Benutzeranleitung / Produktwartung AP561x des Produzenten Schneider Electric
Zur Seite of 26
All content in this pre sentation is protec ted – © 2008 American Power Conversion Corpora tion LDAP Implementation AP561x KVM Switches.
APC by Schneider Electric LDAP Implementation ● Does not require LDAP Schema to be touched! ● Uses existing Schema Attribute field to store configuration setting ● Allows easy implementation.
APC by Schneider Electric IP KVM authentication levels ● Basic • Very simple implementation that allows th e KVM to browse the LDAP directory for user credentials.
APC by Schneider Electric Settings Used in this Lab ● The Microsoft® domain controller (Active Direct ory) acts as the DHCP server and DNS server in these examples. ● The domain is kvmcorp.com . ● The user account that is used to query the domain cont roller for authentication and access controls is kvmldap .
APC by Schneider Electric LDAP Lab Layout Server1 Server2 Server3 OBWI Client IPKVM1 192.168.5.11 LDAP Server KVMcorp.com 192.168.5.100 192.168.5.50 KVM.
APC by Schneider Electric Synchronize Server Module names to AD Computer Object names ● Name the Server Modules to match exactly the names of the computers with which they are connected. This must be done using the OSD from the local port on the IP KVM switch.
APC by Schneider Electric Name the Server Modules via the Local Port OSD From the local OSD, press the Print Scrn key. The Main dialog box appears. Click the name you want to change, and click Modify, rename the server module and click OK.
APC by Schneider Electric Active Directory Tasks NOTE: In a production environment, work with your IT department to create the console query user account and add the IP KVM switches OU.
APC by Schneider Electric Create a user named kvmldap , and assign the password: Password1 Set the Password not to expire Create User to Browse the Directory This is a special user account specificall.
APC by Schneider Electric Create two groups for IP KVM sw itch administrators and users. 1. Right-click IPKVM OU. 2. Choose New Group. 3. Create groups names KVMSwitchAdministration and ServerAdministration .
APC by Schneider Electric NOTE: In a production environment, groups in the Active Directory IPKVM OU would match the organization's hierarchy, usually by functi on, geography, or a combination.
APC by Schneider Electric 1. Right-click each of the two new groups. 2. Click Properties. 3. Click the Members tab. 4. Click Add. 5. Click Object Types.
APC by Schneider Electric Create Computer Object in AD for the IP KVM Switch Create a computer object in the dire ctory for each IP KVM switch with the same name as you will give it in the SNMP panel for the switch. In this Lab, create a computer object named IPKVM1 .
APC by Schneider Electric Log into the Switch Launch your web browser and point it to the IP address of the IP KVM Switch and login with the default Admin user name & PW: apc and apc.
APC by Schneider Electric Name the Switch From the Configure screen, select SNMP and name the switch IPKVM1.
APC by Schneider Electric Enable LDAP Authentication Click on Authentication under Appliance in the Configuration Menu.
APC by Schneider Electric Check the Use LDAP Authentication box. On the Server Parameters tab, enter the IP address of the Primary Server: 192.168.5.100 (domain controller). After this, a reboot of the switch is required. Reboot and log back in as apc with apc as the password and return to the Authentication screen.
APC by Schneider Electric Configure LDAP Search Parameters On the Search Parameters tab, enter the Search DN: cn=kvmldap,cn =users,dc=kvmcorp,d c=com NOTE: The first cn field must match the full na me of the user, not the login name. For example, if the user name is John Doe, then cn=John Doe (note the space in the name).
APC by Schneider Electric Leave Query Parameter at Basic IMPORTANT: This query mode should be used to test your LDAP configuration only. After the basic LDAP communications configuration is successfully tested, change the query mode because Basic mode gives full administration authorization to all IP KVM switches and all attached servers.
APC by Schneider Electric Test the basic LDAP Authentication Log out of the APC Web Interface and go back to the login prompt. Log in as: kvmldap with the password Password1 (the user you created earlier to browse the network.) It should load the APC Management Page if the switch can communicate to the Directory.
APC by Schneider Electric Basic Summary ● Very basic ● Quick to set up ● All users have administrator rights ● Use the “Search Base” in the “LDAP Parameters” to limit user access by ad.
All content in this pre sentation is protec ted – © 2008 American Power Conversion Corpora tion Group Based Authentication.
APC by Schneider Electric Change LDAP Query to Group After the basic LDAP communication test succeeds, Log off, then log in to the IP KVM switch as apc with apc as the password.
APC by Schneider Electric To add or take away rights, just add the Server Module Computer Objects and the Users as members of the respective group. Be sure to include the computer object for the IP KVM Switch as well.
APC by Schneider Electric Group Summary ● Highly granular security ● Port level control ● Attributes set to groups ra ther than individual users ● Hugely scalable ● Ideal for Enterprise cust.
APC by Schneider Electric Conclusion ● LDAP allows you to integrate your KVM with your security infrastructure to provide an easy to use yet powerf ul management tool to keep your servers up and run.
Ein wichtiger Punkt beim Kauf des Geräts Schneider Electric AP561x (oder sogar vor seinem Kauf) ist das durchlesen seiner Bedienungsanleitung. Dies sollten wir wegen ein paar einfacher Gründe machen:
Wenn Sie Schneider Electric AP561x noch nicht gekauft haben, ist jetzt ein guter Moment, um sich mit den grundliegenden Daten des Produkts bekannt zu machen. Schauen Sie zuerst die ersten Seiten der Anleitung durch, die Sie oben finden. Dort finden Sie die wichtigsten technischen Daten für Schneider Electric AP561x - auf diese Weise prüfen Sie, ob das Gerät Ihren Wünschen entspricht. Wenn Sie tiefer in die Benutzeranleitung von Schneider Electric AP561x reinschauen, lernen Sie alle zugänglichen Produktfunktionen kennen, sowie erhalten Informationen über die Nutzung. Die Informationen, die Sie über Schneider Electric AP561x erhalten, werden Ihnen bestimmt bei der Kaufentscheidung helfen.
Wenn Sie aber schon Schneider Electric AP561x besitzen, und noch keine Gelegenheit dazu hatten, die Bedienungsanleitung zu lesen, sollten Sie es aufgrund der oben beschriebenen Gründe machen. Sie erfahren dann, ob Sie die zugänglichen Funktionen richtig genutzt haben, aber auch, ob Sie keine Fehler begangen haben, die den Nutzungszeitraum von Schneider Electric AP561x verkürzen könnten.
Jedoch ist die eine der wichtigsten Rollen, die eine Bedienungsanleitung für den Nutzer spielt, die Hilfe bei der Lösung von Problemen mit Schneider Electric AP561x. Sie finden dort fast immer Troubleshooting, also die am häufigsten auftauchenden Störungen und Mängel bei Schneider Electric AP561x gemeinsam mit Hinweisen bezüglich der Arten ihrer Lösung. Sogar wenn es Ihnen nicht gelingen sollte das Problem alleine zu bewältigen, die Anleitung zeigt Ihnen die weitere Vorgehensweise – den Kontakt zur Kundenberatung oder dem naheliegenden Service.