Managing HP Servers through Firewalls with Insight Management 7.0

6
HP management products
The following HP products are possible management options for HP servers deployed in the DMZ:
HP Insight Control Environment (ICE)-Linux
HP System Management Homepage (SMH)
HP Insight Management Agents (Agents)
HP Insight Management WBEM Providers for Windows (Insight Providers)
HP Infrastructure Orchestration (HPIO)
HP Insight Control Power Management (ICPM)
HP Smart Update Manager (HP SUM)
HP Systems Insight Manager (HP SIM)
HP WEBM Services for HP-UX
HP Insight Control performance management
HP Insight Control Server Deployment (ICSD)
HP Insight Control server migration
HP Version Control Agent (VCA)
HP Version Control Repository Manager (VCRM)
HP Insight Control virtual machine management
HP Virtual Server Environment (VSE)
HP Vulnerability and Patch Management Pack (VPM)
HP Management processors such as Integrated Lights-Out 2 (iLO 2)
HP Insight Control for VMware vCenter Server
HP Onboard Administrator (OA)
HP Virtual Connect Manager (VCM)
For information about these HP management products, see the For more information” section at the
end of this paper. Appendix A: Configuring a separate management network gives port information
related to these products.
Case 1: Management protocols banned from DMZ
In some computing environments, IT security policies restrict management protocols in the secure
environment. Security policies may or may not permit other protocols (such as email or file sharing) in
the DMZ. An acceptable management solution must conform to security restrictions of the
environment.
Even if active management is not possible, some management information can flow from managed
devices in such an environment. Either SNMP or WBEM/WMI can be used to manage ProLiant
servers. These can be configured to prevent access from off the platform. For information on how to
configure SNMP or WBEM, see the documentation for your operating system.
Asset management
In this type of computing environment, administrators can collect system asset information from a
ProLiant server in the DMZ as long as the Agents or WBEM providers are running and an application
is running that can get the data locally. For example, Microsoft Systems Management Server can
get asset information from the Agents and transfer that information to its central server through the