User Manual
UPS Network Management Card 3 User Guide55
You can enable access to the CLI through either Telnet or SSH or through both, by using the Enable check
boxes. Telnet is disabled by default, and SSH is enabled by default. Telnet does not encrypt user names,
passwords, and data during transmission whereas SSH does.
NOTE: If you enable SSH, SCP (SeCure CoPy) is also enabled, for secure file transfer. See “File Transfers” for
more information on the use of SCP.
For the ports to be used to communicate with the NMC, you can change the setting to any unused port from
5000 to 32768 for additional security.
• Telnet Port: This is 23 by default. You must then use a colon (:) or a space to specify the non-default
port, as required by your Telnet client program.
For example, for port 5000 and an IP address of 152.214.12.114, your Telnet client requires one of the
these commands:
telnet 152.214.12.114:5000 or telnet 152.214.12.114 5000
• SSH Port: This is 22 by default. See the documentation for your SSH client for the command line
format required to specify a non-default port. See also “SSH Host Key” below.
SSH Host Key. If you’re using SSH (Secure Shell Protocol) for console (CLI) access, you can add, replace,
or remove the host key on the SSL Host Key screen.
Status indicates whether the host key (private key) is valid. The Status can be:
• SSH Disabled: No host key in use.
• Generating: The NMC is creating a host key because no valid host key was found.
• Loading: A host key is being activated on the NMC.
• Valid: One of the following valid host keys is in the /ssh directory (the required location on the Network
Management Card):
– A 1024-bit or 2048-bit host key created by the Security Wizard
– A 2048-bit RSA host key generated by the Network Management Card
Add or Replace Host Key: Upload a host key file created by the Security Wizard. To use the Security Wizard,
see the Security Handbook on the APC website. To use an externally created host key, load the host key
before you enable SSH (with “Console access” above).
NOTE: To reduce the time required to enable SSH, create and upload a host key in advance. If you enable
SSH with no host key loaded, the NMC takes up to one minute to create a host key, and the SSH server is not
accessible during that time.
Remove: Delete the host key. See screen text also.
To use SSH, you must have an SSH client installed. Most Linux and other UNIX
platforms include
an SSH client, but Microsoft Windows operating systems do not (except Windows 10). Clients for
Windows are available from various vendors, such as PuTTY which is available from
www.putty.org.
SNMP screens
All user names, passwords, and community names for SNMP are transferred over the network as plain text.If
your network requires the high security of encryption, disable SNMP access or set the access for each
community to Read. (A community with Read access can receive status information and use SNMP traps.)










