cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1321
Views
0
Helpful
6
Replies

Harden webgui of CIMC - Standalone C series

mag2suban
Level 1
Level 1

Is there anyway to harden access to the webgui of CIMC of a standalone C series server say C220

Appreciate inputs!

6 Replies 6

Keny Perez
Level 8
Level 8

Hi,

I have not heard of any specific procedure but do you have any specific feature you may be thinking about? I might be able if to tell you if there is something like that or see if at least there is an enhancement request.

-Kenny

We need to access the CIMC over internet for some remote servers (like we did DRAC,ILO in past) and they are in standalone mode ...no UCSM hook in...need to lockdown/harden  access of CIMC as far as possible especially web...saw some ip blocking feature...more like thwart brute force i guess ...but nothing more..restricting source ips  seems more of a UCSM thing i guess...please correct if amiss!

Any features to harden  web access to CIMC appreciated for standalone severs...enablement of hardening can be from CLI also or any means

Appreciate

There is IP Blocking built into the system, but it doesn't appear to do what you need, though the User Guide kinda contradicts this:

http://www.cisco.com/en/US/docs/unified_computing/ucs/c/sw/gui/config/guide/1.5/b_Cisco_UCS_C-series_GUI_Configuration_Guide.151_chapter_01000.html#concept_AC4EC4E9FA3F4536A26BAD49734F23D0

IP blocking  prevents the connection between a  server or website and certain IP addresses or ranges of addresses. IP  blocking effectively bans undesired connections from those computers to a  website, mail server, or other Internet servers.

If WAN access needs to be hardened properly you'll want to use a firewall or ACLs to really be secured. 

Let me look into whether or not we're adding IP filtering in a future release.

Regards,

Robert

Appreciate !...i did however think ipblocking for standalone was more as lockout for bruteforce ...and yes the manual is ambivalent..maybe it talks about UCSM based management pool access ...which is not the case for standalone!

so yes really left wondering ..ACLs at network level was something we consider as a frontline but also wanted something at host level...

gsharma4
Level 1
Level 1

Hi,

Please find the below link,Hope it would help you.

http://www.cisco.com/en/US/docs/unified_computing/ucs/release/notes/OL-26648-01.html

Regards,

Gaurav

is there somethign specific in this that helps with my question ...am i amiss?  Appreciate inputs

Review Cisco Networking for a $25 gift card