Tripp Lite B097016 Owners Manual for B093- B097- and B098-Series Console Serve - Page 105

Configuring for SSH Tunneling to Hosts, 2 SDT Connector Client Configuration

Page 105 highlights

6. SSH Tunnels and SDT Connector 6.1 Configuring for SSH Tunneling to Hosts To set up the console server for SSH tunneled access a network attached host: • Add the new host and the permitted services using the Serial & Network: Network Hosts menu as detailed in section 4.4 Network Hosts. Only these permitted services will be forwarded by SSH to the host. All other services (TCP/UDP ports) will be blocked. Note: Some TCP Ports used by SDT in the console server include: 22 SSH (All SDT tunneled connections) 23 Telnet on local LAN (forwarded inside tunnel) 80 HTTP on local LAN (forwarded inside tunnel) 3389 RDP on local LAN (forwarded inside tunnel) 5900 VNC on local LAN (forwarded inside tunnel) 73XX RDP over serial from local LAN - where XX is the serial port number (i.e. 7301 to 7348 on a 48-port console server) 79XX VNC over serial from local LAN - where XX is the serial port number • Add new Users using the Serial & Network: Users & Groups menu as detailed in 4.4 Network Hosts. Users can be authorized to access the console server ports and specified network-attached hosts. To simplify configuration, the Administrator can first set up Groups with group access permissions, then assign Users to those Group(s). 6.2 SDT Connector Client Configuration The SDT Connector client works with all Tripp Lite console servers. Each of these remote console servers have an embedded OpenSSH-based server, which can be configured to port forward connections from the SDT Connector client to hosts on their local network, as detailed in the previous chapter. The SDT Connector can also be pre-configured with access tools and applications available to be run when access to a particular host has been established. SDT Connector can connect to the console server using alternate OOB access. It can also access the console server itself and access devices connected to serial ports on the console server. 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288

105
6. SSH Tunnels and SDT Connector
6.1 Configuring for SSH Tunneling to Hosts
To set up the console server for SSH tunneled access a network attached host:
• Add the new host and the permitted services using the
Serial & Network: Network Hosts
menu as detailed in section
4.4
Network Hosts
. Only these permitted services will be forwarded by SSH to the host. All other services (TCP/UDP ports) will
be blocked.
Note:
Some TCP Ports used by SDT in the console server include:
22
SSH (All SDT tunneled connections)
23
Telnet on local LAN (forwarded inside tunnel)
80
HTTP on local LAN (forwarded inside tunnel)
3389 RDP on local LAN (forwarded inside tunnel)
5900 VNC on local LAN (forwarded inside tunnel)
73XX RDP over serial from local LAN – where XX is the serial port number (i.e. 7301 to 7348 on a 48-port console server)
79XX VNC over serial from local LAN – where XX is the serial port number
• Add new Users using the
Serial & Network: Users & Groups
menu as detailed in
4.4 Network Hosts
. Users can
be authorized to access the console server ports and specified network-attached hosts. To simplify configuration, the
Administrator can first set up Groups with group access permissions, then assign Users to those Group(s).
6.2 SDT Connector Client Configuration
The SDT Connector client works with all Tripp Lite console servers. Each of these remote console servers have an embedded
OpenSSH-based server, which can be configured to port forward connections from the SDT Connector client to hosts on
their local network, as detailed in the previous chapter. The SDT Connector can also be pre-configured with access tools and
applications available to be run when access to a particular host has been established.
SDT Connector can connect to the console server using alternate OOB access. It can also access the console server itself and
access devices connected to serial ports on the console server.