Server Management - Systems Insight Manager
1834149 Members
2564 Online
110064 Solutions
New Discussion

Monitoring DMZ servers.

 
SOLVED
Go to solution
Jason Warrington
Occasional Advisor

Monitoring DMZ servers.

Hi all,

I would like to use Systems Insight Manager to monitor our HP servers on our DMZ. Would someone be able to tell me what ports I need to open on the firewall to allow the servers to be monitored and updates to be pushed from our software repository.

Thanks...Jason
7 REPLIES 7
Igor Karasik
Honored Contributor
Solution

Re: Monitoring DMZ servers.

Jason,
Did you see
"Managing HP servers through firewalls with HP SIM 5.0"
ftp://ftp.compaq.com/pub/products/servers/management/hpsim/ManagingHPServers-withHPSIM.pdf
and "Port listing" (from page 13) from
"Understanding HP SIM Security"
http://h10018.www1.hp.com/wwsolutions/misc/hpsim-helpfiles/hpsim_5_Security.pdf
Jason Warrington
Occasional Advisor

Re: Monitoring DMZ servers.

Igor,

Thanks for pointing me to those documents. All the information I need is contained in them.

Thanks again.

Jason
Moray Sandison_1
Occasional Advisor

Re: Monitoring DMZ servers.

Jason/Igor,

I looked at both documents and have a question. Port 280 shows as needing to be opened from the CMS to the DMZ in one document and from the DMZ to the CMS in another. Which one is it?
Jason Warrington
Occasional Advisor

Re: Monitoring DMZ servers.

I haven't as yet implemented a solution to monitoring our DMZ servers as I'm still waiting for clearance from the security team here.

However I could not see any reference to port 280 in the first document.
Moray Sandison_1
Occasional Advisor

Re: Monitoring DMZ servers.

if you search for 280 in the PDF you will find it in the port listing table on page 12 and also in the HP SIM server table on page 15
Igor Karasik
Honored Contributor

Re: Monitoring DMZ servers.

Moray
>>Port 280 shows as needing to be opened from the CMS to the DMZ in one document and from the DMZ to the CMS in another

If I understand your question right:
IMHO you don't need to open port 280 from DMZ to CMS. You need port 280 on CMS in order to remote log on (with browser) from client computer (typically system/helpdesk group computer, anyway client computer is not in DMZ) to HP SIM

Moray Sandison_1
Occasional Advisor

Re: Monitoring DMZ servers.

thanks for the info. I am stumped on one thing. I have added the iLO addresses to HP SIM and they "associate" themselves with the already added servers correctly except where the servers are behind a firewall. The iLO cards show as unmanaged and the servers they belong to have the circle with the "i" in them under the MP heading!
Any ideas?