background image

 

41

 

Chain rule 

The Chain rule determines whether the access from the hosts is allowed or not. It can be one of 

these two values: 

  ACCEPT : access allowed

  DROP : access not allowed

 

The rule can be configured to apply to a particular Group level (All, User, Super, Administrator). 

 

When the IP-KVM receives a TCP packet, it will process the packet with the chain rule depicted 

below. The process ordering is important; the packet will enter the chain at rule 1 first, if it meets 

the rule then take action directly, otherwise go to chain rule 2. 

 

 

 

Check the “Enable Group based System Access Control” to edit the rules 

 

Users can add a new IP filtering rule by populating the fields in the new line by using Append or 

Insert. Users can remove a rule by using Replace or Delete. Use Apply to save your changes. 

 

 

42

 

5.5.4 Certificate 

 

 

The IP ACCESS KVM SWITCH CLASSIC uses the Secure Socket Layer (SSL) protocol for any 

encrypted  network  traffic  between  itself  and  a  connected  client.  During  the  connection 

establishment  the  IP  ACCESS  KVM  SWITCH  CLASSIC  has  to  expose  its  identity  to  a  client 

using a cryptographic certificate.  

 

This  certificate  and  the  underlying  secret  key  is  the  same  for  all  IP  ACCESS  KVM  SWITCH 

CLASSIC units and certainly will not match the network configuration that will be applied to the 

IP ACCESS KVM SWITCH CLASSIC by its user. The certificate's underlying secret key is also 

used  for  securing  the  SSL  handshake.  Hence,  this  is  a  security  risk  (but  far  better  than  no 

encryption at all). 

 

However, it is possible to generate and install a new certificate that is unique for a particular IP 

ACCESS KVM SWITCH CLASSIC. In order to do this, the IP ACCESS KVM SWITCH CLASSIC 

is  able  to  generate  a  new  cryptographic  key  and  the  associated  Certificate  Signing  Request 

(CSR) that needs to be certified by a certification authority (CA). A certification authority verifies 

that you are the person you claim you are, and signs and issues a SSL certificate to you. 

 

The following steps are necessary to create and install an SSL certificate for the IP ACCESS 

KVM SWITCH CLASSIC:  

 

1.  Create  an  SSL  Certificate  Signing  Request  using  the  panel  shown  in  the  screen  shot 

above. You need to fill out a number of fields that are explained on the next page. Once 

this  is  done,  click  on  the  Create  button  to  initiate  the  Certificate  Signing  Request 

generation.  The  CSR  can  be  downloaded  to  your  administration  machine  with  the 

Download CSR button (see the illustration on the next page). 

2.  Send the saved CSR to a CA for certification. You will get the new certificate from the CA 

after  a  more  or  less  complicated  traditional  authentication  process  (depending  on  the 

CA). 

Содержание 39415

Страница 1: ...Switch LITE the IP Access KVM SWITCH CLASSIC delivers an advanced IP KVM solution whilst retaining compatibility with older models This manual is based on the CPU IP Access Switch LITE manual and the...

Страница 2: ...se Settings 9 3 4 6 Video Modes 9 4 USAGE 10 4 1 Prerequisites 10 4 2 Logging In 11 4 2 1 Login to the IP ACCESS SWITCH LITE 11 4 3 Navigation 12 4 3 1 Remote Console Main Window 13 4 3 2 Remote Conso...

Страница 3: ...ement No impact on server or network performance Automatically senses video resolution for best possible screen capture High performance mouse tracking and synchronisation User console port for direct...

Страница 4: ...thernet networks the Ethernet adapter should use Category 3 4 5 or 6 UTP cable To establish a 10Mbps connection the cable must be connected to a 10Base T hub 100Mbps Connection For 100Base TX Fast Eth...

Страница 5: ...ith the parameters given in this table When configuring with a serial terminal reset the IP ACCESS KVM SWITCH CLASSIC and immediately press the ESC key You will see some device information and a promp...

Страница 6: ...e synchronization between the local and remote mouse cursors The IP ACCESS KVM SWITCH CLASSIC addresses this problem with an intelligent synchronization algorithm There are two mouse modes available o...

Страница 7: ...er of common video modes When running X11 on the host system please do not use any custom mode lines with special video modes If you do the IP ACCESS KVM SWITCH CLASSIC switch may not be able to detec...

Страница 8: ...M SWITCH CLASSIC for the first time Not changing the password for the super user is a severe security risk and could result in unauthorized access to the switch and to the host system s to which it is...

Страница 9: ...nd your host system uses a US English keyboard layout for instance some special keys on the German keyboard will not work as expected Instead the keys will result in their US English counterpart You c...

Страница 10: ...video settings The IP ACCESS KVM SWITCH CLASSIC features two different dialogs which influence the video settings Video Settings through the HTML Frontend To enable the local video port select this op...

Страница 11: ...sion quality depends on the video picture itself e g the number of the colours or the diversity of pixels The lower the compression quality the more data have to be sent and the longer it may take to...

Страница 12: ...og into the device The credentials that need to be entered for authentication are identical to those of the web interface That means the user management of the Telnet interface is entirely controlled...

Страница 13: ...included on the supplied CD Launch RawWrite you will see the window opposite Insert your floppy disk into your floppy drive Click the Read tab and then click on Select a name and destination for the f...

Страница 14: ...n navigate to the Copy Disc section Select the CD ROM or DVD drive you would like to create an image from Specify the filename of the image and save the CD ROM content in that file Example 1 Create a...

Страница 15: ...sticks can be redirected It is even possible to enable a write support so that for the remote machine it is possible to write data to your local disc Please note that Drive Redirection works on a lev...

Страница 16: ...age emulation and hide the virtual drive if no image file is currently loaded To set this option press the button Apply IMPORTANT 1 Drive Redirection is only possible with Windows 2000 and later versi...

Страница 17: ...and use the Remote Console The default password for both accounts is pass Ensure you change the passwords as soon as you have installed and accessed the IP ACCESS KVM SWITCH CLASSIC for the first time...

Страница 18: ...en several users are accessing the IP ACCESS KVM SWITCH CLASSIC simultaneously The standard colour depth is 16 bit 65536 colours The other colour depths are intended for slower network connections in...

Страница 19: ...of the combination is encountered In this case all pressed keys will be released in reversed sequence So the minus sign builds single separate keypresses and releases The star inserts a pause with a...

Страница 20: ...tting should be suitable for most situations Force Composite Sync Required for Sun Computers To support signal transmission from a Sun machine enable this option If not enabled the picture of the remo...

Страница 21: ...Enable this option to exclude the IP ACCESS KVM SWITCH CLASSIC from the setup protocol 38 5 5 2 Dynamic DNS A freely available Dynamic DNS service dyndns org can be used in the following scenario see...

Страница 22: ...ing again to the Dynamic DNS server by the IP ACCESS KVM SWITCH CLASSIC 40 5 5 3 Security Force HTTPS If this option is enabled access to the web front end is only possible using an HTTPS connection T...

Страница 23: ...will not match the network configuration that will be applied to the IP ACCESS KVM SWITCH CLASSIC by its user The certificate s underlying secret key is also used for securing the SSL handshake Hence...

Страница 24: ...s Note If you destroy the CSR on the IP ACCESS KVM SWITCH CLASSIC there is no way to get it back In case you deleted it by mistake you have to repeat the three steps as described previously 44 Confirm...

Страница 25: ...u must make sure it is not interfering with the IP settings of the IP ACCESS KVM SWITCH CLASSIC and your console computer The default value will work in most cases Modem client IP address This IP addr...

Страница 26: ...after the IP ACCESS KVM SWITCH CLASSIC has been started If the IP ACCESS KVM SWITCH CLASSIC loses power or a hard reset is performed all logging data will be lost To avoid this use one of the log met...

Страница 27: ...its IP address from which host the user comes from and its activity status is displayed RC means that the Remote Console is open If the Remote Console is opened in exclusive mode the term exclusive is...

Страница 28: ...essible However you will be required to login once again Note This process is not reversible and may take some minutes Make sure the IP ACCESS KVM SWITCH CLASSIC s power supply will not be interrupted...

Страница 29: ...ly configured Q 006 Special key combinations e g ALT F2 ALT F3 are intercepted by the console system and not transmitted to the host A 006 You have to define a so called Button Key This can be done in...

Страница 30: ...CAPE ESC F1 F2 F3 F4 F5 F6 F7 F8 F9 F10 F11 F12 PRINTSCREEN SCROLL LOCK BREAK INSERT HOME PAGE UP DELETE END PAGE DOWN UP LEFT DOWN RIGHT NUM LOCK NUMPAD0 NUMPAD1 NUMPAD2 NUMPAD3 NUMPAD4 NUMPAD5 NUMPA...

Страница 31: ...onnection 10 100 Ethernet telephone line modem needed Firmware Upgrade Port 1 x Serial DB9 Pin Max Video Resolution Local 1600 x 1200 Remote 1280 x 1024 OS Compatibility MS Windows family Unix Sum Sol...

Страница 32: ...ry to correct the interference by one or more of the following measures Reorient or relocate the receiving antenna Increase the separation between the equipment and receiver Connect the equipment into...

Отзывы: