<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISEE without browser in Insight Remote Support</title>
    <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538971#M522</link>
    <description>Thx all for your input, Im nearly there now. First posting for me, a very helpful tool.&lt;BR /&gt;&lt;BR /&gt;Lastly, can someone please tell me the the different values possible for 'State' in the incident log (as mentioned by Frauke) and the meaning of each? &lt;BR /&gt;Eg If 9=closed, what do 0, 4, 5, etc mean?&lt;BR /&gt;&lt;BR /&gt;Cant find anything in the HP doco on this one...</description>
    <pubDate>Mon, 09 May 2005 19:12:40 GMT</pubDate>
    <dc:creator>michael denny_1</dc:creator>
    <dc:date>2005-05-09T19:12:40Z</dc:date>
    <item>
      <title>ISEE without browser</title>
      <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538967#M518</link>
      <description>Is there a way to check (and confirm) ISEE connectivity with HP without starting up a browser (ie from the command line?). The mad.log file doesnt look overly reliable (ie reports failures even when working ok..)&lt;BR /&gt;&lt;BR /&gt;Secondly, to ensure ISEE connectivity with HP thru a firewall, what ports should be allowed?&lt;BR /&gt;&lt;BR /&gt;Any info much appreciated.&lt;BR /&gt;Thx</description>
      <pubDate>Thu, 05 May 2005 22:38:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538967#M518</guid>
      <dc:creator>michael denny_1</dc:creator>
      <dc:date>2005-05-05T22:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISEE without browser</title>
      <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538968#M519</link>
      <description>This is how I test my isee connection with HP:&lt;BR /&gt;&lt;BR /&gt;/etc/opt/resmon/lbin/send_test_event -a sysstat_em&lt;BR /&gt;&lt;BR /&gt;run this command on the server in question as root and notify HP that you are running this command for them to check that it reaches them.&lt;BR /&gt;&lt;BR /&gt;The firewall question is more complicated.  Here are a few questions we had for HP and their answers before we implemented our SPOP.&lt;BR /&gt;&lt;BR /&gt;1. What steps are taken to "harden" the SPOP?&lt;BR /&gt;From a software perspective, the person who installs the OS can do whatever they need to as for a standard Windows system according to their internal company requirements â   anti-virus, security tools, etc.  &lt;BR /&gt;HP does not make recommendations as to additional security measures.  &lt;BR /&gt;The SPOP protection depends largely on the Firewall.  Communication is set up to/from specific sets of IP addresses.&lt;BR /&gt;&lt;BR /&gt;2. Which web server is running on the SPOP?&lt;BR /&gt;IIS:  Supports http 80 and https 443.  http 80 listens for monitored client connections.  https 443 listens for Map requests from HP.  &lt;BR /&gt;&lt;BR /&gt;Apache Tomcat:  Supports https 8080 and http 2112.  https 8080 supports guest connection for Map requests from HP.  http 2112 is used internally and needs no external access capability.&lt;BR /&gt;&lt;BR /&gt;3. Why aren't the MAP protocols tunneled via VPN?&lt;BR /&gt;The communication that goes back and forth between the SPOP and the content server is HTTPS.  The engineer uses the VPN tunnel for Remote Access.  Setting up the VPN is not automatic.  It is user driven and requires user (real-time) authentication. Again, the VPN connection is user-based not system based.  To use this for system access is not the purpose of the VPN.  Since the communication associated with MAP requests and telemetry transfer is HTTPS, any gain realized by tunneling https via a VPN connection would be negligible.&lt;BR /&gt;&lt;BR /&gt;MAP functionality was developed by Motive before Remote Access was developed by HP, thus they truly are independent.  For the next release of ISEE MAP requests are pulled by the SPOP thus the inbound 443, 8080 requirements will be going away.&lt;BR /&gt;&lt;BR /&gt;Today, MAPs will not work until we release an SPOP patch what will change the way MAPs are executed.  Because of this, do not TCP 443 and 8080 through your firewall.  Why open holes that can't/won't be used.  &lt;BR /&gt;&lt;BR /&gt;4. Would it be possible to tunnel http from the monitored client to the SPOP in the DMZ config via SSL?&lt;BR /&gt;The communication today from the client to the SPOP is HTTP.  It is RSA encrypted then communicated via HTTP.  This is built into the product.  So at this point tunneling these types of communications is not supported nor planned.&lt;BR /&gt;&lt;BR /&gt;Motive uses RSA technology to encrypt and protect connections from client to SPOP.  This connection can be routed through a proxy.&lt;BR /&gt;&lt;BR /&gt;At this point it would not be possible to modify Motive to use SSL.&lt;BR /&gt;&lt;BR /&gt;5. Can we change the REP port to be something other then 3389?&lt;BR /&gt;Since this is built-in to Windows and we perform the connect to this port for any connections to the SPOP changing this would break the product.  We could no longer perform the TS connection from HP to the SPOP.  Currently, we do not "collect" or manage what the port is or could be. There is currently no plan to use anything but the standard port number.&lt;BR /&gt;&lt;BR /&gt;6. Who provides the VPN software that resides on the SPOP?&lt;BR /&gt;HP uses the integrated into W2K; Routing and Remote Access service to implement L2TP/IPSec VPN connections.&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
      <pubDate>Fri, 06 May 2005 22:39:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538968#M519</guid>
      <dc:creator>Robert Bennett_3</dc:creator>
      <dc:date>2005-05-06T22:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISEE without browser</title>
      <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538969#M520</link>
      <description>Michael,&lt;BR /&gt;&lt;BR /&gt;One way to test ISEE connectivity without a browser installed on the ISEE monitored server is to use telnet as follows:&lt;BR /&gt;&lt;BR /&gt;strauss:/# telnet isee.americas.hp.com 80&lt;BR /&gt;Trying...&lt;BR /&gt;Connected to awtf907.external.hp.com.&lt;BR /&gt;Escape character is '^]'.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Server: Microsoft-IIS/5.0&lt;BR /&gt;Date: Sat, 07 May 2005 11:11:41 GMT&lt;BR /&gt;Content-Type: text/html&lt;BR /&gt;Content-Length: 87&lt;BR /&gt;&lt;BR /&gt;&lt;TITLE&gt;Error&lt;/TITLE&gt;The parameter is incorrect. &lt;BR /&gt;&lt;BR /&gt;Connection closed by foreign host.&lt;BR /&gt;strauss:/#&lt;BR /&gt;&lt;BR /&gt;There are other tools to test connectivity that are accessible only to HP folks; if you have access to HP internal sites contact me by company mail for more details.&lt;BR /&gt;&lt;BR /&gt;The firewall port that must be opened for ISEE varies with ISEE architecture. The standard configuration requires port 80 be opened 'established' back. For the advanced configuration, which uses an SPOP (Support Point Of Presence) to forward the ISEE incidents from every ISEE Client in the enterprise to the HP Support Center, port 443 must be opened 'established' back.&lt;BR /&gt;&lt;BR /&gt;Hope that answers your questions.&lt;BR /&gt;&lt;BR /&gt;Take care,&lt;BR /&gt;frank&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 07 May 2005 06:42:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538969#M520</guid>
      <dc:creator>Frank Alden Smith</dc:creator>
      <dc:date>2005-05-07T06:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISEE without browser</title>
      <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538970#M521</link>
      <description>Hello Michael,&lt;BR /&gt;you can as well use the test scripts that ISEE provides, like /opt/hpservices/RemoteSupport/bin/iseeConnectivity.sh. If the test works that system will provide an ID to you (format: 123456789.1@&lt;SYSTEMNAME&gt;). Go to the directory /opt/hpservices/incidents/123456789.1@&lt;SYSTEMNAME&gt; (or how ever your ID looks like). In this directory you will find a file named incident.dat, open it and check for "State =". If the connection works it should change to the value "9" which is the same like "CLOSED" in the UI.&lt;BR /&gt;Regards&lt;BR /&gt;Frauke&lt;BR /&gt;&lt;/SYSTEMNAME&gt;&lt;/SYSTEMNAME&gt;</description>
      <pubDate>Mon, 09 May 2005 02:08:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538970#M521</guid>
      <dc:creator>Frauke Denker_2</dc:creator>
      <dc:date>2005-05-09T02:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISEE without browser</title>
      <link>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538971#M522</link>
      <description>Thx all for your input, Im nearly there now. First posting for me, a very helpful tool.&lt;BR /&gt;&lt;BR /&gt;Lastly, can someone please tell me the the different values possible for 'State' in the incident log (as mentioned by Frauke) and the meaning of each? &lt;BR /&gt;Eg If 9=closed, what do 0, 4, 5, etc mean?&lt;BR /&gt;&lt;BR /&gt;Cant find anything in the HP doco on this one...</description>
      <pubDate>Mon, 09 May 2005 19:12:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/isee-without-browser/m-p/3538971#M522</guid>
      <dc:creator>michael denny_1</dc:creator>
      <dc:date>2005-05-09T19:12:40Z</dc:date>
    </item>
  </channel>
</rss>

