82
Chapter 6: Secure SSH Tunneling & SDT Connector
Each Console Server has an embedded SSH server and uses SSH tunneling. This enables one Console Server to securely
manageallthesystemsandnetworkdevicesinthedatacenter,usingtext-basedconsoletools(suchasSSH,Telnet,SoL)or
graphicaldesktoptools(VNC,RDP,HTTPS,HTTP,X11,VMware,DRAC,iLOetc).
TosetupSecureTunnelaccess,thecomputerbeingaccessedcanbelocatedonthesamelocalnetworkastheConsole
Server,orattachedtotheConsoleServerviaitsserialCOMport.TheremoteUser/AdministratorthenconnectstotheConsole
ServerthroughanSSHtunnel(viadial-up,wirelessorISDNmodem);abroadbandInternetconnection;anenterpriseVPN
network or a local network.
TosetupthesecureSSHtunnelfromtheClientcomputertotheConsoleServer,youmustinstallandlaunchSSHclient
softwareontheUser/Administrator’scomputer.ItisrecommendedthatyouusetheSDT Connector client software supplied
with the Console Server to do this. SDT Connectorissimpletoinstallanditauto-congures.Itprovidesallyouruserswith
point-and-clickaccesstoallthesystemsanddevicesinthesecurenetwork.Withoneclick,SDT Connector sets up a
secure SSH tunnel from the client to the selected Console Server and then establishes a port forward connection to the
target network connected host or serial connected device. It will then execute the client application that will be used in
communicating with the host.
ThischapterdetailsthebasicSDTConnectoroperations:
• ConguringtheConsoleServerforSSHtunneledaccesstonetworkattachedhostsandsettinguppermittedServicesand
Usersaccess(Section 6.1)
• SettinguptheSDTConnectorclientwithgateway,host,serviceandclientapplicationdetailsandmakingconnections
betweentheClientcomputerandhostsconnectedtotheConsoleServer(Section 6.2)
• UsingSDTConnectortobrowseraccesstheManagementConsole(Section 6.3)
• UsingSDTConnectortoTelnetorSSHconnecttodevicesthatareseriallyattachedtotheConsoleServer(Section 6.4)
ThechapterthencoversmoreadvancedSDTConnectorandSDTtunnelingtopics:
• UsingSDTConnectorforoutofbandaccess(Section 6.5)
• Automaticimportingandexportingofcongurations(Section 6.6)
• ConguringPublicKeyAuthentication(Section 6.7)
• SettingupaSDTSecureTunnelforRemoteDesktop(Section 6.8)
• SettingupaSDTSecureTunnelforVNC(Section 6.9)
• UsingSDTtoIPconnecttohoststhatareseriallyattachedtotheConsoleServer(Section 6.10)