
Chapter 4: Administration Introduction 33
See Chapter 4 for the tasks related to administering SNMP on the SP manager.
VPN on the MergePoint 5224/5240 SP Manager
As described in the MergePoint 5224/5240 Service Processor Manager User Guide, native IP
access to native management features on connected devices is available only after the authorized
user has establish a trusted connection. VPN tunnels are required for a user to obtain native IP
access either by going through the Web Manager or by entering ssh with the nativeipon device
management command.
CAUTION: As discussed in the user’s guide, unlike Native IP access, DirectCommand access automatically
establishes the needed trusted connection. Also, for Native IP to work properly, the authentication method
configured for the SP manager must be the same as the authentication method assigned to the target device.
Once a user has been authenticated and the user’s authorization to access a target device has been
checked, a user with a VPN connection has unlimited access to the target device. The SP manager
cannot control whether a connected target device allows unrestricted access to the rest of the
network; therefore, administrators must take care when configuring users of the target devices to
protect the security of the network.
VPN connections establish encrypted communications between the SP manager and the user’s
workstation. The encryption creates a security tunnel for communications through an intermediate
network which is untrustworthy. The user’s workstation and the SP manager take care of
encryption and decryption on their end.
An administrator must make sure that the appropriate service for the desired type of VPN
connection is enabled (either PPTP or IPSec) on the MergePoint 5224/5240 SP manager before
configuring a VPN connection profile on the SP manager for the type of VPN connections to be
used.
The SP manager
listens for the connection attempt from the IP addresses specified in its connection
profiles and grants or denies the access.
Comentarios a estos manuales