification list Groups Tab to tell you if any groups are assigned to the console Outlets Tab to view power management information Log Rotate Tab to view log rotation settings Console Name Name of the target console Device Name Name of the device used by the console ...

Page 92: ...system name OS Type Operating system used by the console OS Version Version of operating system Location Physical location of the console Status Status of the target console Enable Disable On Demand RDP IP Address The field for entering the IP address of the RDP server to be associated with this port If a physical KVM port is specified in the Port field then an RDP in band connection and a regular...

Page 93: ... shows the users who are notified when an alarm pertaining to the current console is generated To view the Consoles Notify form 1 From the Consoles Detail form click on the Notify tab The system displays the Consoles Notify form Figure 3 11 Consoles Notify Form In the selection box a plus sign indicates a group as opposed to a user USER is the default list which contains all users Back Button to r...

Page 94: ...tab The system displays the Consoles Group form Figure 3 12 Consoles Group Form KVM net Plus Web Control Page The KVM net Plus utilizes a web control page that replaces the OSD during KVM over IP sessions The web control page parameters can be viewed and edited from the APM T To Access the Web Control Page 1 Launch a KVM net Plus KVM viewer session from the APM A window indicating that the KVM vie...

Page 95: ...in the background by a console list control window 2 After the KVM viewer appears bring the console list control window to the foreground 3 Click on the console name that corresponds to the console displayed in the KVM viewer window Note Every time a KVM viewer is launched from the APM a new console is displayed in the console list control window ...

Page 96: ...Web Access for Users 64 APM Installation Configuration and User s Guide Figure 3 14 KVM Console List Control Page A web control page window similar to the window shown in Figure 3 15 appears ...

Page 97: ...o allows you to 1 Reset the mouse and keyboard associated with the console you are accessing 2 Manage outlets associated with the console you are accessing 3 Configure the video contrast and brightness associated with the console you are accessing Note A similar page will appear when you select the console of a KVM net but the parameters can be viewed but not changed ...

Page 98: ...gement Interface is the open standard for machine health and control including remote control The form allows you to monitor server physical health characteristics such as temperature voltage fans power supplies and more To view IPMI Sensors perform the following procedure 1 From the Consoles List form select an IPMI console to view 2 From the Console Detail form click on the Sensor button The sys...

Page 99: ...uthorized access When you select Logs from the menu panel the primary form shown below will prompt you for a range of dates from which to retrieve your logs Table 3 6 Log Types Log Type Definition Access Log Logs that provide logging information i e who accessed the console when and for how long etc about a particular console Events Log Logs that provide information about notifications and alarms ...

Page 100: ...the menu The system brings up the main Console Logs form Table 3 7 Log Selection Form Element Definition Console Device Drop down list to select a console or device that will be the basis of the log s to be retrieved Date From Drop down list to select the starting date of the log s to be viewed Date To Drop down list to select the end date of the log s to be viewed Retrieve Button to download the ...

Page 101: ...dates from which to base your logs by selecting from the Date from and Date to drop down lists The system brings up the Logs Detail form Access Logs The Access Logs default log browser provide all access information e g who accessed the console access date action taken etc about your target console The name of the console port device to which the logs apply to is shown below the tab titles Figure ...

Page 102: ...f time on your target console Figure 3 19 Event Logs Form Table 3 8 Access Logs Form Element Definition Date Date in which the event occurred Time Time of the event User User who connected to the console Action What the user did in response to the alarm Status Status of the console Enable Disable Connection Type of connection e g SSH Web IP address used ...

Page 103: ...target console Figure 3 20 Data Buffer Log Form Note You can also access the Data Buffer log from the Alarms form Table 3 9 Event Logs Form Element Definition Date Date of the event Time Time of the event Ticket Ticket number associated with the event Pattern Trigger Expression Action Action taken to resolve event ...

Page 104: ...l functions Figure 3 21 shows an example of a user PM device detail form Figure 3 21 PM Device Viewer Detail Form Table 3 10 IPDU Viewer Details Form Element Definition Details Opening tab that is the default when you edit a power management device Groups Tab that opens the PM device groups access form for viewing IPDUs Info Tab that opens a display of data read back from the PM device after you c...

Page 105: ... pull down list allowing you to select either ssh ssh_telnet or telnet Status A pull down list allowing you to select either On Demand to enable the PM or Disabled Connected to The name of the controlling device KVM net OnSite ACS or TS to which the PM device is connected Port This is either port 1 or an incremented number for each cascaded device on a KVM net or OnSite or the serial port number o...

Page 106: ...tus forms click on the Get Information button at the bottom of any of the Editing IPDUs Device forms Note None of these parameters can be changed and saved by a regular user but outlet status can be changed between on off or toggle or between locked and unlocked This is done from the PM Device Outlet Control Form Buzzer If selected sounds a buzzer if the alarm threshold is exceeded Syslog If selec...

Page 107: ... you can power on power off toggle lock or unlock After you check the appropriate box es click on the Execute Operations button User s Profile The User s Profile forms allow you to view your profile or contact information and modify a limited number of fields The system allows you to view only your own profile ...

Page 108: ...igned to the current user and the consoles accessed by the user through group association Devices Tab displays the selected devices assigned to the current user and the devices accessed by the user through group association Groups Tab to display the User s Profile Group form which shows all groups to which the current user belongs Security Tab to display the security rule or rules assigned to the ...

Page 109: ... box is selected the admin user can edit the script file var apm bin apm_unlock_admin sh from the Linux shell through the Serial Console Interface Local Password Check box to indicate that local authentication applies to the user If this box is checked the Set Password button becomes active Set Password Button that launches a password setup dialog box Full Name User s full name Email User s email ...

Page 110: ...lick on the dialog box s internal Set Password button Viewing the User s Profile Consoles Form The User s Profile Consoles form displays the Consoles to which you have access Click on the Consoles tab The system displays the User s Profile Consoles form Status Indicates whether the user s access is enabled or disabled GUI Theme A pull down field that lets the user select a choice of colors for the...

Page 111: ...ion Consoles Tab or button to select the current form Select consoles for user access List box from which to select a possible list of user consoles assignable to the current user Add Button to add a selected user console left list box to the Selected consoles list box Delete Button to delete a selected user console right list box and return it to the Select console for user access list box Select...

Page 112: ...s Form Field Definition Devices Tab or button to select the current form Select devices for user access List box from which to select a possible list of user devices assignable to the current user Add Button to add a selected user device left list box to the Selected devices list box Delete Button to delete a selected user device right list box and return it to the Select device for user access li...

Page 113: ...Tab or button to select the current form Select groups for the user List box from which to select a possible list of user groups assignable to the current user Add Button to add a selected user group left list box to the Selected groups list box Delete Button to delete a selected user group right list box and return it to the Select groups for the user list box Selected Groups The list box that sh...

Page 114: ...sers the Security Rule includes access to blades and switches To view the Security form From the menu select User s Profile Details form Security tab The system displays the User s Profile Security form Figure 3 27 User s Profile Security Form Table 3 15 User s Profile Security Form Element Definition Security Tab or button to select the current form Select security rules List box from which to se...

Page 115: ...ule list box Selected security rules The list box that shows the Security Rule assigned to the current user Security rules via user groups The list box that shows the Security Rule assigned to a user group This can be the default USER group or any other defined user groups Table 3 15 User s Profile Security Form Element Definition ...

Page 116: ...User s Profile 84 APM Installation Configuration and User s Guide ...

Page 117: ...s Page 86 Configuration Process Flow Page 86 First Time Configuration Wizard Page 88 AlterPath Manager Web Interface Admin Mode Page 99 Devices Page 105 Alarm Trigger Page 156 Profiles Page 163 Consoles Page 166 Users Page 183 Groups Page 193 Firmware Page 197 Backing Up User Data Page 202 System Recovery Guidelines Page 203 Info Reporting Page 204 Blade Management Module Page 206 Security Rules P...

Page 118: ...revoked Unless a regular user has been configured to be an admin user as well through the User Detail form regular users can use the application only in Access mode Only an administrator or admin user can use the WMI in Admin Mode which allows them to assign admin roles to new users to add users consoles devices console servers alarms and other configuration procedures Note For information on how ...

Page 119: ...urity Rules Info Reporting Jobs Details Password Security Manual Consoles ACL Devices ACL Groups Security Details Users ACL Notify Groups Outlets Log Rotate Details Details Details Details Details List List Users ACL Notify Groups Proxies KVM Viewer Dial Up Log Rotate Console Group Device Group User Group Release notes Connect to serial console Perform First Time Configuration Was reboot successfu...

Page 120: ...nsoles you can define users and assign them to access the target consoles menu option Users and define the triggers that will create alarms and send email notifications menu option Alarm Trigger to users First Time Configuration Wizard Before you run First Time Configuration check to ensure that your system is set up properly If you are using a PC ensure that HyperTerminal is installed on your Win...

Page 121: ... session with the following settings 9600 BPS 8 data bits No parity 1 stop bit ANSI emulation 4 Power on the APM Boot information will scroll up on the screen for a short time until the system is ready for initial configuration input data 5 Press any key to run the First Time Configuration Wizard You will be asked to enter the following parameters Enter a password for root and re type the password...

Page 122: ...gram on page 28 Eth0 can be configured with 2 IP addresses as long as both addresses conform to the subnet and address range of the public LAN Enter the eth0 subnet mask address Select S tatic N one or K eep for the eth1 IP address Enter the eth1 IP address if you selected static Note When you are connecting to a private network see Figure 2 1 Private Network Diagram on page 27 Eth0 the primary Et...

Page 123: ...0 characters Enter the system s domain name max 60 chars Enter the primary nameserver s IP address Enter the secondary nameserver s IP address Enter the NTP server Enter the E mail SMTP server Enter an authentication method local RADIUS TACACS LDAP Kerberos NIS Active Directory Note After you select an authentication service type you will be prompted with questions that are specific to that type o...

Page 124: ...setethernet sethosts setnames setnetwork setntp setserial setsmtp date When you are finished updating any of the configurations that use the preceding commands enter the command saveconf More detailed information on the preceding commands is available under Set Commands on page 264 T To Reset Configuration to Factory Settings If you wish you can reset the configuration to its factory default setti...

Page 125: ...Before the Welcome heading appears the system will prompt you for the following Caution Be sure you answer n to the following questions APM_gregg login root Password WARNING changing system files directly is dangerous and may adversely affect your system s functionality Proceed with caution and only if you know what you are doing root APM_gregg root defconf WARNING this will erase all of your curr...

Page 126: ...u are booting your APM you need to answer some basic configuration questions Once this is done the other APM configuration parameters can be set through its Web Management Interface WMI Press any key to continue You must now set a password for root the system administrative account WARNING this is a very powerful account and as such it s advisable that its password is chosen with care and kept wit...

Page 127: ...8 Libya 55 SystemV 5 Asia 22 GB 39 MET 56 Turkey 6 Atlantic 23 GB Eire 40 MST 57 UCT 7 Australia 24 GMT 41 MST7MDT 58 US 8 Brazil 25 GMT 0 42 Mexico 59 UTC 9 CET 26 GMT 0 43 Mideast 60 Universal 10 CST6CDT 27 GMT0 44 NZ 61 W SU 11 Canada 28 Greenwich 45 NZ CHAT 62 WET 12 Chile 29 HST 46 Navajo 63 Zulu 13 Cuba 30 Hongkong 47 PRC 64 iso3166 tab 14 EET 31 Iceland 48 PST8PDT 65 posix 15 EST 32 Indian ...

Page 128: ...at 15 23 Thu Aug 18 15 23 00 PDT 2005 Enable Ethernet Bonding Y es or N o N n Ethernet eth0 IP address S tatic D HCP or N one S s Enter Ethernet eth0 IP address 192 168 48 162 Enter Ethernet eth0 Subnet Mask 255 255 252 0 Ethernet eth1 IP address S tatic or N one S s Enter Ethernet eth1 IP address 10 10 10 2 Enter Ethernet eth1 Subnet Mask 255 255 0 0 Configure Ethernet Subinterfaces Y es N o or L...

Page 129: ... Directory To use Active Directory as your authentication method select active_directory See To Configure Active Directory on page 292 Limitation of TACACS Plus in ACS Console Access Beware that access to an ACS console through the AlterPath Manager is currently not possible if the ACS serial port is configured to use TACACS Plus authentication Hostname Configuration Must Follow RFC Standard When ...

Page 130: ...to begin web configuration T To Begin Web Configuration 1 Type the URL in the one of the following formats in your web browser non encrypted http nnn nnn nnn nnn encrypted https nnn nnn nnn nnn Where nnn nnn nnn nnn is the IP address of either the first or second Ethernet interface that you defined during the First Time Configuration 2 When the Login screen appears enter admin as the username and ...

Page 131: ...ompleted the First Time Configuration procedure you may login to the AlterPath Manager web interface and use the system in Admin Mode The Admin menu panel contains the following selections Figure 4 2 Admin Menu Bar Selections Configuring the AlterPath Manager requires using the menu in a certain order To facilitate the configuration process the menu choices are discussed in the following order Dev...

Page 132: ...the password field 3 Press Enter Figure 4 3 Logging in as Admin 4 Select the Login button Upon successful login the Users List form appears Note When the AlterPath Manager launches your application screens for the first time the process tends to be slow The system needs to build all the web pages in the AlterPath Manager Once the screens are stored retrieving them should be fast Note The rest of t...

Page 133: ...Basic Functional Fields of a Typical Form The first form to appear when you select an option from the menu panel is called the primary form The Users List form for example is the primary form of the menu option Users user management Logout tab Admin tab Access tab Online help link About system info link User name primary IP address Bar for search and View and data Main menu defaults to Users on Ad...

Page 134: ...ion 4 Modify this line to reference the new location of the online help file Sorting Filtering and Saving a List Form An underscored column heading on any of the list forms indicates that the list may be sorted based on that column heading For example you can sort the previously shown User List form by Username Department Location or Status by clicking on the heading Where there are several unders...

Page 135: ...by selecting the Filter by pull down is automatically saved To search for a particular console use the Search for field Using the Form Input Fields When typing in data into any of the input fields note the following conventions In the web form as it appears on the screen all required fields are shown in red With some exceptions fields cannot contain special or reserved characters If you enter an i...

Page 136: ...ssages To verify an error message you can view the form or screen in question by clicking on the error message This feature allows you to verify or check the error message against the form Figure 4 6 Device Configuration Error Message Clicking the error message generates the form in error Figure 4 7 Form in Error ...

Page 137: ...ce Type form Device detail form Edit devices Device list form Edit link Device detail form Delete devices Device list form Delete button Upload device firmware bootcode or configuration Device list form Upload button Configure device health monitor Device detail form Health Monitor input field Configure Dial Up and enable PPP connection for out of band access to remote device ACS Dial Up form Run ...

Page 138: ...evice and console management forms together Also you may need to refer to the Firmware form for any information you might need pertaining to device firmware When new ACS or TS firmware is imported through the AlterPath Manager the new firmware is added to the database and is reflected in the Firmware List form and in the Firmware Boot dropdown list in the lower left region of the ACS or TS Device ...

Page 139: ...elete devices Figure 4 8 Devices List Form Table 4 2 Device List Form Element Definition checkbox adjacent to each device name Checkbox to select the device to add or upload firmware refer to the buttons below the form to enable these commands Device Device name Click on the device name to connect to the console server or device Click on the column title Device to change the sort order Type The ty...

Page 140: ...nd configuration OnSite Configuration only Firmware The firmware version for this device Log Device log buffer Click on Log to view the logs for this device Status Status of the device Enabled Disabled or OnDemand OnDemand means that the device is enabled only upon user connection Filter By A drop down box that lets you select a filter element from a list of one or more After you select the filter...

Page 141: ...or Device forms associated with the Blade Module see Blade Management Module on page 206 Note IPMI Activation IPMI is a paid for option for AlterPath Manager users The feature is hidden from users who do not need it To activate IPMI Copy the IPMI license file that you purchased from Cyclades into the following directory on your APM var apm licenses data Add Button used to add new devices Delete Bu...

Page 142: ...form click on Add located at the bottom of the form The system displays the Select Device Type form Figure 4 9 Select Device Type Form 3 From the Select Device Type form select from the type of device TS ACS KVM net OnSite or IPMI you wish to add and then click on the Submit button The system displays the Device Detail form based on the selected device type The example below shows the Devices Deta...

Page 143: ...Element Definition Details Currently selected tab User ACL Tab to assign or re assign users or user groups to a device Notify Tab to assign users to be notified about events Groups Tab to assign or re assign user to a user group Proxies Tab to assign a web proxy type to access the web interface of the current device KVM Viewer Tab to set up timeouts and hot keys for KVM viewer KVM net and OnSite o...

Page 144: ...uperuser of the device Note If you plan to upload firmware to a KVM net with a current firmware version of 2 0 0 or earlier you must the Admin Name field to root for the upload to work Admin Password Button to invoke a dialog box used to define the Admin s password This password is used to access the console server port but NOT to change the password You must enter the SAME password registered in ...

Page 145: ...me Base Port TCP port number allocated in the first serial port of the console server Status Dropdown list box to select Enable connection between the AlterPath Manager and the device console is ALWAYS established Disable no connection is established and all child consoles follow this configuration OnDemand connection is established only upon user s request Health Monitor The frequency in which th...

Page 146: ...d You select the firmware to upload and then when you upload the configuration for the device you can select the checkbox to upload the firmware as well Available on KVM net KVM net Plus ACS and TS Note If you upload the firmware to a KVM net currently running FW version 2 0 0 or earlier you must configure the Admin Name for the device as root Back Button to return to the previous page Reset Butto...

Page 147: ...you can configure for a device Table 4 4 Types of Web Proxy Proxy Type Function Reverse Proxy Reverse proxy allows any web server to be viewed through the proxy agent The web server appears to the user as a subdirectory of the proxy server s document tree Advantages Target server does not need to have a routable IP address not accessible outside the AlterPath Manager user workstation and network d...

Page 148: ...pplications Consequently the AlterPath Manager web interface cannot support the following connections Serial console connection to the ACS TS Remote access to the IBM Blade devices Use the KVM viewer to access KVM net console T To Configure the Web Proxy To create or configure a proxy for a device follow the steps below 1 Open the Device List form 2 If the device is new click on the Add button If ...

Page 149: ...t your PC s default gateway and the device s default gateway to the IP addresses of the AlterPath Manager if your PC and the device are in different networks 5 Click on Save to complete the procedure T To Verify your Proxy Setting 1 To verify your configuration return to the Devices List form 2 Place the mouse pointer over a device for which you configured a proxy setting A small box with the choi...

Page 150: ...Dial Back Note Modems are supported on the APM E2000 only The Dial Up form allows you to configure the current device for dial up connection to the network The same form is also used to configure the device for dial back Currently the Dial Back feature only applies to ACS devices When an ACS unit is configured for dial back the AlterPath Manager E2000 can dial out to the remote ACS unit and authen...

Page 151: ...ack to work you must configure it from the web interface and the CLI T To Configure Dial Up Dial Back Note Modems are currently supported on the APM E2000 only To configure Dial Up or Dial Back follow the steps below 1 Go to Devices Dial Up The system displays the Device Dial Up form Figure 4 12 Device Dial Up Form ...

Page 152: ... Modem Mode is enabled either as Primary or Network Backup then this field is required for PPP connection Enter the complete PPP phone number to establish PPP connection to a device or console via web interface CLI or SSH Dialback Mode Select whether to enable or disable dialback mode ACS only PPP Device IP If this is blank the device IP is used for PPP modem connection PPP Local IP If this field ...

Page 153: ...m the Dial Up form provide the following parameter values PPP User The user that you have configured in the APM as the admin user for the ACS PPP Password PPP Auth Method Select PAP or CHAP Note If the PPP User is not configured in the APM then the main user is used for dial out and dial back From the ACS 1 Using a serial console or a telnet or ssh connection create a new user and password for the...

Page 154: ...ou must also configure the following From the AlterPath Manager 1 Using the serial console interface edit the file var apm apm properties 2 Add the AlterPath Manager dial back number in the following parameter dial apm_phone_number phone number One Time Password Configuration Note Modems are currently supported on the APM E2000 only One Time Password is configured on the Dial Up form when you are ...

Page 155: ...sword to turn red indicating the requirement to fill in these fields Note If you check the Automatic PPP IP check box the PPP Device IP and PPP Local IP fields will not need to be filled in as these parameters will automatically be detected The APM does this by reading a list of PPP device IPs and PPP local IPs in its database It will then search starting from 10 0 0 1 until it finds 2 free IP add...

Page 156: ...ld OTP Passphrase button Auto Refresh check box and Random Passphrase check box 6 You can either enter a new OTP user in the OTP User field or leave it as skey the default user name 7 You will either need to fill in the OTP Passphrase field or check the Random Passphrase check box 8 Enable Auto Refresh This will refresh the OTP sequence by resetting the sequence number to 499 automatically when yo...

Page 157: ...l console ports 1 Go to Consoles Console List 2 From the Console List form select the Add button 3 From the Add Console form select KVM Table 4 6 Features Unique to the KVM net Device Configuration Element Definition KVM Viewer Tab to display the configuration form for the KVM Viewer The resulting form is used to configure the Idle Timeout and the various escape sequences for operating the KVM Vie...

Page 158: ...tions the same way as you would group users and consoles See also KVM net Device Configuration on page 149 this chapter OnSite Device Detail Form The example that follows shows the device detail form that is used to configure the OnSite Figure 4 15 Device Detail Form for the AlterPath OnSite Be sure to select the model you select matches the model number of your OnSite OnSite model numbers and the...

Page 159: ...k Device Name and choose your OnSite device See the Consoles section of this chapter for more details IPMI Device Detail Form Note IPMI Activation IPMI is a paid for option for AlterPath Manager users The feature is hidden from users who do not need it To activate IPMI Copy the IPMI license file that you purchased from Cyclades into the following directory on your APM var apm licenses data APM_B_I...

Page 160: ...PMI Device Detail form From the Console Detail form T To Use the IPMI Device Detail Form to Add a Console 1 Open the IPMI Device Detail form Devices Device List Device Detail 2 From the IPMI Device Detail form click on the Save Create Console button The system launches the Console Wizard Table 4 8 Devices Details Form IPMI Element Definition Authentication Information Dropdown box to select the au...

Page 161: ...ogs from the BMC 1 From the IPMI Device Detail form click on the Display Sensors Logs button The system displays a form containing two tabs Sensors tabbed form default displays the current values of all sensors This form refreshes every 15 seconds Logs tabbed form displays all logs read from the BMC You may clear the log database by clicking on the Clear button but be careful because this command ...

Page 162: ...evice logs out When disconnected no data buffer or alarm is available IP Mode When to use this mode int_dhcp internal Select this mode if you are using the AlterPath Manager as your DHCP server You decide on what IP address you wish to use and then save the configuration in the Device Definition form ext_dhcp external Select this mode if you already have a DHCP server in your LAN that you wish to ...

Page 163: ...pload button While automatic uploading saves you from having to open the Device List form and clicking the Upload button be aware that configuring in automatic mode can lead to slow system response due to excessive uploading Modem Dialing Capability for Remote Access to Devices The AlterPath Manager E2000 has modem dialing capability to enable complete out of band access to remote console server d...

Page 164: ...ice change during an upload will prevent your upload from being saved Configuring the Modem Dialing Capability To configure the modem dialing capability follow the steps below 1 From the Dial Up form Devices Add Dial Up form select the Modem Mode Table 4 9 PPP Connection Modes Connection Mode Definition Disabled This is the default mode Primary Network Select this to establish a PPP connection whe...

Page 165: ...ng modems from the modem pool Viewing the latest status of each modem Table 4 10 Modem Mode Choices Option Use this option if you want to use PPP Primary Network As the primary mode of connection Network Backup Only when the network fails Disable Default value If you select this then you don t need to do this procedure Table 4 11 PPP Settings PPP Setting Definition PPP Device IP Optional IP addres...

Page 166: ...you must complete an Alarm Trigger Detail form See Alarm Trigger on page 156 of this chapter Console Wizard The Save Create Consoles button is used to run the Console Wizard which allows you to configure those consoles connected to a device by following the wizard s prompts options and default values The wizard automatically configures the console s and applies them to the device If you use the wi...

Page 167: ...you have before proceeding with the wizard Defaults Sets the profile connection protocol and authentication type Access Select the users who can access the consoles Notify Selects the users to who will be notified in the case of an event Groups Select the groups to which the console s belong Console Selection Lists all consoles that have not been configured for this console server Select the conso...

Page 168: ...a new device you selected Add the system displays a pull down box that lets you select device types Select the type of device that you want b Click the Select button The system displays the Device Details form Figure 4 16 Device Details Form 2 From the Device Details form complete the following required fields for using the Console Wizard Device Name Console Creation Finish This page is shown if y...

Page 169: ...g message to notify you of any data to be overwritten and the choices you have before going ahead with the wizard Figure 4 17 Console Wizard Warning Message Note Use the Back Next and Cancel buttons to navigate through the forms Pressing the Next button saves your current form settings 4 Select the Next button The system brings up the Defaults form which allows you to set the default profile conne...

Page 170: ...r s Guide Figure 4 18 Console Wizard Defaults Form 5 Complete the above fields and then select the Next button when done The system brings up the User Access form Figure 4 19 Console Wizard Access Form USER is the default list which contains all users ...

Page 171: ...then click on the Notify tab to proceed to the User Notification form From the User Notification form select the user s you wish to be notified and then select the Groups tab to display the Groups form Figure 4 20 Console Wizard Notification Form 7 Click the Groups tab and complete the Console Wizard Groups form as necessary 8 Select the Next button to display the Unconfigured Consoles form ...

Page 172: ...on and User s Guide Figure 4 21 Unconfigured Consoles List 9 Select the unconfigured console s that you wish to configure and then select the Next button to display the Edit Console Settings form Figure 4 22 Edit Console Settings Form Page 1 ...

Page 173: ...refix button The system applies the new prefix to all console names 10 From the resulting form modify any settings as needed and then click on the Page 2 2 tab to continue the same form Figure 4 23 Edit Console Settings Form Page 2 11 From the resulting form modify any settings as needed and then click on the IPDU Outlets button if necessary 12 Proceed to the Confirm Console Edits form ...

Page 174: ...current configuration of a Cyclades AlterPath TS ACS or KVM net and through the use of a wizard autopopulate the console parameters based on the existing device configuration settings Warning Consoles with the same names will cause the wizard to fail Since the ACS was designed to accept multiple ports with the same name in the event that the wizard fails due to ports sharing the same name you have...

Page 175: ...lete the input fields with particular attention to the following Device Name Type and Model must match Enter the Admin Name and Admin Password from the configured device IP Address and Netmask from the configured device Select Static from the IP Mode pull down box Place a check mark in the Auto Upload box If you are using internal DHCP mode select IP Mode as int_dhcp and include the ACS TS KVM net...

Page 176: ...he following Manually enable some console ports by directly logging on to the ACS you are configuring in order to allow the auto discover feature to discover those console ports Or Select the Save Create Consoles button on the APM device configuration wizard 6 Select the Next button The following adding console wizard form appears with the Access tab opened Figure 4 25 Adding Console Wizard 7 Sele...

Page 177: ...over allows you to launch Auto Discover sessions on multiple devices with the mouse and keyboard actions normally used to perform this task on just one device To Start a Multiple Auto Discover Session 1 Go to the Device List form 2 Click on the check box to the left of any device in the list on which you wish to launch an Auto Discover session 3 Click on the Auto Discover button shown in Figure 4 ...

Page 178: ...er on just one device T To Connect to a Device To connect to a device follow the steps below 1 From the Device List form click on the device name to which you wish to connect A series of buttons will appear below the device name 2 Select the CLI button Figure 4 27 Selecting the CLI Option for a Device In the following example the selected device is a KVM net switch and the configured connection ty...

Page 179: ...a Device To delete or disconnect a device from the AlterPath Manager follow the steps below 1 From the Devices List form select any device you wish to delete by clicking on the checkbox adjacent to the Device name 2 Select the Delete button T To Delete a Device from a Group To delete a device from one or more groups follow the steps below 1 From the menu panel select Devices The system displays th...

Page 180: ...ce Group You cannot delete a device group using the Device Group form To delete a device group select Groups from the menu and refer to Groups on page 193 in this chapter T To Upload Firmware to a Console Device Using the Device Detail form you can configure the AlterPath Manager to upload firmware from its firmware repository to any ACS or TS device 1 From the Device Detail form Devices Device Li...

Page 181: ...e option appears even if the AlterPath Manager firmware repository is empty If you click on it you must wait for a while before a message appears to let you know that the firmware repository is empty KVM net Device Configuration When connected to a KVM net switch the Devices option also allows you to use the following KVM net forms Table 4 14 Forms Used to Configure KVM net Form Use this form to D...

Page 182: ...ge any of these values Idle Timeout refers to the time in minutes it takes the system to timeout or drop the connection after it remains idle To configure the aforementioned settings for the KVM viewer follow the steps below 1 From the menu select Devices The system displays the Device List form 2 From the Device List form select the Edit column of the KVM device you wish to configure The system d...

Page 183: ...onfiguration and Administration 151 Figure 4 30 KVM Device Details Form 3 From the Device Detail form click on the KVM Viewer tab The system displays the KVM Device Viewer form Figure 4 31 KVM Device Viewer Form ...

Page 184: ...a system command when using the KVM viewer or OSD The primary escape sequence or key is combined with the various escape sequences that follow Default value K Escape Sequences Quit Closes the session to a port and takes you back to the KVM net Main Menu Power Management Initiates a power control session Mouse Keyboard Sync Resets the keyboard and mouse synchronization if either one becomes unavail...

Page 185: ...s the Device List form 2 From the Device List form select the Edit column of the KVM device you wish to configure The system displays the Device Detail form 3 From the Device Detail form click on the Save List Cascade button Port Info Displays any information about the current port Back Button to return to the previous form Reset Button to reset the input fields of the current form Save Button to ...

Page 186: ...cade List Form For a definition of the column fields refer to the Field Definition table of the Cascade Detail form next step 4 To configure a new device for cascading click the Add button Or to edit an existing cascaded device click on the edit link that corresponds to that device The system displays the Device Cascade Detail form ...

Page 187: ...KVM switch Parent Name The name of the primary KVM switch to which you are connecting the secondary device or KVM switch Number of Ports Number of ports contained in the device to be cascaded Port Connected to User 2 The secondary KVM port to be connected to the User 2 port of the primary KVM net Port Connected to User 1 The secondary KVM port to be connected to the User 1 port of the primary KVM ...

Page 188: ...with the Health Monitor feature of the AlterPath Manager which includes the monitoring of any modems configured You can modify these alarm triggers but you cannot delete them For health monitoring triggers to work you must enable alarm triggers using the Alarm Trigger details form Table 4 16 Pre existing Alarm Trigger Entries Alarm Trigger Default Expression Health Monitor HeaLth_MoNiToR Health Mo...

Page 189: ... menu select Alarm Trigger Table 4 17 Forms Used to Configure Alarms Form Function Form s Used Add a new trigger string Alarm Trigger list form Add button Alarm Trigger detail form Edit an alarm trigger Alarm Trigger list form Alarm Trigger name Alarm Trigger detail form Delete an alarm trigger Alarm Trigger list form Delete button Create an alarm for the trigger string and prioritize the alarm Al...

Page 190: ... form section To view or edit the configuration of an alarm trigger click on the alarm trigger name T To Create an Alarm Trigger Use the Alarm Trigger Detail form to define triggers to generate user notifications and alarms To create an alarm trigger follows the steps below 1 From the menu select Alarm Trigger The system displays the Alarm Trigger List form 2 From the Alarm Trigger List form click...

Page 191: ...er Detail form for that trigger Trigger Expression String used to generate a trigger Notify Yes or No Indicates if system needs to notify i e send an email to the user Create Alarm Yes or No Indicates if system needs to send an alarm to the user Priority Indicates the priority or severity level of the alarm Status Enable or disable a trigger Back Button to return to the previous page or form Save ...

Page 192: ...arm trigger s As discussed in the Device Management section this feature is designed to monitor devices on a periodic basis as well as to create log files and to send an alarm notification to specified users Users must have a valid email address as configured in the User Detail form Users User List User Detail to receive alarm notifications Configuration Requirement Device Detail Form For Health M...

Page 193: ...g the Logical AND in the Alarm Trigger Expression To create a logical AND in the alarm trigger expression use the period and asterisk Table 4 19 Health Monitor Frequency Selections Selection Definition Never System will never run Health Monitoring for this device default Daily System will run Health Monitoring at 2 am everyday Weekly System will run Health Monitoring at 3 am every Saturday Monthly...

Page 194: ... go to the Alarm Trigger Details form Alarm Trigger List Health Monitor Figure 4 37 Health Monitoring Alarm Trigger Detail Form 2 From the Alarm Trigger Definition form complete the fields as follows Table 4 20 Alarm Trigger Setup Fields Element Definition Alarm Trigger Name Provide a name to be associated with this particular alarm trigger Trigger Expression Type in HeaLth_MoNiToR NOTE To effecti...

Page 195: ... to be restricted further to HeaLth_MoNiToR NOK in order for users to get messages that only relate to failure and not be bombarded by a large amount of unnecessary messages User Notification For Health Monitor notification to work properly you must add users to the Notify Users list associated with the device Profiles The Profiles option allows you to configure the port profile for a target conso...

Page 196: ...to use a different profile at a later time The Profiles List form is shown below Figure 4 38 Profiles List Form T To Add a New Profile To add a new profile perform the following steps 1 From the Profile List form select the Add button The Profile Detail form appears Table 4 21 Summary of Profiles Forms Action Form s Used Add a new profile Profile list form Add button Profile detail form Edit a pro...

Page 197: ... console supported Description Brief description of the profile Status Port status Enable or Disable Port Speed Serial port baud rate Port Data Size Number of data bits 7 or 8 Port Stop Bits Number of stop bits 1 or 2 Port Parity None even or odd Port Flow Flow control none hardware or software DCD Sensitive How the console server responds to changes to DCD signal Port Break Sequence As indicated ...

Page 198: ...For console forms associated with the Blade Module see Blade Management Module on page 206 of this chapter The Consoles option allows you to perform the following console management procedures Back Save Reset Buttons for the indicated actions Table 4 23 Summary of Console Forms Action Form s Used Add a new console to connect to the AlterPath Manager and for user access Consoles List Add button Sel...

Page 199: ...this chapter Select or change the authentication method for console access Console Detail form Authentication drop down list NOTE The AlterPath Manager authenticates users from the console or terminal server Assign the current console to any number of users Console Detail form Access tab Console Access form Select the users to be notified of any alarms from the current console Console Detail form ...

Page 200: ...o have access to the ACS via the APM Configure ACS consoles for remote local or local remote access local radius radius local local TacacsPlus TacacsPlus local are the options available in this case This allows firmware upgrades and configuration upgrades It also allows console access by root and other users with access 2 If you want to configure remote only authentication or remote down local aut...

Page 201: ...you can view for each page By default the number of consoles or lines per page is set to 512 If you want to change this setting go to To Change the Number of Consoles per Page on page 275 T To Add a Serial Console This procedure uses the serial console as an example of adding a new console While there are variations to the Console Detail form based on the console type to be configured there is a s...

Page 202: ...r s Guide The system displays the Creating New Console form Figure 4 41 Creating New Console Form 3 From the Creating New Console form select the type of console you wish to add The system displays the Console Detail form Figure 4 42 Console Detail Form ...

Page 203: ...rent console to one or more console groups Outlets Tab to display the form used to assign outlets if an IPDU is assigned and connected to the console Log Rotate Tab to display the Log Rotation form used to set log rotation by configurable size or by selected time interval available for ACS and TS devices and consoles as well as KVM devices Console Name Name of the console Device Name Drop down lis...

Page 204: ...list Method used to establish a console connection ssh telnet or raw data Status Drop down list Enable Disable OnDemand Authentication Drop down list to select the type of authentication for the AlterPath Manager to access the console port NNM Selection Name Network Node Management name to be used if you are configuring this port to be monitored by an HP OpenView server Remote Data Buffer 0 to dis...

Page 205: ...VM net version 2 0 0 or greater and the KVM net Plus Table 4 25 KVM net and KVM net Plus Console RDP Connection Fields Field Meaning Port Drop down field for selecting the physical KVM port number of the console This field also has an RDP Only selection that allows you to configure an RDP port without associating it with a physical KVM port RDP IP Address The field for entering the IP address of t...

Page 206: ...r connected to KVM port 2 When an attempt to connect to the port KVM port 2 in this case is made the console viewer will attempt to launch the RDP viewer first by default If the RDP connection is already in use or cannot be made a regular KVM connection will be attempted on KVM port 2 RDP Server Port This field contains the RDP viewer port number associated with this console The default of 3389 ca...

Page 207: ...et Plus Console Port You can also configure a port as RDP Only This allows the KVM net Plus to connect exclusively to an RDP server over the Ethernet in band For this type of configuration a physical KVM port connection is not necessary Figure 4 44 illustrates enabling an RDP Only connection ...

Page 208: ...pull down field Caution Be sure to turn off your web browser s popup blocker before attempting to make an RDP connection An RDP connection will fail if you have your browser s popup blocker turned on T To Select Users to Access the Console Use the Console Users form to assign and authorize one or more users to access the current console 1 From the Console Detail form Consoles Console List Console ...

Page 209: ...ansfers the selected user to the Selected Users view panel on the right 4 To select another user repeat steps 1 and 2 You can also use the Shift key to select multiple users 5 Click on Save to complete the procedure T To Select Users to be Notified Use the Console Notify form to assign one or more users to whom the system can send all notifications email or alarm pertaining to the current console ...

Page 210: ...anel on the right 4 To select another user repeat steps 1 and 2 You can also use the Shift key to select multiple users 5 Click on Save to complete the procedure T To Assign the Console to a Group You can assign the current console to one or more groups using the Console Groups form To use this form however a console group must already exist To create a new group you must select Groups from the ma...

Page 211: ...ted group to the Selected Groups view panel on the right 4 To select another group repeat steps 1 and 2 You can also use the Shift key to select multiple groups 5 Click on Save to complete the procedure T To Delete a Console from a Group To delete a Console from one or more groups follow the steps below 1 From the menu panel select Consoles The system displays the Console List form 2 Under the Con...

Page 212: ...n menu See Groups on page 193 in this chapter T To Connect to a Console To connect to a console using Secure Shell SSH follow the following step Note This does not apply to KVM consoles 1 From the Console List form select the console you wish to connect to by selecting the console name Configuring Outlets The Outlets tab allows you to associate the outlets on an IPDU to a console port On a KVM the...

Page 213: ...le name or device name and then click the EDIT option The system displays the Detail form 2 From the Detail form click the Log Rotate tab 3 Click on the Rotate Log NOW button T To Set Log Rotation in Auto Mode You can also set the log rotation to be automatically performed on a daily weekly or monthly basis To set the system to automatically initiate log rotation on a regular basis perform the fol...

Page 214: ...you purchased from Cyclades into the following directory on your APM var apm licenses data APM_B_IPMI enc Caution Licenses except for factory default licenses must be reinstalled after you recreate the system partition or after you run the installimg command If you want to preserve your licenses before you recreate a system partition or before you run installimg you can edit the file etc files lis...

Page 215: ...red in the AlterPath Manager database in order to access the application Table 4 26 Summary of User Forms Action Form s Used Add a new user User list Add button User detail Authorize the current user to access one or more consoles User detail Access tab User Access form View or edit user information User list username link User detail Set or change a user password User detail Set Password button D...

Page 216: ...tion must be entered in the AlterPath Manager database in order to have access to the application regardless of whether you are using any other authentication services or not RADIUS users for example must still be registered in the AlterPath Manager database through the User Detail form Below is the Users List form Figure 4 48 Users List Form For an explanation of field column refer to Table 4 27 ...

Page 217: ... Table 4 27 Users Detail Form Element Definition Details Tab to display the User Detail form currently displayed Consoles Tab to assign one or more consoles to the current user Devices Tab to assign one or more devices to the current user Groups Tab to assign or re assign the current user to one or more user groups Security Tab to assign one or more security rules to the current user Username As i...

Page 218: ... you activate the password for local authentication in the event that your authentication server fails Set Password Button to display the password dialog box for setting the user password Full Name The full name of the user Email As indicated This field is also used by the Alarm Trigger to notify the user of any event or issue relating to consoles and other system areas delegated to the user Depar...

Page 219: ...rs List form select the user to whom you wish to assign console access The system displays the User Detail form 3 From the User Detail form click on the Consoles tab The system displays the User Console form GUI Theme Drop down list to select GUI colors There is a choice of colors orange default blue gray and green The WMI takes on the color assigned to the user who is currently logged onto the AP...

Page 220: ... button The system transfers the selected group to the Selected Consoles view panel on the right 6 To select another console repeat steps 4 and 5 You can also use the Shift key to select multiple groups 7 Click on Save to complete the procedure T To Select Devices for a User The User Device form allows you to assign one or more consoles for the current user To assign devices to a user follow the s...

Page 221: ...defined groups The Device or DEVICE group is the default device group 5 Click on the Add button The system transfers the selected group to the Selected Devices view panel on the right 6 To select another device repeat steps 4 and 5 You can also use the Shift key to select multiple groups 7 Click on Save to complete the procedure T To Select User Groups for a User The User Group form allows you to ...

Page 222: ... form 3 From the User Detail form click on the Groups tab The system displays the User Groups form Figure 4 52 User Groups Form 4 From the resulting form select from the Select Groups for the User view panel the group you wish to assign to the user 5 Select the Add button The system transfers the selected group to the Selected Groups view panel on the right 6 To select another user group repeat st...

Page 223: ... To delete one or more users from the User List follow the steps below 1 From the User List form click the check box to the left of the username that you wish to delete 2 Click on the Delete button T To Delete a User from a Group 1 From the menu panel select Users The system displays the Users List form 2 From the Users List form click on the user name you wish to remove from a group The system di...

Page 224: ...en server based authentication is being used In this case if the authentication server is unavailable due to network problems then the system can use the local password It is therefore advisable that you set a local password for some users even when server based authentication is being used T To Configure the Local Password To set up local authentication for a user follow the following steps 1 Fro...

Page 225: ...e groups You can edit and delete only those groups that you have created While you can assign devices consoles and users to groups using their respective menu options Devices Consoles and Users it is only through the Groups menu option that you can create groups Figure 4 54 Groups List Form T To Create a Group To create a new group follows the steps below 1 From the menu select Groups The system d...

Page 226: ...orm Figure 4 55 Adding Group Form 3 From the resulting form select the group type you wish to create Device Console or User Based on your selection the system displays the Group Detail form The example below uses the Group General form for the Group Type User Figure 4 56 New User Group General Form ...

Page 227: ...list box the members you wish to add to the group 4 Click on the Save button T To Delete a Group Note You cannot delete the following system generated default groups Device Console and User To delete a group follow the steps below 1 From the menu select Groups The system displays the Groups List form 2 From the Groups List form click on the checkbox of the group that you wish to delete 3 Click on ...

Page 228: ...Groups 196 APM Installation Configuration and User s Guide Figure 4 57 New User Group Security Form ...

Page 229: ...des a management tool for you to Import firmware updates Keep track of firmware updates Document any comments regarding the particular firmware Access manuals and release notes Firmware Management consists of two forms Firmware List form Firmware Detail form Any firmware that you add to the Firmware List form is also reflected in the Firmware Boot pull down list that appears in the Device Detail f...

Page 230: ...SCP To add or import new firmware follow this procedure 1 From the web www cyclades com download the firmware to your computer 2 Using the Linux shell on the serial console interface use the SSH scp command to copy the firmware to AlterPath Manager Example scp v214 tgz root ip_address usr fw 3 Open the Firmware List form and click the Import button The system will add the new firmware to the Firmw...

Page 231: ... configuration you have the choice to select either firmware or configuration or both Note When uploading KVM net or KVM net Plus firmware you should check the Configuration checkbox as well as the Firmware bootcode checkbox even if the current configuration had previously been uploaded Otherwise you will get an indication in the device list that a configuration upload is required Caution When upl...

Page 232: ...Manuals and Release Notes Figure 4 59 Firmware Detail Form The table below defines all the fields in the Firmware Detail form Table 4 28 Firmware Detail Form Element Function Model Model number of the device s supported by the firmware FW Version Firmware version Release Date Release date of the firmware Boot Code Version Type of bootcode and version number HW Revision Hardware tied to the firmwar...

Page 233: ...e firmware installation or update T To Upgrade the AlterPath Manager Firmware You may upgrade the AlterPath Manager firmware by downloading the upgraded software from the web to the AlterPath Manager 1 From the Cyclades website www cyclades com download and copy the firmware to the AlterPath Manager via Secure Copy SCP The firmware is composed of two files AlterPath Manager_v140 tgz Manual Version...

Page 234: ... tgz reboot Backing Up User Data Using the serial console interface you can back up and restore the configuration and data files of the AlterPath Manager to a local or a remote destination This feature allows you to backup and restore either independently or altogether the following data types Table 4 29 APM Data Types Data Type Definition System Configuration Data related to the AlterPath Manager...

Page 235: ... will have the same configuration as the original unit To use the Backup and Restore commands in the serial console interface please refer to Chapter 5 Advanced Configuration System Recovery Guidelines In the event that the AlterPath Manager goes down the system will check the integrity of the file system during the restart If a problem is found then the system will attempt to repair any damage th...

Page 236: ... at the bottom of the screen The system displays the form that you were updating 2 Verify the information to determine if you still need to update the form If you need to update the form then proceed to re update the form and then click on the Save button Optimistic locking is a mechanism to lock objects in multi user systems to preserve integrity of changes so that one person s changes do not acc...

Page 237: ...t by Session Start click on the Session Start column heading Down arrow indicates that the list is in descending order up arrow in ascending order Session End Date and time when the session ended Action The user s action or the system action generated by the user To sort by Action click on the Action column heading Connect Type Connection type used by the session Source IP The source IP address us...

Page 238: ...for plug in feature that enables the AlterPath Manager to provide console management of chassis blades and switches Once configured the module allows authorized users to remotely manage the blades by providing access to the remote console and remote disk of a blade server All blades provide authorized users with Command Line Interface CLI KVM IP virtual media and power options Like most devices su...

Page 239: ... command etc init d tomcat restart Forms Used to Configure the Blade Module The Blade Module in Admin mode comprises the following forms Table 4 31 Summary of Blade Module Forms Menu Option Forms and their Functions Devices Devices List View list of chassis add edit or delete chassis view logs Device Details Edit chassis configuration details set or change admin password run blade wizard Groups Se...

Page 240: ...rrent blade Groups Select blade groups Alarm Triggers Alarm Trigger List View alarm trigger list add edit or delete an alarm trigger Alarm Detail View or configure a selected alarm trigger Users User List View list of users add edit or delete users Details View or configure a selected user Access Select blades and switches to which the current user can access Groups Select one or more groups to wh...

Page 241: ...User General Select group members for the current user group Security Select security rule to be applied to the current user Security Rule Security Rule List View list of security rules add edit or delete a security rule General Enable or disable the current security rule Source IP Define the source IP addresses allowed or not allowed VLAN Subnet Define the VLANs subnets allowed or not allowed Dat...

Page 242: ...h 4 to add edit chassis Delete a blade chassis Run the Blade Wizard to automatically create and configure the blades switches for the currently selected chassis View chassis access log T To Add or Edit the Chassis 1 From the menu select Devices The system displays the Devices List form 2 Perform one of the following steps a If you are adding a new chassis from the Devices List form select the Add ...

Page 243: ...Blade Management Module Configuration and Administration 211 Figure 4 62 Selecting Blade_Center from Devices List The system displays the Devices detail form Figure 4 63 Blade Device Details Form ...

Page 244: ...ed Disable no connection is established and all child consoles follow this configuration OnDemand connection is established only upon user s request Admin Name The admin username superuser of the device This is a required field Admin Password Button to invoke a dialog box used to define the Admin s password This password is used to access the IBM Blade Center port but NOT to change the password Yo...

Page 245: ...click on the Add button or the edit link Details Groups The system displays the Device Groups form IP Address The IP address of the device for IP mode int_dhcp or static Netmask As indicated in dotted notation Default Gateway As indicated in dotted notation DNS As indicated in dotted notation Connection Select telnet or ssh Back Button to return to the previous page Reset Button to reset the form ...

Page 246: ...figured for another group the Device group is the default group for all devices 3 Click on the Add button 4 Repeat steps 2 and 3 if you have another group to add Note To delete any entries from the Selected Groups box highlight the group you wish to delete and then click on the Delete button 5 Click on Save and proceed to the next tabbed form as necessary Proxies To create or configure a web proxy...

Page 247: ... configure a switch perform the steps below 1 From the menu go to Devices click on the Add button or the edit link Details Groups Switch 1 The system displays the Device Switch 1 form Figure 4 65 Blade Device Switch 1 Form 2 Complete the Switch 1 form as necessary Table 4 33 Blade Module Device Switch 1 Form Element Definition IP Address The IP address of the switch which uses the IP mode int_dhcp...

Page 248: ... connection is established and all child consoles follow this configuration IMPORTANT The system will not allow you to add and configure a switch console unless you set this field to Enable Netmask As indicated in dotted notation IP Mode Dropdown list box Select int_dhcp if the AlterPath Manager is the DHCP server for this device or static if using a static IP See Configuring Your DHCP Server on p...

Page 249: ...ard click on the Save Create Blades button in any of the Device forms The series of forms comprising the Blade Wizard in sequential order are as follows Save Button to save your configuration Save Create Blades Button to activate the Blade Wizard Table 4 34 Summary of Blade Wizard Forms Form Name Function Warning Warns the users that existing entries for chassis blades in the AlterPath Manager or ...

Page 250: ... select each blade switch to be configured from the list of unconfigured blades switches Edit Configuration Allows you to edit any of the configured blades switches This form provides advanced configuration options Confirmation Prompts you to review and confirm the configuration Completion Message to indicate successful completion Table 4 34 Summary of Blade Wizard Forms Form Name Function ...

Page 251: ...Blade Management Module Configuration and Administration 219 Figure 4 67 Blade Wizard Connection Method Form Figure 4 68 Blade Wizard User Access Notification Form ...

Page 252: ...Blade Management Module 220 APM Installation Configuration and User s Guide Figure 4 69 Blade Wizard Console Switch Selection Figure 4 70 Blade Wizard Edit Configuration Form Page 1 ...

Page 253: ...ration 221 Figure 4 71 Blade Wizard Edit Configuration Form Page 2 Figure 4 72 Blade Wizard Configuration Confirmation From the Confirmation form you can click the Page 2 2 tab if necessary Finally click on Finish to complete the configuration process ...

Page 254: ... and for each switch CLI and web connections All users access rights to blades and switches and the types of action they are allowed to do are defined in the Security Rules forms Table 4 35 Blade Module Summary of Console Forms Form Name Use this form to Consoles List View list of blades switches add edit or delete blades switches Details tabbed form View or edit blade configuration details e g co...

Page 255: ...ole management forms Details Access Notify and Groups Table 4 36 Blade or Switch Connection Types Connection Type Applies to Use this connection to Linux shell or CLI Blade servers and switches Launch a Linux shell or CLI session using either Telnet or SSH NOTE Power control is available through ec sequence KVM Blade servers only Launch the remote console applet session for KVM VM Blade servers on...

Page 256: ...ou have set the switch to Enable go to Chassis Switch in the Switch Device form otherwise you will receive an error message 4 Complete the rest of the tabbed forms as necessary T To Edit a Blade or Switch To edit a blade or switch 1 Select Consoles from the menu 2 From the Consoles List form select the blade or switch you wish to edit and then select the edit link 3 Complete the rest of the tabbed...

Page 257: ... users except Admin users This rule cannot be deleted Note To configure users and user groups go to Users Groups The Default Rule already allows users to log on You may change it to block connections by default and then allow the valid users If the chosen rule is Allow you must select at least one action from the Authorized Actions tab Security rule management is composed of the following forms Ta...

Page 258: ...ect to a KVM net Connect to the web management interface etc for this rule Table 4 38 Security Rule List Column Descriptions Column Name Definition Rule Name The name of the rule and if applicable the source IPs allowed for this rule Description A brief description of the rule and if applicable the interfaces and the date time allowed for this rule Status States if the rule is Enabled or Disabled ...

Page 259: ... Edit a Security Rule To add or edit a security rule perform the following steps 1 From the menu select Security Rule The system displays the Security Rule list form see previous page 2 Select the Add button to add or select an existing rule to edit The system displays the Security Rules General form ...

Page 260: ...equired a brief description of the rule its status Enabled or Disabled and the rule to be applied to the entire rule Allow or Deny 4 Click on the Save button T To Configure Conditions for Accepting Source Pages 1 Click on the Source IP tab to configure the conditions for accepting source pages for the current rule The system displays the Security Rule Source IP form ...

Page 261: ...llow or Deny that applies to the entire security rule The default permission is configured from the General tabbed form Add Source Conditions This section allows you to define the Source IP that will be used as the conditions for applying it to the rule IP The IP address to be added to the Added Source IP Conditions list box Netmask The netmask to be added to the Added Source IP Conditions list Ad...

Page 262: ...s End IP The ending IP address of a range of IP addresses Hostname Hostname of the workstation If the domainname is not entered then the domainname of the APM is used to filter the source Domain Domain name on which the workstation will connect from If the workstation belongs to subdomain and only domain filtering is entered all sub domains are allowed or denied access based on the rule permission...

Page 263: ...re attempting to sign on again to the APM Security Rules Network Intf The Network Intf Local Area Network Interfaces form allows you to define the interfaces to which a user is either allowed to connect or denied access This feature is designed for situations where multiple network or LAN segments are used or defined Figure 4 77 Security Rule Network Interface Form Table 4 40 Security Rules Networ...

Page 264: ... Select Net Intf Conditions List box that lists all LAN interfaces Select the LAN interface s that will be applied to the rule Add Button to select items from the Select Net Intf Conditions list box and add to the Selected LAN ITF Conditions list box Delete Button to remove any Selected Net Intf Conditions from the right list box Selected Net Intf Conditions List of selected Net Intf conditions th...

Page 265: ...le The default permission is configured from the General tabbed form Day Time Table The table represents the days of a week rows and the hours of a day columns Add Time Period Conditions Define below this title the time period conditions that applies to the default rule by clicking the appropriate boxes Sun Sat check boxes Select the day s to be applied to the default rule Start Time Specify a Sta...

Page 266: ...cted action s by selecting the Add button are listed in the right hand box Figure 4 79 Security Rule Authorized Actions Form End Time Specify an End Time to be applied to the selected day s as part of the time conditions Add Button to add the day and time settings to the Added Time Period Conditions box and apply them to the rule Delete Button to delete the day and time settings from the Added Tim...

Page 267: ...t is connected to a KVM net OnSite or ACS TS device managed by the APM Then you configure outlets on the PM and Table 4 42 Security Rule Actions Authorized Action Use this action to ConnectToDeviceCLI Allow user access to CLI configuration interface ConnectToDeviceGUI Allow user access to web configuration interface ConsoleGUI Allow web access to console ConsoleReadWrite Allow Read and Write acces...

Page 268: ...43 IPDU Device Details Element Definition Details Opening tab that is the default when you either create or edit a power management device Users Tab that opens the PM device user access form Groups Tab that opens the PM device groups access form IPDUs Info Tab that opens a display of data read back from the PM device after you click on the Get Information button This tab does not appear when you a...

Page 269: ...rrent capacity of the PM device Connection A pull down list allowing you to select either ssh ssh_telnet or telnet Status A pull down list allowing you to select either On Demand to enable the PM or Disabled Connected to The name of the controlling device KVM net OnSite ACS or TS to which the PM device is connected Port This is either port 1 or an incriminated number for each daisy chained device ...

Page 270: ...the PM is attached Buzzer If selected sounds a buzzer if the alarm threshold is exceeded Syslog If selected allows PM device alarm events to be logged Back Button that allows you to go back to the previous form without saving any configuration parameters Reset Button that allows you to revert back to the previously saved parameters Save Button that saves the current PM parameter settings Save Crea...

Page 271: ...del pull down list The model number must match the model of the PM connected to the managed AlterPath device 7 Select the connection type from the Connection pull down list The choices are ssh ssh_telnet and telnet 8 Be sure On Demand is selected in the Status pull down list unless you want this feature disabled 9 Be sure the Connected to pull down list shows the device associated with the PM you ...

Page 272: ...vice will also be uploaded This happens even if the parent device is specifically not checked in the upload menu Redundant Fault Tolerant Configuration Note This feature is not supported on the APM E2000 Heartbeat Redundancy Data Synchronization and Failover support provides the ability to back up and restore an APM 2500 or APM 5000 system with little or no downtime in the event of a failure of a ...

Page 273: ...ration 241 Physical Setup of Fault Tolerant APMs Figure 4 82 that follows shows a typical physical connection for a redundant APM configuration Figure 4 82 Connecting 2 APMs in a Redundant Configuration KVM ACS TS LAN Eth0 Eth0 Eth1 Eth1 CAT 5 crossover cable APM APM ...

Page 274: ...Figure 4 84 shows a detailed view of a filled in Heartbeat Configuration form for the primary APM in the configuration Figure 4 85 shows a detailed view of a filled in Heartbeat Configuration form for the redundant APM The two forms are filled out almost identically but observe the following fields in the two forms to see how they differ Configured State Node Name Current System Mated System IP Ad...

Page 275: ...Redundant Fault Tolerant Configuration Configuration and Administration 243 Figure 4 84 Detailed View APM Heartbeat Form for Primary Figure 4 85 Detailed View APM Heartbeat Form for Redundant ...

Page 276: ...m that takes over if the primary system fails or the heartbeat signal is interrupted Current system The current system is the primary system when you are configuring the primary system It is the redundant system when you are configuring the redundant system Mated system The mated system is the redundant system when you are configuring the primary system It is the primary system when you are config...

Page 277: ...st be enabled or you cannot edit any of the other fields under the System tab Ping Nodes List A list of IP addresses to ping in order to detect when primary APM has lost connectivity to the network Be sure to separate the IP addresses with commas and no spaces It is recommended that this field includes the default gateway IP address and the router IP address Node Name The aliases of the APMs you a...

Page 278: ...e field is for the current system and the other field is for the mated system The current system is the primary system when you are configuring the primary system and it is the redundant system when you are configuring the redundant system Note Compare these fields in Figure 4 84 and Figure 4 85 Table 4 45 Heartbeat Form Fields and Meanings Element Meaning and Configuration ...

Page 279: ...release refer to To Upgrade the APM Firmware on page 295 Table 4 46 Synchronization Form Fields and Meanings Element Meaning and Configuration Synchronization Speed The default is 700000 KB second This is the maximum speed allowed for this field Note The APM 2500 and the APM 5000 synchronize using network RAID and DRBD Distributed Replicated Block Device This enables replication of data from the p...

Page 280: ...he redundant APM s console run the restore command on the remote APM system and restore the database a Perform a restore conf example restore conf root 192 168 48 100 backup conf b Perform a restore log example restore log root 192 168 48 100 backup log Your primary APM and redundant APM now have matching firmware and databases 4 Physically configure two APMs with Eth0 ports on a common LAN The IP...

Page 281: ...List field with IP addresses to ping in order to detect when primary APM has lost connectivity to the network It is recommended that this field includes the default gateway IP address and the router IP address Be sure to separate the IP addresses with commas and no spaces 13 Enter an alias in the Node Name field for the primary APM in the column for the current system 14 Enter the IP address for t...

Page 282: ... This is an IP address for the APM web service It must be a static address and it must be the same IP address used when you configured the Service IP for the primary APM Step 11 27 Fill in the Ping Nodes List field with IP addresses to ping in order to detect when primary APM has lost connectivity to the network It is recommended that this field includes the default gateway IP address and the rout...

Page 283: ... not be activated until synchronization completes 37 Check the status of the synchronization by logging onto the console of either APM and entering the command etc init d drbd status A display similar to the following shows the synchronization progress root APM_SW root etc init d drbd status drbd driver loaded OK device status version 0 7 13 api 77 proto 74 SVN Revision 1942 build by root hp 2005 ...

Page 284: ...nning as individual APMs 4 After the APMs reboot upgrade the firmware on each APM See To Upgrade the APM Firmware on page 295 Caution You can mix APM hardware platforms but you must be sure the APM 5000 has APM 5000 firmware and the APM 2500 has APM 2500 firmware Both APMs must have firmware of the same build number and date 5 Reboot the primary APM and then reboot the secondary APM root APM_SW ro...

Page 285: ... then reboot the secondary APM This is necessary to activate the heartbeat configuration Caution Rebooting the primary and redundant APM will start up the synchronization The heartbeat redundancy data synchronization and failover support will not be activated until synchronization completes 9 Check the status of the synchronization by logging onto the console of either APM and entering the command...

Page 286: ...Redundant Fault Tolerant Configuration 254 APM Installation Configuration and User s Guide ...

Page 287: ...s Working from a CLI Page 256 CLI Commands Page 258 Copying and Pasting Text within the Console Applet Window Page 259 Connecting Directly to Ports Page 259 Sample Command Line Interface Page 261 Console Session Hot Keys Page 263 Set Commands Page 264 Re defining the Interrupt Key Page 274 To Change the Number of Consoles per Page Page 275 To Change the ACS TS Admin Name Page 277 Ethernet Bonding ...

Page 288: ... This interface can also be accessed through an ssh connection to the APM s IP address There is also a CLI shell that provides access to ACS TS type consoles T To Log Into the Serial Console Port 1 Connect a terminal or a computer with a terminal emulator to the APM s serial console port using a null modem cable 2 Power on the APM and start the terminal or terminal emulator Configuring Dial Out an...

Page 289: ... following shell commands ssh l username IP_address_of_APM password Note The l in ssh 1 is the alphabetical character l as in lemon If you are an admin user the system will display a menu You can either run the CLI shell from the menu or you can go directly to a Linux system prompt If you log in to the CLI as root you will only have access to the Linux system prompt but you will have all the norma...

Page 290: ...it Option Table 5 1 CLI Specific Commands Command Use this command to man list List the available commands man command name Get a definition of and syntax help for a command consolelist List all consoles allocated to you as defined in the access control list This command also lists the devices in your ACL console console name or console device name Connect to the specified console or device page c...

Page 291: ...g the mouse to capture the entire text and then positioning your cursor to the desired destination as you select the Paste option Note Linux browsers do not support the Copy and Paste feature Connecting Directly to Ports It is possible to connect to console ports using the AlterPath Manager as a security proxy T To Connect from a Windows SSH Client 1 Using a Windows SSH client such as Putty select...

Page 292: ...ty proxy Figure 5 1 PuTTY Configuration of APM as a Security Proxy T To Connect SSH from a Linux or UNIX System Using SSH on a Linux or UNIX system type in ssh user name console name IP address of APM This command opens a SSH connection to the AlterPath Manager checks the username and password checks the access control list to verify user access and then establishes the connection to the appropria...

Page 293: ...line interface as accessed by an admin follows Cyclades APM V_1 4 0 RC1 Oct 11 2005 Console kernel 2 4 25 APM_Gregg login admin Password WARNING changing system files directly is dangerous and may adversely affect your system s functionality Proceed with caution and only if you know what you are doing ...

Page 294: ... 4 0 RC1 10 10 2005 CLI admin Mgr man list console connects to a console consolelist lists all consoles you are allowed to access page prints all lines in a console s logfile searchlog prints lines in a console s logfile that match a pattern man command to get help text of command admin Mgr consolelist Jupiter_01 port 1 Jupiter_02 port 2 Jupiter_03 port 3 Jupiter_04 port 4 toshibaserver port 4 adm...

Page 295: ...n Command Action disconnect a attach read write b send broadcast message c toggle flow control d down a console e change escape sequence f force attach read write g group info i information dump l letter el break sequence list l0 send break per config file l1 9 letter el one nine send specific break sequence o re open the tty and log file p replay the last 60 lines r replay the last 20 lines s spy...

Page 296: ...hentication Page 265 setboot Set the Network Boot Utility Page 266 setcons Set Console Connection Page 267 setdatetime Set System Timezone Date and Time Page 268 setethernet Set Ethernet Speed and Duplexing Page 268 setnames Set Host Domain Names Nameserver Page 270 setnetwork Set Ethernet Subinterfaces Page 271 setntp Set Network Time ProtSocol Server Page 273 setserial Examine the Serial Port Pa...

Page 297: ...e more than one Radius Server root APM gregg data setauth Your configuration will be overwritten by the default files Are you sure you want to continue y n n y Continuing setauth Choose the desirable authentication method local radius tacacs ldap kerberos nis active_directory local Configuration changed Execute saveconf to save the new values in flash WARNING It may be required to restart the sshd...

Page 298: ...ress IP_of_tftpboot Enter Kernel Filename kernel_filename Enter InitRD Filename initRD_filename WARNING make sure you re setting valid values for the network boot parameters or the network boot may not work Current Status ENABLED Local IP Address IP_of_APM Server IP Address IP_of_tftpboot Kernel Filename kernel_filename InitRD Filename initRD_filename Do you wish to save these parameters y N y Sav...

Page 299: ...r Baud Rate in bps 9600 Enter Word Length 5 6 7 or 8 8 Enter Parity even odd or no no Enter Stop Bits 1 or 2 1 Enter Terminal Type vt100 WARNING make sure you re setting valid values for the console parameters or you may make your console inaccessible Current Parameters 9600 8n1 vt100 Do you wish to save these parameters y N y Saving console configuration done NOTE the new console parameters will ...

Page 300: ...T 0 42 Mexico 59 UTC 9 CET 26 GMT 0 43 Mideast 60 Universal 10 CST6CDT 27 GMT0 44 NZ 61 W SU 11 Canada 28 Greenwich 45 NZ CHAT 62 WET 12 Chile 29 HST 46 Navajo 63 Zulu 13 Cuba 30 Hongkong 47 PRC 64 iso3166 tab 14 EET 31 Iceland 48 PST8PDT 65 posix 15 EST 32 Indian 49 Pacific 66 posixrules 16 EST5EDT 33 Iran 50 Poland 67 right 17 Egypt 34 Israel 51 Portugal 68 zone tab Enter the number correspondin...

Page 301: ...Enter the number corresponding to your choice 1 1 Enabling auto negotiation for eth0 Current Ethernet eth1 speed duplex settings AUTO Change Ethernet eth1 speed duplex Y es or N o N y Choose the correct operation mode 1 Auto negotiation 2 10 Mbps full duplex 3 10 Mbps half duplex 4 100 Mbps full duplex 5 100 Mbps half duplex 6 1000 Mbps full duplex 7 1000 Mbps half duplex Enter the number correspo...

Page 302: ...sole nslookup your_APM_IP_address or nslookup your_APM_host_and_domain_name The console display will appear something like the following root APM gregg root setnames Enter the System s Hostname max 30 characters APM gregg Accounting APM Enter the System s Domain Name max 60 chars localdomain domain_name Enter the Primary Nameserver s IP address none 192 168 44 21 Enter the Secondary Nameserver s I...

Page 303: ...net eth0 IP address 192 168 48 162 Enter Ethernet eth0 Subnet Mask 255 255 252 0 Ethernet eth1 IP address S tatic N one or K eep current K s Enter Ethernet eth1 IP address 10 10 10 2 Enter Ethernet eth1 Subnet Mask 255 255 0 0 Configure Ethernet Subinterfaces Y es N o or L ist N l Number of Ethernet Subinterfaces already configured 0 Configure Ethernet Subinterfaces Y es N o or L ist N y Enter the...

Page 304: ...te saveconf to save the new values in flash Do you want to make these changes effective now y n y Reconfiguring network interfaces Added VLAN with VID 2 to IF eth0 Configuring eth0 speed duplex Configuring eth1 speed duplex done Shutting down dhcpd OK Starting dhcpd No interface configured for dhcpd dhcpd not started Stopping Tomcat OK Stopping sniff_port daemon sniff_port Starting sniff_port daem...

Page 305: ...ce you log off the escape sequence is deleted Globally Change file var apm bin con as below To make it permanent you must include this file in etc files list and then run saveconf original line in var apm bin con exec var apm bin console Mlocalhost l USR 1 root APM gregg root setntp Enter the NTP server 192 168 48 164 Configuration changed Execute saveconf to save the new values in flash root APM ...

Page 306: ... command to any application running on the foreground rather than to the console server Unlike c the latter is not a valid key combination for most servers including Sun and should enable you to interrupt the console server as necessary If however you need to re define the command you may do so from the var apm bin apmrun sh file below the commented line shown Redefine CTRL C here Customize it as ...

Page 307: ... restart tomcat as follows etc init d tomcat stop etc init d tomcat start T To Change the Number of Consoles per Page The default number of consoles that you can view from the Consoles List form is set to 512 Edit the var apm apm properties file 4 Go to the apm consolesperpage 512 line 5 Change the 512 in the line to the value desired T To Enable Telnet Telnet is available in the AlterPath Manager...

Page 308: ... file to enable the Kerberized version of telnet 3 Verify that etc protocols has the following entries tcp 6 TCP transmission control protocol udp 17 UDP user datagram protocol Telnetd with PAM support service telnet flags REUSE socket_type stream wait no user root server usr sbin in telnetd log_on_failure USERID disable no Kerberized telnetd service telnet flags REUSE socket_type stream wait no u...

Page 309: ... the ACS TS Admin Name If you want to use another admin name other than root for ACS or TS devices perform the following steps 1 Create a new user in the device Example adduser myadmin 2 Edit the files etc passwd and etc group by setting the userid and groupid of the new user to zero 0 and setting the home directory to root Example etc passwd myadmin dM7VcWSPBOGI 0 0 Embedix User root bin sh etc g...

Page 310: ...onding cannot be implemented on an APM 2500 or an APM 5000 in a private network configuration since the APM 2500 and the APM 5000 will not support expansion cards Ethernet bonding is a method of providing redundancy to an Ethernet connection When Ethernet bonding is enabled the primary Ethernet port operates under normal circumstances If the primary Ethernet port fails a backup or redundant Ethern...

Page 311: ...Ethernet Bonding devices Y es N o or L ist N y Enter the Ethernet numbers for bond0 0 to 1 separated by spaces 0 1 Enter the primary ethernet number for bond0 0 1 or none none 0 Status checking interval for bond0 ms 100 Delay on enabling a slave for bond0 ms 300 Delay on disabling a slave for bond0 ms 300 Bonding bond0 IP address S tatic or N one S Enter Bonding bond0 IP address 192 168 10 2 Enter...

Page 312: ...HCP Example DHCP Configuration Note The example shown is a branch of SETNETWORK or a branch of the Initial Configuration Wizard If the Ethernet default gateway is already configured the following option appears Enable Ethernet Bonding Y es or N o N n Ethernet eth0 IP address S tatic D HCP or N one S d Ethernet eth1 IP address S tatic or N one S s Enter Ethernet eth1 IP address 10 10 10 2 Enter Eth...

Page 313: ...IM is a Cyclades product that links the AlterPath System to the HP OpenView systems management platform In order for the IM to work the AlterPath Manager must contain the NNM license See the AlterPath Integrater for HP OV NNM B 07 50 Integration Guide PAC0436 for details on this product Modem Card Configuration Note Modems are not supported on the APM 2500 or the APM 5000 The AlterPath Manager E20...

Page 314: ...nt a dial up failure When you exclude modems be sure to run and save your configuration as follows 1 Using VI edit the following file vi var apm apm properties ENTER 2 Type in modem pool exclude ttyPS For example to exclude ttyPS2 and ttyPS3 type in modem pool exclude ttyPS2 ttyPS3 3 Once a modem has been excluded you must initialize the configuration by typing in etc init d modem_pool restart War...

Page 315: ...yPS3 2004 04 12 09 35 00 Dial out to acs48 failed NO DIAL TONE Serial Card Configuration The AlterPath Manager supports the use of a PCI based multi port serial cards The cards are used to connect the AlterPath Manager to external modems Up to eight serial devices are created if modems are connected to serial ports and the devices are names ttyPS0 ttyPS7 This section provides basic procedures for ...

Page 316: ...ble ttyPS1 Available ttyPS2 Available ttyPS3 Available Viewing the Latest Status of Each Modem The modems in the modem pool are allocated in a round robin sequence to ensure all modems are exercised to the same degree If a modem fails to dial out the system will allocate the next modem in the modem pool The var log modem_status file contains the result of the last attempted usage of a modem Contai...

Page 317: ...nstead of etc ppp chat init to initialize ttyPS0 2 To define a connect script for a specific port copy etc ppp chat connect as etc ppp chat connect tty device For example if etc ppp chat connect ttyPS0 is present then the system uses this file instead of etc ppp chat connect to dial out through ttyPS0 3 Add the new file names in etc files list 4 Enter saveconf to save your configuration Configurin...

Page 318: ...duser ppp_user Note This must be the same PPP user configured in the AlterPath Manager Dial Up form Also from the ACS set the password for the ppp_user in the ACS using the command and syntax passwd ppp_user Note This must be the same PPP password configured in the AlterPath Manager Dial Up form From the AlterPath Manager go to var apm apm properties file and add the APM phone number in the parame...

Page 319: ...ds in which the AlterPath Manager should wait before allocating the modems for dial in after receiving a confirmation from an ACS that it will call the AlterPath Manager back modem pool on_hook_time 4 For external modems From the ACS edit the file etc inittab and etc pslave conf to Remove the control of Portslave over it and add mgetty For PCMCIA modem From the ACS copy the file etc ppp options tt...

Page 320: ...rver ports 80 443 8080 NIS Configuration To use NIS authentication NIS is selected from the First Time Configuration script To further control NIS authentication edit the following configuration file as follows File to edit etc nsswitch conf Format database service actions service Where Parameter Definition database Available aliases ethers group hosts netgroup network passwd protocols publickey r...

Page 321: ...already present in the NIS server The configuration below enables the system to authenticate NIS users and local users Authenticate the user first through the local database and if the user is not found use NIS passwd files compat shadow files compat group files compat passwd_compat nis shadow_compat nis group_compat nis Authenticate the user first through NIS and if the user is not found use the ...

Page 322: ... networks based on the key distribution model It allows individuals communicating over a network to prove their identity to each other while also preventing eavesdropping or replay attacks It also detects modifications and prevents unauthorized reading How Kerberos Works On a kerberized network the Kerberos database contains principals and their keys for users their keys are derived from their pas...

Page 323: ...Path Manager The AlterPath Manager automatically creates krb5 conf the file that holds information about KDC addresses and port numbers The user however must create the etc krb5 keytab file a binary file that holds the cryptographic keys to validate the Kerberos tickets received There are two different ways to get the etc krb5 keytab file into the AlterPath Manager Method 1 Using SCP copy the etc ...

Page 324: ...tory Note This procedure can either be invoked through the First Time Configuration Wizard or from the setauth command 1 Choose the active_directory authentication method at the following prompt local radius tacacs ldap kerberos nis active_directory local active_directory 2 Enter the Active Directory server authserver 3 Enter the distinguished name of the search base ex dc cyclades dc com dc first...

Page 325: ...dap authentication method at the following prompt local radius tacacs ldap kerberos nis active_directory local ldap 2 Enter the name or IP address of the LDAP server at the prompt Enter the LDAP server LDAP_server_name 3 Enter the server s LDAP base at the prompt ex dc cyclades dc com ou person o cyclades dc first_part_domain_name dc second_part_domain_name Note The second part of the domain name ...

Page 326: ...nit d tomcat stop etc init d apache stop etc init d apache start etc init d tomcat start 4 Use the saveconf command to save the configuration Note If you disable HTTP you must still type https in the browser URL input field to access the APM using the WMI There is no automatic redirection to HTTPs Firmware T To Add Firmware Firmware files tgz are normally downloaded from the web and copied into th...

Page 327: ... and then restart your web browser This will ensure that the browser will not attempt to use a previously opened session or attempt to use any cached static resources 1 From the Cyclades website www cyclades com download and copy the firmware to the server you want to use to store firmware for the AlterPath Manager The firmware is composed of two files all tgz all tgz md5sum 2 From your firmware s...

Page 328: ...mand It is also a good idea to save a copy of each license file on a server that can be accessed by your APM just to be extra safe If at any time you run defconf the file etc files list will revert back to its original state and you will need to reinstall your license Backing Up User Data Using CLI you can back up and restore the configuration and data files of the AlterPath Manager to a local or ...

Page 329: ...which all data is restored The new unit will have the same configuration as the original unit Backup and Restore Commands From the CLI at the Linux shell prompt the command lines for backup and restore are as follows If you do not specify a user then the system uses the current username If you do not specify a host then the system creates a backup on the local host or executes a restore from the l...

Page 330: ... machine under the privileges of the specified user If you do not supply user the system will assume that the current user is the remote one For remote destination ensure that the remote machine is prepared to accept connections to ssh service on port 22 If only the file name is supplied the system will copy the logs locally You can include path names as part of the file name System Recovery Guide...

Page 331: ...ure there is a console terminal set up and connected to the APM s console port See To Log Into the Serial Console Port on page 256 if you need to set this up 2 While you are close enough to the console keyboard to have physical access reset the APM See the section Connectivity and Capacity on page 1 for illustrations of locations of reset buttons on the different APM models The APM will start to r...

Page 332: ...e configuration by entering the following command saveconf 8 Enter the following command to reboot the APM reboot 9 Allow the APM to reboot normally Changing the Database Configuration Note This configuration procedure is for advanced users only GRUB version 0 91 639K lower 522176K upper memory APM APM Network Boot APM Emergency Mode Use the and v keys to select which entry is highlighted Press en...

Page 333: ...en the log file to check is var log conf V_1 3 0 log To restore the previous configuration restconf config tgz old Table 5 5 Default Configuration Values from the apm properties File Property Name Default Property Value If you change the default property value ensure that db apm apmdb The system creates a corresponding database db apm user apm The system creates a corresponding database user db ap...

Page 334: ... To Delete your Default Certificate 1 Verify your default certificate Enter the command keytool list The console will for the password 2 Type in the password changeit as shown The console will show a display similar to the following 3 Delete the default certificate Enter the command keytool delete alias tomcat The console will prompt you for the password After you enter the password the display wi...

Page 335: ...blic csr If you use this command the following information is required root 2500_QA root keytool list Enter keystore password changeit Keystore type jks Keystore provider SUN Your keystore contains 0 entries Table 5 6 Information for the openssl Command Parameter Description Country Name 2 letter code AU The 2 letter country code State or Province Name full name Some State The full name not the co...

Page 336: ...ate Once the CSR is approved the CA sends a certificate e g jcertfile cer to the origin and stores a copy on a directory server If you are satisfied that the certificate is valid then you can import the certificate to your keystore using the import subcommand keytool import alias tomcat file jcert cer You will be prompted for the password 9 Save your configuration Enter the command saveconf The ce...

Page 337: ... stored with the alias and exits if they are different If the alias identifies the other type of keystore entry the certificate will not be imported If the alias does not exist then it will be created and associated with the imported certificate Be sure to check a certificate very carefully before importing it as a trusted certificate View it first using the printcert subcommand or the import subc...

Page 338: ...ide Note It is not required that you execute a printcert subcommand prior to importing a certificate since before adding a certificate to the list of trusted certificates in the keystore the import subcommand prints out the certificate information and prompts you to verify it You then have the option of aborting the import operation This is only the case if you invoke the import subcommand without...

Page 339: ... 5 in 42 418 x 65 024 x 8 89 cm PCI Slots 2 1 not currently supported 3 not currently supported LCD front panel No Yes Yes Modem Support Built in Power Supply 150W single 115 230V autoranging 260W single 115 230V autoranging 2 x 500W hot swap redundant 115 230V autoranging Operating Temperature 50 F to 112 F 10 C to 44 C 50 F to 95 F 10 C to 35 C 50 F to 95 F 10 C to 35 C Operating Humidity 20 to ...

Page 340: ...sed Concurrent serial console sessions 256 fixed 64 to 512 licensed 64 to 2048 licensed Support for KVM net Yes SW 1 1 0 and above Yes SW 1 1 0 and above Yes SW 1 1 0 and above Support for OnSite Yes Yes Yes Support for TS Yes Yes Yes Support for ACS Yes Yes Yes AlterPath Integrator for HP OpenView Yes Yes Yes Heartbeat Failover Data sync No Yes Yes Supported web browsers Internet Explorer 6 0 Moz...

Page 341: ... modem T To Configure the PCMCIA Modem 1 Edit the file etc ppp pap secrets When the file is opened for the first time it should look something like this 2 Add the following line The file should now look something like this This configures the modem to accept any password T To Configure the External Modem To configure your external modem perform the following steps Secrets for authentication using ...

Page 342: ...The all initchat section of the etc portslave pslave conf file appears as follows the first time the file is opened 3 Modify the all initchat section by removing all the symbols from the beginning of each line in the section 4 Change the first line of all initchat to sxx initchat where xx is the number of the serial port to which the external modem is attached all initchat TIMEOUT 10 d l dATZ OK r...

Page 343: ...s 0 0 0 0 and plugin usr lib libpsr so Note If you do not remove these two lines leave the symbol in front of each one 7 Change all autoppp to sxx autoppp where xx is the number of the serial port to which the external modem is attached sxx initchat TIMEOUT 10 d l dATZ OK r n ATZ OK r n TIMEOUT 10 ATM0 OK r n TIMEOUT 3600 RING STATUS Incoming p I HANDSHAKE ATA TIMEOUT 60 CONNECT STATUS Connected p...

Page 344: ...160 5 ms dns 0 0 0 0 and plugin usr lib libpsr so Note If you do not remove these two lines leave the symbol in front of each one 12 Change all pppopt to sxx pppopt where xx is the number of the serial port to which the external modem is attached 13 In the first line of this section change i j to 0 0 0 0 0 0 0 0 14 Remove the backslash from the end of the line that reads idle I maxconnect T sxx au...

Page 345: ...u are enabling syslog ng on the ACS or TS it is not advisable to use root as the Admin Username for this device Instead create a user in the ACS or TS whose name will be the APM Admin Username for that device 19 After creating the user in the ACS or TS give it root privileges by editing etc passwd for the user by changing the UID and GID fields to 0 sxx pppopt 0 0 0 0 0 0 0 0 novj proxyarp modem a...

Page 346: ...ged to 0 is as follows 20 Change the ownership of the user s home directory to root as follows chown root home edson 21 Edit the file etc ssh sshd_config to remove the comment symbol in front of the line AuthorizedKeysFile etc ssh authorized_keys edson fTEQb6zEnuIEQ 0 0 Embedix User home edson bin sh ...

Page 347: ...on or before you run installimg you can edit the file etc files list and add your license file name to the list of files Be sure to use the full path of each license file name you enter into this file For example if the name of the license file you are adding is APM_FA_DLS_64_128 enc you should enter the full path name var apm licenses data APM_FA_DLS_64_128 enc Be sure to follow up with the savec...

Page 348: ... with their corresponding managed console capacities are shown in the table that follows Table C 1 DLS Activations Available at Initial Purchase Part Number DLSs Max Number of Managed Consoles APM 2500 APM 2500 Base System 64 1024 APM B DLS 128 128 2048 APM B DLS 256 256 4096 APM B DLS 512 512 8192 APM 5000 APM 5000 Base System 64 1024 APM B DLS 128 128 2048 APM B DLS 256 256 4096 APM B DLS 512 51...

Page 349: ...nversion Options Conversion Number From To AlterPath 2500 APM FA DLS 64 128 64 128 APM FA DLS 64 256 64 256 APM FA DLS 64 512 64 512 APM FA DLS 128 256 128 256 APM FA DLS 128 512 128 512 APM FA DLS 256 512 256 512 AlterPath 5000 APM FA DLS 64 128 64 128 APM FA DLS 64 256 64 256 APM FA DLS 64 512 64 512 APM FA DLS 64 1024 64 1024 APM FA DLS 64 1536 64 1536 APM FA DLS 64 2048 64 2048 APM FA DLS 128 ...

Page 350: ... will activate your new features T To Install Expanded DLS Activation 1 Log onto your APM as root using the serial console interface 2 Examine the contents of the following the var apm licenses data directory Note At least one file should already be in this directory This file should be named APM_B_DLS enc This is a base license file indicated by the B APM FA DLS 256 512 256 512 APM FA DLS 256 102...

Page 351: ... contain the following files prior to the new expansion APM_B_DLS_64 enc APM_FA_DLS_64_128 enc When you copy your new license file into the var apm licenses data directory it must contain all of the following APM_B_DLS_64 enc APM_FA_DLS_64_128 enc APM_FA_DLS_128_256 enc Note Multiple FA feature activation license files must be named with sequential number ranges as shown in the foregoing example 4...

Page 352: ...ull content scrolled You can also verify your current DLS Activation by logging onto your APM CLI as root and running the following command ls var apm licenses data If DLS is activated the screen will display a file name similar to this APM_B_DLS_256 enc The foregoing file name indicates a DLS capacity of 256 logging sessions ...

Page 353: ...erruns 0 carrier 0 collisions 1038728 txqueuelen 1000 RX bytes 685270715 653 5 Mb TX bytes 548308906 522 9 Mb Interrupt 10 Base address 0xc000 Memory e5020000 e5020038 eth1 Link encap Ethernet HWaddr 00 90 FB 01 8C D7 inet addr 10 10 10 2 Bcast 10 10 255 255 Mask 255 255 0 0 UP BROADCAST RUNNING MULTICAST MTU 1500 Metric 1 RX packets 632 errors 0 dropped 0 overruns 0 frame 0 TX packets 622 errors ...

Page 354: ...Data Logging Session Activation 322 AlterPath Manager Installation Configuration and User s Guide ...

Page 355: ...se being checked can reside either locally on the device being accessed or on an authentication server on the network If an authentication method is selected that relies on a server the corresponding authentication server must be already installed and configured in order for authentication to work Using one or more of the many types of popular authentication methods can reduce administrator worklo...

Page 356: ...ailable even during disk failures Administrators often need to access the BIOS while troubleshooting for example to temporarily change the location from which the system boots How to access the BIOS varies from one manufacturer to the other baud rate Pronounced bawd rate When configuring terminal or modem settings on serial ports and console port connections on AlterPath devices the specified baud...

Page 357: ... Telnet to access an AlterPath OnSite the administrator can then tell the OnSite to perform actions using the CLI by typing commands on the Linux shell s command line Do not be confused by the fact that some Cyclades products offer a management tool called the CLI which has the same name as the term used in general for any command line interface The Admin user can select CLI at a prompt after logg...

Page 358: ...processor needs its own IP address Managing multiple servers with multiple IP address is both expensive and time consuming without consolidation Decryption Decoding of data that has been encrypted using an encryption method Device From the AlterPath Manager s point of view a device is a product that the APM is designed to control directly through an Ethernet port This includes the KVM net ACS TS a...

Page 359: ...rface works IPDU Intelligent power distribution unit Cyclades supports a family of AlterPath PM IPDUs IPMI Intelligent Platform Management Interface An open standards service processor currently adopted by every major server platform vendor Its main benefit over other service processors is that it is installed on servers from many vendors providing one interface and protocol for all servers Its ma...

Page 360: ...anagement console See service processor Management software Each server company that offers a service processor produces its own client side software to access the servers management features through the service processor In some cases management software is imbedded in the service processor and is presented either as a web interface or as a command line interface accessed using SSH or Telnet or a...

Page 361: ...nfrastructure remotely Components include console servers KVM switches IPDUs and service processor managers Enables lights out data centers where computers can be monitored preventively maintained and restored to operation without site visits by technicians Out of band A type of access to assets that is either separate from or independent of the normal production network Used for remote monitoring...

Page 362: ...ice processor technologies they support are shown in the following table Shell A command interpreter on UNIX based operating systems like the Linux operating system that controls most Cyclades products At the time this is being written Microsoft has announced an upcoming release of a Microsoft shell A shell typically is accessed in a terminal window where the shell presents a prompt For example ad...

Page 363: ...dvanced Configuration 331 typing commands in the shell which interprets the commands and performs the specified actions Web Manager Cyclades web management interface WMI which runs in supported browsers ...

Page 364: ...332 APM Installation Configuration and User s Guide ...

Page 365: ...131 Auto Upload device configuration 131 B Backing Up User Data 202 Blade or switch viewing 58 C Centralized authentication 5 Centralized Data Logging 6 Change and Configuration Management 14 Circuit loading 29 CLI Commands 258 COM port connection 31 Command Line Interface CLI 15 Configuration wizard 88 Connectivity and Capacity 1 Console setting 267 Console access deleting a user 191 Console Defi...

Page 366: ...figuration 268 Ethernet subinterfaces 271 Event Logs 70 Examine the Serial Port Parameters 273 External Modem ACS 309 F Failover 240 Fault tolerance 240 Firmware Detail screen 200 Firmware List screen 197 deleting or adding 199 Firmware Management 197 294 Firmware screen 106 Firmware upgrades xxix First Time Configuration 86 First Time Configuration Wizard 88 H Heartbeat 240 Host name 270 Hot keys...

Page 367: ...tional Modes 86 OTP 122 P PCMCIA Modem ACS 309 Power Management 72 235 Pre configuration 30 Pre installation 30 IP Addresses 30 NIC card 30 Prioritized Triggers Alarms 7 Private Network Diagram 27 Private Network Topology 25 Product Installation Checklist 21 Profile Definition screen adding a new profile 164 modifying a profile 166 Profile List screen 163 R Rack mounting Safety considerations 28 R...

Page 368: ...ort technical xxix Switch or blade viewing 58 System recovery 203 298 T Technical Specifications 307 Technical support xxix Technical training xxviii Telnet 275 enable 275 Ticket 52 Time 268 273 set 268 Time and date setting 268 273 Time zone 268 Training xxviii Typographic Conventions xxv U Upgrading firmware xxix User Interface overview 43 User List screen 184 User Management 183 User Profile Ac...

Reviews: