Managing HP servers through firewalls with Insight Management 7.2

White paper| HP Insight Management 7.2
12 | March 2013
With HP SIM installed on the secondary management network, collect system asset information
from a ProLiant server on that management network through the iLO 2 or iLO 3 pass-through. As
a second option, browse to the System Management Homepage
(https://<servername>:2381/) and manually view the asset information.
Appendix A: Configuring a separate management network describes the procedure for
configuring a separate management network. When using SNMP management protocols,
configure SNMP to accept packets only from the IP addresses used on the management network,
or bind SNMP to the secondary network interface (if the operating system allows this). Configure
the HP Insight Management Agents to allow access only from IP addresses on the management
network. Configure the HP SIM to discover the systems on the secondary network. Disable WMI
and WBEM on the primary network by configuring a firewall on the system to disable each of the
protocols on the primary NIC.
Fault management
SNMP traps can be forwarded through the Lights-Out interface on ProLiant servers. This allows
full fault management data to flow into HP SIM or another management product (such as HP
Network Management Center).
The Insight Agents for Microsoft Windows also create Windows Event Log entries. A management
tool such as HP Network Management Center or Microsoft Operations Manager operating in the
same environment can then collect the log entries and send them back to a centralized server.
The Insight Agents for Linux also create entries in the syslog. You can write a script to look for
these entries and take appropriate actions.
Deployment and migration
In this type of computing environment, collect network resource information from a gateway that
is connected to the intranet in the DMZ through bypassing it from the firewall. Hardware
management, deployment, and migration are smooth administration tasks.
Integration
Key integrations are provided through HP Insight Control for Microsoft System Center and HP
Insight Control for VMware vCenter Server. The Insight Control Agents for Microsoft Windows also
create Windows Event Log entries. The Microsoft System Center integration supports OS
deployment and updates, HP ProLiant and Blade System management and alerting, proactive
virtual machine management, and enhanced inventory reporting. The integration happens with
the secondary network that is connected to the network resources.
Control
Insight Control provides single-console integration with the leading management applications.
Insight Control for VMware vCenter Server delivers powerful HP hardware management
capabilities to virtualization administrators without ever having to leave the vCenter console. The
benefit to this approach is that management traffic flows through the secondary network, while
the limited access from the production (primary) network maintains security. In this case, disabling
the firewall rules is not required.