HP StorageWorks XP Command View Advanced Edition Software 6.4 Server Administrator Guide for Device Manager and Provisioning Manager (web) (T1780-96341, July 2010)

Table Of Contents
Overview
12
a different LAN that has a different firewall. The firewall contains strict access rules that allow the
management servers to be accessed only by Device Manager clients or by specified management
application clients.
The following figure illustrates a separate management LAN with a firewall configuration.
Figure 1-3 Most secure configuration: separate management LAN plus firewall
This configuration is the most secure but is the least flexible implementation, because it requires
overhead to manage the various network components, servers, and managed devices. Adding
further security to this configuration requires that the underlying management application OS be
hardened to the maximum possible. This hardening includes disabling services such as Telnet,
FTP, SMTP, or IIS. Additionally, if possible, all unnecessary packages should be removed.
CAUTION: When Physical View of XP24000/XP20000 or XP12000/XP10000/SVS200, or XP
Remote Web Console of XP1024/XP128 is launched, Java Web Start and the web browser on the
web client computer directly communicate with the storage subsystem. For this reason, if the web
client computer and the storage subsystem exist on different networks, you must set up the
networks so that the computer and the storage subsystem can directly communicate with each
other.
1-2-3 Second-most secure configuration: separate
management LAN plus firewalled devices under
management
In this configuration, the machine hosting the Device Manager server and all other application
servers must be single-homed, and the actual managed devices must be separated from Device