HP Ilo 2 User Guide
Have a look at the manual HP Ilo 2 User Guide online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 1114 HP manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.

Configuringdirectorysettings iLO2enablesadministratorstocentralizeuseraccountadministrationusingdirectoryservices. YoumusthavetheConfigureiLO2SettingsprivilegetoconfigureandtesttheiLO2directory services.ToaccessDirectorySettings,clickAdministration>Security>Directory. iLO2directorysettingsenableyoutocontroldirectory-relatedbehaviorfortheiLO2directory youareloggedinto.Thesesettingsinclude: •DisableDirectoryAuthentication–Enablesyoutoactivateordeactivatedirectorysupporton thisiLO2directory. —Ifdirectoryauthenticationisenabledandconfiguredproperly,userscanloginusing directorycredentials. —Ifdirectoryauthenticationisdisabled,usercredentialsarenotvalidatedusingthedirectory. •UseHPExtendedSchema–Selectsdirectoryauthenticationandauthorizationusingdirectory objectscreatedwithHPschema.SelectthisoptionifthedirectoryhasbeenextendedwithHP schema,andyouplantouseit. •UseDirectoryDefaultSchema–Selectsdirectoryauthenticationandauthorizationusinguser accountsinthedirectory.SelectthisoptionifthedirectoryisnotextendedwithHPschema. Useraccountsandgroupmembershipsareusedtoauthenticateandauthorizeusers.After enteringthedirectorynetworkinformation,tograntusersaccesstoiLO2,clickAdminister Groups,andenteroneormorevaliddirectorydistinguishednamesandprivileges. •EnableLocalUserAccounts–Enablesyoutolimitaccesstolocalusers. IfLocalUserAccountsareenabled,ausercanloginusinglocallystoredusercredentials.— —IfLocalUserAccountsaredisabled,useraccessislimitedtovaliddirectorycredentials only. AccessusingLocalUserAccountsisenabledifDirectorySupportisdisabledand/ortheiLO 2SelectoriLO2AdvancedLicenseisrevoked.Youcannotdisablelocaluseraccessifyou areloggedinusingalocaluseraccount. Security51

iLO2directoryserversettingsenablesyoutoidentifythedirectoryserveraddressandport.These settingsinclude: •DirectoryServerAddress–EnablesyoutospecifythenetworkDNSnameorIPaddressof thedirectoryserver.Youcanspecifymultipleservers,separatedbyacomma(,)orspace(). IfUseDirectoryDefaultSchemaisselected,enteraDNSnameintheDirectoryServerAddress fieldtoallowauthenticationwithuserID.Forexample: directory.hp.com 192.168.1.250, 192.168.1.251 •DirectoryServerLDAPPort–SpecifiestheportnumberforthesecureLDAPserviceonthe server.Thedefaultvalueforthisportis636.However,youcanspecifyadifferentvalueif yourdirectoryserviceisconfiguredtouseadifferentport. •iLO2DirectoryProperties–IdentifiestheLOMobjectinthedirectorytree.Thisinformation isusedtodetermineuseraccessrights.YoucanconfigureiLO2withthepasswordtothe LOMobjectatthistimehowever,thisinformationisnotuseduntildirectoryconfiguration supportisprovided. •LOMObjectDistinguishedName–SpecifieswherethisLOMinstanceislistedinthedirectory tree.Forexample:cn=iLO 2 Mail Server,ou=Management Devices,o=hp. UsersearchcontextsarenotappliedtotheLOMObjectDistinguishedNamewhenaccessing thedirectoryserver. •LOMObjectPassword–SpecifiesthepasswordtotheiLO2objectthatiLO2usestoverify thedirectoryforupdates(LOMObjectDistinguishedName). •ConfirmPassword–VerifiesyourLOMObjectPassword.IfyoualtertheLOMObjectPassword, reenterthenewpasswordinthisfield. •UserLoginSearchContextsenablesyoutospecifycommondirectorysubcontextssothatusers donotneedtoentertheirfulldistinguishednameatlogin. Youcanidentifyallobjectslistedinadirectoryusinguniquedistinguishednames.However, distinguishednamescanbelongandusersmightnotknowtheirdistinguishednames,orhave accountsindifferentdirectorycontexts.iLO2attemptstocontactthedirectoryserviceby distinguishingname,andthenappliesthesearchcontextsinorderuntilsuccessful. DirectoryUserContextsspecifyusernamecontextsthatareappliedtotheloginname. Example1: Insteadoflogginginascn=user,ou=engineering,o=hpasearchcontextof ou=engineering,o=hpallowsloginasuser. Example2: IfasystemismanagedbyInformationManagement,Services,andTraining,searchcontexts like: Directory User Context 1:ou=IM,o=hp Directory User Context 2:ou=Services,o=hp Directory User Context 3:ou=Training,o=hp Allowusersinanyoftheseorganizationstologinbyusingjusttheircommonnames.Ifauser existsinboththeIMorganizationalunitandtheTrainingorganizationalunit,loginisfirst attemptedascn=user,ou=IM,o=hp. Example3(ActiveDirectoryonly): MicrosoftActiveDirectoryallowsanalternateusercredentialformat.Searchcontextsinthis formatcannotbetestedexceptbysuccessfulloginattempt.Ausercanloginas: [email protected]@domain.hp.comallowsthe usertologinasuser. 52ConfiguringiLO2

TotestthecommunicationbetweenthedirectoryserverandiLO2,clickTestSettings.Formore information,see“Directorytests”(page53). Directorytests TovalidatecurrentdirectorysettingsforiLO2,clickTestSettingsontheDirectorySettingspage. TheDirectoryTestspageappears. Thetestpagedisplaystheresultsofaseriesofsimpletestsdesignedtovalidatethecurrentdirectory settings.Additionally,itincludesatestlogthatshowstestresultsandanyissuesthathavebeen detected.Afteryourdirectorysettingsareconfiguredcorrectly,youdonotneedtorerunthese tests.TheDirectoryTestsscreendoesnotrequireyoutobeloggedinasadirectoryuser. Toverifyyourdirectorysettings: 1.Enterthedistinguishednameandpasswordofadirectoryadministrator.Agoodchoicewould bethesamecredentialsusedwhencreatingtheiLO2objectsinthedirectory.Thesecredentials arenotstoredbyiLO2.TheyareusedtoverifytheiLO2objectandusersearchcontexts. 2.Enteratestusernameandpassword.Typically,thisaccountwouldbeintendedtoaccessthe iLO2beingtested.Itcanbethesameaccountasthedirectoryadministrator.However,the testscannotverifyuserauthenticationwithasuperuseraccount.Thesecredentialsarenot storedbyiLO2. 3.ClickStartTest.Severaltestsbegininthebackground,startingwithanetworkpingofthe directoryuserthroughestablishinganSSLconnectiontotheserverandevaluatinguser privilegesastheywouldbeevaluatedduringanormallogin. Whilethetestsarerunning,thepageperiodicallyrefreshes.Atanytimeduringtestexecution,you canstopthetestsormanuallyrefreshthepage.Consultthehelplinkonthepagefortestdetails andactionsintheeventoftrouble. Encryption iLO2providesenhancedsecurityforremotemanagementindistributedITenvironments.Web browserdataisprotectedbySSLencryption.SSLencryptionofHTTPdataensuresthatthedatais secureasitistransmittedacrossthenetwork.iLO2providessupportfortwoofthestrongest availablecipherstrengths;theAdvancedEncryptionStandard(AES)andtheTripleDataEncryption Standard(3DES).iLO2supportsthefollowingcipherstrengths: •256-bitAESwithRSA,DHEandaSHA1MAC •256-bitAESwithRSAandaSHA1MAC •128-bitAESwithRSA,DHEandaSHA1MAC •128-bitAESwithRSAandaSHA1MAC •168-bitTripleDESwithRSAandaSHA1MAC •168-bitTripleDESwithRSA,DHEandaSHA1MAC iLO2alsoprovidesenhancedencryptionthroughtheSSHportforsecureCLPtransactions.iLO2 supportsAES128-CBCand3DES-CBCcipherstrengthsthroughtheSSHport. Ifenabled,iLO2enforcestheusageoftheseenhancedciphers(bothAESand3DES)overthe securechannels,includingsecureHTTPtransmissionsthroughthebrowser,SSHport,andXML port.WhenAES/3DESencryptionisenabled,youmustuseacipherstrengthequaltoorgreater thanAES/3DEStoconnecttoiLO2throughthesesecurechannels.Communicationsandconnections overlesssecurechannels(suchastheTelnetport)arenotaffectedbytheAES/3DESencryption enforcementsetting. Bydefault,remoteconsoledatauses128-bitRC4bi-directionalencryption.TheCPQLOCFGutility usesa168-bitTripleDESwithRSAandaSHA1MACciphertosecurelysendRIBCLscriptstoiLO 2overthenetwork. Security53

Encryptionsettings YoucanviewormodifythecurrentencryptionsettingsusingtheiLO2interface,CLP,orRIBCL. ToviewormodifycurrentencryptionsettingsusingtheiLO2interface: 1.ClickAdministration>Security>Encryption. TheEncryptionpageappears,displayingthecurrentencryptionsettingsforiLO2.Boththe currentnegotiatedcipherandtheencryptionenforcementsettingsappearonthispage. •CurrentNegotiatedCipherdisplaysthecipherinuseforthecurrentbrowsersession. AfterloggingintoiLO2throughthebrowser,thebrowserandiLO2negotiateacipher settingtouseduringthesession.TheEncryptionpageCurrentNegotiatedCiphersection displaysthenegotiatedcipher. EncryptionEnforcementSettingsdisplaysthecurrentencryptionsettingsforiLO2.Enforce AES/3DESEncryption(ifenabled)enablesiLO2toonlyacceptconnectionsthroughthe browserandSSHinterfacethatmeettheminimumcipherstrength.Acipherstrengthof atleastAESor3DESmustbeusedtoconnecttoiLO2ifthissettingisenabled.Enforce AES/3DESEncryptioncanbeenabledordisabled. 2.Tosavechanges,clickApply. WhenchangingtheEnforcementsettingtoEnable,closeallopenbrowsersafterclicking Apply.Anybrowsersthatremainopenmightcontinuetouseanon-AES/3DEScipher. ToviewormodifycurrentencryptionsettingsthroughtheCLPorRIBCL,seetheHPIntegrated Lights-OutManagementProcessorScriptingandCommandLineResourceGuideathttp:// h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual& lang=en&cc=us&docIndexId=64179&taskId=135&prodTypeId=18964&prodSeriesId=1146658. ConnectingtotheiLO2usingAES/3DESencryption AfterenablingtheEnforceAES/3DESEncryptionsetting,iLO2requiresyoutoconnectthrough securechannels(webbrowser,SSH,orXMLport)usingacipherstrengthofatleastAESor3DES. ToconnecttoiLO2throughabrowser,thebrowsermustbeconfiguredwithacipherstrengthof atleastAESor3DES.IfthewebbrowserisnotusingAESor3DESciphers,iLO2displaysan errormessageinformingyoutoclosethecurrentconnectionandselectthecorrectcipher. SeeyourbrowserdocumentationtoselectacipherstrengthofatleastAESor3DES.Different browsersusedifferentmethodsofselectinganegotiatedcipher.YoumustlogoutofiLO2through thecurrentbrowserbeforechangingthebrowsercipherstrength.Anychangesmadetothebrowser ciphersettingwhileloggedintoiLO2mightenablethebrowsertocontinueusinganon-AES/3DES cipher. AllclientoperatingsystemsandbrowserssupportedbyiLO2,supporttheiLO2AES/3DES EncryptionfeatureexceptwhenusingWindows2000ProfessionalwithInternetExplorer.By default,Windows2000ProfessionaldoesnotsupportAESor3DESciphers.Ifaclientuses Windows2000Professional,youmustuseanotherbrowser,orupdatetheoperatingsystem. InternetExplorerdoesnothaveauser-selectablecipherstrengthsetting.Youmustedittheregistry toenableInternetExplorertoconnecttoiLO2whentheEnforceAES/3DESEncryptionsettingis enabled.ToenableAES/3DESencryptioninInternetExplorer,opentheregistryandset HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ FIPSAlgorithmPolicyto1. 54ConfiguringiLO2

NOTE:Incorrectlyeditingtheregistrycanseverelydamageyoursystem.HPrecommendscreating abackupofanyvalueddataonthecomputerbeforemakingchangestotheregistry.For informationonhowtorestoreyourregistry,seetheMicrosoftKnowledgeBasearticleathttp:// support.microsoft.com/kb/307545. ToconnecttoiLO2throughanSSHconnection,seeyourSSHutilitydocumentationtosetthe cipherstrength. WhenconnectingthroughtheXMLchannel,theCPQLOCFGutilityusesasecure3DEScipherby default.CPQLOCFG2.26orlaterdisplaysthefollowingcurrent-connectioncipherstrengthonthe XMLoutput.Forexample: Connecting to Server.. Negotiated cipher: 168-bit Triple DES with RSA and a SHA1 MAC AESencryptionisnotsupportedbyInternetExploreronaWindows2000Professionalclient.To useAESencryptionwiththisoperatingsystem,useanotherbrowser(suchasMozilla). HPSIMsinglesign-on(SSO) HPSIMSSOenablesyoutobrowsedirectlyfromHPSIMtoyourLOMprocessor,bypassingan intermediateloginstep.TouseSSO,acurrentversionofHPSIMisrequired,andyoumustconfigure yourLOMprocessortoacceptthelinksfromHPSIM.HPSIMrequiresthelatestupdatesand patchestofunctioncorrectly.FormoreinformationaboutHPSystemsInsightManagerandavailable updates,seetheHPwebsiteathttp://www.hp.com/go/hpsim. HPSIMSSOisalicensedfeatureavailablewiththepurchaseofoptionallicenses.Formore information,see“Licensing”(page26). TheHPSIMSSOpageenablesyoutoviewandconfigureSSOsettingsthroughtheiLO2interface. Formoreinformation,see“SettingupHPSIMSSO”(page57). YoucanalsoaccessHPSIMSSOconfigurationsettingsusingscripts,textfiles,andthrougha command-lineusingtext-basedclientssuchasSSHoverthenetworkorfromtheoperatingsystem onthehostcomputer.ScriptingSSOenablesyoutousethesameSSOsettingsonallyourLOM processors.Formoreinformation,examplescripts,andCLPextensionstoread,modify,andwrite HPSIMSSOconfigurationsettings,seetheHPIntegratedLights-OutManagementProcessor ScriptingandCommandLineResourceGuideathttp://h20000.www2.hp.com/bizsupport/ TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us& docIndexId=64179&taskId=135&prodTypeId=18964&prodSeriesId=1146658. SettingupiLO2forHPSIMSSO BeforeyoustartSSOsetup,youmusthavethenetworkaddressofHPSIMandensurethatalicense keyisinstalled.TosetupSSO: 1.EnableSingleSign-OnTrustModebyselectingeitherTrustbyCertificate(recommended), TrustbyName,orTrustAll. 2.AddtheHPSIMcertificateoftheservertoiLO2. a.ClickAddanHPSIMServer. b.EntertheHPSIMservernetworkaddress. c.ClickImportCertificate. ThecertificaterepositoryissizedtoallowfivetypicaliLO2certificates.However,certificate sizescanvaryiftypicalcertificatesarenotissued.Thereis6KBofcombinedstorageallocated forcertificatesandiLO2servernames.Whentheallocatedstorageisused,nomoreimports areaccepted. AftersettingupSSOiniLO2,logintoHPSIM,locatetheLOMprocessor,selectTools>System Information>iLOas...HPSIMlaunchesanewbrowserthatisloggedintotheLOMmanagement processor. Security55

AddingHPSIMtrustedservers YoucaninstallHPSIMservercertificatesusingscriptingthatissuitableformassdeployment.For moreinformation,seetheHPIntegratedLights-OutManagementProcessorScriptingandCommand LineResourceGuideathttp://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp? contentType=SupportManual&lang=en&cc=us&docIndexId=64179&taskId=135& prodTypeId=18964&prodSeriesId=1146658.ToaddHPSIMserverrecordsusingabrowser: 1.ClickAdministration>Security>HPSIMSSO. 2.ClickAddanHPSIMServer. 3.Toauthenticatetheserver,chooseoneofthefollowing: •ToaddanHPSIMserverusingTrustbyNameauthentication,enterthefullnetworkname oftheHPSIMserverintheAddaTrustedHPSIMServerNamesection.ClickAddServer Name. TrustbyNameauthenticationusesfullyqualifieddomainnames;forexample, sim-host.hp.cominsteadofsim-host.Ifyouareunsureofthefullyqualifieddomain name,usethenslookup hostcommand. •ToretrieveandimportacertificatefromatrustedHPSIMserver,enterthefullnetwork nameofanHPSIMServerintheRetrieveandimportacertificatefromatrustedHPSIM Serversection.ClickImportCertificatetorequestthecertificatefromtheHPSIMserver andautomaticallyimportit.ThisrecordsupportsSSOTrustbyNameandSSOTrustby Certificate. TopreventanycertificatetamperingdirectlyimportanHPSIMservercertificate.To directlyimportanHPSIMservercertificate,retrievetheHPSIMcertificatedateusingone ofthefollowingoptions: ◦Usingaseparatebrowserwindow,browsetotheHPSIMserverathttp://:280/GetCertificate. CutandpastethecertificatedatafromHPSIMintoiLO2. ◦ExporttheHPSIMservercertificatefromtheHPSIMuserinterfacebyselecting Options>Security>Certificates>ServerCertificate.Openthefileusingatexteditor, andcopyandpasteallthecertificaterawdataintoiLO2. ◦Usingcommand-linetoolsontheHPSIMserver,theHPSIMcertificatecanbe extractedusingthetomcat-codedaliasfortheHPSIMcertificate.Forexample: mxcert -l tomcat Thecertificatedataresembles: -----BEGIN CERTIFICATE----- . . . several lines of encoded data . . . -----END CERTIFICATE----- AfterpastingtheHPSIMserverbase-64encodedx.509certificatedataintotheDirectly importaHPSIMServerCertificatesection,clickImportCertificatetorecordthedata. ThistypeofrecordsupportsSSOTrustbyNameandSSOTrustbyCertificate. ThereareotherwaystoretrieveHPSIMservercertificatedata.Formoreinformation,seeyourHP SIMdocumentation. 56ConfiguringiLO2

SettingupHPSIMSSO TheHPSIMSSOpageallowsyoutoviewandconfiguretheexistingiLO2SingleSign-Onsettings. YoumusthavetheConfigureiLO2privilegetoalterthesesettings.ToaccessiLO2SSOsettings, clickAdministration>Security>HPSIMSSO. TheHPSystemsInsightManagerSingleSign-OnSettingspageincludesthefollowingfieldsand options: •SingleSign-OnTrustMode–EnablesyoutocontrolhowSSO-initiatedconnectionsare accepted: —TrustNone(default)–RejectsallSSOconnectionrequests. —TrustbyCertificate(mostsecure)–EnablesonlySSOconnectionsfromanHPSIMserver matchingacertificatepreviouslyimportedintoiLO2. —TrustbyName–EnablesSSOconnectionsfromanHPSIMservermatchingaDNSname orcertificatepreviouslyimportedintoiLO2. —TrustAll(leastsecure)–AcceptsanySSOconnectionsinitiatedfromanyHPSIMserver. UserswhologintoHPSIMareauthorizedbasedupontheroleassignmentattheHPSIM server.TheroleassignmentispassedtotheLOMprocessorwhenSSOisattempted.Youcan configureiLO2privilegesforeachroleintheSingleSign-OnSettingssection.Formore informationabouteachprivilege,see“Useradministration”(page28). Usingdirectory-baseduseraccounts,SSOattemptstoreceiveonlytheprivilegesassignedin thissection.Lights-Outdirectorysettingsdonotapply.Defaultprivilegeassignmentsare: ◦User–Loginonly ◦Operator–Login,RemoteConsole,PowerandReset,andVirtualMedia ◦Administrator–Login,RemoteConsole,PowerandReset,VirtualMedia,ConfigureiLO 2,andAdministerUsers •HPSIMTrustedServers–EnablesyoutoviewthestatusoftrustedHPSIMserversconfigured touseSSOwiththecurrentLOMprocessor.ClickAddaSIMServertoaddaservername, importaservercertificate,ordirectlyinstallaservercertificate.Formoreinformation,see “AddingHPSIMtrustedservers”(page56). TheservertabledisplaysalistofregisteredHPSIMserverswiththestatusofeach.Theactual numberofsystemsalloweddependsonthesizeofthestoredcertificatedata. Althoughasystemmightberegistered,SSOmightberefusedbecauseofthecurrenttrustlevel orcertificatestatus.Forexample,ifanHPSIMservernameisregisteredandthetrustlevelis settoTrustbyCertificate,SSOisnotallowedfromthatserver.Likewise,ifanHPSIMserver Security57

certificateisimported,butthecertificatehasexpired,SSOisnotallowedfromthatserver. Additionally,therecordsarenotusedwhenSSOisdisabled.iLO2doesnotenforceSSO servercertificaterevocation. —Status–Indicatesthestatusoftherecord(ifanyareinstalled). —Description–Displaystheservername(orcertificatesubject).Athumbnailofacertificate indicatesthattherecordcontainsastoredcertificate. —Actions–Displaystheactionsyoucantakeonaselectedrecord.Theactionsdisplayed dependonthetypeandnumberofrecordsinstalled: ◦RemoveName–Removestheservernamerecord. ◦RemoveCertificate–Removesthecertificaterecord. RemoteConsoleComputerLock RemoteConsoleComputerLockenhancesthesecurityofaniLO2managedserverbyautomatically lockinganoperatingsystem,orloggingoutauserwhenaremoteconsolesessionterminatesor thenetworklinktoiLO2islost.UnlikeRemoteConsoleorIntegratedRemoteConsole,thisfeature isstandardanddoesnotrequireanadditionallicense.Asaresult,ifyouopenaRemoteConsole SessionoranIntegratedRemoteConsolewindowandhavethisfeatureconfigured,itwilllockthe operatingsystemwhenthewindowisclosedevenifadditionalfeaturelicensesarenotinstalled. YoucanviewandconfiguretheRemoteConsoleComputerLocksettingsthroughtheAdministration orRemoteConsoletabsintheiLO2interface.TheRemoteConsoleComputerLockfeatureis disabledbydefault. TochangetheRemoteConsoleComputerLocksettings: 1.LogintoiLO2usinganaccountthathastheConfigureiLO2Settingsprivilege. 2.ClickAdministration>Security>RemoteConsole.TheComputerLockSettingspageappears. 3.Modifythesettingsasrequired: •Windows–UsethisoptiontoconfigureiLO2tolockamanagedserverrunninga Windowsoperatingsystem.TheserverautomaticallydisplaystheComputerLockeddialog boxwhenaremoteconsolesessionisterminatedortheiLO2networklinkislost. •Custom–UsethisoptiontoconfigureiLO2touseacustomkeysequencetolocka managedserverorlogoutauseronthatserver.Youcanselectuptofivekeysfromthe list.Theselectedkeysequenceisautomaticallysenttotheserveroperatingsystemwhen aremoteconsolesessionisterminatedortheiLO2networklinkislost. •Disabled–UsethisoptiontodisabletheRemoteConsoleComputerLockfeature. TerminatingaremoteconsolesessionorlosinganiLO2networklinkdoesnotlockthe managedserver. YoucancreateaRemoteConsoleComputerLockkeysequenceusingthekeyslistedinthe followingtable. e1F4ESC f2F5L_ALT g3F6R_ALT 58ConfiguringiLO2

h4F7L_SHIFT i5F8R_SHIFT j6F9L-CTRL k7F10R_CTRL l8F11L_GUI m9F12R_GUI n:" " (Space)INS o;!DEL p$PG_UP s?%PG_DN t@&ENTER u['TAB v\(BREAK w])BACKSPACE x^*NUM PLUS y_+NUM MINUS z',SCRL LCK {a-SYS RQ }b.F1 |c/F2 ~d0F3 4.ClickApplytosavechanges. Thisfeaturecanalsobeconfiguredusingscriptingorcommandlines.Formoreinformation,see theHPIntegratedLights-OutManagementProcessorScriptingandCommandLineResourceGuide athttp://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp? contentType=SupportManual&lang=en&cc=us&docIndexId=64179&taskId=135& prodTypeId=18964&prodSeriesId=1146658. Network TheNetworkSettingsandDCHP/DNStabsoftheNetworksectionenableyoutoviewandmodify networksettingsforiLO2. OnlyuserswiththeConfigureiLO2Settingsprivilegecanchangethesesettings.Usersthatdo nothavetheConfigureiLO2Settingsprivilegecanviewtheassignedsettings. TochangenetworksettingsforiLO2: Network59

1.LogintoiLO2usinganaccountthathastheConfigureiLO2Settingsprivilege.Click Administration>Network. 2.SelectNetworkSettingsorDHCP/DNS. 3.Changethesettingsasneeded. 4.Aftercompletinganyparameterchanges,clickApplytocompletethechanges. iLO2restarts,andtheconnectionofyourbrowsertoiLO2terminates.Toreestablishaconnection, wait60secondsbeforelaunchinganotherbrowsersessionandloggingin. NetworkSettings TheNetworkSettingspagedisplaystheNICIPaddress,subnetmask,andotherTCP/IP-related informationandsettings.FromtheNetworkSettingsscreen,youcanenableordisableDHCPand configureastaticIPaddressforserversnotusingDHCP.Alluserscanviewthenetworksettings, butonlyuserswiththeConfigureiLO2Settingsprivilegecanchangethesesettings.Toaccessthe NetworkSettingspage,clickAdministration>Network>Network.TheNetworkSettingspage appearswiththefollowinginformationandsettings: •NICenablesyoutosettheiLO2NICtoEnabled,Disabled,ortoSharedNetworkPort. Enabled–EnablestheprimaryiLO2networkinterface.◦ ◦Disabled–DisablestheiLO2networkinterface.YoumustusetheiLO2RBSUorother host-basedscriptingutilitytore-enablethenetworkinterface. ◦SharedNetworkPort–EnablesnetworkingusingthedesignatedhostEthernetport.The portappearsastwoseparateEthernetMACsandIPaddressesonthenetwork.Formore information,see“iLO2SharedNetworkPort”(page61). •DHCPenablesyoutoselectstaticIP(disabled)orenablestheuseofaDHCPservertoobtain anIPaddressfortheIntegratedLights-Out2subsystem. YoucannotsettheiLO2IPAddressandSubnetMaskifDHCPisenabled.DisablingDHCP enablesyoutoconfiguretheIPaddress.TheIPAddressfieldalsoappearsontheDHCP/DNS Settingspageforconvenience.ChangingthevalueoneitherpagechangestheDHCPsetting. •IPAddressistheiLO2IPaddress.IfDHCPisused,theiLO2IPaddressisautomatically supplied.Ifnot,enterastaticIPaddress.TheIPAddressfieldappearsontheDHCP/DNS pageforconvenience.EnteringvaluesinthefieldoneitherpagechangestheIPaddressof theiLO2. •SubnetMaskisthesubnetmaskoftheiLO2IPnetwork.IfDHCPisused,theSubnetMaskis automaticallysupplied.Ifnot,enterthesubnetmaskforthenetwork. •GatewayIPAddressdisplaystheIPaddressofthenetworkgateway.IfDHCPisinuse,the GatewayIPAddressisautomaticallysupplied.Ifnot,enterthenetworkgatewayaddress. •iLO2SubsystemNameisanameusedbytheiLO2subsystem.IfDHCPandDNSare configuredcorrectly,thisnamecanbeusedtoconnecttotheiLO2subsysteminsteadofthe IPaddress.Formoreinformation,see“iLO2subsystemnamelimitations”(page61). •LinkcontrolsthespeedandduplexoftheiLO2networktransceiver.Thecurrentlinkspeed oftheprimarydedicatediLO2NICcanbehighlighted.Linksettingsincludethefollowing: —Automatic(default)enablesiLO2tonegotiatethehighestsupportedlinkspeedand duplexwhenconnectedtothenetwork. —100Mb/FDforcesa100-Mbconnectionusingfullduplex. —100Mb/HDforcesa100-Mbconnectionusinghalfduplex. —10Mb/FDforcesa10-Mbconnectionusingfullduplex. —10Mb/HDforcesa10-Mbconnectionusinghalfduplex. 60ConfiguringiLO2