White Papers
Understanding OpenManage Mobile (OMM) and Quick Sync Security (PowerEdge 14th Gen servers and
MX Chassis)
10
Technical support and resources
2.3 Remote console security
OMM can start third party remote console (VNC) applications based on the RFB protocol. OMM Android
integrates with bVNC, while OMM iOS integrates with RealVNC and Remoter Pro.
When connecting to the 14
th
generation PowerEdge servers, these connections can be channeled over
SSH by using standard iDRAC credentials. On iOS, this requires the paid Remoter Pro app.
On Android, connections to the 12
th
and 13
th
generation PowerEdge servers can be channeled over TLS. The
connection is secured by using a dedicated VNC password.
2.4 Remote Connection Security—best practices
To help secure an environment by using OMM for remote management:
• Use a VPN to secure access to the management network from remote sites. Avoid connecting
iDRAC and OME systems directly to the internet.
• When making a management network available by using Wi-Fi, use the best available security
configuration, such as WPA2 with a random key.
• Use VNC over SSH or VNC clients with TLS encryption enabled.
• Change the iDRAC root credentials to something other than the default.
• Consider using a proxy server to control outbound internet access from the OME or OMM.
Note: Currently, no iOS VNC clients can communicate with the 12
th and
13
th
generation iDRAC over TLS. If
you are confident in the security of your management Wi-Fi or VPN network, use only unencrypted VNC
connections.