Chapter 1: Introduction ..........7 Overview ....................8 Product Models and Configurations ............. 8 Connectors on the AlterPath ACS ............10 Accessing ACS and Connected Devices ..........10 Web Manager ..................11 Prerequisites for Using the Web Manager ......... 11 Types of Users ..................
Page 4
Contents Rule ..................... 17 Add Rule and Edit Rule Options ............ 18 SNMP ....................23 Notifications, Alarms, and Data Buffering ........24 Syslog Servers ................24 Prerequisites for Logging to Syslog Servers ....... 24 Administering Users of Connected Devices ........25 Planning Access to Connected Devices .........
Page 6
Contents Custom Security Profile .............. 84 Serial Port Settings and Security Profiles ........87 Step 2: Network Settings ..............91 Step 3: Port Profile ................. 94 Step 4: Access ................. 97 Step 5: Data Buffering ..............102 Step 6: System Log ............... 107 Chapter 6: Configuring the ACS in Expert Mode 111 Overview of Menus and Forms ............
Page 7
Custom Security Profile ............237 Serial Port Settings and Security Profiles ......... 240 Security Certificates ..............246 Certificate for HTTP Security ........... 246 User Configured Digital Certificate .......... 246 X.509 Certificate on SSH ............246 AlterPath ACS Installation, Administration, and User’s Guide...
Page 8
Contents Chapter 10: Ports Menu & Forms ......247 Physical Ports ................249 General ..................251 Connection Profiles ..............252 Console Access Server (CAS) Profile Connection Protocols ... 253 Terminal Server (TS) Profile Connection Protocols ....253 Bidirectional Telnet Protocol ............ 255 Modem and Power Management Connection Protocols ...
Page 9
Working inside the AlterPath ACS ..........334 Replacing the Battery ............... 335 FCC Warning Statement ..............335 Notice About FCC Compliance for all AlterPath ACS Models ..336 Canadian DOC Notice ..............336 Aviso de Precaución S-Mark Argentina .......... 336 Trabajar dentro del AlterPath ACS ..........
Page 11
Figure 1-1: ACS Front with PCMCIA Card Slots ......8 ACS Back with Connectors .......... 8 Figure 1-2: AlterPath ACS family of advanced console servers ..9 Figure 1-3: Figure 1-4: ACS Connectors............10 IPDU Integration With ACS ........27 Figure 1-5: ACS Setup Example............
Page 12
Figures Administrator > Web Manager Buttons ...... 74 Figure 4-1: Figure 4-2: Administrator > Web Manager Login Form ....77 Figure 4-3: Administrator > Multi Administrator Login Message 78 Administrator > Security Advisory Message....79 Figure 4-4: Example of Web Manager Form in Wizard Mode ..80 Figure 4-5: Example of Web Manager Form in Expert Mode ..
Page 13
Figure 7-24: Expert > Applications > Terminal Profile Menu ..153 Expert >Terminal Profile Menu “Add Option” Dialog Figure 7-25: Box ................153 Expert > Terminal Profile Menu Example ....154 Figure 7-26: AlterPath ACS Installation, Administration, and User’s Guide xiii...
Page 21
Tables Typographic Conventions..........4 Table v-1: Other Terms and Conventions ......... 5 Table v-2: Model Numbers and Configuration Options ....8 Table 1-1: Table 1-2: Enabled services to access the ACS under each security profile................13 Enabled services to access the serial ports under each Table 1-3: profile.
Page 22
Tables Regular User > Outlet Management Buttons ....64 Table 3-4: Table 3-5: Regular User > Information on the View IPDUs Info Form ..................65 Table 3-6: Regular User > IPDU Multi-Outlet Ctrl. Form Icons..68 Regular User > Password Management Form....69 Table 3-7: Administrator >...
Page 23
Table 9-2: Expert > Add User Dialog Field Names and Definitions..................219 Expert > Active Ports Sessions Information....223 Table 9-3: Tasks for Setting up Authentication Servers....227 Table 9-4: AlterPath ACS Installation, Administration, and User’s Guide xxiii...
Page 24
Tables Expert > Enabled services to access the ACS under each Table 9-5: security profile............. 238 Table 9-6: Expert > Enabled services to access the serial ports under each security profile............ 238 Expert > Enabled protocols for each security profile Table 9-7: shown with a check mark.
Page 25
Expert > Backup Config Type Storage Device Form.. 322 Table 11-9: Table 11-10: Expert > Upgrade Firmware Form Fields ....324 AlterPath ACS Installation, Administration, and User’s Guide...
Page 27
Procedures To check Java Plug-in Support in the Browser.......... 38 To Install JRE Version 1.4.2 or later and Register the Plug-in....39 To rack-mount ACS, perform the following steps: ........40 To Connect Devices to Serial Ports ............41 To Connect to the Console Port ..............42 To Power on the ACS ................
Page 28
To Configure Users to Manage Power Outlets on IPDUs ....... 134 To Specify IPDU Names, Alarms, Syslogging........136 To Download AlterPath PM Software From Cyclades......138 To Upgrade Software on an AlterPath PM ..........139 To Power On or Power Off a Group of Outlets in the Same Power State143 To Power On or Power Off a Group of Outlets in Different Power State143 To Lock or Unlock a Group of Outlets in the Same Power State....
Page 29
To Configure a Serial Port Connection Protocol for a Console Connection ........................256 To Configure a Serial Port Connection Protocol for a Bidirectional Telnet........................258 To Configure a Serial Port Connection Protocol for a Terminal Server.. 260 AlterPath ACS Installation, Administration, and User’s Guide xxix...
Page 30
Procedures To Configure a Serial Port Connection Protocol for an External Modem........................262 To Configure a Power Management Protocol for an IPDU..... 264 To Associate an Alias to a Serial Port ............. 267 To Configure Serial Port Settings to Match the connected devices..267 To Configure User Access to Serial Ports ..........
Before You Begin This installation, administration, and user’s guide provides background information and procedures for installing, configuring, and administering the Cyclades™ AlterPath ACS and for accessing connected servers and other connected devices. Audience This manual is intended for installers and system administrators of the ACS and for users who may be authorized to connect to devices, to manage power through the ACS, and to monitor the ACS’s temperature.
Before You Begin Document Organization The document contains the following chapters: 1: Introduction An overview of the features of the AlterPath ACS and necessary prerequisite information for understanding the rest of the information in this guide. 2: Installation and Configuration...
Page 33
Appendix B details safety information. Index Provides a way to look up terms. In the online version of this manual, clicking the terms in the index brings you to where they are used in the manual. AlterPath ACS Installation, Administration, and User’s Guide...
Before You Begin Related Documents The following document for the Cyclades AlterPath ACS is shipped with the product. • AlterPath ACS Quick Start Guide (hard-copy) The following documents for Cyclades AlterPath products mentioned in this guide are on the Documentation CD shipped with the product and they are also available at: http://www.cyclades.com/docs...
Cyclades regional support centers. Cyclades Technical Training Cyclades offers a suite of technical courses to increase your knowledge of the AlterPath ACS. To learn more about Cyclades Technical Training Center and offerings, please visit our website at www.cyclades.com/training, call us at 1-888-292-5233, or send an email to training@cyclades.com.
Page 36
Before You Begin http://www.cyclades.com/support/downloads.php to download the latest firmware. See “Upgrade Firmware” on page 323 for instructions on how to upgrade the firmware on your AlterPath ACS.
Introduction This chapter introduces the AlterPath ACS family of advanced console servers, provides an overview of its features, and briefly describes the features for understanding the information and procedures in the rest of this manual. Overview Page 8 AlterPath ACS Models and Configurations...
Figure 1-2: ACS Back with Connectors Product Models and Configurations There are two models of the AlterPath ACS based on the number of power supplies, and five models based on the number of serial ports. In addition there are -48VDC single or dual power supply models available, which are used in certain countries and industries.
ATP0010 ATP0050 AlterPath ACS16 ATP0100 ATP0150 AlterPath ACS32 ATP0190 ATP0200 AlterPath ACS48 The following figure illustrates the AlterPath ACS family of advanced console servers. Figure 1-3: AlterPath ACS family of advanced console servers AlterPath ACS Installation, Administration, and User’s Guide...
Introduction Connectors on the AlterPath ACS The following figure depicts the connectors on the back of an ACS8. Power Supplies Ethernet Port Serial Ports Console Port Figure 1-4: ACS Connectors The number of serial ports and power supplies depends on the model, see table 1-1 for model numbers and configurations options.
When DHCP is enabled, a leased IP address is assigned to ACS. The leased IP address may change every time ACS reboots. Therefore, an additional step needs to be taken to find out the dynamically-assigned IP AlterPath ACS Installation, Administration, and User’s Guide...
Manager features. Security The AlterPath ACS includes a set of security profiles that consists of predefined parameters to control access to ACS and its serial ports. This feature provides more control over the services that are active at any one time.
Access to Serial Ports Secure Moderate Open Custom Default Console (Telnet) Console (SSH) Console (Raw) Serial Port Authentication Bidirect (Dynamic Mode Support) 1-The Default security profile parameters is the same as Moderate profile. AlterPath ACS Installation, Administration, and User’s Guide...
Introduction Table 1-4: Enabled protocols for each profile shown with a check mark. Other Services Secure Moderate Open Custom Default SNMP ICMP IPSec 1-The Default security profile parameters is the same as Moderate profile. Authentication ACS supports a number of authentication methods that can help the administrator with the user management.
Page 45
Radius authentication is tried first, switching to Radius/Local Local if unsuccessful. Local authentication is performed only when RadiusDownLocal the Radius server is down. Authentication is performed using a TACACS+ TACACS+ authentication server. AlterPath ACS Installation, Administration, and User’s Guide...
Introduction Authentication Type Definition TACACS+ authentication is tried first, TACACS+/Local switching to Local if unsuccessful. Local authentication is tried only when the TACACS+DownLocal TACACS+ server is down. The ACS administrator can set up VPN connections to establish an encrypted communications between the ACS and a host on a remote network. The encryption creates a security tunnel for a dedicated communications.
When a packet is filtered, its characteristics are compared against the rules one-by-one. All defined characteristics must match. If no rules are found then the default action for that chain is applied. AlterPath ACS Installation, Administration, and User’s Guide...
Introduction Administrators can do the following to specify packet filtering: • Add a new chain and specify rules for that chain • Add new rules to existing chains • Edit a built-in chain or delete the built-in chain rules Add Rule and Edit Rule Options When you add or edit a rule you can define any of the options described in the following table.
Specifying any of the flags: “SYN” (synchronize), “ACK” TCP Flags (acknowledge), “FIN” (finish), “RST” (reset), “URG” (urgent), “PSH” (push), and one of the “Any,” “Set,” or “Unset” conditions, filters TCP packets for the specified flag and the selected condition. AlterPath ACS Installation, Administration, and User’s Guide...
Introduction UDP Protocol Options When you select UDP as a protocol when specifying a rule, you can select the UDP options defined in the following table. Table 1-8: UDP Protocol Packet Filtering Options Field Definition Specify a source or destination port number for filtering in the Source Port “Source Port”...
Page 51
The “Target” is the action to be performed on an IP packet that matches all the criteria specified in a rule. The target actions are: • ACCEPT • DROP • RETURN • • REJECT AlterPath ACS Installation, Administration, and User’s Guide...
Introduction If the “LOG” and “REJECT” targets are selected, additional options are available. The following table describes the options for the “LOG” Target. Table 1-9: LOG Target Action Options Options Definition emerg Log Level alert crit warning notice info debug The prefix to use in the log entry.
See “To Configure SNMP” on page 191. To Activate the SNMP Service. See “Services” on page 193 To configure one or more serial ports See “SNMP Trap to send SNMP traps. Notifications Entry” on page AlterPath ACS Installation, Administration, and User’s Guide...
Introduction Notifications, Alarms, and Data Buffering The ACS administrator can setup logging, notifications, and alarms to alert administrators about problems. System generated messages on ACS and the connected servers or devices can be sent to syslog servers for handling. The administrator can also configure data buffering to store data from communication on serial ports for monitoring.
List all devices that need to be connected to IPDUs and the users who need to access them. Configuring Access to Connected Devices During hardware installation of ACS, the installer connects the servers, devices, and any IPDUs to the serial ports. AlterPath ACS Installation, Administration, and User’s Guide...
Introduction During software configuration, the ACS administrator performs the common tasks listed in the following table. Table 1-10: Tasks for Configuring Access to Connected Devices Task Where documented Configure a serial port connection protocol Page 256 for a console connection Configure user access to serial ports.
“To Delete, Add, or Edit an IPMI Device to management Enable or Disable IPMI Power Management” on page 148 Configure ports for power management by “To Configure a Serial Port for IPDU or authorized users IPMI Power Management” on page 285. AlterPath ACS Installation, Administration, and User’s Guide...
IPMI devices while logged into the ACS with administrative rights. The ipmitool command is documented in the AlterPath ACS Installation, Administration, and User’s Guide. Options for Managing Power The sections listed below describe the different ways that the authorized users can perform power management through ACS.
ACS administrators can use the ipmitool command to manage power on IPMI devices while logged into the ACS with administrative rights. The ipmitool command is documented in the AlterPath ACS Command Reference Guide. AlterPath ACS Installation, Administration, and User’s Guide...
Chapter 2 Installation and Configuration This chapter covers the topics listed in the following table. Shipping Box Contents Page 32 Important Pre-Installation Requirements Page 38 Basic Installation Procedures Page 39 Other Methods of Accessing the Web Manager Page 49 Installing PCMCIA Cards Page 51 Connecting AlterPath PM IPDUs Page 52...
The list is numbered for internal cross-referencing among descriptions within this table. Table 2-1: Shipping Box Contents for ACS4 - ACS48 Item Description Purpose PAC0266 Documentation CD PDF copies of this guide and all other Cyclades product documents.
Page 63
DC single or dual this table or if you have power supply special requirements. products. CAB0010 NEMA5--15P. Flat United States and Canada blades with round grounding pin. CAB0037 Schuko. Round pin Continental Europe attachment plug. AlterPath ACS Installation, Administration, and User’s Guide...
Page 64
Installation and Configuration Item Description Purpose CAB0055 Oblique flat blades Australia and New Zealand with ground. CAB0056/ Rectangular blade UK and Ireland CAB0104 plug. CAB0278 Flat blades with Japan round grounding pin. ADB0017 RJ45 to DB25F To connect the console port crossover adapter to a computer that has a DB- 25 male connector.
Use to mount the ACS to a brackets with rack or cabinet. To mount on 8 - screws (2 a wall, order the brackets spares) under part number: HAR0220. Table 2-2: Shipping Box Contents for ACS1 Item Description Purpose AlterPath ACS Installation, Administration, and User’s Guide...
Page 66
Installation and Configuration PAC0266 Documentation CD PDF copies of this guide and all other Cyclades product documents. PAC0199 AlterPath ACS Basic installation guide in QuickStart Guide printed format. Written for users experienced in installing Cyclades products. ADB0036 RJ45 to DB9F...
Page 67
Power supply for ACS1. +5V/2.5A CAB0052 Power Cable United States and Canada 6ft. 2-Pin CAB0053 Schuko. Round pin Continental Europe CAB0074 Oblique flat blades Australia and New Zealand CAB0075 Rectangular blades UK and Ireland AlterPath ACS Installation, Administration, and User’s Guide...
Installation and Configuration Important Pre-installation Requirements Before installing and configuring ACS, ensure that you have the following: • Root Access on your local UNIX machine in order to use the serial ports. • An appropriate Terminal application for your operating system. •...
“Mounting the ACS” on page 40 Make an Ethernet connection “Making an Ethernet Connection” on page 41 Connect servers and other devices to be “Connecting Servers and Other Devices to managed through the ACS ACS” on page 41 AlterPath ACS Installation, Administration, and User’s Guide...
Installation and Configuration Task Where Documented Make a direct (terminal) connection to “Making a Direct Connection to Configure the prepare ACS for basic network Network Parameters.” on page 42 configuration Power on the ACS and the connected “Powering on the ACS and the Connected devices Devices”...
Note: For AlterPath ACS16 and AlterPath ACS32 models with single or dual DC power supplies, make sure you use shielded cables when connecting devices to the serial ports. Shielded cables are required to comply with NEBS Level 3 certification on these models. AlterPath ACS Installation, Administration, and User’s Guide...
Installation and Configuration Making a Direct Connection to Configure the Network Parameters. Perform the following steps to connect a terminal or a computer to the console port of the ACS. On a PC, ensure that HyperTerminal or another terminal emulation program is installed on the Windows operating system.
In preparation to make ACS available on the network, collect the following information from your system administrator and proceed with the network configuration procedure. • Hostname • An IP address for ACS • Domain name AlterPath ACS Installation, Administration, and User’s Guide...
Installation and Configuration • DNS IP address • Gateway IP address • Network mask • NTP server’s IP address (if you are using a time/date server) Performing Basic Network Configuration Using the wiz Command The following procedure assumes that a hardware connection is made between the ACS’s console port and the COM port of a computer.
1. Launch the Configuration Wizard by entering the wiz command. [root@CAS root]# wiz As shown in the sample screen below, the system brings up the configuration wizard banner and begins running the wizard. AlterPath ACS Installation, Administration, and User’s Guide...
Page 76
Installation and Configuration 2. At the prompt, enter n to change the defaults. Set to defaults (y/n)[n]: n 3. Press Enter to accept the default hostname, otherwise enter your own hostname. Hostname [CAS]: fremont_branch_ACS 4. Press Enter to keep DHCP enabled, or enter “n” to specify a static IP address for ACS.
Page 77
ACS may be set up with a static IP address at your site. By default, ACS uses the IP address provided by the DHCP server. If your network does not use DHCP, then ACS defaults to 192.168.160.10. AlterPath ACS Installation, Administration, and User’s Guide...
Installation and Configuration Selecting A Security Profile Using the Web Manager After the initial configuration, connect to the Web Manager by entering the IP address of the ACS in a supported browser. Note: Once you login to the Web Manager, a Security Profile must be selected in order to further configure ACS using the Web Manager.
Wizard Mode" Web Manager in Expert Mode. Appendix 6 "Configuring the ACS in Expert Mode" Other Methods of Accessing the Web Manager You can access the Web Manager using one of the following methods. AlterPath ACS Installation, Administration, and User’s Guide...
This procedure assumes that DHCP is enabled, and that you are able to obtain the dynamic IP address that is currently assigned to ACS. 1. Mount the AlterPath ACS. 2. Connect computers and other devices to be managed through the ACS.
To see a list of supported PCMCIA cards go to http://www.cyclades.com/ products/3/alterpath_acs, or www.cyclades.com > Products > IT Infrastructure Management > AlterPath ACS > Click here for a list of supported PCMCIA cards. To Install a PCMCIA Card 1. Insert the PCMCIA card into slot 1 or slot 2.
Installation and Configuration Figure 2-4: PCMCIA Eject Button in Web Manager 2. Physically remove the card from the slot. To Configure a PCMCIA Card See Chapter 8, “To Configure a PCMCIA Card”, and the sections related to the type of card you need to configure. Connecting AlterPath PM IPDUs You can connect AlterPath Power Management (PM) intelligent power distribution units (IPDUs) to the serial ports on the ACS using an RJ-45 to RJ-...
AlterPath PM that is connected to the serial port on ACS. 2. Connect the other end of the cable to the “IN” port of the next AlterPath 3. Repeat Steps 1 and 2 until you have connected the desired number of AlterPath PMs. AlterPath ACS Installation, Administration, and User’s Guide...
Page 66 Security Page 69 Using the Web Manager ACS users perform most tasks through the Cyclades Web Manager. The Web Manager runs in a browser and provides a real-time view of all the equipment that is connected to the ACS.
Web Manager for Regular Users The ACS administrator can use the Web Manager to configure users and ports. An authorized user can access connected devices through the Web Manager to troubleshoot, maintain, recycle power, and reboot connected devices. Logging in to the Web Manager 1.
The form in the middle changes according to which menu option is selected. The following table illustrates the functions that are common to all the forms. Table 3-1: Common Screen Information Form Area Purpose Click this button to log out. AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users Table 3-1: Common Screen Information (Continued) Form Area Purpose Displays the hostname and IP address assigned during initial configuration, and the model number of the ACS. Brings up the online help. Connect When you select the “Connect” option, the following form appears. Figure 3-3: Regular User >...
ACS followed by the session type, in this case “ssh”. Figure 3-4: Java Applet The following table describes the available buttons in the Java applet: Table 3-2: Java Applet Buttons Button Purpose To send a break to the terminal AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users Table 3-2: (Continued)Java Applet Buttons Button Purpose To disconnect from the Java applet Select the left icon to reconnect to the server or device; or select the right icon to end the session and disconnect from the Java applet. Connect to Serial Ports The list of serial ports includes the port names or administrator-defined aliases only for ports you have permission to access.
To use Telnet in a shell, enter the following command: telnet hostname | IP_address TCP_port_number To Close a Telnet Session Enter the Telnet hotkey defined for the client. The default is “Ctrl ]” and “q” to quit. AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users To Use SSH to Connect to a Device Through a Serial Port For this procedure, you need the username configured to access the serial port, the TCP port number, and the hostname of the ACS or its IP address. •...
Figure 3-6: Regular User > Outlets Manager (no permissions) The following form appears if you have permission to manage power on one or more outlets of the AlterPath PM. Figure 3-7: Regular User > Outlets Manager (with permissions) AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users The form shows separate entries for each serial port configured for power management, a name for the configured serial port if one is defined by the administrator, and the number of IPDUs connected. The matrix displays a line item for each outlet you are authorized to manage.
Whether syslogging has been configured for messages Syslog from this IPDU. Whether a buzzer has been configured to sound when Buzzer a specified alarm threshold is exceeded. Total number of outlets on all connected IPDUs. Number of Outlets AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users Table 3-5: Regular User > Information on the View IPDUs Info Form Description Example Whether over current protection is enabled (to prevent Over Current outlets from being turned on if the current on the Protection IPDU exceeds the specified threshold).
Figure 3-9: Regular User > IPDU Multi-Outlet (no permissions) The following form appears if you have permission to view and control the outlets that a multi power supply server or device is connected to. AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Regular Users Figure 3-10: Regular User > IPDU Multi-Outlet (with permissions) Notice in the above figure that the first line of each group, the light bulb, the lock icon, and the Cycle button operate over the entire group. The light bulb and lock icons next to the individual outlets are used to display the status of each outlet but cannot be used to control the individual outlets.
3. Enter the new password in the “New Password” and the “Repeat New Password” fields. 4. Click OK. 5. Log out and log in using your new password to verify your password change. AlterPath ACS Installation, Administration, and User’s Guide...
This chapter is for system administrators who use the Web Manager to configure the ACS and its users. For information on how to configure ACS using vi or Command Line Interface (CLI), please consult the AlterPath ACS Command Reference Guide.
Web Manager for Administrators Cyclades Web Manager ACS administrators perform most tasks through the Cyclades Web Manager either locally or from a remote location. The Web Manager provides a real- time view of the equipment that is connected to the ACS.
Specify Message Filtering” on page 165“ Configure devices for IPMI power “IPMI Power Management” on page 145 management. Select an authentication method for “Authentication” on page 224 accessing connected devices. Configure packet filtering. “Firewall Configuration” on page 194 AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Administrators Common Features of Administrator Forms The common features of all Web Manager forms for ACS administrators are described in the following sections. • Buttons and ACS Information • Getting more information Buttons and ACS Information The following figure shows the control buttons that display at the bottom of the form when the logged in user is an administrator.
Click the “apply changes” If “try changes” has not been previously button clicked, updates the appropriate configuration files. Overwrites the backed up copy of the configuration files. AlterPath ACS Installation, Administration, and User’s Guide...
Click this button to log out. Displays the hostname, IP address assigned during initial configuration, and the model number of the AlterPath ACS. Logging Into the Web Manager The following procedure describes the login process to the Web Manager, and what should be expected the first time you login to ACS.
Caution: It is important to change the “root” password as soon as possible to avoid security breaches. If another administrator is already logged in, the dialog box shown in the following screen example appears. AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Administrators Figure 4-3: Administrator > Multi Administrator Login Message Click the appropriate radio button and then click Apply. Note: The following Security Advisory appears the first time ACS is accessed. Browser’s pop-up blocker should be disabled for this dialog box to appear.
The ACS Web Manager operates in two modes: 1. Wizard 2. Expert In Wizard mode, the Expert button displays. In Expert mode, the Wizard button displays. Clicking these buttons toggles between Wizard and Expert mode. Expert is the default mode. AlterPath ACS Installation, Administration, and User’s Guide...
Web Manager for Administrators Wizard Mode The Wizard mode is designed to simplify the setup and configuration process by guiding the administrator through six configuration steps. When you log in to ACS as an administrator or as a user with administrative privileges, by default the system point to Expert Mode>Ports>Ports Status form.
Chapter 5 Configuring ACS in Wizard Mode There are six configuration steps displayed in the menu panel of the Web Manager in Wizard mode. The following table lists the sections where the steps are described. Step 1: Security Profile Page 83 Step 2: Network Settings Page 91 Step 3: Port Profile...
Configuring ACS in Wizard Mode Note: SSH root access is enabled when the security profile is set to “Moderate” or “Open”. If a “Secured” security profile is selected, you need to switch to a “Custom” security profile, and enable “allow root access” option. 2.
Access to Serial Ports Secure Moderate Open Custom Default Console (Telnet) Console (SSH) Console (Raw) Serial Port Authentication Bidirect (Dynamic Mode Support) 1-The Default security profile parameters is the same as Moderate profile. AlterPath ACS Installation, Administration, and User’s Guide...
ICMP IPSec 1-The Default security profile parameters is the same as Moderate profile. The first step in configuring your AlterPath ACS is to select a Security Profile. One of the following situations is applicable when you boot the ACS unit.
The following reminder dialog box appears before you proceed to Step2: Network Setting. Figure 5-2: Security and Serial Ports Configuration Alert AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode To Select or Configure a Security Profile The following procedure assumes you have installed a new ACS at your site, or you have reset the unit to factory default. 1. Enter the assigned IP address of the ACS in your browser and login as an administrator.
4. Select a pre-defined Security Profile by pressing one of the “Secure”, “Moderate”, “Open”, or “Default” profiles, or create a “Custom” profile. The following dialog box appears when you select the “Custom” profile. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Figure 5-5: Custom Security Profile Dialog Box Caution: Take the required precautions to understand the potential impacts of each individual service configured under the "Custom" profile Refer to Table 5-1 on page 85, and the subsequent tables for a comparison of the available services in each security profile.
During initial setup of the ACS, the administrator configures the basic network settings that were required to enable logins through the Web Manager. You can skip this step if the current settings are correct. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode In preparation to configure network settings collect the following information and proceed with the network configuration procedure. • Hostname • An IP address for ACS • Domain name • DNS server’s IP address • Gateway IP address •...
3. Enter the following network information: • Host Name • IP addresses • Network Mask • Domain Name • DNS Server • Gateway IP 4. Select “apply changes” to save configuration to flash. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode 5. Select the “Next” button, or proceed to “Step 3: Port Profile”. Step 3: Port Profile Selecting “Step 3: Port Profile” brings up a form for configuring the Console Access Profile (CAS). The protocol used to access the serial ports can be configured in this form.
Options range from 5–8 1 [Default] Must match the number of stop bits used Stop Bits by the devices connected to all ports. Options are either 1 or 2 AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Table 5-4: Wizard > Serial Port Profile Parameters and Usage (Continued) Parameter Options Description Check for enabled. If the “Authentication Required” is Authentication enabled, user authentication is enforced Required Unchecked for disabled. using the local passwd database. [Default] To specify other authentication methods such as RADIUS, TACACS+, LDAP,...
“admin” group, enabling them to administer the connected devices without the ability to change the configuration of the ACS. By default any user can access any port as long as they have a valid user ID and password. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Figure 5-9: Wizard > Step 4:Access The Access form lists the currently defined Users and has “Add”, “Change Password”, and “Delete” buttons. In the Users list by default, there is a “root” account that cannot be deleted. The “root”...
Select whether the user of this group is a “NonBio” [Default] or a [dropdown list] “BioUser.” The “BioUser” group should only be selected if authentication will be made through the Cyclades AlterPath Bio (biometric authentication). AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Table 5-5: Wizard > Add User Dialog: Field Names and Definitions Field Name Definition Optional. The default shell when the user makes an SSH or a Telnet Shell connection. Choices are: sh [Default] or bash. Optional notes about the user’s role or configuration.
ACS’s IP address. For security reasons, change the “root” password from the default “tslinux” as soon as possible. 1. Select “Step 3: Access.” The “Access” form displays. 2. Select the name of the user whose password you want to change. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode 3. Click “Change Password.” The “Change User Password” dialog box displays. 4. Enter the new password in both fields, and click OK. 5. Click “apply changes.” Step 5: Data Buffering Selecting “Step 5: Data Buffering” brings up a form to allow logging the console data to a data buffer file either locally in ACS or remotely to an external storage source such as an NFS server or Syslog server.
The following figure shows the form when Data Buffering is set to enabled, and the “Destination” is set to “Local”. Figure 5-13:Wizard > Step 5: Data Buffering [Local] The following figure shows the form when data buffering is set to “Destination Remote” AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Figure 5-14:Wizard > Step 5: Data Buffering [Remote] The following table provides description for each field whether local or remote destination is selected. Table 5-6: Wizard > Data Buffering Field Names and Definitions Field Name Definition Where the buffer files should be stored.
(with an adapter) or other storage device in a PCMCIA slot. For a list of supported PCMCIA cards refer to http://www.cyclades.com/products/3/ alterpath_acs AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode Note: You can perform advanced configuration in Expert mode including the option of setting up data buffering separately for individual or groups of serial ports. To Configure Data Buffering 1. Select “Step 4: Data Buffering” 2.
Selecting “Step 6: System Log” brings up a form for identifying one or more syslog servers to receive syslog messages generated by the ACS’ serial ports. Syslogging for IPDUs is also possible, if IPDU power management is configured. See Chapter 7, “IPDU Power Mgmt. AlterPath ACS Installation, Administration, and User’s Guide...
Configuring ACS in Wizard Mode The form appears as shown in the following figure. Figure 5-15:Wizard > Step 6: System Log Note: To configure syslog with data buffering features for specific ports, switch to the Expert Mode, Ports > Physical Ports > Modify Selected Ports > Data Buffering.
Table 5-8: ACS Configuration and Expert Menus Chapters Configuring the ACS in Expert Chapter 6, “Configuring the ACS Mode in Expert Mode Applications Menu [Expert] Chapter 7, “Applications Menu & Forms AlterPath ACS Installation, Administration, and User’s Guide...
Page 140
Configuring ACS in Wizard Mode Table 5-8: ACS Configuration and Expert Menus Chapters Network Menu [Expert] Chapter 8, “Network Menu & Forms Security Menu [Expert] Chapter 9, “Security Menu & Forms Ports Menu [Expert] Chapter 10, “Ports Menu & Forms Administration Menu [Expert] Chapter 11, “Administration Menu &...
Chapter 6 Configuring the ACS in Expert Mode This chapter provides an overview of configuring the ACS Web Manager in Expert Mode. The following chapters in this manual introduces the Expert mode forms and functionality. The Expert mode is designed for the advanced user administrator who needs to configure the ACS beyond the capabilities of the basic wizard mode.
Configuring the ACS in Expert Mode These forms are identified by their tabs. Select the tab to access the desired form. Top Menu Left Menu Tabs Form Area Command buttons Wizard/Expert Figure 6-1: Expert Mode Screen Elements Note: Procedures in this manual use shortcuts to tell how to get to Web Manager forms.
Configuring the ACS in Expert Mode Description of Forms in Expert Mode The following table briefly describes the functionality of each menu and the related forms. For detailed procedures refer to the page where documented for each section. Table 6-2: Expert > Applications Form Use This Form To: Where...
Define or activate the method of Chapter 8, Page 193 Services access (i.e., Telnet, SSH, SNMP, IPSec). Configure static IP tables, and how Chapter 8, Page 194 Firewall packets should be filtered. Configuration AlterPath ACS Installation, Administration, and User’s Guide...
Configuring the ACS in Expert Mode Table 6-3: Expert > Network Menu Selection Use this menu to: Where Documented View information about the local Chapter 8, Page 210 Host Table network environment. View table of hosts; create, edit, and delete hosts. To manually add routes.
Table 6-6: Administration Menu Selection Use this menu to: Where Documented information on the system Chapter 11, Page 302 View System Information hardware, version, file system and PCMCIA cards loaded AlterPath ACS Installation, Administration, and User’s Guide...
Page 148
Defines the settings for loading the operating system in the event that the ACS fails to boot successfully. The AlterPath ACS can boot from its internal firmware or from the network. This section configures the required parameters. Backup Configuration Use a FTP server to save and Chapter 11, Page 320 retrieve your ACS configuration;...
Page 149
Description of Forms in Expert Mode AlterPath ACS Installation, Administration, and User’s Guide...
Chapter 7 Applications Menu & Forms This Chapter describes the “Applications” menu and the related forms. The following table provides a description of the left menu panel and links to the detailed information and procedures. Table 7-1: Expert > Applications Menu Menu Selection Use this menu to: Where...
Applications Menu & Forms Table 7-1: Expert > Applications Menu Menu Selection Use this menu to: Where Documented Configure a menu of commands that will be Page 152 Terminal Profile presented to the user when they power on their Menu computer terminal and login to the ACS.
• Connect to ACS Clicking the “Connect to ACS” radio button and clicking the “Connect” button, brings up a Java applet running an SSH session similar to the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-3: Expert > SSH session Java Applet Note: SSH root access is enabled when the security profile is set to “Moderate” or “Open”. If a “Secured” security profile is selected, you need to switch to a “Custom”...
This procedure logs you into the ACS as a “Regular User” in a SSH session. 1. Go to Applications > Connect in Expert mode. 2. Click the “Connect to ACS” radio button. 3. Click the “Connect” button. A Java applet viewer appears. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Note: If your security profile is set to “Moderate” or “Open” you receive a “login” prompt, otherwise, an authentication form appears. You cannot authenticate unless you change the security profile to “Custom” and enable “allow root access”.
(in seconds) that the system waits between turning on the currently- selected outlet and the next outlet. • Save the current configuration to Flash memory. The following figure shows an Outlets Manager form. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-6: Expert > Applications > IPDU Power Mgmt. > Outlets Manager The following table illustrates what each icon indicates Table 7-2: Expert > Outlets Manager Icons Description Button Purpose Yellow bulbs indicate an outlet is switched on.Gray indicates an outlet is switched off.
1. Go to Applications > IPDU Power Mgmt. > Outlets Manager The “Outlets Manager” form appears. 2. To switch an outlet on or off, click the adjacent light bulb. 3. To lock or unlock an outlet, click the adjacent padlock. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms 4. To momentarily power an outlet off and then on again, click the adjacent “Cycle” button. 5. To change the outlet’s name or the power up interval, click the adjacent “Edit” button. The Edit Outlet dialog box appears. a.
For example, the configuration illustrated in Figure 7-9 there are two sets of data. Master Unit Information and Slave 1 Information. There are two PM8 15A IPDUs are daisy-chained through Serial Port 1. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Table 7-4: Expert > View IPDUs Unit Information Description Example AlterPath PM model number PM8 15A Model AlterPath PM firmware version 1.5.0 Software Version Number of amperes that triggers an alarm or syslog 15.0A Alarm Threshold message if it is reached Current level on the IPDU 0.0A...
Clicking “Add” brings up the following dialog box where you can specify one or more comma-separated user names and one or more outlets. Figure 7-11: Expert > IPDU Power Mgmt. > Users Manager > Add User AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms When a user is added, their name is added to the list on the Users Manager form, as shown in the following figure. To Configure Users to Manage Power Outlets on IPDUs 1. Go to Applications > IPDU Power Mgmt. > Users Manager. The “Users Manager”...
IPDU(s). The following figure shows the Configuration form when two AlterPath PMs are connected to Serial port 1 configured for power management. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-12: Expert > Applications > IPDU Power Mgmt. > Configuration Note: The number of amps shown in the Master Unit (and Slave units if available) pull-down menu varies according to the model of the connected PM. Figure 7- 12 shows number 15 for two 15 amp PMs as a Master and a Slave.
/tmp/pmfirmware file is present and the software version it contains is more recent than the installed version, information about the new version is displayed, and an “Update” button appears on the form. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms To Download AlterPath PM Software From Cyclades You can use this procedure to download software from the Cyclades website. 1. On a computer in the same subnet as the ACS, bring up a browser and go to the download section of the Cyclades website at: http://www.cyclades.com/support/downloads.php...
This procedure requires the following: • A more-recent version of the AlterPath PM software than the one shown on the “Software Upgrade” form, which is available from Cyclades web site. • You downloaded the more-recent version of the AlterPath PM software and copied it into the ACS’s /tmp directory with the filename...
Applications Menu & Forms Figure 7-14: Expert > Applications > IPDU Multi-Outlet Ctrl Whether the power supplies are connected to the same PM or not, all outlets that are configured to the same serial port can be treated as a group and controlled simultaneously from this form.
Cycle button operate over the entire group. The light bulb and lock icons next to the individual outlets are used to display the status of each outlet but cannot be used to control the individual outlets. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-16: Expert > Applications > Multi-Outlet Control Icons The icons in the first line of each group are described in the following table. Table 7-5: Expert > IPDU Multi-Outlet Ctrl form icons Button Purpose A grey light bulb icon indicates that the group is off. A yellow light bulb indicates that the group is on.
Page 173
1. Go to Applications > IPDU Multi-Outlet Ctrl. 2. To power on the group, click the yellow light bulb adjacent to the group name. All of the outlets turns on. 3. To power off the group, do the following steps: AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms a. Click the yellow light bulb icon adjacent to the group name once to turn all of the outlets off. All of the outlets are in the same state. b. To turn all of the outlets on, click the grey light bulb icon adjacent to the group name.
As shown in the following figure, if no IPMI devices have been added previously, only the “Add” button appears. Figure 7-17:Expert > Applications > IPMI Power Mgmt. When an “Add” button or “Edit” button is pressed, a form appears for adding or editing a device. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-18:Expert > IPMI Power Mgmt. “Add/Edit IPMI Device” Dialog Boxes After you fill out the fields or make changes and save the changes, the device is added to the IPMI Devices list or the configuration for the device is changed.
Table 7-7: Expert > IPMI Power Mgmt. Form Icons Button Purpose A yellow light bulb indicates the current state of the device. Clicking the light bulb icon toggles the state of the device. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Button Purpose When the status is unknown, a question mark appears instead of the light bulb. A question mark indicates either of the following conditions. • The device was added or deleted and the changes were not saved. •...
“Power Management” tab. 3. To enable Power Management of a device connected to the current port and plugged into a connected IPDU, click “Enable Power Management on this port.”. The following form appears. AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms Figure 7-20: Expert > Serial Port > Power Management > Enable Power Management 4. Click the “Add” button The “Add Outlet” dialog box appears. Figure 7-21: Expert > Power Management Add Outlet Dialog Box 5. Enter the outlet number(s) - separated by comma - into which the device is connected to.
Figure 7-22: Expert > Serial Port > Power Management > User Permissions 3. Enter a valid user name or group name in the “New User/Group” field, and click “Add.” 4. Click “Done.” 5. Click “apply changes.” AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms To enable IPMI Power Management of an IPMI device connected to the currently-selected port Check the checkbox next to “Enable IPMI on this port.” The “IPMI key” and “IPMI Server” fields appear. Figure 7-23: Expert > Serial Port > Power Management > Enable IPMI 2.
SSH sessions on remote hosts. When you click “Add,” the “Add Option” dialog box appears, as shown in the following figure. Figure 7-25: Expert >Terminal Profile Menu “Add Option” Dialog Box AlterPath ACS Installation, Administration, and User’s Guide...
Applications Menu & Forms For example, you can create a menu called “SSH to Servers” with options that launch SSH connections to several servers, such as the one shown in the following screen example. Figure 7-26: Expert > Terminal Profile Menu Example The command menu then appears when the terminal is powered on.
PCMCIA Management supports several PCMCIA cards including modem, ISDN, GSM, CDMA, wireless LAN, Ethernet LAN, Compact Flash, and IDE drives for data buffer storage. For the list of supported cards go to http:// www.cyclades.com/products/3/alterpath_acs and click on the supported PCMCIA cards.
Network Menu & Forms Menu Selection Use this menu to: Where Documented Configure one or more VPN connections to Page 183 VPN Connections other systems or ACS attached devices. Configure Simple Network Management Page 188 SNMP Protocol (SNMP) with community names, OID and user names.
Network Figure 8-1: Expert > Network > Host Settings [DHCP Enabled] If the “DHCP” is not enabled, then other options appear on the form as shown in the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-2: Expert > Network > Host Settings [DHCP Disabled] The following table provides a brief definition of the Host Settings form fields. Table 8-2: Expert > Host Settings Form Fields Filed Name Field Definition The fully qualified domain name identifying Host Name the specific host computer on the network.
Page 191
DNS Server Address of the backup Domain Name Secondary DNS Server. Server The name that identifies the domain, for Domain Name example, domainname.com. The IP address to the gateway on the subnet. Gateway IP AlterPath ACS Installation, Administration, and User’s Guide...
You need to change the interface to bond0 in order to reference the bonded interface. See “To Configure Network Services” on page 194, or The AlterPath ACS Installation, Administration, and User’s Guide, Chapter 3.
Page 193
Enter a positive integer in the “Updelay” field. This value represents the time that the system will wait to make the primary interface active after it has been detected as up, measured in milliseconds. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms 9. Click “apply changes.” Syslog When Network > Syslog is selected the form shown in the following figure appears. Figure 8-3: Expert > Network > Syslog You can use the Syslog form to configure how the ACS handles system logged messages.
“New Syslog Server” field, and clicking the “Add>>” button. 5. Configure the message filtering as per your requirements. 6. Click “apply changes.” PCMCIA Management When Network > PCMCIA Management is selected the following form appears. AlterPath ACS Installation, Administration, and User’s Guide...
For Configuration details refer to the ACS Command Reference Guide, Chapter 7, Section 7.3 “Generic Dial-Out”. For a list of the supported PCMCIA cards, refer to AlterPath ACS web site at http://www.cyclades.com/products/3/alterpath_acs, or go to www.cyclades.com and follow the links to Products > IT Infrastructure Management >...
Page 197
IDE PCMCIA card in a slot, it automatically mounts and no configuration is necessary through this form. The card information appears under the “Card Type” column as shown in the following figure. 4. Click the Configure button. 5. The “Slot” dialog box appears AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms 6. Select the desired PCMCIA card type from the pull-down menu. 7. Follow the procedure that corresponds to the type of the PCMCIA card you have installed. Page 171 Configuring a Modem PCMCIA Card Page 172 Configuring an ISDN PCMCIA Card Page 175 Configuring a GSM PCMCIA Card...
The phone number that the ACS uses to call back. Phone Number If you click the PPP checkbox, additional fields for a local and remote IP address and a “Call Back” checkbox appear, as shown in the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-6: Expert > PCMCIA Modem Card Configuration Dialog Box - If you enable “Call Back”, the Phone Number field appears on the Slot dialog box, as shown in the following figure. Figure 8-7: Expert > Modem PCMCIA Card Configuration Dialog Box - Call Back...
You can use the “PCMCIA Management” form under “Network” to enable users to connect to the ACS through an ISDN PCMCIA card. When you select ISDN from the pull-down menu, the dialog box shown in the following figure appears. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-8: Expert > ISDN PCMCIA Card Configuration Dialog Box The following table provides a brief description of the fields available in the ISDN dialog box. Table 8-4: Expert > Form Fields for an ISDN Card Field Name Definition Select ISDN from the pull-down menu.
You can use the “PCMCIA Management” form under “Network” to enable a remote user to call into the ACS through an installed and configured GSM PCMCIA card. When you select GSM from the pull-down menu, the dialog box shown in the following figure appears. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-9: Expert > GSM PCMCIA Card Configuration Dialog Box When the “Call Back” checkbox is checked, the Phone Number field appears as shown in the following figure. Figure 8-10: Expert > GSM PCMCIA Card Configuration Dialog Box - Call Back The following table provides a brief description of the fields available in the GSM dialog box.
4. Enter a personal identification number known to the owner of the GSM card in the “PIN Number” field. 5. To enable call back, do the following: a. Check the “Call Back” check box. The “Phone Number” field appears on the Slot dialog box. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms b. Enter a number for the ACS to use to call back the GSM phone. 6. Click OK. 7. Click “apply changes.” Configuring an Ethernet PCMCIA Card You can use the “PCMCIA Management” form under “Network” to configure an Ethernet PCMCIA card.
PCMCIA Compact Flash card or a PCMCIA Hard Disk Drive. When you select Compact Flash/Hard Disk from the pull-down menu, the dialog box shown in the following figure appears. Figure 8-12: Expert > PCMCIA Compact Flash/Hard Disk Configuration Dialog Box AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms The following table provides a brief description of the fields available in the Compact Flash/Hard Disk dialog box. Table 8-7: Expert > Form Fields for a Compact Flash/Hard Disk Field Name Definition Select Compact Flash/Hard Disk from the Pull- [PCMCIA Card] down menu.
The network address of the Ethernet. Network Mask The unique identifier for the wireless access MyPrivateNet point. (ESSID) The communication channel with the access Channel point. The translation of data into code during Encrypted transmission. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Field Name Definition The key or password to decode the encrypted data. To Configure a Wireless LAN PCMCIA Card 1. Install the wireless LAN card and select “Wireless LAN” from the pull- down menu on the PCMCIA Management form. 2.
The local IP address of the CDMA card used Local IP by the ppp connection. The remote IP address of the CDMA card used Remote IP by the ppp connection. The speed used by ACS to access the card. Speed AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Field Name Definition Additional initialization parameter to be sent to Additional the card. CDMA configuration has a default Initialization command sequence to initialize the card, but if additional initialization command is required by the card, it will be added to default command sequence.
ACS and the gateway. IPSec is the protocol used to construct the secure tunnel. IPSec provides encryption and authentication services at the IP level of the protocol stack. When “VPN Connections” is selected under “Network”, the form shown in the following figure appears. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-15: Expert > Network > VPN Connections You can use the form to add a VPN connection or edit one that is already in the list. When you click the “Edit” or “Add” buttons, a “New/Modify Connection”...
The following table describes the fields and options on the form. Check with your system administrator who defined and configured the security protocols, if needed. The information must match exactly on both ends, local and remote. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Table 8-10: Expert > Field and Menu Options for Configuring a VPN Connection Field Name Definition Any descriptive name you want to use to identify this Connection Name connection such as “MYCOMPANYDOMAIN-VPN.” The authentication protocol used, either “ESP” Authentication (Encapsulating Security Payload) or “AH”...
Enter the IP address of the router through which the host’s packets reach the Internet in the “NextHop” fields. d. Enter the netmask for the subnet in the “Subnet” fields in CIDR notation. For example, 192.168.0.0/24 which translates to 255.255.255.0. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms e. If “RSA Key” is selected, generate the key for the ACS (left host) and find out the key from the remote gateway (right host). You can use copy and paste to enter the key in the “RSA Key” field. f.
ACS to an SNMP management application, such as HP Openview, Novell NMS, IBM NetView, or Sun Net Manager. The following table explains the required parameters to complete the SNMP form and the associated dialog boxes. AlterPath ACS Installation, Administration, and User’s Guide...
Table 8-11: Expert > Fields and Menu Options for SNMP Configuration Field or Menu Option Description The email address of the ACS’s administrator, for example, SysContact acs_admin@cyclades.com. The physical location of the ACS. SysLocation SNMP v1 and v2 only. A Community defines an access Community environment.
• To add an SNMPv1/SNMPv2 entry, press the “Add” button under the “SNMPv1/SNMPv2 Configuration” table. • To add an SNMPv3 entry, press the “Add” button at the bottom of the “SNMPv3 Configuration” table. AlterPath ACS Installation, Administration, and User’s Guide...
Page 222
Network Menu & Forms The “New/Modify SNMP Daemon Configuration” dialog box appears. 3. To edit any SNMP configuration, do the following steps. a. To edit an SNMPv1/SNMPv2 entry, select the entry from the “SNMPv1/SNMPv2 Configuration” list and click the “Edit” button. b.
Telnet [enabled by default] • SSH [enabled by default] • SNMP [enabled by default] • IPSec Each of these services is required when Telnet, SSH, SNMP, or VPN are configured, as described in the following table. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Table 8-13: Expert > When Services Must be Enabled Service Name Notes and Where Documented Enable if you select “Console (Telnet)”. See “To Configure a Serial Port Telnet Connection Protocol for a Console Connection” on page 256. Enable if you select “Console (SSH).
• Add new chains • Edit rules for chains “Edit” Button Selecting one of the default chains and pressing the “Edit” button, the “Edit Chain” dialog box shown in the following figure appears. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-22: Expert > Firewall Configuration “Edit Chain” Dialog Box Only the policy can be edited for a default chain. The options are “ACCEPT,” and “DROP.” Note: User-defined chains cannot be edited. If a user-defined chain is selected for editing, the message shown in the following figure appears.
Figure 8-25:Expert > Firewall Configuration “Add Chain” Dialog Box Adding a chain only creates a named entry for the chain. Rules must be configured for the chain after it is added to the list of chains. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms “Edit Rules” Button If the “Edit Rules” button is pressed, a form appears with a list of headings like the one shown in the following figure. The example shows the OUTPUT chain selected for editing. Figure 8-26: Firewall Configuration “Edit Rules for chain_name” Form The buttons shown in the following figure appear at the bottom of the form.
ACCEPT, DROP, RETURN, LOG or REJECT the packet by sending a message, translating the source or the destination IP address, or sending the packet to another user-defined chain. The default target pull-down menu is shown in the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-29:Firewall Configuration “Add Rule” and “Edit Rule” Target Menu Options Source or Destination IP and Mask If you add a value in the “Source IP” field, incoming packets are filtered for the specified IP address, and if you add a value in the “Destination IP” field, outgoing packets are filtered for the specified IP address.
If TCP is selected as the protocol when specifying a rule, the additional fields shown in the following figure appear on the bottom of the form. Figure 8-33:Firewall Configuration “Add Rule” and “Edit Rule” TCP Protocol Fields and Menu Options AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms The following table defines the fields and menu options in the “TCP Options ” Section. Table 8-14: Expert > TCP Options Fields Field/Menu Option Definition A port number for filtering in the “Source Port” or “Destination Source Port Port”...
Page 233
ICMP Protocol Fields If ICMP is selected as a protocol, the “ICMP Type” pull-down menu appears in the “ICMP Options Section” at the bottom of the Firewall Configuration form. The following figure shows the options. AlterPath ACS Installation, Administration, and User’s Guide...
"Inverting" an item negates the selected rules. Rules will apply to Inverted everything except the selected options. The types of packets to be filtered: Fragments • All packets • 2nd, 3rd... fragmented packets • Non-fragmented and 1st fragmented packets AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms LOG Target If you select “LOG” from the “Target” field, the fields and menus shown in the following figure appear in the “LOG Options Section” at the bottom of the form. Figure 8-37:Firewall Configuration “Add Rule” and “Edit Rule” LOG Target Fields The following table defines the menu options and fields in the “LOG Options Section.”...
Network Menu & Forms Table 8-18: Expert > Reject Options Sections Field Name Definition ICMP network prohibited alias. icmp-net-prohibited ICMP host prohibited alias. icmp-host- prohibited Echo reply alias. echo-reply TCP RST packet alias. tcp-reset Note: The packets are matched (using tcp flags and appropriate reject type) with the REJECT target.
Page 239
If you select one of the default chains, the “Edit Chain” dialog box appears. 3. Select the desired policy from the Policy pull-down menu, and then click 4. Click “apply changes.” 5. To edit any rules for this chain, go to "To Edit a Rule" AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms To Add a Rule 1. Go to Network > Firewall Configuration 2. Select the chain to which you want to add a rule from Chain list, and then click the “Edit Rules” button. 3. Click the “Add Rule” button. The “Add Rule”...
The Static Routes form allows you to manually add routes. The Routing Table defines which interface should transmit an IP packet based on destination IP information. Static routes are a quick and effective way to route data from one subnet to another. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Selecting Network > Static Routes brings up the form shown in the following figure. Figure 8-40: Expert > Network > Static Routes Clicking the “Edit” or “Add” buttons brings up a form shown in the following figure.
Figure 8-42: Expert > Static Routes “Add” and “Edit” Dialog Boxes - Network Route The following figure shows the fields and menus that appear when the “Host” route type is selected from the “Route” pull-down menu. AlterPath ACS Installation, Administration, and User’s Guide...
Network Menu & Forms Figure 8-43: Expert > Static Routes “Add” and “Edit” Dialog Boxes - Host Route The following table describes the fields that appear when you select a routing type from the “New/Modify Route” dialog boxes. Table 8-19: Expert > Fields and Menus for Configuring Static Routes Field or Menu Name Definition Choices are “Default,”...
“Host IP” field. 5. Select “Gateway” or “Interface” from the “Go to” pull-down menu and enter the address of the gateway or the name of the interface in the adjacent field. 6. Click “apply changes.” AlterPath ACS Installation, Administration, and User’s Guide...
Chapter 9 Security Menu & Forms This Chapter describes the “Security” menu and the related forms. The following table provides a description of the left menu panel and links to the detailed information and procedures. Table 9-1: Expert > Security Menu Menu Selection Use this menu to: Where Documented...
Security Menu & Forms Users and Groups Users and Groups form allows you to do the following tasks: • Set up user access to the ACS Web Manager • Assign users to specific groups that share common access rights • Assign or change passwords •...
The password associated with the user name. Group On the Group pull-down menu, select “Regular User [Default]” or “Admin.” Note: To configure a user to be able to perform all administrative functions, select the “Admin” group. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Table 9-2: Expert > Add User Dialog Field Names and Definitions (Continued) Field Name Definition Shell Optional. The default shell is /bin/sh when the user makes a SSH or Telnet connection. Comments Optional notes about the user’s role or configuration. Adding a Group If you click the “Add”...
4. Enter the new password in the “New Password” field and enter it again in the “Repeat New Password” field. 5. Click OK. 6. Click “apply changes.” To Add a Group 1. Go to Security > Users and Groups The Users & Groups form displays. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms 2. Under the list of groups, click “Add.” The “Add Group” dialog box displays. 3. Enter the name for the new group in the “Group Name” field. 4. Enter one user name or multiple comma-separated user names in the “Users”...
Where the network connection is from. From Login time in hours and minutes. If login was not on the Login same day, the date of login also appears. How long since last activity. Idle AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Field Name Definition The amount of CPU time consumed by all active processes JCPU including currently running background jobs. The amount of CPU time consumed by the current PCPU process. Name of the current process. What To View, Kill, or Refresh Active User Sessions 1.
Configuring Authentication for ACS Logins The default authentication method for ACS is Local. You can either accept the default or select another authentication method from the “Unit Authentication” pull-down menu on the AuthType form. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Figure 9-6: Expert > Security > Authentication > AuthType Form Any authentication method selected for ACS is used for authentication of any user attempting to log into the ACS through Telnet, SSH, or the Web Manager. To Configure the ACS Login Authentication Method 1.
229 LDAP LDAP, LDAP/Local, or See “To Configure an LDAPDownLocal LDAP Authentication Server” on page 231 Kerberos Kerberos, Kerberos/Local, or See “To Configure a KerberosDownLocal Kerberos Authentication Server” on page 233 AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Table 9-4: Tasks for Setting up Authentication Servers. Method Variations Procedures NIS, Local/NIS, NIS/Local, or See “To Configure a NIS NISDownLocal Authentication Server” on page 235 To Configure a RADIUS Authentication Server Perform the following procedure to configure a RADIUS authentication server when ACS or any of its ports are configured to use RADIUS authentication method or any of its variations (Local/RADIUS, RADIUS/ Local, or RADIUS/DownLocal).
Go to Security > Authentication > TACACS+ in Expert mode. The TACACS+ form appears as shown in the following figure. Figure 9-8: Expert > Security > Authentication > TACACS+ Fill in the form according to your local TACACS+ server configuration. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms To apply “Authorization” in addition to authentication to the box and ports, select the “Enable Raccess Authorization” check box. By default “Raccess Authorization” is disabled, and no additional authorization is implemented. When “Raccess Authorization” is enabled, the authorization level of users trying to access ACS or its ports using TACACS+ authentication is checked.
1. Go to Security > Authentication > LDAP in Expert mode. The “LDAP” form displays with “LDAP Server” and “LDAP Base” fields filled in from with the current values in the /etc/ldap.conf file. AlterPath ACS Installation, Administration, and User’s Guide...
LDAP server is “o,” then replace dc in the base field with o, as in o=value,o=value. 4. Replace the default base name with the name of your LDAP domain. For example, for the LDAP domain name cyclades.com, the correct entry is: dc=cyclades,dc=com. 5. Enable “Secure LDAP”, if required.
Go to Network > Host Table in Expert mode. The “Host Table” form appears. b. Add an entry for ACS if none exists and an entry for the Kerberos server. Click “Add.” AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms The “New/Modify Host” dialog appears. ii. Enter the address in the “IP Address” field. iii. Enter the name in the “Name” field. iv. Enter an optional alias in the “Alias” field. 2. Make sure that time, date, and timezone settings are synchronized on the ACS and on the Kerberos server.
ACS or any of its ports is configured to use NIS authentication method or any of its variations (Local/NIS, NIS/Local, or NISDownLocal). 1. Go to Security > Authentication > NIS in Expert mode. The NIS form displays as shown in the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Figure 9-12:Expert > Security > Authentication > NIS 2. Fill in the form according to your configuration of the NIS server. 3. Click “apply changes.” Security Profiles Selecting Security > Security Profile brings up the form shown in the following figure.
The Custom Security Profile opens up a dialog box to allow custom configuration of individual protocols or services. Note: By default, a number of protocols and services are enabled in the Custom profile, however, they are configurable to user’s custom requirements. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms The following tables illustrate the properties for each of the Security Profiles. The enabled services in each profile is designated with a check mark. Table 9-5: Expert > Enabled services to access the ACS under each security profile. Access to ACS Secure Moderate...
IPSec 1-The Default security profile parameters is the same as Moderate profile. The first step in configuring your AlterPath ACS is to define a Security Profile. One of the following situations is applicable when you boot up the ACS unit.
Security Menu & Forms Serial Port Settings and Security Profiles All serial ports on ACS units shipped from the factory are disabled by default. The administrator can enable ports individually or collectively and assign specific users to individual ports. The following figure shows the default factory settings of serial ports. Figure 9-14: Expert >...
1. Enter the assigned IP address of the ACS in your browser and login as an administrator. The following security warning dialog box appears. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Figure 9-17: Security Advisory Dialog Box Note: Your browser’s pop-up blocker should be disabled for this dialog box to appear. 2. Review the Security Advisory and click the “Close” button. 3. The Web Manager is redirected to Wizard > Step 1: Security Profile The following form is displayed.
4. Select a pre-defined Security Profile by pressing one of the “Secure”, “Moderate”, “Open”, or “Default” profiles, or create a “Custom” profile. The following dialog box appears when you select the “Custom” profile. AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Figure 9-19: Custom Security Profile Dialog Box Caution: Take the required precautions to understand the potential impacts of each individual service configured under the "Custom" profile. Refer to Table 9-5 on page 238, and the subsequent tables for a comparison of the available services in each security profile.
Configure Users and Groups “Users and Groups” on page 218 Configure Serial Ports “Physical Ports” on page 249 Configure Network Settings “Host Settings” on page 158 Configure IPDU Power Management “IPDU Power Mgmt.” on page AlterPath ACS Installation, Administration, and User’s Guide...
Security Menu & Forms Security Certificates ACS generates its own self-signed SSL certificate for HTTPS using OpenSSL. Note: It is highly recommended that you use the “openssl” tool to replace the ACS generated certificate. Certificate for HTTP Security A certificate for HTTP security is created by a CA (Certificate Authority). Certificates are most commonly obtained through generating public and private keys using a public key algorithm like RSA or X.509.
Chapter 10 Ports Menu & Forms This Chapter describes the “Ports” menu and the related forms. The following table provides a description of the left menu panel in the Web Manager and links to the detailed information and procedures. Table 10-1: Expert > Ports Menu Menu Selection Use this menu to: Where Documented...
Ports Menu & Forms Menu Selection Use this menu to: Where Documented View information on the data Page 299 Ports Statistics reception (Rx bytes) and transmission (Tx bytes) on each physical port. View current CAS user(s), Baud rate, frame, parity, break, and overruns.
“Modify Selected Ports” button, and set values for an individual or a group of ports. Selecting “Modify Selected Ports” or “Modify All Ports” option brings up a form with the following six AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms tabs Figure 10-3: Expert > Ports > Physical Ports > “Modify ..Ports ” Tab Options To Select One or More Serial Ports Go to Ports > Physical Ports in Expert mode The Physical Ports form appears. To select a port or ports, do one of the following steps.
Under Ports > Physical Ports in Expert Mode, if you select one or more ports from the ports list and click the Modify button, the General form appears as shown in the following form. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-4: Expert > Ports > Physical Ports > General Form The General form allows you to define general port settings, connect to an IPDU port, and select the connection type to a serial port (SSH, Telnet, or both).
Terminal Server (TS) Profile Connection Protocols When a computer terminal is connected to the console port on a device, a Terminal Server (TS) profile must be defined for the serial port. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Selecting the appropriate connection protocol on the Ports > Physical Ports > General form is part of defining the TS profile. You can configure serial ports to support computer terminals in the following two ways: • Dedicate a terminal to access a single remote server by means of either Telnet, SSHv1, SSHv2, or Raw Socket connections.
Note: If the user does not login within a configurable timeframe, the serial port returns to an idle state. The timeout period can be configured through the Web Manager Ports > Physical Ports > Access form. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms The administrator can build custom menus using the “Terminal Profile Menu” form accessible from Web Manager, Applications > Terminal Profile Menu, or from a terminal window using the command. You should menush_cfg specify the bidirectional shell command, in the Web Manager, /bin/menush Ports >...
3. To change the connection protocol, select one of the options from the “Connection Protocol” pull-down menu: Console (Telnet), Console (SSH), Console (Telnet & SSH), or Console (Raw). The default is Console (Telnet). AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-7:Connection Protocols > Console 4. If you want to change any of the other current settings, see "To Configure Serial Port Settings to Match the connected devices" on page 267. 5. To further configure the serial port’s connection protocol: •...
Ports Menu & Forms 4. If you want to change any of the other current settings, see "To Configure Serial Port Settings to Match the connected devices" on page 267. 5. Go to “Access” tab and configure the following settings: •...
Figure 10-12: Expert > Ports > Physical Ports > Terminal Server Connection 3. To change the connection protocol, select a Terminal Server connection from the “Connection Protocol” pull-down men, “Telnet”, “SSHv1”, “SSHv2”, “Local Terminal”, or “Raw Socket”. Figure 10-13:Connection Protocols > Terminal Server AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms 4. To configure a terminal to automatically connect to ACS, do the following steps. a. Select “Local Terminal” from the “Connection Protocol” pull-down menu. b. Define a terminal profile menu. “Terminal Profile Menu” form is at Expert >...
Ports Menu & Forms 4. If you want to change any of the other current settings, see "To Configure Serial Port Settings to Match the connected devices" on page 267. 5. To further configure the serial port’s connection protocol: • For user access and authentication methods, see "Access"...
3. To change the connection protocol, select “Power Management” from the “Connection Protocol” pull-down menu. Figure 10-19: Connection Protocols > Power Management 4. Enter a desired name for the IPDU in the “Alias” field. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms 5. Select an access method to the IPDU from the “Allow Access by” drop- down menu. The options are SSH, Telnet, or SSH and Telnet. Selecting an access option activates the “Access” and “Other” tabs. 6. Go to “Access” tab. a.
The settings for a serial port must match the connection settings on the connected device. 1. Go to Ports > Physical Ports in Expert mode, and select a port or ports to modify. The General form appears. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-21: Expert > Ports > Physical Ports > Serial Port Settings 2. To change the baud rate, select an option from 2400 to 921600 Kbps from the Baud Rate pull-down menu. The default is 9600, which is the most common baud rate for serially- managed devices.
Under Ports > Physical Ports in Expert Mode, after you select one or more serial ports, and click the Modify Port(s), select the Access form from the tabbed menu. The following form appears. Figure 10-22:Expert > Ports > Physical Ports > Access Form AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms The following table describes the menu and fields on the Access form. Table 10-5: Expert > Access Form Fields Field Description Authorized Users/Groups Restrict or deny access to a serial port by specifying one or more users or groups. You can deny access to one or more users or groups by entering an exclamation point (!) before the user or group name.
Kerberos, LDAP, RADIUS, or TACACS+, the user can get access denial if either the authentication server is down, or it does not authenticate him/her. An authentication fallback mechanism can be AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms defined in case the first authentication level fails. See the following table on authentication methods and fallback mechanisms. Table 10-6: Expert > Authentication Methods Authentication Type Definition No authentication. None Authentication is performed using a Kerberos Kerberos server.
2. Click the Access tab. 3. To select an authentication method, select one of the options in the Type menu. 4. Click “Done.” 5. Click “apply changes.” The changes are stored in /etc/portslave/pslave.conf on ACS. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms 6. Make sure that an authentication server is specified for the selected authentication type. The following table lists the procedures that apply to each authentication method. Table 10-7: Expert > Procedures to Configure an Authentication Server Authentication Method Where Documented "To Configure a Kerberos Authentication...
Note: Go to Wizard > Step 5:System Log, or Expert > Network > Syslog to set up a syslog server. The following form shows both checkboxes (“Enable Data Buffering” and “Buffer to Syslog”) and the “Local” destination selected. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-24: Expert > Ports > Physical Ports > Data Buffering The following table describes the fields available in the data buffering form. Table 10-8: Expert > Data Buffering Form Fields Field Name Definition Destination Location for the data files. Either “Local” or “Remote” Mode (Local Destination) circular or linear.
ACS from the system administrator of the syslog server. Options range from Local0 to Local7. 1. Go to Ports > Physical Ports in Expert mode, and select a port or ports to modify. 2. Select the Data Buffering tab. AlterPath ACS Installation, Administration, and User’s Guide...
Page 308
Ports Menu & Forms The Data Buffering form displays. 3. Select “Enable Data Buffering” and perform the following steps. a. From the “Destination” pull-down menu, choose “Local” or “Remote” to specify whether the data buffer files are stored locally or remotely on a file server.
Under Ports > Physical Ports in Expert Mode, after you select one or more serial ports, and click the Modify Port(s), you can select the Multi User form from the tabbed menu. The following form appears. Figure 10-25:Expert > Port > Physical Ports >Multi User AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms The Multi User form enables you to open more than one session from the same serial port. Multiple users can connect simultaneously to a serial port. To connect to a port or start a shared session, the user must have permission to access the port.
4. To configure the type of data that displays on the monitor in a port-sharing session, select an option from the “Sniff Mode” pull-down menu. 5. If you have allowed multiple sessions, complete the following fields. a. Add user names to the “Privilege Users” field. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms b. Enter a hot key in the “Menu Hotkey” field to display the sniffer menu on the monitor. The default shown is [^z]. The caret stands for the Ctrl key. c. Enable the “Notify Users” field, if desired. 6.
The default for IPMI power management is Ctrl+Shift+i (^I) Select the device configured for IPMI power IPMI Server (available only if management. IPMI is enabled) View listbox for the PM enabled ports and the assigned PowerMgmt Port outlet numbers. AlterPath ACS Installation, Administration, and User’s Guide...
Page 314
Ports Menu & Forms Field Name Definition The key sequence which the authorized user(s) can use Power Management Key to perform power management. The default for IPDU power management is Ctrl+p (^p) Radio button to allow all users to perform power Allow All Users management on the configured port.
Enter the outlet number(s) into which the device is connected to separated by commas. c. Click OK. The power management port and the specified outlet numbers display on the PowerMgmt Port list. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms d. Enter the power management hot key in the “Power Management Key” field. Enter a caret (^) for the escape key, as in ^p. The caret stands for the Ctrl key. • If you want to configure IPMI power management on this port, continue to Step 3.
Under Ports > Physical Ports in Expert Mode, after you select one or more serial ports, and click the Modify Port(s), you can select the Other form from the tabbed menu to configure other options. The following form appears. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-31:Expert > Ports > Physical Ports > Other Form You can use this form to configure other settings. The options on this form may be less common settings. The following table describes the available fields in the “Other” form. Table 10-12: Expert >...
Page 319
Set terminal options. STTY Options Usually 250 to 500 milliseconds. It’s a Break Interval logical zero on the TXD or RXD lines to reset the communications line. Usually a character sequence ~break Break Sequence (Ctrl-b) AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Field Name Definition Enter the text you wish to appear as a Login Banner login banner when logging into a terminal. This field should be populated with the Host to Connect IP address of the device you are connecting to.
4. To change the keep-alive interval, enter another number in the “TCP Keep-alive Interval” field. 5. To change the idle timeout interval, enter another value in the “Idle Timeout” field. 6. Specify stty options, if desired, in the “STTY Options” field. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms 7. To change the break interval, enter a new number in the “Break Interval” field. 8. To change the break sequence, enter a new sequence in the “Break Sequence” field. 9. To change the content of the login banner, enter new text in the “Login Banner”...
Figure 10-33: Expert > Ports > Virtual Ports > New/Modify Port Dialog Box The following table describes the fields available in the Virtual Ports New/ Modify Port dialog box. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Table 10-13: Expert > New/Modify Port Dialog Box Fields Field Name Definition Number of ports on each slave unit. Number of Ports Choices are 1, 4, 8, 16, 32 and 48. The first unallocated port number for First Local Port Number the slave.
1. Go to Ports > Virtual Ports in Expert mode, and click the “Add” button to add new slave ports, or click the “Edit” button to edit a slave port. The New/Modify Port dialog box appears. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Figure 10-35: Expert > Ports > Virtual Ports > New/Modify Port Dialog Box 2. From the drop-down menu select the number of ports that you want to assign as slaves. Choices are 1, 4, 8, 16, 32 and 48. 3.
Use this form to assign a name or alias to the slave ports in the cluster. Use a naming convention for effective management of the ACS units and the connected devices on your network. AlterPath ACS Installation, Administration, and User’s Guide...
Ports Menu & Forms Ports Status Selecting Ports > Port Status in Expert mode, brings up the following read- only form, which displays tabular serial port status information. Figure 10-37: Expert > Ports > Ports Status (Read-Only) The information in the following table is available in the Ports Status read- only form.
Port Displays the name (alias) for the serial port if Alias one is assigned by the administrator. The measure of how fast data is moving Baud Rate between devices. Data transmitted. Tx Bytes AlterPath ACS Installation, Administration, and User’s Guide...
Page 330
Ports Menu & Forms Column Name Description Data received. Rx Bytes A formatted packet of data usually associated Frame with the Data-Link layer. Error checking bit appended to a data packet. Parity A method of checking the accuracy of transmitted characters. Parity is usually not used, but can be odd or even.
Chapter 11 Administration Menu & Forms This Chapter describes the “Administration” menu and the related forms. The following table provides a description of the left menu panel links to the detailed information and procedures. Table 11-1: Expert > Administration Menu Menu Selection Use this menu to: Where Documented...
Administration Menu & Forms Menu Selection Use this menu to: Where Documented Configure ACS to boot from its Page 317 Boot Configuration internal firmware or from the network. This section defines the settings for loading the operating system in the event that the ACS fails to boot successfully.
Figure 11-1: Expert > Administration > System Information You can use the form to view the information shown in the following table. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Table 11-2: System Information Parameters Information • Kernel Version System • Current Date • Up Time • Power Supply State • CPU Type • Clock Speed • Revision • Bogomips • MemTotal Memory • MemFree • Buffers •...
1. Go to Administration > System Information in Expert mode. The System Information form appears. 2. To view all the information scroll down the form. Notifications Selecting Administration > Notifications in Expert mode brings up the following form. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Figure 11-2: Expert > Administration > Notifications You can use this form to set up alarm notifications about system issues, problems, or other events of interest that occur on the devices that are connected to the serial ports. You can configure notifications to be sent to users through email, pager or SNMP traps.
Serial Ports Alarm Notification Email Notifications Entry When you go to Administration > Notifications, select “Email” from the pull- down menu, and click on “Add” or “Edit” button the following dialog box appears. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Figure 11-3: Expert > Administration > Notifications > Email > Add/Edit Dialog box The following table describes the available fields in the email notification entry dialog box. Table 11-4: Expert > Email Notifications Dialog Box Fields Field Name Definition The trigger expression used to generate an...
8. Enter or change the SMTP server’s IP address in the “SMTP Server” field. 9. Enter or change the SMTP port number in the “SMTP Port” field. 10. Click “OK.” 11. Click “apply changes.” AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Pager Notifications Entry When you go to Administration > Notifications, select “Pager” from the pull- down menu, and click on “Add” or “Edit” button the following dialog box appears. Figure 11-4: Expert > Administration > Notifications > Pager > Add/Edit Dialog box...
3. If you need to edit an existing notification select it from the drop-down list and proceed. 4. Enter or change the pager number in the “Pager Number” field. 5. Enter or edit the text that describes the event in the “Text” field. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms 6. Enter or change the Short Message Services (SMS) user name, the SMS server’s IP address or name, and the SMS port number in the “SMS User Name,” “SMS Server,” and “SMS Port” fields respectively. 7. Click “OK.” 8.
• Authentication Failure • EGP Neighbor Loss • Enterprise Specific The password used to authenticate the traps. Community The IP address of the server running the Server SNMP. The content of the notification. Body AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms To Configure a Trigger for SNMP Trap Notification for Serial Ports 1. Go to Administration > Notifications in Expert mode, select SNMP Trap from the pull-down menu. If desired, enable “Notification Alarm for Data Buffering” for an alarm to sound when the trigger action occurs; and click either Add or Edit.
Enabling Network Time Protocol (NTP) synchronizes the ACS’s system clock with an NTP server, which maintains the true time (the average of many high-accuracy clocks around the world). If you enable the “Network Time Protocol”, the following form appears. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Figure 11-7: Expert > Administration > Time/Date > NTP Enable Setting Time and Date with NTP NTP (Network Time Protocol) is an Internet standard protocol which enables your system clock to be synchronized with the true time, defined as the average of many high-accuracy clocks around the world.
• A TFTP or BOOTP server must be available on the network. • An upgraded ACS boot image file must be downloaded from Cyclades and available on the TFTP or BOOTP server. • ACS must be configured with a fixed IP address.
Administration Menu & Forms The following table describes the boot configuration form fields. Table 11-7: Expert > Boot Configuration Form Fields Field Name Definition A fixed IP address or a DHCP assigned IP IP Address assigned address to the ACS unit. to Ethernet Whether the watchdog timer is active or Watchdog Timer...
Choose an Ethernet speed from the “Fast Ethernet” pull-down menu. f. Specify the maximum number of packets that the CPU handles before an interrupt in the “Fast Ethernet Max. Interrupt Events” field. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms 8. Click “apply changes.” Backup Configuration Selecting Administration > Backup Config in Expert mode brings up the form shown in the following figure. Figure 11-9: Expert > Administration > Backup Config The “Type” pull-down menu options on this form are “FTP” and “Storage Device.”...
Save Saves the configuration Load Downloads a previously saved copy of the configuration file from the selected device. When “Storage Device” is selected from the “Type” pull-down menu , the following form appears. AlterPath ACS Installation, Administration, and User’s Guide...
Administration Menu & Forms Figure 11-10: Expert > Administration > Backup Config > Storage Device The following table describes the available fields when “Storage Device” is selected from the “Type” drop-down menu. Table 11-9: Expert > Backup Config Type Storage Device Form Field Name Definition The system saves the configuration in the storage...
8. Click “apply changes” 9. Reboot the system. See Administration > Reboot for details, if needed. Upgrade Firmware Selecting Administration > Upgrade Firmware in Expert mode brings up the form shown in the following figure. AlterPath ACS Installation, Administration, and User’s Guide...
Kernel, applications, and configuration files. The firmware is upgradeable using an FTP server. You can upgrade the firmware directly through Cyclades’ FTP site at ftp://ftp.cyclades.com, or download the new firmware to a local FTP server and upgrade from there.
Field/Menu Definition Name Username recognized by the ftp server. The Cyclades ftp username for Username download is “anonymous” Password associated with the username. You can use any password for Password “anonymous” login in the password field. The pathname of the firmware on the ftp server.
Administration Menu & Forms The Cyclades ftp server accepts any password for “anonymous” login. 6. Enter the pathname of the file on the ftp server in the “Path and Filename” field. On the Cyclades ftp server, the directory is under pub/cyclades/ alterpath/acs/released/version_number/ 7.
Figure 11-13:Expert > Administration > Online Help Cyclades host the online-help on an FTP server accessible from the Internet. The path to the Cyclades FTP server is configured by default on ACS and is viewable in the “Online Help Path” field as http://www.cyclades.com/online-...
To Configure the Online Help Path 1. Using an FTP tool navigate to the following FTP site and download the desired version of the online help files. ftp://www.cyclades.com/online-help/acs/<firmware version> 2. In the ACS Web Manager navigate to Administration > Online Help in Expert mode.
Appendix A Technical Specifications The following table lists the AlterPath ACS hardware specifications MPC855T (PowerPC Dual-CPU) Memory 128MB DIMM SDRAM / 16MB CompactFlash Interfaces 1 Ethernet 10/100BT on RJ45 1 RS232 Console on RJ45 RS232 Serial Ports on RJ45 PCMCIA slots supporting: Secondary Ethernet, Wireless networking, CDMA, GPRS, GSM, V.90 modems, ISDN.
Page 360
Technical Specifications Certification FCC Part 15, A EN55022, A (CE) EN55024 UL 1950 Solaris Ready™ NEBS - ACS16 and ACS32 with Single or Dual DC Power Supplies...
Appendix B Safety, Regulatory, and Compliance Information The following Safety Information for AlterPath ACS are described in this appendix. Safety Guidelines for Rack-Mounting the ACS Page 331 Safety Precautions for Operating the ACS Page 332 NEBS Certification Page 334 Working inside the AlterPath ACS...
Safety, Regulatory, and Compliance Information Temperature The manufacturer's maximum recommended ambient temperature for the AlterPath ACS is 122 ºF (50 ºC). Elevated Operating Ambient Temperature If the ACS is installed in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient temperature.
Page 363
Do not spill food or liquids on ACS. Caution: Do not push any objects through the openings of the AlterPath ACS. Doing so can cause fire or electric shock by shorting out interior components.
NEBS certification requirements. Caution: Observe all central office safety precautions when connecting and disconnecting the AlterPath ACS power supplies from the DC power source. To comply with NEBS requirements, ensure that your site adheres to the environmental criteria described in the NEBS specifications.
Herstellers. FCC Warning Statement The AlterPath ACS has been tested and found to comply with the limits for Class A digital devices, pursuant to Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment.
Caution: No hacer funcionar el AlterPath ACS con la tapa abierta. Caution: Para prevenir un corto circuito en el AlterPath ACS al desconectarlo de la red, primero desconectar el cable del equipo y luego el cable que conecta a la red.
2 amperes, con conductor de 0.75 mm (18 AWG). Trabajar dentro del AlterPath ACS No intente dar servicio al AlterPath ACS, solo que este bajo la dirección de Soporte Técnico de Cyclades. Si este es el caso, tome las siguientes precauciones: Apague el AlterPath ACS.
Safety, Regulatory, and Compliance Information Batería Caution: Una batería nueva puede explotar, si no esta instalada correctamente. Remplace la batería cuando sea necesario solo con el mismo tipo recomendado por el fabricante de la batería. Deshacerse de la batería de acuerdo a las instrucciones del fabricante de la batería.
Glossary Authentication The process by which a user’s identity is checked within the network to ensure that the user has access to the requested resources. Basic In/Out System Chips on the motherboard of a computer contain read only (BIOS) memory instructions that are used to start up a computer. The operating system of a PC also makes use of BIOS instructions and settings to access hardware components such as a disk drive.
Page 370
Glossary BogoMips BogoMips (from "bogus" and MIPS). Unscientific measurement of CPU speed made by the Linux kernel when it boots to calibrate an internal busy-loop. Bonding (Linux) Ability to detect communication failure transparently, and switch from one LAN connection to another. The Linux bonding driver has the ability to detect link failure and reroute network traffic around a failed link in a manner transparent to the application.
Page 371
Command line interface. An interface that commands. Through CLI, individual commands can be given to the computer one at a time using the keyboard. Cyclades products run the Linux operating system, and most Cyclades products provide CLI access. Administrators type "CLI" on the command line of the Linux shell.
Page 372
Glossary Console Terminal used to configure network devices at boot (start-up) time. Also used to refer to the keyboard, video and mouse user interface to a server. Console Port Most of the equipment in a data center (servers, routers, switches, UPS, PBX, etc.) has a serial console port for out-of- band management purposes.
Page 373
Flash refers to a type of memory that can be erased and reprogrammed in units of memory known as blocks rather than one byte at a time; thus, making updating to memory easier. AlterPath ACS Installation, Administration, and User’s Guide...
Page 374
Glossary Flow Control A method of controlling the amount of data that two devices exchange. In data communications, flow control prevents one modem from "flooding" the other with data. If data comes in faster than it can be processed, the receiving side stores the data in a buffer.
Page 375
(and vice versa) across an insecure network connection. It works by assigning a unique key called a ticket to each user that logs on to the network. The ticket is then embedded in messages to identify the sender of the message. AlterPath ACS Installation, Administration, and User’s Guide...
Page 376
Glossary After a client and server has used Kerberos to prove their identity, they can also encrypt all of their communications to assure privacy and data integrity as they go about their business. LDAP Lightweight Directory Access Protocol. A software protocol for enabling anyone to locate organizations, individuals, and other resources such as files and devices in a network, whether on the Internet or on a corporate intranet.
Page 377
Internet protocol address Network masks divide IP addresses into two parts (network address and address of a particular host within the network). Mask have the same form as IP addresses (i.e. AlterPath ACS Installation, Administration, and User’s Guide...
Page 378
Glossary 255.255.255.0), however, its value is needed to be understood as a 32-bit number with certain number of ones on the left end and zeros as the rest. The mask cannot have an arbitrary value. The primary function of a subnet mask is to define the number of IP hosts that participate in an IP subnet.
Page 379
Even - Parity bit set so that there is an even number of 1 bits None - Parity bit is ignored, value is indeterminate PCMCIA Personal Computer Memory Card International Association. An organization consisting of some 500 companies that has AlterPath ACS Installation, Administration, and User’s Guide...
Page 380
Glossary developed a standard for small, credit card-sized devices, called PC Cards. Originally designed for adding memory to portable computers, the PCMCIA standard has been expanded several times and is now suitable for many types of devices including network cards (NICs). The PCMCIA 2.1 Standard was published in 1993.
Page 381
SMTP server on another computer. SNMP Short for Simple Network Management Protocol, a set of protocols for managing complex networks. The first versions of SNMP were developed in the early 80s. SNMP works by AlterPath ACS Installation, Administration, and User’s Guide...
Page 382
Glossary sending messages, called protocol data units (PDUs), to different parts of a network. SNMP-compliant devices, called agents, store data about themselves in Management Information Bases (MIBs) and return this data to the SNMP requesters. (Source: Webopedia) SNMP Traps Notifications or Event Reports are occurrences of Events in a Managed system, sent to a list of managers configured to receive Events for that managed system.
Page 383
Terminal Server A terminal server has one Ethernet LAN port and many RS-232 serial ports. It is used to connect many terminals to the network. Because they have the same physical interfaces, AlterPath ACS Installation, Administration, and User’s Guide...
Page 384
Glossary terminal servers are sometimes used as console access servers. 1. In Unix, refers to any terminal; sometimes used to refer to the particular terminal controlling a given job (it is also the name of a Unix command which outputs the name of the current controlling terminal).
Page 385
(or reload) button in a Web browser if a Web site does not fully load after a certain length of time following the entry of a Uniform Resource Locator (URL). AlterPath ACS Installation, Administration, and User’s Guide...
Index in Wizard mode, configuring logins, configuring authentication for access mounting 13, 85, 238 allow SSH root packet filtering root to reboot SSH root working inside the AltherPath access requirements, port action, boot access server active ports sessions (CAS) profile, console add rule 252, 341 (CAS), console...
Page 388
Index alarms bidirectionshell command alias biometric authentication alias, port IP BIOS allow BogoMips 162, 340 multiple sessions bonding 13, 85, 238 SSH root access boot action AltherPath ACS, connectors on the boot configuration AltherPath ACS, working inside the boot, to configure ACS AltherPath PM IPDUs, connecting bootp applications menu &...
Page 389
Ethernet PCMCIA cards CSLIP 66, 132 GSM PCMCIA cards current ISDN PCMCIA cards custom, security profile modem PCMCIA cards network parameters ports ports for power management ports for power management using CLI 53, 293 daisy-chain AlterPath ACS Installation, Administration, and User’s Guide...
Page 390
Index 24, 274 data buffering encrypted Destination escape sequence File Size ESSID 318, 343 Local files Ethernet Mode Ethernet PCMCIA cards, configuring NFS File Path events, data buffering off-line Expert mode Remote server configuring ACS in 105, 277 time stamp menus and forms mapping data size data buffering events...
Page 394
Index PCPU processing time powermgmt port 169, 256, 350 physical ports planning access to connected devices ppp-no auth plug-in, Java pre-installation requirements PM IPDUs, connecting AltherPath prerequisites for port logging to syslog servers destination multi-outlet control 11, 72 powermgmt using the web manager source pre-shared secret primary IP...
Page 395
14, 86, 239, 351 setting time and date with NTP RS232 signal settings, host RSA key shell rule, add shipping box contents run checksum shortcuts, navigation RX bytes simple network management protocol (SNMP) slave AlterPath ACS Installation, Administration, and User’s Guide...
Page 396
Index 65, 131, 164 SLIP syslog buffer size 309, 351 SMTP server sniff mode servers 14, 23, 86, 188, 239 SNMP servers, prerequisites for logging SNMP trap notification system information SNMP trap notifications system information, to view SNMP traps SNMP, simple network management protocol SNMPv1 SNMPv2...
Page 397
16, 354 vpn connections UDP protocol updelay upgrade ACS’s firmware 5, 323 firmware software 318, 354 watchdog timer usage, CPU web manager user logging into adding other methods of accessing multi power management AlterPath ACS Installation, Administration, and User’s Guide...
Page 398
Index 11, 72 prerequisites for using web manager for administrators web manager for regular users windows EMS wireless LAN PCMCIA cards, configuring wiz command wizard mode Wizard mode, configuring ACS in working inside the AltherPath ACS X.509 Cerfiticate on SSH...
Need help?
Do you have a question about the AlterPath ACS and is the answer not in the manual?
Questions and answers