Opengear ACM7000 Manuale utente

User Manual
ACM7000 Remote Site Gateway
ACM7000-L Resilience Gateway
IM7200 Infrastructure Manager
CM7100 Console Servers
Version 4.6 2019-09-11

2
Safety
Follow the safety precautions below when installing and operating the console server:
• Do not remove the metal covers. There are no operator serviceable components inside.
Opening or removing the cover may expose you to dangerous voltage which may cause fire or
electric shock. Refer all service to Opengear qualified personnel.
• To avoid electric shock the power cord protective grounding conductor must be connected
through to ground.
• Always pull on the plug, not the cable, when disconnecting the power cord from the socket.
Do not connect or disconnect the console server during an electrical storm. Also use a surge
suppressor or UPS to protect the equipment from transients.
FCC Warning Statement
This device complies with Part 15 of the FCC rules. Operation of this device is subject to the following
conditions: (1) This device may not cause harmful interference, and (2) this device must accept
any interference that may cause undesired operation.
Proper back-up systems and necessary safety devices should be utilized to protect against
injury, death or property damage due to system failure. Such protection is the responsibility
of the user.
This console server device is not approved for use as a life-support or medical system.
Any changes or modifications made to this console server device without the explicit
approval or consent of Opengear will void Opengear of any liability or responsibility of injury
or loss caused by any malfunction.
This equipment is for indoor use and all the communication wirings are limited to inside of
the building.

User Manual
Copyright
©Opengear Inc. 2019. All Rights Reserved.
Information in this document is subject to change without notice and does not represent a
commitment on the part of Opengear. Opengear provides this document “as is,” without warranty of
any kind, expressed or implied, including, but not limited to, the implied warranties of fitness or
merchantability for a particular purpose.
Opengear may make improvements and/or changes in this manual or in the product(s) and/or the
program(s) described in this manual at any time. This product could include technical inaccuracies or
typographical errors. Changes are periodically made to the information herein; these changes may be
incorporated in new editions of the publication.

4
TABLE OF CONTENTS
1 THIS MANUAL ....................................................................................................................................... 6
1.1 TYPES OF USERS ........................................................................................................................................ 6
1.2 MANAGEMENT CONSOLE ........................................................................................................................... 6
1.3 MORE INFORMATION ................................................................................................................................. 7
2 SYSTEM CONFIGURATION ..................................................................................................................... 8
2.1 MANAGEMENT CONSOLE CONNECTION ......................................................................................................... 8
2.2 ADMINISTRATOR SET UP .......................................................................................................................... 10
2.3 NETWORK CONFIGURATION ...................................................................................................................... 11
2.4 SERVICE ACCESS AND BRUTE FORCE PROTECTION .......................................................................................... 15
2.5 COMMUNICATIONS SOFTWARE .................................................................................................................. 18
2.6 MANAGEMENT NETWORK CONFIGURATION ................................................................................................. 19
3 SERIAL PORT, HOST, DEVICE & USER CONFIGURATION ........................................................................ 28
3.1 CONFIGURE SERIAL PORTS ........................................................................................................................ 28
3.2 ADD AND EDIT USERS .............................................................................................................................. 38
3.3 AUTHENTICATION ................................................................................................................................... 42
3.4 NETWORK HOSTS .................................................................................................................................... 42
3.5 TRUSTED NETWORKS ............................................................................................................................... 43
3.6 SERIAL PORT CASCADING .......................................................................................................................... 45
3.7 SERIAL PORT REDIRECTION (PORTSHARE) .................................................................................................... 49
3.8 MANAGED DEVICES ................................................................................................................................. 50
3.9 IPSEC VPN ............................................................................................................................................ 52
3.10 OPENVPN ............................................................................................................................................ 55
3.11 PPTP VPN ............................................................................................................................................ 63
3.12 CALL HOME ........................................................................................................................................... 68
3.13 IP PASSTHROUGH ................................................................................................................................... 71
3.14 CONFIGURATION OVER DHCP (ZTP) .......................................................................................................... 73
3.15 ENROLLMENT INTO LIGHTHOUSE ................................................................................................................ 75
4 FIREWALL, FAILOVER & OOB ACCESS ................................................................................................... 76
4.1 DIALUP MODEM CONNECTION .................................................................................................................. 76
4.2 OOB DIAL-IN ACCESS .............................................................................................................................. 76
4.3 DIAL-OUT ACCESS ................................................................................................................................... 79
4.4 OOB BROADBAND ETHERNET ACCESS ........................................................................................................ 83
4.5 BROADBAND ETHERNET FAILOVER .............................................................................................................. 83
4.6 CELLULAR MODEM CONNECTION ............................................................................................................... 84
4.7 CELLULAR OPERATION ............................................................................................................................. 93
4.8 FIREWALL & FORWARDING ....................................................................................................................... 96
5 SSH TUNNELS & SDT CONNECTOR ..................................................................................................... 105
5.1 CONFIGURING FOR SSH TUNNELING TO HOSTS ........................................................................................... 106
5.2 SDT CONNECTOR CLIENT CONFIGURATION ................................................................................................ 106
5.3 SDT CONNECTOR TO MANAGEMENT CONSOLE .......................................................................................... 115
5.4 SDT CONNECTOR: TELNET OR SSH CONNECT TO SERIALLY ATTACHED DEVICES .................................................. 115
5.5 USING SDT CONNECTOR FOR OUT-OF-BAND CONNECTION TO THE GATEWAY .................................................... 117
5.6 IMPORTING (AND EXPORTING) PREFERENCES .............................................................................................. 118
5.7 SDT CONNECTOR PUBLIC KEY AUTHENTICATION ......................................................................................... 119
5.8 SETTING UP SDT FOR REMOTE DESKTOP ACCESS ......................................................................................... 120
5.9 SDT SSH TUNNEL FOR VNC ................................................................................................................... 121
5.10 USING SDT TO IP CONNECT TO HOSTS THAT ARE SERIALLY ATTACHED TO THE GATEWAY ...................................... 123
5.11 SSH TUNNELING USING OTHER SSH CLIENTS (E.G. PUTTY) ........................................................................... 127

User Manual
6 ALERTS, AUTO-RESPONSE & LOGGING ............................................................................................... 129
6.1 CONFIGURE AUTO-RESPONSE .................................................................................................................. 129
6.2 CHECK CONDITIONS ............................................................................................................................... 131
6.3 TRIGGER ACTIONS ................................................................................................................................. 142
6.4 RESOLVE ACTIONS ................................................................................................................................. 145
6.5 CONFIGURE SMTP, SMS, SNMP AND/OR NAGIOS SERVICE FOR ALERT NOTIFICATIONS ..................................... 145
6.6 LOGGING ............................................................................................................................................. 150
7 POWER, ENVIRONMENT & DIGITAL I/O ............................................................................................. 153
7.1 REMOTE POWER CONTROL (RPC) ............................................................................................................ 153
7.2 UNINTERRUPTIBLE POWER SUPPLY(UPS) CONTROL .................................................................................... 158
7.3 ENVIRONMENTAL MONITORING .............................................................................................................. 167
7.4 DIGITAL I/O PORTS ............................................................................................................................... 172
8 AUTHENTICATION ............................................................................................................................. 175
8.1 AUTHENTICATION CONFIGURATION .......................................................................................................... 175
8.2 PAM (PLUGGABLE AUTHENTICATION MODULES) ....................................................................................... 188
8.3 SSL CERTIFICATE ................................................................................................................................... 189
8.4 ADDING OPENGEAR CUSTOM ATTRIBUTES .................................................................................................. 192
9 NAGIOS INTEGRATION ...................................................................................................................... 193
9.1 NAGIOS OVERVIEW ............................................................................................................................... 193
9.2 CONFIGURING NAGIOS DISTRIBUTED MONITORING ...................................................................................... 194
9.3 ADVANCED DISTRIBUTED MONITORING CONFIGURATION ............................................................................. 199
10 SYSTEM MANAGEMENT .................................................................................................................... 207
10.1 SYSTEM ADMINISTRATION AND RESET ....................................................................................................... 207
10.2 UPGRADE FIRMWARE ............................................................................................................................ 207
10.3 CONFIGURE DATE AND TIME ................................................................................................................... 208
10.4 CONFIGURATION BACKUP ....................................................................................................................... 210
10.5 DELAYED CONFIGURATION COMMIT ......................................................................................................... 212
10.6 FIPS MODE ......................................................................................................................................... 213
11 STATUS REPORTS ............................................................................................................................... 214
11.1 PORT ACCESS AND ACTIVE USERS ............................................................................................................. 214
11.2 STATISTICS ........................................................................................................................................... 215
11.3 SUPPORT REPORTS ................................................................................................................................ 215
11.4 SYSLOG ............................................................................................................................................... 216
11.5 DASHBOARD ........................................................................................................................................ 218
12 MANAGEMENT .................................................................................................................................. 221
12.1 DEVICE MANAGEMENT .......................................................................................................................... 221
12.2 PORT AND HOST LOGS ........................................................................................................................... 222
12.3 TERMINAL CONNECTION ......................................................................................................................... 222
12.4 POWER MANAGEMENT .......................................................................................................................... 224
APPENDIX A: HARDWARE SPECIFICATION ................................................................................................... 225
APPENDIX B: SAFETY & CERTIFICATIONS ..................................................................................................... 227
APPENDIX C: CONNECTIVITY, TCP PORTS & SERIAL I/O ............................................................................... 228
13 APPENDIX E: TERMINOLOGY ............................................................................................................. 234
END USER LICENSE AGREEMENTS ............................................................................................................... 239
14 APPENDIX G: SERVICE & STANDARD WARRANTY ............................................................................... 245

1 THIS MANUAL
This User Manual explains installing, operating, and managing Opengear console servers. This manual
assumes you are familiar with the Internet and IP networks, HTTP, FTP, basic security operations, and
your organization’s internal network.
1.1 Types of users
The console server supports two classes of users:
• Administrators who have unlimited configuration and management privileges over the console
server and connected devices as well as all services and ports to control all the serial connected
devices and network connected devices (hosts). Administrators are set up as members of the
admin user group. An administrator can access and control the console server using the config
utility, the Linux command line or the browser-based Management Console.
• Users who have been set up by an administrator with limits of their access and control authority.
Users have a limited view of the Management Console and can only access authorized configured
devices and review port logs. These users are set up as members of one or more of the pre-
configured user groups such as PPTPD, dialin, FTP, pmshell, users, or user groups the
administrator may have created. They are only authorized to perform specified controls on
specific connected devices. Users, when authorized, can access and control serial or network
connected devices using specified services (e.g. Telnet, HHTPS, RDP, IPMI, Serial over LAN,
Power Control).
Remote users are users who are not on the same LAN segment as the console server. A remote user
may be on the road connecting to managed devices over the public Internet, an administrator in
another office connecting to the console server over the enterprise VPN, or in the same room or the
same office but connected on a separate VLAN to the console server.
1.2 Management Console
The Opengear Management Console allows you to configure and monitor the features of your Opengear
console server. The Management Console runs in a browser and provides a view of the console server
and all connected devices.
Administrators can use the Management Console to configure and manage the console server, users,
ports, hosts, power devices, and associated logs and alerts. Non-admin users can use the Management
Console with limited menu access to control select devices, review their logs, and access them using the
built-in Web terminal.
The console server runs an embedded Linux operating system, and can be configured at the command
line. You can get command line access by cellular / dial-in, directly connecting to the console server’s
serial console/modem port, or by using SSH or Telnet to connect to the console server over the LAN (or
connecting with PPTP, IPsec or OpenVPN).

User Manual
For command line interface (CLI) commands and advanced instructions, download the Opengear CLI and
Scripting Reference.pdf from http://ftp.opengear.com/download/manual/current/.
1.3 More information
For more information, consult:
• Opengear Products Web Site: See https://opengear.com/products. To get the most up-to-date
information on what’s included with your console server, visit the What’s included section for your
particular product.
• Quick Start Guide: This guide that shipped with your console server takes you through initial basic
Opengear configuration.
• Opengear Knowledge Base: Visit https://opengear.zendesk.com to access technical how-to
articles, tech tips, FAQs, and important notifications.
• Opengear CLI and Scripting Reference: http://ftp.opengear.com/download/manual/current/
Opengear CLI and Scripting Reference.pdf.

Chapter 2: System Configuration
8
2 SYSTEM CONFIGURATION
This chapter provides step-by-step instructions for the initial configuration of your console server and
connecting it to the Management or Operational LAN. The steps are:
§ Activate the Management Console.
§ Change the administrator password.
§ Set the IP address console server’s principal LAN port.
§ Select the services to be enabled and access privileges.
This chapter also discusses the communications software tools that an administrator may use to access
the console server, and the configuration of the additional LAN ports.
2.1 Management Console Connection
Your console server comes configured with a default IP Address 192.168.0.1 and subnet mask
255.255.255.0.
For initial configuration, we recommend that you connect a computer directly to the console. If you do
choose to connect your LAN before completing the initial setup steps, make sure that:
• There are no other devices on the LAN with an address of 192.168.0.1.
• The console server and the computer are on the same LAN segment, with no interposed router
appliances.
2.1.1 Connected computer set up
To configure the console server with a browser, the connected computer should have an IP address in the
same range as the console server (for example, 192.168.0.100):
• To configure the IP Address of your Linux or Unix computer, run ifconfig.
• For Windows PCs:
1. Click Start > Settings > Control Panel and double click Network Connections.
2. Right click on Local Area Connection and select Properties.
3. Select Internet Protocol (TCP/IP) and click Properties.
4. Select Use the following IP address and enter the following details:
o IP address: 192.168.0.100
o Subnet mask: 255.255.255.0
5. If you want to retain your existing IP settings for this network connection, click Advanced and
Add the above as a secondary IP connection.
2.1.2 Browser connection
Open a browser on the connected PC / workstation and enter https://192.168.0.1.
Log in with:
Username> root
Password> default

User Manual
The Welcome screen appears.
The Welcome screen lists initial installation configuration steps. These steps are:
Change default administration password (Users page. See Chapter 2.2)
Configure the local network settings (System > IP page. See Chapter 2.3)
Configure console server features:
• Configure serial ports settings (Serial & Network > Serial Port page. See Chapter 3)
• Configure user port access (Serial & Network > Users page. See Chapter 3)
If your system has a cellular modem you will be given the steps to configure the cellular router features:
• Configure the cellular modem connection (System > Dial page. See Chapter 4)
• Allow forwarding to the cellular destination network (System > Firewall page. See Chapter 4)
• Enable IP masquerading for cellular connection (System > Firewall page. See Chapter 4)
After completing each of the above steps, you can return to the configuration list by clicking the Opengear
logo in the top left corner of the screen.
NOTE If you are not able to connect to the Management Console at 192.168.0.1 or if the default
Username / Password are not accepted, reset your console server (See Chapter 10).

Chapter 2: System Configuration
10
2.2 Administrator Set Up
2.2.1 Change default root System Password
Change the default password before granting the console server any access to your computers and
network appliances.
1. Click Serial & Network > Users & Groups or, on the Welcome screen, click Change default
administration password.
2. Scroll down and locate the root user entry under Users and click Edit.
3. Enter the new password in the Password and Confirm fields.
NOTE Checking Save Password across firmware erases saves the password so it does not get erased
when the firmware is reset. If this password is lost, the device will need to be firmware recovered.
4. Click Apply. Log in with the new password
2.2.2 Set up a new administrator
Create a new user with administrative privileges and log in as this user for administration functions, rather
than using root.
1. Click Serial & Network > Users & Groups and click Add User.
2. Enter a Username.
3. In the Groups section, check the admin box.
4. Enter a password in the Password and Confirm fields.
5. Click Apply.
Questo manuale è adatto per i seguenti modelli
3
Indice
Altri manuali Opengear Server

Opengear
Opengear sd4001 Manuale utente

Opengear
Opengear ACM5004-GV Manuale utente

Opengear
Opengear IM4000 Manuale utente

Opengear
Opengear CM4132 Manuale utente

Opengear
Opengear SD4008 Manuale utente

Opengear
Opengear cm4008 Manuale utente

Opengear
Opengear IMG4004-5 Manuale utente

Opengear
Opengear IM7216-2-24E Manuale utente

Opengear
Opengear SD4000 Manuale utente

Opengear
Opengear SD4002 Manuale utente



















