Wednesday, December 14, 2011

Effective Out Of Band Management

Out of band management, offers various solutions for problems occurring at unmanned equipment sites at remote locations. A small problem can cause the primary network to shut down, and for this, console server is an effective tool for managing problems at a remote location. The device is similar to a router or switch with its serial ports connected to the consoles of other machines. The software housed in the device enables you to log into any of the required consoles and operate them from anywhere in the network, as each port is assigned a unique IP address.

As the console server can effectively and remotely access important command functions that are sensitive, it is imperative to have proper security to prevent unauthorized access.  Although most servers include good security features like filtering of IP addresses and password protection, it may not be able to alert the administrators when an actual hack is taking place. In such a case, it is necessary to include an alarm function for invalid access. 



This type of alarm function will alert the support staff or administrators when any suspicious password activity is detected. Such a function can also include an option where the user can specify the number of access attempts that are allowed, before the alarm is triggered. Once the alarm is triggered, it should be able to alert the primary staff, and in case there is no response, the console server should be able to send the notification to multiple staff members.

It is also quite useful if the alarm notifications for invalid access are sent through various popular protocols of communications like SYSLOG messages, SNMP traps, text messages, and emails. However, as an ultimate failsafe precaution, the function can include a temporary shutdown of the network access after the alarm is triggered. In such a case, an option should be provided to the administrator, to define the duration of the lockout.

It is also necessary to maintain a log of invalid access attempts. This will provide good amount of data for studying trends, and finding out the number of legitimate attempts that were invalid, and the ones that were perpetrated possibly by hackers. Such log analysis can be carried out on a regular basis, if lot of invalid access activity is seen over a period. This will also prompt administrators to take additional security precautions.

The console server provides out of band access capabilities, which are crucial for managing problems in remote racks of network equipments. Without these capabilities, a lot of time and manpower can be wasted accessing this remote sites. However, the importance of such capabilities should not overshadow the need for proper security, and a multi-layered approach with additional alarms for invalid access is highly effective.