Page 2
USA Notification Warning: Changes or modifications to this unit not expressly approved by the party responsible for compliance could void the user’s authority to operate the equipment. Note: This equipment has been tested and found to comply with the limits for a Class A digital device, pursu- ant to Part 15 of the FCC Rules.
Page 4
Instructions This symbol is intended to alert the user to the presence of important operating and maintenance (servicing) instructions in the literature accompanying the appliance. Dangerous Voltage This symbol is intended to alert the user to the presence of uninsulated dangerous voltage within the product’s enclosure that may be of sufficient magnitude to constitute a risk of electric shock to persons.
Sensor management options ... 10 Authentication ... 13 Security Profiles’ Effects on Users’ Actions... 14 Options for Accessing the MergePoint 5224/5240 SP Manager, Managing User Passwords and Managing IPDU Power Outlets and Target Devices ... 15 Command Line Access Through Console Logins ... 15 Accessing the MergePoint 5224/5240 SP Manager Console ...
Page 6
MergePoint 5224/5240 Service Processor Manager User Guide Chapter 2: Accessing the MergePoint 5224/5240 Appliance and Target Devices ... 21 Accessing the MergePoint 5224/5240 SP Manager’s Console ... 21 Accessing Management Features From the User Shell Menu... 22 Accessing the Console of a Target Device... 24 Creating an SSH Tunnel ...
Page 7
Table of Contents Appendix A: MindTerm Applet Reference ... 59 Appendix B: Technical Support ... 66 Index... 67...
Page 8
MergePoint 5224/5240 Service Processor Manager User Guide...
Figure 1.2: Example Graph for Readings From a Fan Sensor ... 11 Figure 2.1: Device Access Menu ... 23 Figure 2.2: MergePoint 5224/5240 Appliance VPN Example Using IPSec ... 27 Figure 3.1: Web Manager Login Screen ... 38 Figure 3.2: User Options on the Web Manager ... 39 Figure 3.3: Target Devices Web Manager Screen ...
Page 10
MergePoint 5224/5240 Service Processor Manager User Guide...
MergePoint service processor (SP) manager: • Supported Target Devices on page 2 • MergePoint 5224/5240 SP Manager’s Advantages for Target Device Management on page 2 • Web Manager on page 4 • Web Manager on page 4 •...
MergePoint 5224/5240 Service Processor Manager User Guide Supported Target Devices A target device managed by the MergePoint 5224/5240 SP manager can be one of the following: • An SP on a server. SPs are out their servers. • A server or other type of device that does not have an SP but that provides access to its command line through a dedicated Ethernet port.
Figure 1.1 is a conceptual illustration of a secure path between a remote user and an SP through the MergePoint 5224/5240 SP manager. A remote user is shown, but users may also be locally located, on the same LAN. In Figure 1.1, the remote user accesses the MergePoint 5224/5240 SP manager through a network connection to the public Ethernet port.
MergePoint 5224/5240 Service Processor Manager User Guide Web Manager The Web Manager may be used when the MergePoint 5224/5240 SP manager is managed as a standalone. If the MergePoint 5224/5240 SP manager is managed through DSView 3 management software, access to the Web Manager is usually disabled.
Only one administrative user can be connected to the MergePoint 5224/5240 SP manager at a time. Regular users may be authorized for access to management features available on the connected SPs or other types of target devices. NOTE: The administrator may create and enable a custom security profile that has the override authorization feature set, which causes all authenticated users to have all access to all target devices.
Table 1.3 shows the device console management (SoL) option names and command names used when you are logged into the Web Manager, when you have selected a target device from the spshell menu on the MergePoint 5224/5240 SP manager console and when you are entering the ssh command on a remote workstation.
Table 1.4: Event Log (SEL) Management Options (Continued) Method spshell menu in the MergePoint 5224/ 5240 SP manager console ssh command Access to native features on a target device Both Native IP and DirectCommand management options provide native access to target devices and enable an authorized user to connect directly either to the web management interface of a target device or to the command line of a device that redirects console output to a dedicated Ethernet port.
Web Manager, when you have selected a target device from the spshell menu on the MergePoint 5224/5240 SP manager console and when you are entering the ssh command on a remote workstation.
Web Manager, when you have selected a target device from the spshell menu on the MergePoint 5224/5240 SP manager console and when you are entering the ssh command on a remote workstation. The power management options are only available for managed servers with SPs.
Cold boot: the server is fully restarted (the same effect as issuing a Power cycle command) If an SP has more than one type of reset option, the MergePoint 5224/5240 SP manager Reset command performs the highest level of reset: the cold boot option if available.
Sensors List Display Graph Button Figure 1.2: Example Graph for Readings From a Fan Sensor Table 1.9 shows graph features that can be modified. An error message appears if you enter a value that is greater than or lower than the supported range of values. Table 1.9: Sensor Graph Parameters Field/Menu y-Axis Boxes...
Page 24
Table 1.10 shows the sensor management options available when you are logged into the Web Manager, when you have selected a target device from the spshell menu on the MergePoint 5224/ 5240 SP manager console and when you are entering the ssh command on a remote workstation.
Authentication Anyone accessing the MergePoint 5224/5240 SP manager must log in by entering a username and password. Controlling access by requiring users to enter names and passwords is called authentication. The usernames and passwords entered during login attempts are checked against a database.
MergePoint 5224/5240 Service Processor Manager User Guide Security Profiles’ Effects on Users’ Actions When the MergePoint 5224/5240 SP manager is being managed without DSView 3 management software, the administrator needs to select a security profile based on the security requirements of the organization.
MergePoint 5224/5240 SP manager’s console port. The user or administrator logs in through a terminal or through a terminal emulation program running on a connected workstation.
SP Shell (spshell) When you select Access devices from the login menu shown in Table 1.12, the MergePoint 5224/ 5240 SP manager shell, /usr/bin/spshell, displays a list of target devices you are authorized to access, as shown in the following example.
The following example command line allows an authorized user whose username is fred to turn on the power for a server whose alias is configured on the MergePoint 5224/5240 SP manager as drac, when the IP address of the MergePoint 5224/5240 SP manager is 192.168.29.22: % ssh t fred:drac@192.168.29.22 poweron...
• SP power management Allows the user to manage power for a server whose SP is connected to the MergePoint 5224/ 5240 SP manager when the SP provides power management capabilities. See Power management options on page 9 for details about power management of connected servers that have SPs.
• Information about services that are enabled or disabled on the MergePoint 5224/5240 SP manager. For example, the administrator may have configured the MergePoint 5224/5240 SP manager so that HTTP or SSH v1 are disabled.
As described under User Shell (rmenush) on page 16 and SP Shell (spshell) on page 17, authorized users who connect to the MergePoint 5224/5240 SP manager’s console are presented with a menu of choices. From the initial menu, users can bring up a list of target devices that they are authorized to access and then access a submenu of management actions they can perform on the selected target device.
To access the MergePoint 5224/5240 SP manager console: If you are using a terminal or terminal emulation program installed on a workstation that is physically connected to the console port of the MergePoint 5224/5240 SP manager, start the terminal session with the following factory-default console port settings.
Chapter 2: Accessing the MergePoint 5224/5240 Appliance and Target Devices Figure 2.1: Device Access Menu After a target device is selected, pressing the user is authorized to perform on the target device. Not all listed actions are supported for all SPs. The following example shows the SP action menu for an rsa-type SP.
The user knows the alias of the target device that allows console access • The user knows know the IP address or DNS name of the MergePoint 5224/5240 SP manager To use an ssh command to connect directly to a device’s or SP’s console: To connect directly to a device’s console, enter the...
Chapter 2: Accessing the MergePoint 5224/5240 Appliance and Target Devices If you have connected to the MergePoint 5224/5240 SP manager console as an administrative or root user, type /usr/bin/spshell Select the name of the target device to access. Press Enter Return Select the desired action from the menu that displays.
Page 38
SSH tunnel. Click Add. In the Category pane, select Session. Enter the IP address or DNS-managed name of the MergePoint 5224/5240 SP manager in the Host Name (or IP address) field. Select SSH as the protocol.
Figure 2.2 shows an illustration of a single user’s workstation running IPSec on the right end and the MergePoint 5224/5240 SP manager on the left end, with a router and the Internet between the MergePoint 5224/5240 SP manager and the user’s workstation.
IPSec VPN routing requirements If a route is necessary for the MergePoint 5224/5240 SP manager and the user’s workstation to exchange packets, a route can be specified by setting one or both of the Right and Left nexthop parameters to the IP address of a host route and selecting Add and route as the boot action.
Creating a default route on the user’s workstation to the MergePoint 5224/5240 SP manager is not a viable approach. The route would cause the loss of DNS and other local services (such as Internet and mail service) for the user’s workstation.
When Shared Secret is used, the secret is shared on both ends. The MergePoint 5224/5240 SP manager administrator needs to give the user a copy of the configuration parameters used to configure the IPsec connection profiles on the MergePoint 5224/ 5240 SP manager, usually by providing a copy of the relevant portions of the ipsec.conf file, which...
NOTE: The MergePoint 5224/5240 SP manager’s administrator must provide the appropriate IP address for this procedure, which is not the same as the public IP address assigned to the MergePoint 5224/5240 SP manager’s public interface. The IP address is either the appliance side IP address configured for the private subnet where the target device resides or a virtual IP address configured for the MergePoint 5224/5240 SP manager.
The following procedures describe how to access native features on an SP after either a PPTP, IPSec or SSH tunnel exists. To access a native web application (Web Manager): Enter the private or virtual IP address of the MergePoint 5224/5240 SP manager in a browser. The Web Manager appears. Log into the Web Manager.
Bring up the management application from the SP’s command line. Obtaining and Using One Time Passwords for Dial This section is for users authorized to dial into the MergePoint 5224/5240 SP manager through an external modem, PC modem or phone card when the one time password (OTP) authentication method is configured for logins to that target device.
Page 46
MergePoint 5224/5240 Service Processor Manager User Guide Each OTP user needs a local user account on the MergePoint 5224/5240 SP manager, must be registered with the OTP system and must be able to obtain the OTP username, OTP secret pass phrase and OTP passwords needed for logins.
The following sections describe how all types of users (authorized and administrative) can use the Web Manager to access the MergePoint 5224/5240 appliance, manage connected SPs and other devices, manage power outlets on any connected IPDUs and manage their own passwords: •...
The IP address of the MergePoint 5224/5240 appliance must be known. Entering the IP address of the MergePoint 5224/5240 appliance into the address field of one of the supported browsers listed in Table 3.1 is the first step required to access the Web Manager.
Web Manager. See the MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide for details. Figure 3.1 shows the login screen for the Web Manager that appears when the MergePoint 5224/ 5240 appliance IP address is entered in a Microsoft Internet Explorer browser.
PPP connection to the MergePoint 5224/5240 appliance. Enter the IP address of the MergePoint 5224/5240 appliance in a supported browser. See Table 3.1 on page 36 for a list of supported browsers, if needed. The Web Manager login screen appears.
A menu of options appears on the left. The fields, buttons and menus in the screen area in the middle differ according to which option is selected. MergePoint 5224/5240 appliance administrators see the same list of options shown in Figure 3.2 under the administrator’s Access tab. The Access tab is one of multiple tabs that are available on the Web Manager whenever an administrator logs in.
MergePoint 5224/5240 Service Processor Manager User Guide • Links to the management features the user is allowed to access on that target device • The name (alias) assigned to the target device • A real IP address (if a virtual IP address is not assigned to the target device) •...
Accessing a Target Device’s Console Clicking the Device Console link on the Target devices screen launches a terminal window running a Java applet and creates a console connection with the target device. Figure 3.4 shows an example terminal window with a connection to the console of a Compaq Proliant server with an iLO type SP.
MergePoint 5224/5240 Service Processor Manager User Guide To manage a server’s power through its SP (Web Manager): Log into the Web Manager. Select the Power link from the Action pull-down menu associated with the target device for which you want to manage power.
Users can bring up multiple instances of the sensor plotter page and view different sensors in different graphs at the same time. The graph displays a new reading at a specified interval. The default, which is user-configurable, is five seconds. Sensors List Display Graph Button Figure 3.6: Sensor Plotter Page...
MergePoint 5224/5240 Service Processor Manager User Guide Viewing and Clearing Event Logs Clicking the Event Log button on the Target devices screen displays the system event log (SEL) menu from the server where the SP resides. Event messages are sent by the SP when system management events are detected.
Native IP Enable only if a secure tunnel exists between the user’s workstation and the MergePoint 5224/5240 SP manager. See To enable access to Native IP on a target device (Web Manager): on page 46 for more details.
Tasks for creating secure tunnels and obtaining native IP access on page 8 describes tasks for creating the secure tunnel that must exist between the user’s workstation and the MergePoint 5224/ 5240 SP manager before an authorized user can enable Native IP and the Go to native web interface can be active.
After a DirectCommand connection is created during a Web Manager session, the Java applet that creates the secure tunnel between the user and the MergePoint 5224/5240 SP manager and that manages DirectCommand connections stays loaded until the Web Manage login session is ended, even if all DirectCommand connections are closed.
MergePoint 5224/5240 Service Processor Manager User Guide Figure 3.9: Direct Command: Connected and Go to DirectCommand Interface DirectCommand connection link Users can see information about and manage all currently active DirectCommand connections by clicking the DirectCommand Connected link, which brings up the dialog shown in Figure 3.10.
If the VPN connection is being made using IPSec, the authorized user may use the MergePoint 5224/5240 appliance’s IP address to bring up the Web Manager first and go to the Target device screen before making the VPN connection. After subsequently making the VPN connection, the user can reload the form to see the Enable Native IP link active.
Page 62
The MergePoint 5224/5240 appliance administrator has done all of the following: • Authorized your MergePoint 5224/5240 appliance user account for PPTP access • Provided you with the PPTP password if it is different from your MergePoint 5224/5240 appliance password • Enabled the PPTP service •...
NOTE: The IP address is the one assigned to the public interface of the MergePoint 5224/5240 appliance. 12. Click the Next button. 13. Click the Finish button. Accessing the MergePoint 5224/5240 SP Manager Console (Web Manager) Selecting the Appliance option on the Web Manager menu, then clicking the Connect button brings up a window running a MindTerm Java applet with an SSH connection to the MergePoint 5224/ 5240 appliance, as shown in Figure 3.11.
MergePoint 5224/5240 Service Processor Manager User Guide Figure 3.12: User Menu When Connected to the Console For information about what the administrative user can do on the MergePoint 5224/5240 appliance console, see the MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide.
Figure 3.15 appears if the user is not authorized to manage power on any outlets or if the MergePoint 5224/5240 appliance cannot detect an IPDU connected to the AUX port. Contact the MergePoint 5224/5240 appliance administrator for help if you receive this message.
MergePoint 5224/5240 Service Processor Manager User Guide Figure 3.15: IPDU Access Failed Message from Outlets Manager If a regular user clicks the Outlets Manager tab under the Access - IPDU menu option, the screen displays a list of all the outlets the user is authorized to manage. If an administrative user clicks Outlets Manager under the Access - IPDU menu option, all the power outlets on all connected IPDUs are listed, as shown in Figure 3.16.
The name that appears on the screen is either the default s1, which is the port number of the AUX port or an administrator-defined name. A yellow bulb indicates that the outlet’s power is on. A gray bulb indicates that the outlet’s power is off. An open padlock indicates that the outlet is unlocked. A closed padlock indicates a locked outlet.
MergePoint 5224/5240 Service Processor Manager User Guide Viewing IPDU information When a regular user or administrative user selects Access - IPDU - View IPDU Info, the View IPDU Info screen appears. Figure 3.18: View IPDU Info Screen The following table shows the information displayed on the View IPDU Info screen for each IPDU.
Table 3.4: IPDU Information Under Unit Information (Continued) Field Description Software Version IPDU firmware version Alarm Threshold Number of amperes that triggers an alarm or syslog message if it is reached Current Current level on the IPDU Maximum Detected Maximum current detected Temperature Temperature on the IPDU (only available on selected models that have temperature sensors)
MergePoint 5224/5240 Service Processor Manager User Guide Configuring Your Password Clicking the Password option on the Web Manager left menu brings up the Changing password for user <username> screen, as shown in Figure 3.20. Figure 3.20: Password Screen NOTE: Your password cannot exceed 30 characters.
Figure A.1 shows an example window that appears when the root user is connected to the console of an SP with an alias of rdqailo. The same terminal window appears whether the connection is being made to the console of an MergePoint 5224/5240 appliance, an SP, a server or another type of device.
MergePoint 5224/5240 Service Processor Manager User Guide MindTerm home: C:\Documents and Settings\username\mindterm\ Figure A.1: Root Log into MindTerm Running an SSH Console Session MindTerm terminal menu options As is shown in first line of the screen output shown in Figure A.1, you can bring up the terminal...
Figure A.2: Terminal Menu Table A.1: Console Session Terminal Menu Options level Option level Option File Save Settings (Ctrl+Shift+s) Capture to File (Ctrl+Shift+c) Send ASCII File Close (Ctrl+Shift+c) Appendices Description Saves current settings to a user selected file. Starts capturing terminal output to a file, or if this menu option is selected when output is currently being captured, stops capturing.
Page 75
Table A.1: Console Session Terminal Menu Options (Continued) level Option level Option Settings Connection (continued) (continued) Terminal (Ctrl+Shift+t) Appendices Description Security • Protocol • Host key type • Cipher • Mac • Compression Features • X11 forward • Local display •...
Page 76
MergePoint 5224/5240 Service Processor Manager User Guide Table A.1: Console Session Terminal Menu Options (Continued) level Option Settings (continued) Auto Save Settings Tunnels Setup Help About MindTerm Using hotkeys during console sessions MindTerm hotkeys have two components: an escape sequence and a command key. The escape...
the applet displays hotkey combinations that you can use to get help ( The following table shows all the available hotkeys, which are entered after the escape sequence. Table A.2: Hotkeys Available During Console Sessions Action Disconnect Send broadcast message Down a console Force attach read/write Information dump...
Page 78
Appendix B: Technical Support Our Technical Support staff is ready to assist you with any installation or operating issues you encounter with your Avocent product. If an issue should develop, follow the steps below for the fastest possible service. To resolve an issue: Check the pertinent section of this manual to see if the issue can be resolved by following the procedures outlined.
Page 79
IPSec IP address 46 using to bring up a native web application 45 test packet exchange between user workstation and MergePoint 5224/ 5240 SP manager 30 callback accessing the Web Manager through 37 configuring at the remote caller’s end 19...
Page 81
28, 31, 47 iLO devices native Web access on 7 supported management features 5 information users need 20 Internet access to the MergePoint 5224/5240 SP manager 15 IP addresses 3 ipconfig command 28, 31, 47 IPDUs accessing through Web Manager 4...
Page 82
MergePoint 5224/5240 Service Processor Manager User Guide MergePoint 5224/5240 SP manager command line access 15 console, access by administrative users 4 options for accessing 15 MindTerm applet when a user connects to a console...
Page 83
PPTP assigned MergePoint 5224/5240 SP manager IP address 29 password 29 service 14 connections 27 disabling when done 20 routing requirements 28 prerequisites for creating a VPN tunnel 27 for creating PPTP VPN tunnels 50 for dialing-in using PPP 19...
Page 84
MergePoint 5224/5240 Service Processor Manager User Guide spshell list of devices 16–17 submenu management commands 17 device console management command 6 native IP management commands 8 power management command 9 reset command 10 SEL management command 6 sensor management command 12...
Page 85
16 authentication requirements 13 prerequisites for using 36 regular users features 39 option for accessing the MergePoint 5224/ 5240 SP manager, connected devices and power 15 who can access 37 web server providing native web access to a...
Page 86
MergePoint 5224/5240 Service Processor Manager User Guide...
Need help?
Do you have a question about the MergePoint 5224 and is the answer not in the manual?
Questions and answers