Page 2 - FCC Warning Statement; is operated in a commercial environment.; Canadian DOC Notice; the Canadian Department of Communications.
FCC Warning Statement The Cyclades ACS 5000 advanced console server has been tested and found to comply with the limits for Class A digital devices, pursuant to Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is ope...
Page 4 - Symbols Used
Symbols Used NOTE: The following symbols may appear within the documentation or on the appliance. Instructions This symbol is intended to alert the user to the presence of important operating andmaintenance (servicing) instructions in the literature accompanying the appliance. Dangerous Voltage This...
Page 5 - T A B L E O F C O N T E N T S; Introduction
T A B L E O F C O N T E N T S Introduction 1 Overview 1 Connectors on the Console Server 1 Accessing the Console Server and Connected Devices 2 Web Manager 3 Prerequisites for Using the Web Manager 3 Types of Users 4 Security 4 Authentication 4 IPv6 6 Services not supporting IPv6 6 VPN 6 Packet ...
Page 6 - Cyclades
Performing basic network configuration using the wiz command 18 Adding users and configuring ports using the web manager 22 Other Methods of Accessing the Web Manager 22 Connecting PDUs 23 Web Manager for Regular Users 25 Using the Web Manager 25 Features of Regular User Forms 25 Connect 27 Connect ...
Page 7 - Table of Contents; vii
Configuring the Console Server in Expert Mode 51 Overview of menus and forms 51 Applications Menu and Forms 53 Connect 53 IPDU Power Management 54 Applications - IPDU Power Mgmt. - Outlets Group Ctrl 57 Applications - IPDU Power Mgmt. - View IPDUs Info 57 Applications - IPDU Power Mgmt. - Configurat...
Page 9 - O verview; Each model in the Cyclades; Connectors on the Console Server
Introduction 1 1 O verview Each model in the Cyclades ® ACS 5000 advanced console server family is a 1U appliance serving as a single access point for accessing and administering servers and other devices,supporting both IPv4 and IPv6 protocols. The following figure shows the front of the consoleser...
Page 10 - Accessing the Console Server and Connected Devices; An external modem
Figure 1.2: ACS 5000 Console Server Connectors NOTE: The number of serial ports and power supplies depends on the model. Number Description 1 Power connection. This may be single or dual power. Dual power requires two power cords. 2 Serial port connectors. 3 Ethernet port connectors. 4 Console port ...
Page 11 - W eb M anager; Access the web manager using one of the following ways:; Prerequisites for Using the W eb M anager; Chapter 1: Introduction
• Connecting a server running a terminal emulation program enables an administrator to loginto the console server and either enter commands in the console server shell or use theCommand Line Interface (CLI) tool. NOTE: Only one root or admin user can have an active CLI or web manager session. A seco...
Page 12 - Types of Users; The console server supports the following user account types:; avocent; Security; The following table lists the supported authentication methods.
• A web manager user account must be defined. The admin has an account by default, andcan add regular-user accounts to grant access to the connected servers or devices using theweb manager. Types of Users The console server supports the following user account types: • The root user who can manage t...
Page 14 - Services not supporting IPv6; VPN; VPN Connections; Packet Filtering; Structure of IP filtering
IPv6 The console server is compliant with IPv4, IPv6 and dual stack protocols so that you canenable IPv4 only, IPv6 only or both protocols, with support for dial-up connections andprimary network connections. You can configure the appliance to obtain its IPv6 networkparameters from a DHCPv6 server, ...
Page 15 - The chains which contain the rules controlling filtering.; Chain; Add a new chain and specify rules for that chain; Add rule and edit rule options
• The view table of the Firewall Configuration form containing a list of chains. • The chains which contain the rules controlling filtering. Chain A chain is a named profile that includes one or more rules defining either a set of characteristicsto look for in a packet or what to do with any packet ...
Page 16 - UDP protocol options
Flag any of the above elements with Inverted to perform target action on packets not matching any criteria specified in that line. For example, if you select DROP as the target action, specify Inverted for a source IP address and do not specify any other criteria in the rule, any packets arriving fr...
Page 17 - SNM P; For more information, see; Notifications, Alarm s and Data Buffering; Syslog servers; Prerequisites for logging to syslog servers
SNM P The administrator can activate the Simple Network Management Protocol (SNMP) agent thatresides on the console server so that the SNMP agent sends notifications about significantevents or traps to an SNMP management application. The console server SNMP agent supportsSNMP v1/v2 and v3. For more ...
Page 18 - console server into the local2 facility.; M anaging Users of Connected Devices; Configuring access to connected devices; Console Server and Pow er M anagem ent; Avocent SPC power control devices.
São Paulo console server into the local1 facility and to aggregate messages from Fremont console server into the local2 facility. On syslogger the system administrator has configured the system logging utility to write messages from the local1 facility to the /var/log/saopaulo-config file and the me...
Page 19 - Additional requirements for Server Technology IPDUs; For
• Server Technology Sentry™ family of Switched Cabinet Power Distribution Units (CDUs)and switched CDU Expansion Module (CW/CX) power devices. • Server Technology Sentry Power Tower XL™ (PTXL) and Power Tower ExpansionModule (PTXM) power devices. • Server Technology Sentry Smart CDU (CS) and smart C...
Page 20 - Configuring power management; Configuring ports for power management by authorized users
• With the IPDU ID assigned to the IPDU • With the port number to which the IPDU is connected The IPDU and port number are always followed by one or more outlet numbers inbrackets: [outlets]. Commas between outlet numbers indicate multiple outlets. Hyphensindicate a range. For example, [1,5-8] speci...
Page 21 - Options for managing power; Power management through the web manager; ipmitool; Hostnam e Discovery
For IPMI power management, the default hotkey is Ctrl+Shift+I . For IPDU power management, the default hotkey is Ctrl+p . Options for managing power Authorized users can perform power management through the console server by using forms inthe web manager, from a power management screen while logged ...
Page 23 - Installation; Im portant Pre-installation Requirem ents; Root Access on your local UNIX machine to use the serial ports.; Basic Installation Procedures; Mounting the console server
Installation 2 15 Im portant Pre-installation Requirem ents Before installing and configuring the console server, ensure you have the following: • Root Access on your local UNIX machine to use the serial ports. • An appropriate terminal application for your operating system. • IP address, DNS, Netwo...
Page 24 - To rack mount the console server:; Mount the console server in a secure position.; Making an Ethernet connection; To connect devices to serial ports:
Figure 2.1: Placement of Mounting Brackets To rack mount the console server: 1. Install the brackets on to the front or back edges of the console server using a screwdriverand the screws provided with the mounting kit. 2. Mount the console server in a secure position. Making an Ethernet connection C...
Page 25 - Making a direct connection to configure the network parameters.; To connect to the console port:; Chapter 2: Installation
Making a direct connection to configure the network parameters. On your Microsoft® Windows workstation, ensure that a terminal emulation program isinstalled. On servers running a UNIX-based operating system such as Solaris or Linux, makesure that a compatible terminal emulator such as Kermit or Mini...
Page 26 - Turning on the console server and the connected devices; To turn on the console server:; Performing basic network configuration using the wiz command; To log into the console server through the console:; ACS 5000 console server login:; root; To use the wiz command to configure network parameters:; wiz
Turning on the console server and the connected devices Perform the following procedures in the order shown to avoid problems with components onconnected devices. To turn on the console server: 1. Make sure the console server’s power switch is off. 2. Plug in the power cable. 3. Turn the console ser...
Page 27 - To configure for IPv4 protocol:; Enter
*********************************************************** ********* C O N F I G U R A T I O N W I Z A R D ********* *********************************************************** INSTRUCTIONS for using the Wizard: You can: 1) Enter the appropriate information for your system and press ENTER or 2) Pre...
Page 28 - Current configuration:; To configure for IPv6 protocol:
NOTE: If you choose to use DHCP and have selected IPv4 enabled (option 0 ), the IPv4 Current Configuration verification screen will be displayed as shown below. *************************************************************** *********** C O N F I G U R A T I O N W I Z A R D *********** *************...
Page 29 - Selecting a security profile using the web manager
• Stateless Only: The router will multicast the IPv6 prefix along with the consoleserver’s MAC address, then listen for the other devices on the local network to allowthe router to assign the IPv6 address. • Static: You must manually assign a unique IPv6 address for the console server. • DHCP: The r...
Page 30 - Selecting a security profile; Security Profiles; Adding users and configuring ports using the web manager; Security Menu; O ther M ethods of Accessing the W eb M anager; To use a dynamic IP address to access the web manager:
Selecting a security profile Select a pre-defined security profile or define a custom profile for specific services. The profiles are: • Secured - Disables all protocols except sshv2, HTTPS and SSH to serial ports. • Moderate - Enables sshv1, sshv2, HTTP, HTTPS, Telnet, SSH and Raw connections tose...
Page 31 - Turn on the console server and connected devices.; To use the default IP address to access the web manager:; Connecting PDUs; Avocent PM PDUs should be the first in the daisy chain.; Connecting third-party IPDUs; Console server serial
3. Turn on the console server and connected devices. 4. Enter the console server’s IP address in the browser’s address field. 5. Log in to the console server and finish configuring users and other settings using the web manager. To use the default IP address to access the web manager: The default I...
Page 32 - To daisy-chain PDUs to the console server:; Connect the other end of the cable to the IN port of the next PDU.
To daisy-chain PDUs to the console server: This procedure assumes that you have one Avocent PM PDU or Cyclades IPDU connected to aserial port on the console server. NOTE: Daisy-chaining is not possible with SPC power control devices. ServerTech PDUs will allow only one level (Master and Slave) of da...
Page 33 - Web Manager for Regular Users; Using the W eb M anager; Authorized users can access devices connected to serial ports:; To log into the web manager:; Press; Features of Regular User Form s
Web Manager for Regular Users 3 25 Using the W eb M anager Console server users perform most tasks through the web manager. The web manager runs in abrowser and provides a real-time view of all equipment connected to the console server. Authorized users can access devices connected to serial ports: ...
Page 35 - Connect; Connect to the console server; Connect to serial ports; Port access requirements; Connect
Connect When you select the Connect option, the form displayed will allow you to connect to the console server or its serial ports. Permission to access a port or perform power management is granted by the administrator whenyour user account is created. Connect to the console server When you click t...
Page 36 - Connection protocols for serial ports; TCP port numbers for serial ports; Ctrl; To use SSH to connect to a device through a serial port:
Connection protocols for serial ports You can access a server or a device connected to a serial port by using the connection protocolspecified for the port. The following table shows the protocols available for the serial ports. Connection Type Protocol Console Access Server (CAS) Telnet, ssh, Teln...
Page 37 - IPDU Pow er M anagem ent; option will display a form with two tabs, Outlets Manager; Outlets Manager; When you select
IPDU Pow er M anagem ent IPDU management allows you to manage the power outlets on power management applianceproducts. If you have permission to manage outlets on a power management appliance,selecting the IPDU Power Mgmt. option will display a form with two tabs, Outlets Manager and View IPDUs Info...
Page 39 - Bank Information
Form Heading Description Example Model IPDU model number. Avocent CycladesPM20i/30A PDU Number of Outlets IPDU number of outlets. 20 Number of Banks IPDU number of banks/circuits. 2 Single-Phase/3-Phase IPDU number of phases. Single-Phase Software Version IPDU firmware version. 1.9.2 PDU Current IPD...
Page 40 - To change your password:
Form Heading Description Example Type (Name) Type of the sensor. Temperature-Internal Current information displays the actual alarm state of the current level based on the configuredthresholds when available. The alarm state can have one of the following values: • Tripped - when hardware overcurrent...
Page 41 - Web Manager for Administrators; Com m on Features of Adm inistrator Form s; The following table describes the uses for each control button.
Web Manager for Administrators 4 33 This chapter is for system administrators who use the web manager to configure the consoleserver and its users. For information on how to configure the console server using vi or CommandLine Interface (CLI), please consult the Cyclades ACS 5000 Command Reference G...
Page 43 - Logging Into the W eb M anager; O verview of Adm inistrative M odes; Wizard mode
Logging Into the W eb M anager The following procedure describes the login process to the web manager and what should beexpected the first time you log in to the console server. To log into the web manager: 1. Enter the IP address of the console server in the address field of your browser. NOTE: The...
Page 44 - Expert mode
Figure 4.2: Example of Web Manager Form in Wizard Mode Expert mode Expert is the default mode when logging in to the console server. The following is a typicalconsole server screen in Expert mode. The main difference in the interface when you switchbetween the two modes is the addition of a top menu...
Page 45 - Chapter 4: Web Manager for Administrators
Figure 4.3: Example of Web Manager Form in Expert Mode Chapter 4: Web Manager for Administrators 37
Page 47 - Step 1: Security Profile; Pre-defined security profiles; There are three pre-defined security profiles:; Default security profile
Configuring the Console Server inWizard Mode 5 39 Step 1: Security Profile A security profile consists of a set of parameters that can be configured in order to have morecontrol over the services active at any time. Pre-defined security profiles There are three pre-defined security profiles: • Secur...
Page 49 - Review the security advisory and click the; Select a pre-defined security profile by pressing one of the
The first step to configure your console server is to select a security profile. One of thefollowing situations is applicable when you boot the console server. • The console server is starting for the first time or after a reset to factory default. In thissituation when you boot the console server a...
Page 50 - Step 2: Netw ork Settings; To configure the network settings:
CAUTION: Take the required precautions to understand the potential impacts of each individual service configured under the Custom profile. NOTE: It is not possible to continue working in the web manager without selecting a security profile. A reminder dialog box will appear if you attempt to navigat...
Page 51 - Chapter 5: Configuring the Console Server in Wizard Mode
In Wizard mode, the system assumes that all devices will be connected to the serial ports withthe same parameter values. If you need to assign different parameters to the serial ports thateach server or device is connected to, use the Expert mode, Ports - Physical Ports to assignindividual port par...
Page 52 - To set parameters for all serial ports:; Authentication Required
Parameter Options Description Stop Bits 1 [Default] Options are either 1 or 2 Must match the number of stop bits used by thedevices connected to all ports. AuthenticationRequired Check for enabled. Unchecked for disabled. [Default] If the Authentication Required is enabled, user authentication is en...
Page 54 - To change a password:; Step 5: Data Buffering
6. Enter comments to identify the user’s role or configuration in the Comments field(optional). 7. Click OK . 8. Click the apply changes button. To delete a user: 1. Select Step 3: Access . The Access form displays. 2. Select the username to delete. 3. Click Delete . 4. Click apply changes . To chan...
Page 56 - To configure data buffering:
NOTE: You can perform advanced configuration in Expert mode including the option of setting up data buffering separately for individual or groups of serial ports. To configure data buffering: 1. Select Step 4: Data Buffering. 2. Click the Enable Data Buffering checkbox. The Destination pull-down men...
Page 59 - Applications; Configuring the Console Server in Expert M ode; Overview of menus and forms
Applications 6 51 Configuring the Console Server in Expert M ode Most applications require that you set the web manager to Expert mode. If you are in Wizardmode and need to perform advanced configuration, click the Expert button at the bottom of theleft menu panel to switch to Expert mode. If the Wi...
Page 61 - Applications M enu and Form s; Expert; Connecting to the console server; Connecting to devices connected to the serial ports; To connect to the console server:
Number Description 6 Command buttons. The command buttons are common to all web manager screens and are used to try changes, cancel changes, apply changes, reload pages or select the online help. NOTE: The unsaved changes / no unsaved changes indicator at the far right is green (no unsaved changes) ...
Page 62 - To connect to a device through a serial port:; IPDU Power Management; Applications - IPDU Power Mgmt - Outlets Manager
1. Go to Applications - Connect in Expert mode. 2. Click the Connect to ACS 5000 radio button. 3. Click the Connect button. A Java applet viewer appears. NOTE: The login prompt is displayed whenever your security profile is set to Moderate or Open ; otherwise, an authentication form appears. You can...
Page 63 - Edit
• Turn outlets on and off • Cycle power • Lock outlets to prevent accidental changes in power state (Avocent PM PDUs andCyclades IPDUs only) • Unlock the outlets (Avocent PM PDUs and Cyclades IPDUs only) • Assign an alias to the outlet (to identify the device for which it provides power) • Save the ...
Page 67 - Environmental Sensors Information; To view and reset IPDU information:; Clear
Form Heading Description Example Power Factor Phase power factor. N/A Environmental Sensors Information Type (Name) Type of the sensor. Temperature-Internal Current information displays the actual alarm state of the current level based on the configuredthresholds when available. The alarm state can ...
Page 69 - To download Cyclades IPDU software:; To upgrade software on non-Cyclades IPDUs:
Shown Element Type Description Phases thresholds Number field Enter for each phase the current threshold: High Critical, HighWarning, Low Warning and Low Critical. Environmentalthreshold Number field Enter the thresholds for each environmental sensor: High Critical,High Warning, Low Warning and Low ...
Page 70 - To upgrade software on a Avocent PM PDU:; pmfwupgrade; Expert - Applications - PM D Configuration; Expert - Applications - PMD Configuration; Applications - PMD Configuration- General
software is available and for information on how to upgrade the device. To upgrade software on a Avocent PM PDU: 1. Download the new firmware in /tmp directory. 2. Use the pmfwupgrade command to perform the upgrade. See the ACS 5000 Command Reference Guide for more detailed instructions. Expert - Ap...
Page 71 - outlets; To configure an outlet group:; Applications - PMD Configuration - Users Management; To authorize a user for IPDU power management:
Specify groups of outlets using the following format: IPDU_ID [ outlets ] Where IPDU_ID is the name configured for the IPDU (such as ilA) and outlets are numbersseparated with commas or with dashes (to indicate a range), as in the following example: ilA[1,2,5-15] You can assign outlets from more tha...
Page 72 - Outlet entry conventions
3. In the User field, enter the username. 4. In the Outlets field, enter the group name, IPDU number and outlets that the user cancontrol. 5. Click OK . Outlet entry conventions In the most basic case, only the IPDU’s ID and the outlets named in brackets following the IDare needed to specify which o...
Page 73 - Expert - Applications - Term inal Profile M enu; To create a menu for a local server terminal:
Method Description By name If the outlet has been assigned a name, such as “myoutlet,” entering myoutlet is sufficient and no other path name is needed. By IPDU then outlet Entering IPDUB[3] will designate the same outlet. By serial port then outlet Entering !ttyS2-B[3] will designate the same outle...
Page 75 - Network Menu and Forms; Host Settings
Network Menu and Forms 7 67 This chapter describes the Network menu and related forms. The following table provides adescription of the left menu panel. Menu Selection Use This Menu to: Host Settings Configure the network parameters such as Host Name, IP addresses,DNS services and Gateway. Additiona...
Page 76 - General host settings; Disabling and enabling IPv4 or IPv6 protocols; Disabling IPv4
General host settings The following table describes the fields on the Network - Host Settings form. Field name Field type Description Mode Pull-down menu Select Internet protocol from IPv4, IPv6 or Dual-Stack, which allows concurrent use of both IPv4 and IPv6 protocols. NOTE: Selecting IPv4 will ena...
Page 77 - Disabling/Enabling IPv6; IPv4 settings
tab will be disabled. NOTE: If services not supporting IPv6 are needed, you will have to select Dual-Stack (IPv4 and IPv6) and those services will be available only for IPv4. Disabling/Enabling IPv6 If you disable IPv6, configuration of IPv6 addresses will not be allowed and the IPv6 tab willbe disa...
Page 78 - DHCP; IPv6 settings
Check DHCP (checked by default) to have the console server pull network parameters from the DHCP server. If this box is not checked (DHCP disabled), the following fields are displayed inthe form. Field name Field Definition Primary Address Enter the primary IPv4 address of the console server. Networ...
Page 79 - IPv6 Ethernet interfaces; Access to DNS servers
Field name Field Definition Method Select Stateless only , Static or DHCP methods from the pull-down menu for the desired Ethernet port configuration method. Selecting one of these options chooses the method used to obtain and configure IPv6 addresses. Stateless only: IPv6 local addresses will be ob...
Page 80 - Network - Host Settings; apply changes; To configure IPv4 protocol:
• SNMP • Sending SNMP trap • Remote authentication (except to NIS) • Access to hosts • Stateful and stateless packet filtering (firewall) • Static routes • Sending messages and events to SMTP servers • Sending data to data buffering servers • Access to NTP server • FTP for configuration backup • FTP...
Page 81 - To configure IPv6 protocol:
a. Enter the IP address of the console server in the Primary Address field. b. Enter the netmask in the Network Mask field. c. Enter the address of the secondary console server in the Secondary Address field, ifused. d. Specify the network mask of the secondary IP in the Secondary Network Mask field...
Page 82 - Syslog; Add
Syslog You can use the Syslog form to configure how the console server handles system-loggedmessages. The Syslog form allows you to perform the following: • Specify one or more syslog servers to receive syslog messages related to ports. • Specify rules for filtering messages. The top field on the fo...
Page 83 - Chapter 7: Network Menu and Forms
VPN Connections Virtual Private Network (VPN) enables a secured communication between the console serverand a remote network by utilizing a gateway and creating a secured connection between theconsole server and the gateway. IPSec is the protocol used to construct the secure tunnel. IPSecprovides en...
Page 87 - Firew all Configuration
4. For SNMP v1 or v2 configuration, enter or change the following information: a. Enter the community name in the Community field. b. Enter the source IP address or range of IP addresses in the Source field. 5. For SNMP v3 configuration, enter or change the following information: a. Enter the userna...
Page 88 - Edit button; Delete button; Add button
• Edit default chains • Delete user-added chains • Add new chains • Edit rules for chains Edit button Selecting one of the default chains and pressing the Edit button opens the Edit Chain dialog box. Only the policy can be edited for a default chain. The options are ACCEPT and DROP. NOTE: User-defin...
Page 89 - Inverted checkboxes; Target pull-down menu options; or; Source or destination IP and mask
Figure 7.1: Expert - Firewall Configuration Add Rule and Edit Rule Dialog Boxes Inverted checkboxes If the Inverted checkbox is enabled for the corresponding option, the target action is performed on packets that do not match any of the criteria specified in that line. For example, if you select DRO...
Page 90 - Numeric protocol fields; TCP protocol fields; UDP protocol fields
Numeric protocol fields If Numeric is selected as the protocol when specifying a rule, a text field appears to the right of the menu for the desired number. TCP protocol fields If TCP is selected as the protocol when specifying a rule, the additional fields shown in thefollowing table appear on the ...
Page 91 - LOG target
ICMP protocol fields If ICMP is selected as a protocol, the ICMP Type pull-down menu is displayed in the ICMPOptions Section at the bottom of the Firewall Configuration form. Select the ICMP type neededfrom the list. Input interface, output interface and fragments If an interface (such as eth0 or e...
Page 92 - REJECT target; REJECT; Firewall configuration procedures; Network - Firewall Configuration
REJECT target If REJECT is selected from the Target pull-down menu, the following pull-down menu appears. Any Reject with option causes the input packet to be dropped and a reply packet of the specified type to be sent. Field Name Definition Reject with Reject with means that the filter will drop th...
Page 94 - Host Table; To define the console server’s IP address and hostname; Static Routes
Host Table The Host Table form enables you to keep a table of hostnames and IP addresses that composeyour local network and provides information on your environment. To define the console server’s IP address and hostname 1. Go to Network - Host Tables . The Host Tables form appears. 2. To edit a hos...
Page 97 - Security Menu and Forms; Users and G roups
Security Menu and Forms 8 89 Users and G roups The Users and Groups form allows you to perform the following tasks: • Set up user access to the console server's web manager • Assign users to specific groups that share common access rights • Assign or change passwords • Create new groups and add to t...
Page 98 - Adding a User; Adding a Group
Adding a User If you click the Add button on the Security - Users and Groups form under the Users List, the Add User dialog box appears. The following table describes the fields in the Add User dialogbox. Field Name Definition User Name Name of the user to be added. Password The password associated ...
Page 99 - To change a user’s password:; Active Ports Sessions
2. Select the name of a user or group to delete. 3. Click Delete . 4. Click apply changes . To change a user’s password: 1. Go to Security - Users and Groups. The Users and Groups form displays. 2. Select the name of the user whose password you wish to change. 3. Click Change Password . The Change U...
Page 100 - To view, kill or refresh active user sessions:; Security - Active Ports Sessions; Authentication
form to view who is logged into each port and the processes they are running. Open sessionsare displayed with their identification and statistical data, the related data such as CPU usagefor a specific client, JCPU processes and PCPU processing time. The Kill Sessions and Refresh buttons either end ...
Page 101 - Configuring authentication for console server logins; To configure the console server's login authentication method:; Go to
Configuring authentication for console server logins The default authentication method for the console server is Local. You can either accept thedefault or select another authentication method from the Unit Authentication pull-down menuon the AuthType form. Any authentication method selected for the...
Page 102 - To configure a RADIUS authentication server:; Group authorization on RADIUS; To configure a TACACS+ authentication server:
To configure a RADIUS authentication server: Perform the following procedure to configure a RADIUS authentication server when theconsole server or any of its ports are configured to use RADIUS authentication method or anyof its variations (Local/RADIUS, RADIUS/Local or RADIUS/DownLocal). 1. Go to Se...
Page 103 - Group authorization on TACACS+
5. To specify a number of times the user can request authentication verification from theserver before sending an authentication failure message to the user, enter a number in theRetries field. 6. Click apply changes . Group authorization on TACACS+ Using an authorization method in addition to auth...
Page 104 - To configure LDAP authentication:; Group Authorization on LDAP
• An account for admin. • If LDAP authentication is specified for the console server, accounts for all users who needto log in to the console server to administer connected devices. • If LDAP authentication is specified for serial ports, accounts for users who needadministrative access to the connec...
Page 106 - To configure a NIS authentication server:
9. Fill in the form according to your local setup of the Kerberos server. 10. Click apply changes . To configure a NIS authentication server: Perform the following procedure to configure a NIS authentication server when the consoleserver or any of its ports are configured to use NIS authentication m...
Page 107 - Custom security profile; Chapter 8: Security Menu and Forms
Custom security profile The Custom Security Profile opens up a dialog box to allow custom configuration of individualprotocols or services. NOTE: By default, a number of protocols and services are enabled in the Custom profile; however, they are configurable to a user's custom requirements. The foll...
Page 108 - The console server is restarting normally.; Serial port settings and security profiles
Other Services Secure Moderate Open Default SNMP N/A N/A Yes N/A RPC N/A N/A Yes N/A ICMP N/A Yes Yes Yes FTP N/A N/A N/A N/A IPSec N/A N/A N/A N/A Table 8.5: Enabled Protocols for Each Security Profile The first step in configuring your console server is to define a security profile. One of thefoll...
Page 109 - To select or configure a security profile:; Security certificates; Certificate for HTTP security
• If you reconfigure the security profile and restart the web manager, you need to make surethe serial ports protocols and access methods match the selected security profile. To select or configure a security profile: The following procedure assumes you have installed a new console server at your si...
Page 111 - Ports Menu and Forms; Physical Ports; To select one or more serial ports:; Shift; To enable or disable serial ports:
Ports Menu and Forms 9 103 Physical Ports By selecting Ports - Physical Ports in Expert mode, you can enable or disable ports and configure parameters for individual or a group of serial ports. You can select contiguous serial ports on the form by using the Shift key or non-contiguous ports by using...
Page 112 - General form; Modify; Connection profiles
4. Click apply changes . General form Under Ports - Physical Ports in Expert Mode, if you select one or more ports from the ports listand click the Modify button, the General form appears. The General form allows you to define general port settings, connect to an IPDU port andselect the connection t...
Page 113 - Terminal Server (TS) profile connection protocols; When configuring serial ports to support terminals, you can:; Chapter 9: Ports Menu and Forms
Protocol Name Result Console (TelnetSSH) Authorized users can use Telnet and/or SSH to connect to theconsole of the connected device simultaneously. When multiplesessions feature is configured, simultaneous Telnet and/or SSHsessions are allowed through the serial port. Console (Raw) Authorized users...
Page 114 - When the attached terminal is turned on and the; Bidirectional Telnet protocol
Protocol Name Result SSHv2 Dedicates a server terminal connected to the selected serial port toaccess a server using the SSHv2 protocol. When the attachedterminal is turned on, the console server opens a SSHv2 session onthe server. The server’s IP address should be specified on the Otherform, Ports ...
Page 115 - Modem and power management connection protocols
Modem and power management connection protocols The following table shows the connection protocols for modems or IPDUs connected to theserial ports. Protocol Name Result PPP-No Auth Starts a PPP session without interactive authentication required.Assumes the specified console server serial port is ...
Page 118 - To configure a power management protocol for an IPDU:
5. To further configure the serial port’s connection protocol: • For user access and authentication methods, see Access on page 112. • To configure modem initialization and PPP options see Other on page 121. 6. If you are finished, click Done . 7. Click apply changes . To configure a power managemen...
Page 120 - Access; To configure user access to serial ports:
Access Under Ports - Physical Ports in Expert Mode, select one or more serial ports and click Modify Port(s) . Select Access form from the tabbed menu. The Access form appears. The following table describes the menu and fields on the Access form. Field Description Authorized Users/Groups Restrict or...
Page 121 - Authentication methods and fallback mechanism
2. Click the Access tab. The Access form appears. 3. To restrict access to one or more users or to a group of users, enter previously defined useror group names in the Authorized Users/Groups field, with names separated by commas. 4. To deny access to one or more users or groups, preface the user or...
Page 122 - To configure a serial port login authentication method:; Ports - Physical Ports; Data Buffering
Authentication Type Definition NISDownLocal Local authentication is performed only when the NIS server is down. Radius Authentication is performed using a Radius authentication server. Radius/Local Radius authentication is tried first, switching to Local if unsuccessful. RadiusDownLocal Local authen...
Page 124 - To configure data buffering for serial ports:
Field Name Definition Timeout (seconds) Amount of time in seconds that the console server will try to discover thehostname. If it cannot be identified in that time, a default name will be assumed. Show Menu Choose from the following options to select what will be shown when connectedto the serial po...
Page 125 - Multi User
12. Click the radio button next to one of the following options: a. Buffer Syslog at all times b. Buffer only when no user is connected to the port 13. Click Done . 14. Click apply changes . To configure alarm notifications to be sent based on the type of buffered data, select Expert - Administratio...
Page 126 - Power Management
Menu Option Description Yes (show menu) More than two simultaneous users can connect to the same serial port. A Sniffer menu is presented to the user and they can choose to: Open a sniff session Open a read/write session Cancel a connection Send a message to other users connected to the same serial ...
Page 128 - To configure a serial port for IPDU power management:
Field Name Definition New User/Group (available only if Allow Users/Groups radio button is selected) Entry field to add a new user/group. Allowed Users/Groups (available only if Allow Users/Groups radio button is selected) View list box of authorized users or groups. Power management while connected...
Page 129 - To configure a serial port for IPMI power management:
8. Click apply changes . NOTE: If you wish to configure IPMI power management on this port, continue to the IPMI configuration procedure below. To configure a serial port for IPMI power management: This procedure assumes you have added the connected IPMI device in the Applications - IPMIPower Mgmt. ...
Page 131 - To configure terminal server connection options:; Click the
4. To change the port number for the serial port, enter another number in the TCP Port field. 5. To assign a name to the port’s IP address, enter an alias in the Port IP Alias field (consoleconnection protocol only). 6. If connecting to a Microsoft Windows Server 2003 operating system through theEme...
Page 132 - Virtual Ports; This section shows you how to define and configure the slaves.
10. For a dedicated terminal, enter the IP address of the desired host in the Host to Connect field. 11. Enter the type of terminal in the Terminal Type field. 12. Click Done . 13. Click apply changes . Virtual Ports NOTE: Virtual Ports is available only for IPv4 protocol. The virtual ports form all...
Page 133 - To cluster console servers or modify cluster configuration:; Ports - Virtual Ports; To assign names to slave ports in the cluster; Port Names
Field Name Definition Remote IP The IP address of the slave. First Remote TCP Port Number The first TCP port number of the slave. The default is 7001. Protocol The communication protocol used by the Slave. The options are Telnetor SSH. Once you have configured the slave console server and defined th...
Page 134 - Ports Status; Refresh
Ports Status The information in the following table is available in Ports - Ports Status in read-only form. Allusers have access to this form. The information on this page gets updated when you click the Refresh button. Column Name Description Port The serial port number. Alias Displays the name (al...
Page 135 - To configure hostname discovery probe and answer strings [Expert]:
Expert - Ports - Hostnam e Discovery An administrator can use the Expert - Ports - Hostname Discovery screen to configure lists ofprobe and answer strings that apply to all serial ports that have been configured for hostnamediscovery. See Hostname Discovery on page 13 for details about how the strin...
Page 137 - Administration Menu and Forms; System Inform ation; Selecting
Administration Menu and Forms 10 129 System Inform ation Selecting Administration - System information in Expert mode displays a form containing information about all of the system parameters as shown in the following table. Information Parameters System Information Serial Number Kernel Version Curr...
Page 138 - To view system information:; Administration - System Information; Notifications; Administration - Notifications
Information Parameters Memory Information MemTotal MemFree Buffers Cached SwapCached Active Inactive HighTotal HighFree LowTotal LowFree SwapTotal SwapFree Dirty Writeback Mapped Slab CommitLimit Committed_AS PageTables VmallocTotal VmallocUsed VmallocChunk Ram Disk Usage Filesystem 1k-blocks Used A...
Page 139 - Email Notifications Entry
Field Name Definition Notification Alarm for Data Buffering Enable by placing a checkmark in this field [unlabeled view table] List of alarm types and triggers [unlabeled dropdown list] Email, pager or SNMP notification methods Table 10.2: Notifications Form Fields Clicking the Add button or selecti...
Page 143 - Port; To set the time and date manually:
Serial ports alarm notification You can configure the notification entry form to monitor the DCD signal so that the systemwill generate an alarm in any of the following events. • A serial console cable is removed from the console server • A device/server attached to the console is turned off The con...
Page 144 - Pacific; To use the custom option to set daylight savings time:
To configure time and date using an NTP server: NTP is disabled by default. 1. Go to Administration - Time/Date in Expert mode. The Time/Date form displays. 2. Select a time zone from the Timezone pull-down list. 3. Select Enable from the Network Time Protocol pull-down menu. 4. Type the IP address ...
Page 145 - Boot Configuration; Administration - Boot Configuration
6. Click apply changes . Boot Configuration Boot configuration defines the location from which the console server loads the operatingsystem. The console server can boot from its internal firmware or from the network. By default,the console server boots from Flash memory. Selecting Administration - B...
Page 146 - To configure the console server boot:
Field Name Definition Fast Ethernet The speed of the Ethernet connection. Select the appropriate Ethernet setting if you need to change the Auto Negotiation (default value): 100BaseT Half-Duplex 100BaseT Full-Duplex 10BaseT Half-Duplex 10BaseT Full-Duplex Fast Ethernet Max.Interrupt Events The maxim...
Page 147 - Backup Configuration; To back up or restore the configuration files using an FTP server:; Administration - Backup Config
Backup Configuration Selecting Administration - Backup Config in Expert mode displays the Backup Configuration form. NOTE: Use an FTP server to save and retrieve your console server configuration. For the backup configuration to work, the FTP server must be on the same subnet. Ensure that it is acce...
Page 148 - Upgrade Firm w are; To upgrade the console server firmware:; Administration - Upgrade Firmware
Upgrade Firm w are Selecting Administration - Upgrade Firmware in Expert mode displays the Upgrade Firmware form. You can use this form to configure an automated upgrade of the console server’sfirmware, which includes the Kernel, applications and configuration files. The firmware isupgradeable usi...
Page 149 - Reboot; To reboot the console server:; O nline Help
Reboot Selecting Administration - Reboot in Expert mode brings up a simple form containing only a Reboot button. Clicking the Reboot button reboots the console server. To reboot the console server: 1. Go to Administration - Reboot in Expert mode. 2. Click the Reboot button. A confirmation dialog box...
Page 150 - To configure the local online help path:; Administration - Online Help
To configure the local online help path: 1. Extract the files using the appropriate unzip utility for your O/S and put them into thedesired directory under the web server’s root directory. This must be a publicly accessibleweb server For example, the following command line would work on a server run...
Page 151 - Appendix A: Technical Specifications; A P P E N D I C E S
143 Appendix A: Technical Specifications Hardware CPU MPC855T (PowerPC Dual-CPU) Memory 128MB DIMM SDRAM min./ 16MB Compact Flash min. Interfaces 1 Ethernet 10/100BT on R-J45 1 RS232 Console on RJ-45 RS232 Serial Ports on RJ-45 Power Internal 100-240VAC, 50/60 Hz Dimensions 17 x 8.5 x 1.75 in (43.18...
Page 153 - Appendices
Appendix B: Safety and environm ental guidelines for rack-m ounting the console server NOTE: Each heading and its contents in this section is also provided in German ( Deutsch ) in italics immediately following the English version. The following considerations should be taken into account when rack-...
Page 156 - Working inside the console server; Turn the console server off.; Electrostatic Discharge (ESD) Precautions; Avoid working in carpeted areas and
CAUTION: Do not push any objects through the openings of the Cyclades ACS 5000 advanced console server. Doing so can cause fire or electric shock by shorting out interior components. Zur Vermeidung von Brandgefahr oder elektrischen Schlägen bitte keine Gegenstände durchdie Öffnungen des Cyclades ACS...
Page 159 - Appendix C: Technical Support; Call the Avocent Technical Support location nearest you.
Appendix C: Technical Support Our Technical Support staff is ready to assist you with any installation or operating issues youencounter with your Avocent product. If an issue should develop, follow the steps below forthe fastest possible service. To resolve an issue: 1. Check the pertinent section o...
Page 161 - For Technical Support:
590-815-501B For Technical Support: www.avocent.com/support