Page 2
POWER ON This symbol indicates the principal on/off switch is in the on position. POWER OFF This symbol indicates the principal on/off switch is in the off position.
Page 4
USA Notification Warning: Changes or modifications to this unit not expressly approved by the party responsible for compliance could void the user's authority to operate the equipment. Note: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules.
The CPS is a serial over IP network appliance that provides non-blocked access and control for multiplatform servers and serial devices such as routers, power management devices and firewalls. This includes Avocent SPC power distribution units that provide advanced power management and security.
To avoid potentially fatal shock hazard and possible damage to equipment, please observe the following precautions: • Do not use a 2-wire extension cord in any Avocent product confi guration. • Test AC outlets at the computer and monitor (if used) for proper polarity and grounding.
Page 11
• Circuit Overloading: Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of circuits might have on overcurrent protection and supply wiring. Consider equipment nameplate ratings for maximum current. • Reliable Earthing: Reliable earthing of rack mounted equipment should be maintained.
Chapter 2: Installation and Configuration Hardware Overview Figure 2.1 shows the front panel of a CPS1610. Figure 2.1: CPS1610 Front Panel The lower left area of the front panel contains five LEDs and two buttons, which are described in the following table. CPS LEDs and Buttons LED/Button POWER...
CPS. The ONLINE LED will illuminate within one minute to indicate that the CPS self-test is complete. If the ONLINE LED blinks, contact Avocent Technical Support for assistance.
Page 17
Configuring the IP address and subnet mask You may use any of three methods to configure the CPS IP address and subnet mask: BootP, Telnet Command Line Interface (CLI) or the serial CLI on port 1. These methods work as documented on most Windows® and UNIX systems; however, the actual implementation on your system may differ from the instructions provided.
Page 18
CPS Installer/User Guide After the IP address is configured successfully, launch a Telnet session to the CPS IP address. Then, see Initial CPS login in this chapter. To confi gure the IP address and subnet mask using a Telnet CLI: Ensure that your server or workstation has a Telnet client and is located on the same LAN segment as the CPS.
Page 19
To log in to the CPS for the fi rst time: At the Username prompt, type Admin. There is no factory default password for the Admin user. At the Password prompt, press Return. Avocent CPS1610 S/W Version 2.1 (ASCII) Username: Admin...
CPS Installer/User Guide Reinitializing the CPS Reinitializing the CPS removes configured information. This may be useful when reinstalling the CPS at another location in your network. The CPS stores configuration information in FLASH databases. During reinitialization, the FLASH erase has two phases. The first phase erases the CPS configuration database, which contains all nonvolatile data except the IP address.
Page 21
Operations Contents Overview ........17 Configuring Serial Port Settings ....17 Connecting to Serial Devices .
Chapter 3: Operations Overview The CPS and its ports can be easily configured and managed to meet your requirements for device connection, user authentication, access control, power status monitoring, port history information display and SNMP compliance for use with third-party network management products. Support for SSH (Secure Shell) access via third-party clients is also provided.
Page 24
CPS Installer/User Guide To confi gure serial console port settings: Issue a Port Set command. You may specify settings for one or all ports. PORT [<port>|ALL] SET TD=CONSOLE [NAME=<name>] [BAUD=<baud>] [SIZE=<size>] [PARITY=<parity>] [STOP=<stop_bits>] [FLOW=<fl ow_ctrl>] [TIMEOUT=<time-out] [SOCKET=<socket>] [CHAR=^<cli_char>] [TOGGLE=NONE|DTR] [POWER=<signal>] To confi...
Connecting to Serial Devices The CPS offers several methods for connecting to attached serial devices: Telnet, serial CLI, PPP and SSH. If a user attempts to connect to a port that is already in use, and if the user attempting to connect has an access level equal to or higher than the currently-connected user, the connecting user will be prompted with the choice of preempting the current user or dropping the connection.
Data entered at the Telnet client is written to the attached serial device. Any data received by the CPS from the serial device is output to your Telnet client. You may access the CPS and its ports using Avocent-provided or third-party Telnet client applications.
Standalone third-party Telnet clients You may use third-party Telnet clients to access the CPS directly without DS management software. Connecting to devices from the serial CLI port By factory default, port 1 of the CPS is configured with the serial CLI, which prohibits the use of port 1 with an attached serial device.
CPS Installer/User Guide To end a device session that was initiated with a Connect command, issue a Disconnect command. DISCONNECT For more information, see Server CLI command, Connect Command and Disconnect Command in Chapter 5. Connecting to devices using PPP The CPS supports remote PPP access using an auto-answer modem that answers calls and establishes the PPP protocol with a dial-in client.
Page 29
For more information, see Show Server CLI command and Server PPP command in Chapter 5. To display PPP confi guration information: Issue a Show Server PPP command. SHOW SERVER PPP For more information, see Show Server PPP command in Chapter 5. Configuring and using dial-in connections You can attach an external modem to the CPS serial CLI port for dial-in serial CLI access to the CPS.
CPS Installer/User Guide Connecting to devices using SSH The CPS supports version 2 of the SSH (Secure Shell) protocol (SSH2). The CPS SSH server operates on the standard SSH port 22. The shell for this connection provides a CLI prompt as if you had established a Telnet connection on port 23.
Page 31
SSH Authentication Methods Method Description PW (default) SSH connections will be authenticated with a username/ password. With this method, a user’s defi nition must include a valid password in order for that user to authenticate an SSH session. A password can authenticate to a DSAuth or RADIUS server or to the local user database.
Page 32
CPS Installer/User Guide For more information, see Using Authentication Modes and Encryption in this chapter. SSH user keys A user’s SSH key is specified in a User Add or User Set command. You may define a key even if SSH is not currently enabled. The key can be specified in one of two ways: •...
Page 33
If you are reenabling SSH, you are prompted to use the existing SSH server key or generate a new key. Enter Y to use the existing key or N to generate a new key. For more information, see Server SSH command in Chapter 5. To disable SSH session access to the CPS: Issue a Server SSH command with the Disable parameter.
CPS Installer/User Guide command may be used to override the Server CLI access character on a per-port basis. For more information, see Server CLI command and Port Set command in Chapter 5. To display CLI access character information: Issue a Show Server CLI command. SHOW SERVER CLI For more information, see Show Server CLI command in Chapter 5.
Page 35
To add a user: Issue a User Add command. USER ADD <username> [PASSWORD=<pwd>] [SSHKEY=<keyfi le>] [FTPIP=<ftpadd>] [KEY=<sshkey>] [ACCESS=<access>] You must specify a username. You must also specify a password or SSH user key information, or you may specify both. You may also include an access level or access rights.
CPS Installer/User Guide To display information about all users, issue a Show User command with the All parameter. SHOW USER ALL For more information, see Show User command in Chapter 5. Access rights and levels Most CPS commands require the user to have access rights to use the commands.
CPS user database and no encryption is used. DS authentication DS authentication uses an Avocent DS authentication service (DSAuth) to authenticate CPS users. Encryption is automatically enabled. You must specify either the IP address of a primary DS authentication server and optionally, the IP address of a secondary DS authentication server, or you must indicate that any DS authentication server may be used.
Page 38
CPS Installer/User Guide Local authentication Local authentication uses the CPS unit’s internal user database to authenticate users. RADIUS authentication RADIUS authentication uses an external third-party RADIUS server containing a user database to authenticate CPS users. The CPS, functioning as a RADIUS client, sends usernames and passwords to the RADIUS server.
This method cannot be used when SSH connections are enabled, nor can it be combined with any other authentication method. Authentication summary The CPS allows concurrent use of multiple authentication modes. This allows Telnet, SSH and DSView clients to all access a single CPS as long as the appropriate authentication methods are enabled.
Page 40
DES. The order in which you specify the SSL types is not signifi cant. Encryption Type None. SSL Single DES encryption. * SSL Triple DES encryption. * SSL 128-bit encryption, which is compatible with the Avocent Telnet client that uses RC4 encryption. * SSH2 encryption.
The following command enables connections via SSH2 clients only. Plain text Telnet and Avocent SSL connections will be refused. server security encrypt=ssh To specify encryption method(s): Issue a Server Security command, using the Encrypt parameter to specify one or more encryption algorithm values, separated by commas.
CPS Installer/User Guide A locked-out user will remain locked-out until the specified time elapses, the CPS is power-cycled or the user is unlocked by an administrator with the User Unlock command. A user with the ADMIN access level can unlock all users except a user with the APPLIANCEADMIN level.
Page 43
Port History Mode Commands Command Description Bottom B sets the view location to the bottom of the fi le minus 23 history display lines, if available. Clear C clears the port history buffer. Next N increments the current history display line by the number of lines per page and outputs a new history display page.
Page 44
CPS Installer/User Guide To access port history mode: Issue a Port History command. PORT HISTORY The PORT HISTORY > prompt appears. To control the port history buffer display when you connect: Issue a Server CLI command, using the History parameter to specify the Hold or Auto option: SERVER CLI HISTORY=HOLD|AUTO •...
Managing SNMP Structures The CPS provides a set of commands that create and manage SNMP structures for use by third-party network management products. These commands cover the following operations: • Enabling and disabling SNMP UDP port 161 SNMP processing • Defi...
Page 46
To disable all SNMP traps, issue a Server SNMP Trap command with the Disable and All parameters. In this case, the numbered list is not displayed. SERVER SNMP TRAP DISABLE ALL For more information, see Server SNMP Trap command in Chapter 5. The Avocent web site www.avocent.com/support describes the supported traps.
Page 47
To add or delete SNMP trap destination addresses: To add an SNMP trap destination address, issue a Server SNMP Trap Destination command with the Add parameter and the destination’s IP address. You may defi ne up to four destination addresses, using separate commands.
Page 48
CPS Installer/User Guide To display SNMP confi guration information: Issue a Show Server SNMP command. SHOW SERVER SNMP The display includes information specified with the Server SNMP, Server SNMP Community, Server SNMP Manager, Server SNMP Trap and Server SNMP Trap Destination commands. For more information, see Show Server SNMP command in Chapter 5.
Page 49
Using CPS Commands Contents Accessing the CLI ......45 Entering Commands ......45 Understanding Conventions .
Chapter 4: Using CPS Commands Accessing the CLI You may access the CLI in three ways: using the Telnet CLI, using the serial CLI or entering the CLI access character during a session to a serial device. When the CLI is accessed, its prompt appears (>), indicating you may type a command. Entering Commands At the command prompt, type a command and then press Return or Enter.
CPS Installer/User Guide When commands take effect Each command is completely processed before the next command can be entered. Some commands prompt for confirmation before they are processed. In these cases, you must confirm or cancel by entering Y or N respectively. If you enter a Server FLASH command or if you change the CPS IP address with a Server Set command, a CPS reboot is required before the change becomes effective.
Page 53
In this case, both SERVER and REBOOT are positional commands. In most cases, one or more spaces separate positional commands, positional parameters and keyword parameters. For most positional commands, positional parameters or keyword parameters, you only need to enter the first three characters. The exceptions are: •...
CPS Installer/User Guide In the following example, there are spaces between BAUD, the equal sign and the value 57600. Spaces are not permitted between keyword parameters and their values. > POR 2 SET BAUD = 57600 FLOW=XON ERR 26 - SET keyword parameter invalid Syntax conventions This manual uses the following command syntax conventions: •...
Page 55
CPS Command Summary (Continued) Command Description, Access Right and Access Level * Port Logout Terminates the CPS session on a specifi ed port. Access right: USER; Access level: A and AA Port Set Changes port settings. Access right: SCON or PCON; Access level: A and AA Quit Terminates the current CPS session.
Page 56
CPS Installer/User Guide CPS Command Summary (Continued) Command Show Port Alert Show Server Show Server CLI Show Server PPP Show Server RADIUS Show Server Security Show Server SNMP Show User User Add User Delete User Logout User Set User Unlock * A indicates ADMINISTRATOR level, AA indicates APPLIANCEADMIN level.
Chapter 5: CPS Commands Connect Command The Connect command establishes a connection from the CPS serial CLI port to a device attached to another port on that CPS. If the specified port is already in use, you will receive an error message. To use this command, you must have previously issued a Server CLI command with the Connect=On parameter.
CPS Installer/User Guide Help Command Parameter Parameter <command_name> Examples The following command displays information about the Show Server CLI command. help sho ser cli The following command displays a list of all commands. help Port Commands The Port command has several forms, as listed in the following table. Port Command Summary Command Port Alert Add...
Port Alert Add Command Parameters Parameter Description <port> Port number in the range 1-8 for a CPS810 or 1-16 for a CPS1610. <string> 3-32 character string. Port Alert Copy command The Port Alert Copy command copies the alert strings from one port (from_port) to another (to_port).
CPS Installer/User Guide Port Alert Delete Command Parameter Parameter <port> Example The following command deletes defined alert strings from port 3. > PORT 3 ALERT DELETE Alert-strings assigned to port 3: 1) The first alert string 2) The second alert string 3) The third alert string 4) The fourth alert string Select Alert-string(s) to delete>...
Port History Mode Commands Command Description Bottom B sets the history view location to the bottom of the fi le minus 23 history display lines, if available. Clear C clears the port’s history buffer. Next N increments the current history display line by the number of lines per page and a new history display page is output.
CPS Installer/User Guide Port Set command The Port Set command changes CPS port settings in the CPS configuration database. At least one keyword parameter and value must be specified. For more information, see Configuring Serial Port Settings in Chapter 3. Access right: SCON or PCON;...
Page 65
Port Set Command Parameters (Continued) Parameter Description FLOW=<signal> Flow control signal. For hardware fl ow control, be sure the control signals are correctly wired, or data loss may occur. The fl ow control signal cannot also be used for power status monitoring. Valid values are: XONXOF RTSCTS DTRDCD...
CPS Installer/User Guide Example The following command sets a baud rate of 57600 and enables XON/XOFF flow control on port 2. > port 2 set baud=57600 flow=xonxof Quit Command The Quit command terminates the current CPS session and terminates your Telnet connection to the CPS.
Server Command Summary (Continued) Command Description Server SNMP Enables/disables SNMP processing. Server SNMP Community Defi nes read, write and trap community strings. Server SNMP Manager Defi nes/deletes SNMP management entities. Server SNMP Trap Enables/disables SNMP traps. Server SNMP Trap Destination Defi nes/deletes destinations for enabled SNMP traps. Server SSH Enables/disables SSH session access to the CPS.
(cps1Øapp.img) contains the CPS program that provides CPS functionality. You will need a TFTP server. Download the latest FLASH image from Avocent. Save the image file to the appropriate directory on the TFTP server. Access right: SCON; Access level: AA...
Syntax SERVER FLASH BOOT|APP HOSTIP=<tftp_add> IMAGE=<host_file> Server FLASH Command Parameters Parameter Description BOOT Indicates the BIOS/Bootstrap image should be updated. Indicates the application image should be updated. HOSTIP=<tftp_add> IP address of TFTP server host. IMAGE=<host_fi le> Name of fi le on TFTP server host containing the image fi le. Example The following command updates the CPS boot image program using the image file name c:\winnt\system32\drivers\cps1Øbt.img, which is located on the...
CPS Installer/User Guide Server PPP Command Parameters (Continued) Parameter REMOTEIP=<rem_ip> IP address to assign to the PPP client end of the PPP connection. MASK=<subnet> Examples The following command enables the PPP server with a local IP address of 192.168.0.1, a remote IP address of 192.168.0.2 and a subnet mask of 255.255.255.0.
Server RADIUS Command Parameters (Continued) Parameter Description USER-RIGHTS=<attr> Attribute number defi ned on the RADIUS server, in the range 1-255. AUTHPORT=<udp> UDP port for RADIUS authentication server, in the range 1-65535. This value is usually 1645, but may be 1812. Default = 1645 TIMEOUT=<time-out>...
Page 72
CPS Installer/User Guide Access right: SCON; Access level: AA Syntax SERVER SECURITY [AUTHENTICATION=<auth_mode>] Server Security Command Parameters Parameter AUTHENTICATION= <auth_mode> ENCRYPT=<encrypt> Encryption algorithm to use. Multiple values may be specifi ed, DSAUTH=<dsauth> DSCLEAR LOCKOUT=<hours> Examples The following command specifies that the CPS user database will be used to authenticate users, and the strongest encryption negotiated between triple DES and 128-bit will be used.
> ser sec auth=ds dsauth=any encrypt=3des,128 The following command sets the CPS to accept connections via Telnet and via Avocent SSL using Triple DES or RC4 encryption. Users who fail to authenticate after five consecutive attempts will be locked-out for 24 hours.
CPS Installer/User Guide Server SNMP Community command The Server SNMP Community command defines read, write and trap SNMP community strings. Community names are case-sensitive. For more information, see Managing SNMP Structures in Chapter 3. Access right: SCON; Access level: AA Syntax SERVER SNMP COMMUNITY [READCOMM=<name>] Server SNMP Community Command Parameters...
NOTE: By default, all traps are disabled. The portAlert trap must be enabled for port alert processing to be performed. For more information, see Managing SNMP Structures in Chapter 3. The Avocent web site www.avocent.com/support lists the supported traps. Access right: SCON; Access level: AA Syntax...
CPS Installer/User Guide server snmp trap enable Traps now disabled: 1) linkUp 2) userAdded 3) userDeleted Select trap(s) to enable>1,3-4 Server SNMP Trap Destination command The Server SNMP Trap Destination command defines or deletes destinations for enabled SNMP traps. Once you define destinations for enabled SNMP traps, when a trap occurs, the CPS will generate SNMP trap messages to each defined SNMP trap destination.
Server SSH Command Parameters Parameter Description ENABLE|DISABLE Enables or disables SSH session access to the CPS. AUTH=<auth> SSH authentication methods. You must enter the entire value; abbreviations are not permitted. Valid values are: PW|KEY KEY|PW PW&KEY KEY&PW Default = PW Show Commands The Show command has several forms, as listed in the following table.
Page 78
CPS Installer/User Guide Show Port Command Parameter Parameter <port> NAMES The following tables list the display fields for a SHOW PORT command that specifies one or all ports. Show Port Command Display Fields for Console Ports Field Port Serial Port Settings TX Bytes RX Bytes Errors...
Show Port Command Display Fields for SPC Ports Field Content Status ONLINE indicates the SPC is powered on, OFFLINE Indicates the SPC is powered off. Version SPC fi rmware version. Sockets Number of sockets on the SPC, either 8 or 16. Minload Minimum load amp value (from SPC command).
CPS Installer/User Guide Show Server Command Display Fields (Continued) Field Port Username Duration Socket From Socket IP Input and Output BOOT Show Server CLI command The Show Server CLI command displays the CPS serial CLI settings. Access right: SMON; Access level: A and AA Syntax SHOW SERVER CLI Show Server CLI Command Display Fields...
Show Server PPP command The Show Server PPP command displays the current CPS PPP settings that were configured with the Server PPP command. Access right: SMON; Access level: A and AA Syntax SHOW SERVER PPP Show Server RADIUS command The Show Server RADIUS command displays the current CPS RADIUS settings that were configured with the Server RADIUS command.
CPS Installer/User Guide Show Server Security Command Display Fields (Continued) Field DS Credential Fingerprint (Hex) Fingerprint (BB) Show Server SNMP command The Show Server SNMP command displays SNMP configuration information. Access right: SMON; Access level: A and AA Syntax SHOW SERVER SNMP Show User command The Show User command displays information about one or all users.
Show User Command Display Fields (Continued) Field Contents Locked YES if user is locked-out, NO if not. Last Login System up time value when the user logged in. Port Serial port to which user is connected. Username Username. Duration Duration of user’s session. Socket Telnet CPS socket number.
CPS Installer/User Guide SPC Command Parameters Parameter <port>|ALL MINLOAD=<amps> MAXLOAD=<amps> <socket>|ALL WAKE=ON|OFF ONMIN=<time> OFFMIN=<time> User Commands The User command has several forms, as listed in the following table. User Command Summary Command User Add User Delete User Logout User Set User Unlock Description Either a port number in range 1-8 for a CPS810 or 1-16 for a...
User Add command The User Add command adds a new user to the CPS user database. The CPS user database holds a maximum of 64 user definitions. For more information, see Managing Users, Connecting to devices using SSH and Access rights and levels in Chapter 3.
CPS Installer/User Guide The following command adds the username JaneDoe, with access to all ports. The name of the SSH public user key file is cps_key2.pub. This file is located on the FTP server at IP address 10.0.0.3. > user add JaneDoe ssh=cps_key2.pub ftp=10.0.0.3 access=pall The following command adds the username JDoe and gives that user the Appliance Administrator access level, which enables access to all ports and CPS commands.
User Set command The User Set command changes a user’s configuration in the CPS user database. For more information, see Managing Users, Connecting to devices using SSH and Access rights in Chapter 3. You may delete a user’s password or key; however, each user must have a password or a key, so you cannot remove both.
CPS Installer/User Guide User Set Command Parameters (Continued) Parameter ACCESS=<access> (Continued) Examples The following command sets the access rights for JohnDoe so that he can access all ports and have configuration and monitor access rights. >user set JohnDoe access=pall,scon,smon The following command removes the server configuration access right for JohnDoe, and leaves other access rights intact.
Appendices Appendix A: Technical Specifications The following table lists the CPS technical specifications. CPS Product Specifi cations Device Ports Network Connection Dimensions Agency Approvals Number 8 (CPS810); 16 (CPS1610) Type Serial ports Connectors Serial port RJ-45 Number Type Ethernet: IEEE 802.3, 10BaseT Fast Ethernet: IEEE 802.3U, 100BaseT Connector RJ-45...
CPS Installer/User Guide Appendix B: Device Cabling Each CPS serial port has an RJ-45 connector for attaching a serial device. Figure B.1 shows the RS-232 pinouts plus the wiring diagrams for cables that connect to terminals and PCs. Figure B.1: RJ-45 Pinouts and Cable Wiring Diagrams...
Page 93
Appendices RJ-45 modular adaptors and cables Modular adaptors are available from Avocent to convert RJ-45 modular jacks to DB-25 or DB-9 connectors. These modular adaptors, when used with 8-wire modular cables, provide the same functions shown in Figure B.1. Figure B.2 shows the modular adaptors available from Avocent.
Page 94
210093 210094 210095 790200 750122 If you choose to use a non-Avocent cable, make sure the cable is reversing, as shown in Figure B.3. Figure B.3: 8-wire RJ-45 Reversing Cable Description 10 foot 8-wire Reversing Modular Cable. 25 foot 8-wire Reversing Modular Cable.
Appendix C: Ports Used The following table lists the UDP and TCP port numbers used by the CPS. The values assume a default CPS configuration; some values are configurable. Ports Used by CPS Port Type and Number Used for TCP 22 SSH2, if enabled.
Appendix D: Technical Support Our Technical Support staff is ready to assist you with any installation or operating problems you encounter with your Avocent product. If an issue should develop, follow the steps below for the fastest possible service: Check the pertinent section of the manual to see if the issue can be resolved by following the procedures outlined.
Page 97
Avocent Corporation warrants to the original retail purchaser that this product is and will be free from defects in materials and workmanship for a period of 24 months from the date of purchase. Additionally, all Avocent products carry an unconditional thirty-day satisfaction guarantee. If, for any reason, you are dissatisfi...
Need help?
Do you have a question about the CPS1610 CPS and is the answer not in the manual?
Questions and answers