27
The Services Access settings specify which services the Administrator can use over which network interface to access the
consoleserver.ItalsonominatestheenabledservicesthattheAdministratorandtheUsercanusetoconnectthroughthe
Console Server to attached serial and network connected devices.
• Thefollowinggeneralserviceaccessoptionscanbespecied:
HTTPS
This ensures the Administrator has secure browser access to all the Management Console menus on the Console
Server.ItalsoallowsappropriatelyconguredUserssecurebrowseraccesstoselectedManage menus. For
information on certificate and user client software configuration refer Chapter 9 - Authentication. By default
HTTPSisenabled,anditisrecommendedthatonlyHTTPSaccessbeusediftheConsoleServeristobe
managedoveranypublicnetwork(e.g.theInternet).
HTTP
The HTTP service allows the Administrator basic browser access to the Management Console. It is recommended
the HTTP service be disabled if the Console Server is to be remotely accessed over the Internet.
Telnet
ThisgivestheAdministratortelnetaccesstothesystemcommandlineshell(Linuxcommands).Whilethismay
besuitableforalocaldirectconnectionoveramanagementLAN,itisrecommendedthisservicebedisabledif
the Console Server is to be remotely administered. This service may also be useful for local Administrator and the
User access to selected serial consoles
SSH
This service provides secure SSH access. It is recommended you choose SSH as the protocol where the
Administrator connects to the Console Server over the Internet or any other public network. This will provide
authenticated communications between the SSH client program on the remote PC/workstation and the SSH sever
in the Console Server. For more information on SSH configuration refer Chapter 9 - Authentication.
• Therearealsoanumberofrelatedserviceoptionsthatcanbeconguredatthisstage:
SNMP
This will enable netsnmpintheConsoleServer,whichwillkeeparemotelogofallpostedinformation.SNMPis
disabledbydefault.TomodifythedefaultSNMPsettings,theAdministratormustmaketheeditsatthecommand
line as described in Chapter 15 – Advanced Configuration
TFTP/
FTP
IfaUSBashcardorinternalashisdetectedontheConsoleServer,thenenablingthisservicewillsetup
default tftp and ftpserversontheUSBash.Theseserverareusedtostorecongles,maintainaccessand
transaction logs etc. Files transferred using tftp will be stored under /var/tmp/usbdisk/tftpboot
Ping
ThisallowstheConsoleServertorespondtoincomingICMPechorequests.Pingisenabledbydefault,however
for security reasons this service should generally be disabled post initial configuration
Nagios
AccesstotheNUTUPSmonitoringandNagiosNRPEmonitoringdaemons
NUT
AccesstotheNUTUPSmonitoringandNagiosNRPEmonitoringdaemons
• Andtherearesomeserialportaccessparametersthatcanbeconguredonthismenu:
Base
TheConsoleServerusesspecicdefaultrangesfortheTCP/IPportsforthevariousaccessservicesthatUsers
andAdministratorscanusetoaccessdevicesattachedtoserialports(ascoveredinChapter 4 – Configuring
Serial Ports).TheAdministratorcanalsosetalternaterangesfortheseservices,andthesesecondaryportswill
then be used in addition to the defaults.
The default TCP/IP base port address for telnetaccessis2000,andtherangefortelnetisIPAddress:Port(2000
+serialport#)i.e.2001–2048.SoiftheAdministratorweretoset8000asasecondarybasefortelnetthen
serialport#2ontheConsoleServercanbetelnetaccessedatIPAddress:2002andatIPAddress:8002.The
defaultbaseforSSHis3000;forRawTCPis4000;andforRFC2217itis5000
RAW/
Direct
YoucanalsospecifythatserialportdevicescanbeaccessedfromnominatednetworkinterfacesusingRawTCP,
directTelnet/SSH,unauthenticatedTelnetservicesetc
• ClickApply.Asyouapplyyourservicesselections,thescreenwillbeupdatedwithaconrmationmessage:
Message Changes to configuration succeeded
Chapter 3: Initial System Configuration