20.01.2013 Views

HP BladeSystem Onboard Administrator User Guide - HP Business ...

HP BladeSystem Onboard Administrator User Guide - HP Business ...

HP BladeSystem Onboard Administrator User Guide - HP Business ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Security considerations<br />

This section documents the architecture and best practice security recommendations to be considered when<br />

configuring the <strong>Onboard</strong> <strong>Administrator</strong> and the default setting comparisons with the previous version.<br />

<strong>BladeSystem</strong> network architecture overview<br />

All device bays, interconnect modules, and <strong>Onboard</strong> <strong>Administrator</strong> modules are connected to an internal<br />

enclosure network that is managed by the active <strong>Onboard</strong> <strong>Administrator</strong>. Network traffic from business<br />

applications running on server blades is routed through interconnect switch modules and onto on the<br />

production network.<br />

Although it is possible for the management and production networks to be connected, the management<br />

network should be isolated from production traffic and the intranet. From a security perspective, this reduces<br />

access and ability to attack the management interfaces. From an efficiency standpoint, separate networks<br />

keep production traffic off of the management network.<br />

Recommended security best practices<br />

In addition to the best practices, note these additional considerations.<br />

Physical presence considerations<br />

Physical access to a system often implies administrator privilege. The <strong>Onboard</strong> <strong>Administrator</strong> is no exception.<br />

For more information on how to configure the <strong>Onboard</strong> <strong>Administrator</strong> administrator, see Configuring the <strong>HP</strong><br />

<strong>BladeSystem</strong> c7000 enclosure and enclosure devices (on page 65).<br />

• Verifying physical cabling<br />

The <strong>BladeSystem</strong> enclosure can have many cables attached to the enclosure. Cables connected to the<br />

interconnect switch modules are generally for production network traffic. All other cables and ports are<br />

generally for enclosure management network traffic and should be carefully inspected.<br />

o Ensure that enclosure link ports are connected only to enclosure link ports on other enclosures.<br />

o Inspect <strong>Onboard</strong> <strong>Administrator</strong> serial ports for unauthorized connections.<br />

o Inspect <strong>Onboard</strong> <strong>Administrator</strong> USB ports for unauthorized connections.<br />

• Securing the Insight Display LCD panel<br />

Introduction 20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!