07-08-2011 03:09 AM - edited 03-01-2019 09:58 AM
Hi All,
is it possible to restrict access for certain users to a specific blade on the UCS either via KVM or another method?
we have AD integration enabled but i guess the problem will be that i give them access, then they will be able to access all the blades & not 1 specific one.
any suggestions.
Thanks
Kassim
07-09-2011 10:02 AM
Kassim,
First, make sure that TCP Port 2068 is not being blocked.
Following options are available to grant access only to KVM.
Method #1 -- Access as IPMI user
Method #2 -- Standalone KVM tool
Method #3 -- KVM Viewer
Method #4 -- KVM Manager
For method #1 and #2, configure IPMI policy with a IPMI user having admin role and then associate it to required service-profiles / blades.This is non-disruptive configuration.
Method #1 -- as IPMI user
Access KVM via one of the following URLs
## Enter user name, password & blade's management IP address
http://
## OR we can include IP address of the specific blade in URL as a parameter
http://
Method #2 -- Standalone KVM tool
Tool is available for both Windows and Linux systems.
To run a standalone KVM, download kvm.zip file from the Fabric Interconnect ( FI )
http://
and extract the contents to a folder.
On Windows, double click launchkvm.bat file to launch the KVM.
On Linux, enable the execute permission by " chmod 777 launchkvm.sh " and then launch it by running " ./launchkvm.sh "
For method #3 and #4, access can be restricted to specific blades by associating appropriate role,locale and organization.
#1 Map blades to an organization
#2 Create a locale and include the organization
#3 Assign the user with " server-profile " role and assign it to appropriate locale
Method #3 -- KVM Viewer
To launch KVM viewer
http://
http://
Method #4 -- KVM Manager
Access the KVM launch manager via FI ip address or use the following direct link
http://
In this view, user will be able to see all blades but only will be allowed access to blades associated with organization and locale.
NOTE :- This was based on UCSM 1.4.3 and for locally authenticated users. Need to check out options for users authenticated through LDAP.
HTH
Padma
07-12-2011 02:33 AM
Hi Padma,
Thanks for the info. I will give it a go.
Kassim
03-07-2012 09:54 PM
Hi Padramas,have you tried with the latest firmware 2.0.1w to use local authentication with locale to specific organisation and only seeing their server in the kvm manager ? Or have you found another way to accomplish this ?
03-08-2012 12:15 AM
David,
I just did quick test ( 2.0.1t ) in lab where I associated a user to custom role that has only " service-profile-ext-access " privilege in it and mapped with corresponding locale ( organization )
With this configuration, user will be able to access KVM for blades within the locale.
For other blades, it will launch a login window and will fail when you try to authenticate.
HTH
Padma
02-05-2013 03:08 AM
Hello,
even in sw version 2.1, KVM user role (service profile ext access) still have read-only access to management. I really don't want to let my kvm users see all the equipment, server profiles, etc.
Any clue to create KVM role ONLY ? Without RO access to management ?
Thanks
Regards,
Pavel
02-05-2013 06:19 AM
It's another request that's in the pipe. No commit timeframe yet.
Robert
04-18-2018 08:19 AM
We are at UCSM2.2.8g and we would like to restrict some GROUP to just have KVM. i think above post is OLD & may be still valid but could someone help in details please? thank you
04-18-2018 08:35 AM
04-18-2018 08:57 AM
Thanks Pranav, but with that they CAN login to UCSM and see other business HW< configurations< and global policies etc, which we would like to restrict.
we already have the ORG & Local created for this business UNIT but with that they have some access to that ORG-locale but have READONLY rights to the UCSM as whole.
WE want to restrict the UCSM access completely, and give only KVM with KVM-IP (like rack server mgmt.).
we are OK with local user but AD is preferred...
04-18-2018 09:09 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide