
28 MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide
Telnet on the MergePoint 5224/5240 SP Manager
Telnet is not encrypted, so the SP manager controls its use to protect communications. By default,
the Telnet service is disabled, while a Telnet client is used for proxied communications between
users on the public network and target devices on the private network side of the SP manager.
Telnet service configuration
The Telnet service is not supported by any of the default security profiles and telnetd is not active,
to prevent users from using Telnet clients from remote workstations either to connect to the SP
manager or to connect through the SP manager to target devices. Encrypted SSH clients may be
used instead. An administrator can choose to enable the Telnet service. Even if the Telnet service is
enabled, the SP manager
-specific target device management commands cannot be passed as
parameters to the telnet command but only to the ssh command. Chapter 4 describes how to enable
the Telnet service.
Telnet client configuration
A Telnet client is used when proxying communications between users and most types of target
devices on the private network because all supported target device types support Telnet
connections while some do not support SSH. The SP manager uses ipmitool commands for
IPMI
-type SPs. If an SP must be on the public network, then the administrator should strongly
consider configuring an SSH client to be used instead of the Telnet client, if SSH is supported by
the SPs. Chapter 4 describes how to configure an SSH client to be used instead of the Telnet client
when communicating with SPs.
HTTPS on the MergePoint 5224/5240 SP Manager
For HTTPS (secure HTTP based on SSL) to work, an SSL certificate must be present on the SP
manager, so a self
-signed certificate is automatically generated. To reduce the risks posed by
weaknesses inherent in self
-signed certificates, administrators are strongly advised to replace the
automatically
generated self-signed certificate with an SSL certificate from an official certificate
authority (CA). See To replace the self-signed certificate with one from a certificate authority: on
page 119 for the procedure.
DHCP on the MergePoint 5224/5240 SP Manager
Both a DHCP client and a DHCP server are available on the SP manager.
DHCP client
The SP manager’s DHCP client is active, with DHCP enabled by default for the primary Ethernet
port. With the default configuration, if the SP manager cannot find a DHCP server on the same
subnet, it falls back to using the default IP address.
Commenti su questo manuale