A More Secure and Cost-Effective Replacement for Modems



Similar documents
SCS3205/4805 Quick Start Guide

L2F Case Study Overview

User s Manual TCP/IP TO RS-232/422/485 CONVERTER. 1.1 Introduction. 1.2 Main features. Dynamic DNS

The ABCs of KVMs: How Remote KVM Switches Put You in Control of Your Data Center

Electronic Transaction Market Industry Whitepaper. Systech Corporation Internet Payment Gateways

Out-of-Band Management: the Integrated Approach to Remote IT Infrastructure Management

3.1 RS-232/422/485 Pinout:PORT1-4(RJ-45) RJ-45 RS-232 RS-422 RS-485 PIN1 TXD PIN2 RXD PIN3 GND PIN4 PIN5 T PIN6 T PIN7 R+ PIN8 R-

50-Port 10/100/1000Mbps with 4 Shared SFP. Managed Gigabit Switch WGSW Quick Installation Guide

SecureLinx Spider Duo Quick Start Guide

User s Guide Digi CM

ZyWALL 5. Internet Security Appliance. Quick Start Guide Version 3.62 (XD.0) May 2004

Applicazioni Telematiche

Secure, Remote Access for IT Infrastructure Management

Connecting and Setting Up Your Laptop Computer

This techno knowledge paper can help you if: You need to setup a WAN connection between a Patton Router and a NetGuardian.

Linksys Gateway SPA2100-SU Manual

1 Getting Started. Before you can connect to a network

IPG/7700 Hardware Manual SYSTECH. Document number Revision A

Managing Serial Devices in a Networked Environment

Prestige 202H Plus. Quick Start Guide. ISDN Internet Access Router. Version /2004

Unpacking the Product. Rack Installation. Then, use the screws provided with the equipment rack to mount the firewall in the rack.

Vantage RADIUS 50. Quick Start Guide Version 1.0 3/2005

Palomar College Dial-up Remote Access

UTStarcom UT-300R2U. ADSL Modem. UTStarcom, Inc. USER GUIDE. Release: 1.0. Doc. Code:

One Port Serial Server Users Manual Model ESP901, ESP901E

Securely manage data center and network equipment from anywhere in the world.

DSL-2600U. User Manual V 1.0

Application Note 2. Using the TCPDIAL & TCPPERM Commands to Connect Two TransPort router Serial Interfaces Over TCP/IP.

Introduction To Computer Networking

BRI to PRI Connection Using Data Over Voice

Opengear Technical Note

LAN / WAN Connection Of Instruments with Serial Interface By Using a Terminal Server

SIP Proxy Server. Administrator Installation and Configuration Guide. V2.31b. 09SIPXM.SY2.31b.EN3

Experiment # 6 Remote Access Services

Chapter7 Setting the Receiving PC for Direct Upload. Setting the Receiving PC for Direct Upload For Windows For Macintosh...

DRO-210i LOAD BALANCING ROUTER. Review Package Contents

Virtual Private Network and Remote Access

UDS-10, UDS100, UDS200 Quick Start Guide Copyright Lantronix is a trademark of Lantronix. All rights reserved Rev.

Cisco ISE Command-Line Interface

Prestige 314 Read Me First

CCT vs. CCENT Skill Set Comparison

Cable Pinouts. SRP I/O Module

Multi-Homing Dual WAN Firewall Router

Firewall VPN Router. Quick Installation Guide M73-APO09-380

Starting a Management Session

PN5212/PN5320/PN7212/PN7320

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

Domain 3.0 Networking... 1

Overview of the Cisco 2500 Series Access Server

TK C -25 C 95% RH EMC TK701G TK701U TK704G TK704U TK704W. TK-Series Cellular Router

DS SERIES SOLUTIONS ALL AT ONCE

NCC Blade Network Communication Controller

Broadband Router ESG-103. User s Guide

Prestige 650R-31/33 Read Me First

VPN Overview. The path for wireless VPN users

1 Serial RS232 to Ethernet Adapter Installation Guide

Prestige 324. Prestige 324. Intelligent Broadband Sharing Gateway. Version 3.60 January 2003 Quick Start Guide

USER GUIDE. Ethernet Configuration Guide (Lantronix) P/N: Rev 6

Voice Over Internet Protocol (VoIP) Configuration

Cisco Which VPN Solution is Right for You?

Mobile Router MR600 User Guide

BiPAC 7404V series. VoIP/(802.11g) ADSL2+ (VPN) Firewall Router. Quick Start Guide

Virtual Private Network and Remote Access Setup

Student Halls Network. Connection Guide

Executive Summary and Purpose

Using Debug Commands

ETHERNET WEATHER STATION CONNECTIONS Application Note 33

Wireless Router Setup Manual

SUPERSTACK II HUB TR NETWORK MANAGEMENT MODULE INSTALLATION GUIDE

FTP Automation Guide

IP SERIAL DEVICE SERVER

Using the DNP3.0 Protocol via Digi Device Servers and Terminal Servers

System i and System p. Customer service, support, and troubleshooting

Tera Term Telnet. Introduction

NPort s Ethernet Modem Mode

Installation & Configuration Manuel. Socket Server. OpenAT application

The BANDIT Device in the Network

ERserver. iseries. Remote Access Services: PPP connections

Comtrend 1 Port Router Installation Guide CT-5072T

Cisco 831 Router and Cisco SOHO 91 Router Cabling and Setup Quick Start Guide

Opengear Application Note

ZyXEL VoIP 2602HWL - Setup guide

DS Series Solutions Integrated Solutions for Secure, Centralized Data Center Management

How to Connect SSTP VPN from Windows Server 2008/Vista to Vigor2950

PC/POLL SYSTEMS Version 7 Polling SPS2000 Cash Register TCP/IP Communications

IT Networking and Security

Data Communication Networks and Converged Networks

Network Client. Troubleshooting Guide FREQUENTLY ASKED QUESTIONS

DOORKING SYSTEMS 1830 SERIES NETWORK WORKSHOP LAN APPLICATIONS ACCESS CONTROL SOLUTIONS LOCAL AREA NETWORK (LAN) CONNECTION REV 04.

isco Connecting Routers Back to Back Through the AUX P

Multi-Homing Security Gateway

Prestige 324 Quick Start Guide. Prestige 324. Intelligent Broadband Sharing Gateway. Version V3.61(JF.0) May 2004 Quick Start Guide

PFSENSE Load Balance with Fail Over From Version Beta3

MODBUS TCP to RTU/ASCII Gateway. User s Manual

TW100-BRV204 VPN Firewall Router

Transcription:

A More Secure and Cost-Effective Replacement for Modems Lantronix, Inc. 15353 Barranca Parkway Irvine, CA 92618 Tel: +1 (800) 422-7055 Fax: +1 (949) 450-7232 www.lantronix.com

Abstract For companies, service organizations and government agencies that desire a more reliable, secure and less expensive alternative to conventional modem systems, Lantronix has developed the Secure Console Server console for remote IT troubleshooting. With IT equipment spread over a large geographic area, organizations with large IT infrastructures can benefit greatly from a centralized management solution rather than relying upon IT staff housed in diverse offsite locations. While conventional modems can be used to provide some of the needed connections for centralized access, they can be problematic in that they lack critical attributes to ensure reliability, security, ease of use and cost effectiveness. This application note illustrates how the Lantronix SCS400 console server can be efficiently used as a higher quality, more reliable and more secure alternative to costly dedicated modem phone lines. This application note also provides information on how the SCS400 can improve network troubleshooting and administration by enabling users to respond to local and remote IT incidents quickly. Specific benefits and uses of the SCS400 will be discussed, as will general design guidelines for utilizing this powerful product most effectively. Product Overview The SCS400 is a network device with Ethernet ports and a TCP/IP protocol stack that provides remote access to IT and telecom equipment. It can initiate a connection from a serial port to an IP address and is capable of mimicking the behavior of a modem. With its modem emulation mode and unique dial back capability, the SCS400 offers several communications solutions that create network functionality, including the ability to manage legacy equipment in an IP environment. With the SCS400 s modem emulation mode the serial ports on the SCS400 behave like a modem by responding to AT commands. On a normal modem, an ATDT, followed by a phone number, instructs the modem to dial that number. On the SCS400 in modem emulation mode, an ATDT, followed by an IP address, instructs the SCS400 to open a TCP/IP connection to that IP address. To maintain compatibility with modem dialing programs, IP addresses are expressed using twelve digits without dots (for example, ATDT192168001001). IP destination ports can be expressed using a comma, which is commonly supported by modem dialers to insert pauses in a dial sequence, such as ATDT192168001001,3001. In addition the SCS400 offers the flexibility of in-band and out-of-band management capabilities, depending on customer needs and configurations. System administrators benefit from the ability to rectify local and remote IT problems more quickly by leveraging their existing IP network or a modem connection. The SCS400 also features a number of security benefits that ensure the integrity of equipment and data including strong encryption, authentication and the break safe features of Sun Solaris. Regardless of target market or industry, this device is ideal for remotely troubleshooting IT issues by linking to the hub, telecom switch and CPU at the site of the problem. A More Secure and Cost-Effective Replacement for Modems 2

Application Examples- Scenario 1: Modem Replacement Consolidating multiple managed devices through a single IP based network in order to eliminate the need for dedicated modem lines. In this example, the customer s network would likely still employ a phone line and modem for remote connections. But rather than one phone and modem required for each managed device, all devices are managed though the same phone line and modem. With this application, a customer has a device that is only capable of remote communication using a modem, with a serial interface that is programmed to configure, dial, and answer a modem using AT commands. The SCS400 offers a solution that mimics a modem on the serial side, but transfers data over a common medium, in this case an Ethernet network. The general layout for this type of application would be: However, there are variations that sometimes exist in this environment. One is a case where the SCS400 uses an internal or external modem to dial the Internet, basically serving as the router for its side of the connection. The layout in this scenario would be: In another such scenario, the SCS400 is dialed by the client (either dial-in or dialback). This same physical setup can be used to make a modem emulation session on the serial port of the SCS400 and trigger it to dial the host using a routing table. The layout for this would be: There are further permutations of this setup that can use these functions. However, to understand them at a generic level, one must consider the following functions separately. A More Secure and Cost-Effective Replacement for Modems 3

a. Without Modem Emulation b. With Modem Emulation The WAN in the above scenario constitutes any method available to link networks, whether it be two routers over a dial-up, a VPN connection over DSL, ATM or T1. The result of the above example is that the cost of maintaining a phone line for each device is eliminated. In its place is a device, the SCS400, which uses the network. The difference is that the network is generally already in place for other purposes such a file sharing, printing, Internet access, etc. So instead of legacy devices causing additional costs in phone lines, they are simply another device utilizing the network. Scenario 2: Device Management Centralized device management from a support location for remote IT troubleshooting. In this example, the IT professional Telnets from the server to the SCS400 by providing either the modem name or address. The router then makes a call over its modem to the modem at the necessary adjacent site. The support modem calls the other facility s modem and establishes a connection between the router and the SCS400. A More Secure and Cost-Effective Replacement for Modems 4

Once user authentication is established, the SCS400 then instructs the other facility s modem to hang up the call and dial back to the support modem using a pre-stored phone number. The facility s modem dials the support modem and authentication is repeated. Once established, the call then creates a Telnet session over the PPP connection between the server and SCS400. As a result, the IT department can access another facility s site just as though it was connected locally at the console. The dial-back capability starts out with a similar scenario to the one mentioned in scenario 1. However, in this case, the purpose of the phone lines is to dial into a device to manage it, where in the modem replacement scenario, the devices are generally dialing out. In this case, a situation where dial-back might be used would look like this: It is important to note that in either of these two scenarios, it is possible for both uses to be performed on the same physical setup, though they are considered distinctly different functions of the SCS400. Key Benefits of the SCS400 Cost Effectiveness Limits number of phone lines and modems required Through its modem emulation mode and dial-back capabilities, the SCS400 eliminates the need for additional dedicated phone lines and modems, reducing the operating costs associated with traditional IT troubleshooting systems. Extends the life of current equipment Because of the advanced nature of the SCS400 and its capability to interact on a TCP/IP based network, the life of existing legacy equipment can be extended far beyond a traditional modem system. Organizations can delay the need to upgrade equipment, thereby saving or redirecting IT funds to more critical investment areas. Centralized and event management capabilities speed recovery The ability to remotely diagnose and correct problems from virtually anywhere via the Internet saves organizations a great deal of time and money and helps ensure critical systems maintain 100 percent uptime. Addressing a problem from a central vantage point at the time it occurs eliminates the uncertainties associated with a system spread across geographical locations. Organizations no longer need to rely A More Secure and Cost-Effective Replacement for Modems 5

upon offsite personnel to communicate, evaluate and rectify situations. Furthermore, the central management allows organizations to better track the history of problems in order to evaluate whether broader corrective measures are needed. As an added benefit, event logging and email notification further accelerate troubleshooting activity. Event management features help users locate the source of equipment problems and diagnose them quickly. Each serial port can be independently configured to store console messages from attached equipment, then alert a network manager of a potential issue by email over the network or through an alternate modem connection. Upon notification, network managers can easily review the stored console messages to determine the root of the problem. Enhanced Security Wider range of security offerings This secure console server ensures the integrity of customer data and equipment by incorporating robust security protocols. Authentication limits access to authorized users only, via login and password (typically determined by username), modem dial back, PAP/CHAP, Radius, Kerberos or SecureID. Stored user profiles help restrict access to equipment and services as necessary, while Secure Shell (SSH) safeguards login passwords and in-transit data through encryption. SSH is an extremely important protocol that maintains overall network security through strict authentication for protection against intruders as well as symmetric encryption to protect transmission of dangerous packets. Reliability and Ease of Use More options to access equipment Accessibility to all types of equipment is available via both in-band management (Ethernet) for convenient access over IP networks, and out-of-band management using a local terminal or modem. The SCS400 features a configurable menu system by which the user can select specific remote equipment to access quickly and easily based on descriptions customized by the organization. For example, menus can be organized by equipment location and name or configured specifically for each user, limiting access to equipment. Centralized management improves troubleshooting success rate and convenience The centralized approach saves time by enabling organizations to more effectively allocate resources. The result is an IT staff and resource pool that is better focused and more efficient. In addition, SCS400 s system supports the immediate resolution of problems, which reduces lag time and improves the overall performance of IT troubleshooting. Limited space requirements The physical dimensions of the SCS400 are significantly less than that of a modem system. Features: Interfaces: Ethernet 10-BaseT/100Base-TX RJ45 Serial Speed: 300bps to 230bps A More Secure and Cost-Effective Replacement for Modems 6

Four RS-232 connectors (DB9 male, DTE) PCMCIA Type I and II PC Card -- supports wireless, modems and storage cards. RTS, CTS, DSR, DCD, and DTR modem control Flow control via XON/XOFF, hardware or none CPU/Memory requirements: 32-bit processor 2MB Flash 4MB RAM Power requirements: 9-30 VDC 0.184A at 12VDC AC adapter Operating environment requirements: 5-50 degrees Celsius/41-122 degrees Fahrenheit Lantronix is a registered trademark, and Secure Console Server is a trademark of Lantronix, Inc. A More Secure and Cost-Effective Replacement for Modems 7