Opengear User Manual 4.4.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
User Manual ACM5000 Remote Site Managers ACM5500 Management Gateways ACM7000 Resilience Gateways IM7200 & IM4200 Infrastructure Managers CM7100 Console Servers Revision 4.32 2019-4-10 Table of Contents Safety Please take care to follow the safety precautions below when installing and operating the console server: - Do not remove the metal covers. There are no operator serviceable components inside. Opening or removing the cover may expose you to dangerous voltage which may cause fire or electric shock. Refer all service to Opengear qualified personnel. - To avoid electric shock the power cord protective grounding conductor must be connected through to ground. - Always pull on the plug, not the cable, when disconnecting the power cord from the socket. Do not connect or disconnect the console server during an electrical storm. Also it is recommended you use a surge suppressor or UPS to protect the equipment from transients. FCC Warning Statement This device complies with Part 15 of the FCC rules. Operation of this device is subject to the following conditions: (1) This device may not cause harmful interference, and (2) this device must accept any interference that may cause undesired operation. Proper back-up systems and necessary safety devices should be utilized to protect against injury, death or property damage due to system failure. Such protection is the responsibility of the user. This console server device is not approved for use as a life-support or medical system. Any changes or modifications made to this console server device without the explicit approval or consent of Opengear will void Opengear of any liability or responsibility of injury or loss caused by any malfunction. This equipment is for indoor use and all the communication wirings are limited to inside of the building. 2 Data Center and Remote Site Management - User Manual User Manual Copyright © Opengear Inc. 2019. All Rights Reserved. Information in this document is subject to change without notice and does not represent a commitment on the part of Opengear. Opengear provides this document “as is,” without warranty of any kind, expressed or implied, including, but not limited to, the implied warranties of fitness or merchantability for a particular purpose. Opengear may make improvements and/or changes in this manual or in the product(s) and/or the program(s) described in this manual at any time. This product could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein; these changes may be incorporated in new editions of the publication. Table of Contents TABLE OF CONTENTS THIS MANUAL 12 INSTALLATION 15 2.1 Models 15 2.1.1 ACM5000 kit components 16 2.1.2 ACM5500 kit components 17 2.1.3 ACM7004-2, ACM7004-5, ACM7008-2 kit components 17 2.1.4 ACM7005-4 Remote Site Gateway kit components 18 2.1.5 IM4208-2, IM4216-2, IM4232-2, IM4248-2 and IM4216-34 kit components 18 2.1.6 IM7208-2, IM7216-2, IM7216-2-24U-DAC, IM7232-2 and IM7248-2 kit components 19 2.1.7 CM7116-2, CM7132-2 and CM7148-2 kit components 19 2.2 Power Connection 20 2.2.1 All IM7200, IM4200 and CM7100 -DAC models 20 2.2.2 All ACM5000 and ACM7000 models 20 2.2.3 All ACM5500 models 21 2.2.4 IM7200-DDC and IM4200-DDC power 21 2.3 Network Connection 22 2.4 Serial Port Connection 23 2.4.1 Opengear Classic RJ45 pinout (option –X0) 25 2.4.2 Cisco Rolled (Cyclades) RJ45 pinout (option -X1) 25 2.4.3 Cisco RJ45 pinout (option -X2) 26 2.5 USB Port Connection 26 2.6 Fitting Cellular SIM and Antennas 27 2.6.1 ACM5004 -G and -L models 28 2.6.2 ACM5500 -G models 28 2.6.3 ACM5500 -L models 29 2.6.4 ACM7000 -L models 29 2.6.5 IM4200 -G models 30 2.6.6 All IM7200 models 31 2.6.7 IM7200 -L models 31 2.7 Digital I/O and Environmental Sensors 32 SYSTEM CONFIGURATION 32 3.1 Management Console Connection 32 3.1.1 Connected computer set up 32 3.1.2 Browser connection 33 3.2 Administrator Set up 35 3.2.1 Change default root System Password 35 3.2.2 Set up a new Administrator 36 3.2.3 Name the System 36 3.3 Network Configuration 37 3.3.1 IPV6 configuration 38 3.3.2 Dynamic DNS (DDNS) configuration 39 3.4 Services and Service Access 40 3.4.1 Brute Force Protection 44 3.5 Communications Software 45 3.5.1 SDT Connector 45 3.5.2 PuTTY 45 3.5.3 SSHTerm 46 3.6 Management Network Configuration 46 3.6.1 Enable the Management LAN 46 3.6.2 Configure the DHCP serVer 48 3.6.3 Select Failover or broadband OOB 50 3.6.4 Aggregating the network ports 51 3.6.5 Wi-Fi Wireless LAN 52 3.6.6 Static routes 56 SERIAL PORT, HOST, DEVICE & USER CONFIGURATION 58 4 Data Center and Remote Site Management - User Manual User Manual 4.1 Configure Serial Ports 58 4.1.1 Common Settings 59 4.1.2 Console SerVer Mode 60 4.1.3 SDT Mode 66 4.1.4 DeVice (RPC, UPS, EMD) Mode 66 4.1.5 Terminal SerVer Mode 67 4.1.6 Serial Bridging Mode 67 4.1.7 Syslog 68 4.1.8 NMEA Streaming 68 4.1.9 Cisco USB console connection 70 4.1.10 USB Consoles 71 4.2 Add and Edit Users 71 4.2.1 Set up new Group 73 4.2.2 Set up new Users 74 4.3 Authentication 76 4.4 Network Hosts 76 4.5 Trusted Networks 77 4.6 Serial Port Cascading 78 4.6.1 Automatically generate and upload SSH keys 79 4.6.2 Manually generate and upload SSH keys 80 4.6.3 Configure the slaVes and their serial ports 81 4.6.4 Managing the slaVes 83 4.7 Serial Port Redirection (PortShare) 83 4.8 Managed Devices 84 4.9 IPsec VPN 87 4.9.1 Enable the VPN gateway 87 4.10 OpenVPN 90 4.10.1 Enable the OpenVPN 90 4.10.2 Configure as SerVer or Client 91 4.10.3 Windows OpenVPN Client and SerVer set up 94 4.11 PPTP VPN 99 4.11.1 Enable the PPTP VPN serVer 99 4.11.2 Add a PPTP user 101 4.11.3 Set up a remote PPTP client 101 4.12 Call Home 103 4.12.1 Set up Call Home candidate 103 4.12.2 Accept Call Home candidate as Managed Console SerVer on CMS 104 4.12.3 Calling Home to a generic central SSH serVer 106 4.13 IP Passthrough 106 4.13.1 Downstream Router Setup 107 4.13.2 IP Passthrough Pre-Configuration 107 4.13.3 IP Passthrough Configuration 107 4.13.4 Service Intercepts 108 4.13.5 IP Passthrough Status 108 4.13.6 CaVeats 108 4.14 Configuration over DHCP (ZTP) 109 4.15 Enrollment into Lighthouse 5 111 FIREWALL, FAILOVER & OOB ACCESS 111 5.1 Dialup Modem Connection 112 5.2 OOB Dial-In Access 112 5.2.1 Configure Dial-In PPP 112 5.2.2 Using SDT Connector client 115 5.2.3 Set up Windows XP or later client 115 5.2.4 Set up earlier Windows clients 115 5.2.5 Set up Linux clients 116 5.3 Dial-Out Access 116 5.3.1 Always-on dial-out 116 Table of Contents 5.3.2 FailoVer dial-out 117 5.4 OOB Broadband Ethernet Access 119 5.5 Broadband Ethernet Failover 120 5.6 Cellular Modem Connection 122 5.6.1 Connecting to a GSM HSUPA/UMTS carrier network 122 5.6.2 Connecting to a CDMA EV-DO carrier network 124 5.6.3 Connecting to a 4G LTE carrier network 126 5.6.4 Verifying the cellular connection 127 5.6.5 Cellular modem watchdog 128 5.6.6 Dual SIM failoVer 128 5.6.7 Automatic SIM Slot Detection 129 5.6.8 Multi-carrier cellular support 130 5.7 Cellular Operation 132 5.7.1 OOB access set up 132 5.7.2 Cellular failoVer setup 133 5.7.3 Cellular routing 135 5.7.4 Cellular CSD dial-in setup 135 5.8 Firewall & Forwarding 136 5.8.1 Configuring network forwarding and IP masquerading 138 5.8.2 Configuring client deVices 139 5.8.3 Port / Protocol forwarding 141 5.8.4 Firewall rules 143 SSH TUNNELS & SDT CONNECTOR 145 6.1 Configuring for SSH Tunneling to Hosts 146 6.2 SDT Connector Client Configuration 147 6.2.1 SDT Connector client installation 147 6.2.2 Configuring a new gateway in the SDT Connector client 148 6.2.3 Auto-configure SDT Connector client with the user’s access privileges 149 6.2.4 Make an SDT connection through the gateway to a host 150 6.2.5 Manually adding hosts to the SDT Connector gateway 151 6.2.6 Manually adding new serVices to the new hosts 152 6.2.7 Adding a client program to be started for the new serVice 154 6.2.8 Dial in configuration 155 6.3 SDT Connector to Management Console 156 6.4 SDT Connector: telnet or SSH connect to serially attached devices 157 6.5 Using SDT Connector for out-of-band connection to the gateway 158 6.6 Importing (and exporting) preferences 160 6.7 SDT Connector Public Key Authentication 160 6.8 Setting up SDT for Remote Desktop access 161 6.8.1 Enable Remote Desktop on the target Windows computer to be accessed 161 6.8.2 Configure the Remote Desktop Connection client 162 6.9 SDT SSH Tunnel for VNC 165 6.9.1 Install and configure the VNC Server on the computer to be accessed 165 6.9.2 Install, configure and connect the VNC Viewer 166 6.10 Using SDT to IP connect to hosts that are serially attached to the gateway 168 6.10.1 Establish a PPP connection between the host COM port and console server 168 6.10.2 Set up SDT Serial Ports on console server 171 6.10.3 Set up SDT Connector to ssh port forward over the console server Serial Port 172 6.11 SSH Tunneling using other SSH clients (e.g.