HP Remote Device Access Service Brief

4
HP uses the CAS to tunnel connections (via SSH port forwarding) to target systems in the
customer's network. No special setup is required, other than that the system is running an SSH
daemon.
Virtual Customer Access System
The Virtual CAS (vCAS) is a pre-packaged CAS that includes advanced authentication, access
control, and auditing capabilities. Customers may download and run this virtual appliance on a
VMware ESX Server or VirtualBox host system instead of a basic CAS.
HP Instant Customer Access Server
The HP Instant CAS (HP iCAS) manages the customer's side of the Meet In The Middle
connection. It is controlled by the iCAS start page on the RAMS. Its two main features are that
it allows the customer to connect outbound via SSH to a RAMS on the HP network and also
allows the customer to control access to targets on their network.
The Customer Access System
A Customer Access System (CAS) is required for all RDA connection methods, except Virtual
Support Room. The CAS hosts the SSH server and provides a central point for customers to control
remote access into their environment. Customers determine the login of each HP user individually to
allow or deny specific services or access to specific computers within their network. HP uses the
CAS to tunnel connections (via SSH port forwarding) to target systems in the customer's network.
No special setup is required, other than that the system is running an SSH daemon.
The CAS can be set up as a virtual system using the RDA Virtual CAS, which is a virtual appliance
that runs within the VMware ESX Server or VirtualBox environment. The Virtual CAS is a pre-
packaged CAS that includes advanced authentication, access control, and auditing capabilities.
Customers may download and run this virtual appliance on a VMware ESX Server or VirtualBox
host system, instead of a basic CAS.
The Virtual CAS kit is around 113 MB and has the following key characteristics:
Authentication
The Virtual CAS provides a single sign on authentication mechanism. When an HP user logs
into a virtual CAS as they connect to target systems, the CAS authentication occurs
automatically.
Access Control
From the Web user interface the customer may control which HP support agents can access
the CAS and restrict to where they can connect.
Audit Logs
The Virtual CAS maintains a detailed log, visible to the customer, of remote access sessions
through the CAS into the customer environment. The log details the HP support agent’s email
address, the date and time of the RDA session and the details of the target the HP support
agent connected to.
Manageability
The Virtual CAS has an integrated patch and update mechanism. The customer may select to
have patches and updates applied automatically, or they may manually apply them.
Low Footprint/Low Cost
The Virtual CAS is small in size (<115MB) and does not rely on licensed third party software.
The CAS can also be setup instantly using the HP Instant CAS, which is installed on the customer's
desktop. The HP iCAS is used by a HP customer to initiate and manage connections from a point in
their network to the HP RAMS server in order to "meet" the HP Service Engineer for a remote
support session.
The Instant CAS kit is around 1.40 MB and has the following capabilities:
Provides a browser base user interface
Provides a mechanism for connecting to HP