white paper Unisys Internet Remote Support Systems & Technology, CMP-based Servers
Introduction Remote Support is a method of connecting to remotely located systems for remote administration, real-time diagnosis, system configuration and/or repair, or online file transfers. Unisys Internet Remote Support enables a Unisys Remote Support Analyst (RSA) to see exactly what the remote client is seeing in real-time as it is occurring on the system. It also gives the remote client the ability to watch the session and interactively participate with the RSA to resolve an issue. Unisys Internet Remote Support can be used on all CMPbased systems. For example: ES7000 64-bit and 32-bit versions Libra Voyager/Dorado External Service Processors (CMP system controllers) Management servers Client workstations Note: Contact your Unisys representative if you are unsure whether your server supports Unisys Internet Remote Support.
Table of Contents Unisys Internet Remote Support 4 Unisys Internet Remote Support Provisions 4 Benefits of Using Unisys Internet Remote Support 4 How Unisys Internet Remote Support Works 5 Conclusion 7 3
Unisys Internet Remote Support Unisys Internet Remote Support Provisions Unisys Internet Remote Support makes a remote connection between Unisys clients and Unisys support analysts via LAN/WAN network connections over the Internet possible. Unisys Internet Remote Support provides robust security by arbitrating data streams between internal Unisys resources and customer servers. It intermediates data between external connections, from which it receives secure requests, and internal resources, to which it makes requests on behalf of authenticated users. Unisys Internet Remote Support provides Unisys and its customers with secure and controlled access to remote servers from any properly configured Web browser. Unisys Internet Remote Support eliminates the need to deploy Extranet toolkits in a traditional perimeter network (DMZ) or provide a remote access Virtual Private Network (VPN). Benefits of Using Unisys Internet Remote Support Unisys Internet Remote Support provides a number of significant benefits to Unisys customers. These benefits include: Time savings Less time is required to diagnose a problem on a remote system. All the customer needs to do is contact Unisys, schedule a remote support session, and connect to Unisys Internet Remote Support at the designated time. During the session, the RSA is able to remotely see and experience firsthand exactly what the customer or the Unisys Customer Service Representative (CSR) is seeing on the system as it is happening. Reduced costs Time is money, and faster problem resolution results in cost savings for both Unisys and the customer. A Unisys RSA is able to gather needed 4
logs, records, files, and other diagnostic information that aid in resolution of the problem without having to burden the customer with an onsite visit. Less system downtime Systems configured for Unisys Internet Remote Support can be diagnosed, audited, and remotely administered in real time while the customer or CSR participates interactively or observes. Consequently, standard customer applications can continue to be run if desired. Expert and tool availability Unisys RSAs based anywhere in the world can attend a remote support session and, because more than one RSA can participate, Unisys can provide a team of experts suited to the particular issue at hand. Similarly, because programs and utilities can be remotely run or managed, as well as logs and files transferred between the remote client and Unisys, a richer set of diagnostic utilities can be used. Accurate remote administration By using certain types of recording software, the remote sessions can be recorded and preserved for archival or training purposes. Secure sessions The biggest concern of customers when connecting systems to the Internet is protecting their servers and data from unauthorized access. Unisys Internet Remote Support provides Secure Socket Layer (SSL) encryption protection throughout the entire connection. SSL encryption is the same security that most Internet-based businesses use with credit card purchases. Partition security A CMP partition does not need to be connected to the Internet for a Unisys Internet Remote Support session to take place. Access to a partition can be obtained if the partition is connected to the controlling Service Processor or management server, which is connected to the Internet. Intuitive user interface The user interface provided by Unisys Internet Remote Support is intuitive, so minimal training is required. How Unisys Internet Remote Support Works Hardware Requirements For Unisys, the requisite hardware is already in place and functioning to provide safe, secure connectivity via the Internet. For Unisys clients, there is no real hardware requirement other than what is required to physically connect the client s system to the WAN at the client s location. This implies that hubs, switches, routers, and firewalls exist and are configured to allow outbound connectivity via TCP/IP over port SSL TCP port 443 to the Internet. Software Requirements The only software requirement for using Unisys Internet Remote Support is that all participants must have a functioning Internet Web browser capable of accepting SSL certificates and employing SSL encryption. Meeting coordinators must have Java (Sun Java) installed in order to connect to the Remote Support Appliance and set up meetings. Note: Browser utilities such as MSN Toolbar or Google Desktop may interfere with the Remote Support log-on Web page loading correctly. Client Site Setup The client s firewall must allow traffic on TCP port 443 from the client s system to https://remotesupport.unisys.com/ (IP: 129.225.216.130). Additionally, the client s system must be able to resolve remotesupport.unisys.com and its subdirectories via the Global Internet DNS infrastructure. The client s network administrators need to provide physical TCP/IP connectivity for the remote system through their firewall using TCP port 443 to the Internet. The client s remote system that will be participating in an on-line Remote Support Meeting is required to employ an Internet browser capable of accepting security certificates and encrypting data using SSL technology. 5
Specific rules should be set on the client s firewall to tighten security by limiting traffic so that connections are IP-to-IP specific and limited to TCP port 443. The firewall should be configured to allow connectivity with the Unisys Remote Support Meeting Appliance to be enabled or disabled by the client s network administrators on an asneeded basis. Security The Remote Support Meeting Appliance is isolated from both the Unisys internal network and the Global Internet. All interactions are monitored, logged, and audited to ensure accountability. Data associated with the remote desktop is not stored on the meeting appliance, just the session usage. Physical security ensures that both host and client sites are secure by using encryption to protect data exchanged within remote sessions. The Unisys Remote Support Meeting Appliance ensures that each remote session is secure from outside entities. Each connection is secured by employing Secure Sockets Layer (SSL) encryption to protect data exchanged within the session. SSL encryption ensures that user names, passwords, and all subsequent data are transmitted within secure VPN tunnels employing a 128- or 168-bit encryption algorithm. Although Remote Support is not suited to all support scenarios, it should be considered as the required initial support/diagnostic step when working with the Unisys Client Support Center (CSC) on the following types of critical support requests: Partitions failed, but recovered A Remote Support connection via a browser running on a partition, management server, client workstation, or service processor enables a client and CSC specialist to view, collect, and transfer diagnostic material to Unisys for analysis. Partitions failed and will not recover A Remote Support connection via a browser running on the service processor, management server or client workstation enables a client and CSC specialist to view, collect, and transfer diagnostic data to Unisys for analysis without waiting for onsite support. CSC contacted for assistance with partition reconfiguration or reboot assistance A Remote Support connection via a browser on a service processor, management server, or client workstation enables a client to pass control to a CSC specialist to perform the required tasks, or enables a client to retain control with the CSC specialist simply viewing and describing the required steps. When Unisys Internet Remote Support Can Be Used Remote Support plays a vital role in the Unisys support structure, providing immediate "on-site support" capabilities by remote Client Support Center specialists (and engineering support personnel, if required), without the deployment delays associated with dispatching a Unisys CSR to the site. Training The user interface for the Unisys Remote Support Meeting Appliance is fairly straightforward. Minimal training is required. Most users will be able to navigate the simple screens and links that are presented to the user upon connecting to the Unisys Remote Support Meeting Appliance. Remote Support is not restricted by time or distance. A CSR can be located anywhere in the world and be capable of connecting to a client s system. 6
Conclusion If a client needs to resolve a mission-critical issue immediately and has an Internet Web browser that support SSL encryption, then Unisys Internet Remote Support should be used. The benefits of using Unisys Internet Remote Support include time savings, reduced costs, less system downtime, expert and tool availability, accurate remote administration, secure sessions, partition security, and an intuitive user interface. To learn more about Unisys Internet Remote Support, contact Unisys today at 1-800-874-8647, ext. 621 or 585-742-6865, ext. 621, or visit us on the Web at www.unisys.com. 7
For more information, contact your Unisys representative. Or call Unisys today at: 1-800-874-8647, extension 985 (U.S. and Canada) 00-1-585-742-6780, extension 985 (Other countries) If you're in a hurry to learn more, visit our Website at: HTTP://www.unisys.com/products Specifications are subject to change without notice 2006 Unisys Corporation All rights reserved. Unisys is a registered trademark of Unisys Corporation. All other brands or products referenced herein are acknowledged to be trademarks or registered trademarks of their respective holders. Printed in U S America 1/06 3826 6433-002