HP Ilo 2 User Guide
Here you can view all the pages of manual HP Ilo 2 User Guide. The HP manuals for Server are available online for free. You can easily download all the documents as PDF.
Page 151
3.CreateHPRoleobjectsintherolesorganizationalunitusingtheHPprovidedConsoleOne snap-instool. a.Right-clicktherolesorganizationalunitfoundintheregion2organizationalunit,and selectNew>Object. b.SelecthpqRolefromthelistofclasses,andclickOK. c.EnteranappropriatenameontheNewhpqRolepage.Inthisexample,therolewill containuserstrustedforremoteserveradministrationandwillbenamedremoteAdmins. ClickOK.TheSelectObjectSubtypepageappears. d.BecausethisrolemanagestherightstoLights-OutManagementdevices,selectLightsOut...
Page 152
5.Usingthesameprocedureasinstep4,editthepropertiesoftheremoteMonitorsrole: a.AddthethreeiLO2deviceswithinhpdevicesunderregion1totheManagedDevices listontheRoleManagedDevicesoptionoftheHPManagementtab. b.AdduserstotheremoteMonitorsroleusingtheMemberstab. c.SelecttheLogincheck-box,andclickApply>Close.UsingtheLightsOutManagement DeviceRightsoptionoftheHPManagementtab,membersoftheremoteMonitorsrole canauthenticateandviewtheserverstatus....
Page 153
Members Afteruserobjectsarecreated,theMemberstaballowsyoutomanagetheuserswithintherole. ClickingAddenablesyoutobrowsetothespecificuseryouwanttoadd.Highlightinganexisting userandclickingDeleteremovestheuserfromthelistofvalidmembers. SettingupHPschemadirectoryintegration153
Page 154
eDirectoryRoleRestrictions TheRoleRestrictionssubtabenablesyoutosetloginrestrictionsfortherole.Theserestrictions include: •Timerestrictions •IPnetworkaddressrestrictions IP/mask— —IPrange •DNSname Timerestrictions Youcanmanagethehoursavailableforlogonbymembersoftherolebyusingthetimegrid displayedintheRoleRestrictionssubtab.Youcanselectthetimesavailableforlogonforeachday oftheweekinhalf-hourincrements.Youcanchangeasinglesquarebyclickingit,orasectionof...
Page 155
eDirectoryLights-OutManagement Afteraroleiscreated,rightsfortherolecanbeselected.Usersandgroupobjectscannowbe mademembersoftherole,givingtheusersorgroupofuserstherightsgrantedbytherole.Rights aremanagedontheLightsOutManagementDeviceRightssubtaboftheHPManagementtab. Theavailablerightsare: •Login–Thisoptioncontrolswhetheruserscanlogintotheassociateddevices. Loginaccesscanbeusedtocreateauserwhoisaserviceproviderandwhoreceivesalerts fromiLO2butdoesnothaveloginaccesstoiLO2....
Page 156
•ServerResetandPower–Thisoptionallowstheusertoremotelyresettheserverorpowerit down. •AdministerLocalUserAccounts–Thisoptionallowstheusertoadministeraccounts.Theuser canmodifytheiraccountsettings,modifyotheruseraccountsettings,addusers,anddelete users. •AdministerLocalDeviceSettings–ThisoptionallowstheusertoconfigureiLO2settings. ThesesettingsincludetheoptionsavailableontheGlobalSettings,NetworkSettings,SNMP Settings,andDirectorySettingsscreensoftheiLO2browser. Userloginusingdirectoryservices...
Page 157
Directory”(page140),and“DirectoryservicesforeDirectory”(page149).Ingeneral,youcan usetheHPprovidedsnap-instocreateobjects.ItisusefultogivetheLOMdeviceobjects meaningfulnames,suchasthedevicenetworkaddress,DNSname,hostservername,or serialnumber. •ConfiguretheLights-Outmanagementdevices EveryLOMdevicethatusesthedirectoryservicetoauthenticateandauthorizeusersmustbe configuredwiththeappropriatedirectorysettings.Fordetailsonthespecificdirectorysettings,...
Page 158
Anadminusergainstheloginrightfromtheregularusergroup.Moreadvancedrightsareassigned throughtheAdminrole,whichassignsadditionalrights–ServerResetandRemoteConsole. TheAdminroleassignsalladminrightsServerReset,RemoteConsole,andLogin. Howdirectoryloginrestrictionsareenforced Twosetsofrestrictionspotentiallylimitadirectoryuser'saccesstoLOMdevices.Useraccess restrictionslimitauser'saccesstoauthenticatetothedirectory.Roleaccessrestrictionslimitan...
Page 159
NOTE:Whendirectoriesareenabled,accesstoaparticulariLO2isbasedonwhethertheuser hasreadaccesstoaRoleobjectthatcontainsthecorrespondingiLO2object.Thisincludesbut isnotlimitedtothememberslistedintheroleobject.IftheRoleissetuptoallowinheritable permissionstopropagatefromaparent,thenmembersoftheparentwhichhavereadaccess privilegeswillalsohaveaccesstoiLO2.Toviewtheaccesscontrollist,navigatetoUsersand Computers,openthepropertiesscreenfortheRoleobjectandselecttheSecuritytab....
Page 160
IPaddressandsubnetmaskrestrictions IPaddressandsubnetmaskrestrictionsenabletheadministratortospecifyarangeofaddresses thataregrantedordeniedaccessbytherestriction.ThisformathassimilarcapabilitiesasanIP addressrangebutmightbemorenativetoyournetworkingenvironment.AnIPaddressandsubnet maskrangeistypicallyspecifiedusingasubnetaddressandaddressbitmaskthatidentifies addressesthatareonthesamelogicalnetwork. Inbinarymath,ifthebitsofaclientmachineaddress,addedwiththebitsofthesubnetmask,...