Showing posts with label IT infrastructure. Show all posts
Showing posts with label IT infrastructure. Show all posts

Monday, January 23, 2012

Escaping the pitfalls of remote data center management

Data Center Infrastructure Management (DCIM) continues to be a hot topic for data center managers in 2012 and while it’s important to keep up with new tech developments, it’s equally important to once in a while stop, and make sure that your basic management needs are really covered.

When dealing with IT infrastructure in a data center, remote access methods have become a key part of the IT manager’s tool box. But managing these tools is a sizable job in itself. In every IT environment there are a variety of remote access tools that have been purchased departmentally or have come into the data center or network closet as a result of the preferences of different technical teams, who've chosen – and don’t want to relinquish – these tools to accomplish specific tasks. All of this brings significant complexity to the overall data center management process. 

Data centers are highly dynamic and complex environments. They are multi-disciplinary, multi-vendor and multi-user to name just a few. New equipment is added at an astounding rate, in some cases to geographically disparate locations. All of this has to be accessed and managed in a remote, efficient and secure manner that doesn’t leave you relying on the glue on the back of a post-it note to be able to find critical information in the event of an IT emergency. 

A few weeks ago, we described how a DCIM system is compromised if you cannot manage the access to your data center infrastructure. When you’re faced with downed systems and are in a somewhat helpless state, having a readily available solution that enables you to diagnose, access, troubleshoot and fix a problem remotely over the LAN or Internet can be the difference between an ordinary workday and one that leaves you anxiously scrambling for answers and wasting precious time.

In our upcoming live webinar ‘The Secret Behind A Bulletproof DCIM Strategy’ on Tuesday, January 24th @ 2pm EST, we discuss more about remote data center management and how Remote Access Management is a critical piece of DCIM, used daily by IT admins to run, maintain and fix their data center's IT infrastructure. Register Now!

Wednesday, January 18, 2012

Data center security - a look at the other side of the firewall

In today’s cyber world nobody in his right mind, business or individual, operates without a firewall. But – did you know that around 80 percent of all security threats to organizations come from the inside? Astonishingly enough most companies focus their security resources on preventing external hackers from causing them harm, and no matter how successful firewalls and various intrusions detection/preventing systems are, they are not of much help when the attack/intrusion comes from within the organization, behind the firewall doors…

While people, or workers from within your organization can actually do far more damage to your business than any hacker, this threat is often over looked, not given enough attention or forgotten all together. A recent global study with more than 5.500 IT personnel reveals that increased threats to sensitive and confidential data are caused due to a lack of control and oversight of privileged users.

Think about it for a moment, do you (or anyone else inside your organization) really know how many of your employees, IT personnel, external contractors - or even former IT staff – have access to your critical systems and data? Or, for that sake, do you know how many of your company’s IP addresses, passwords and user names are currently floating around inside your IT department on various spreadsheets and post-it notes?

One security layer that could easily be implemented to protect against such threats is an application that manages remote access inside, as much as outside, of the organization’s data center. This would provide you with a simple way to administer IP addresses, user profiles and user rights while avoiding password sharing with external service providers. Think of it as a firewall behind the firewall - it will allow you to centrally manage and control who has access to what, and with what level of permissions, while it at the same time you can see which privileged users entered which target, from which IP address, through which access method. This will also ensure you that the right access, to the right equipment is given ONLY to the right people inside your organization. 

To learn more on how easily you can protect your internal passwords and increase the security to your own IT infrastructure, watch this video!

Tuesday, December 13, 2011

How long does the glue on DCIM post-it notes last?


As a top IT pro in the data center, you’re probably chuckling because you actually know the answer to that question!

When it boils down to Data Center Infrastructure Management (DCIM) monitoring your equipment is just not enough. Even the most organized IT manager has innumerable sticky notes papering their walls.  Accompanied with a host of homegrown spreadsheets dedicated to organizing the long lists of IP addresses, passwords, and multivendor equipment information you need to access and control your IT infrastructure smoothly, on a daily basis.  And that makes perfect sense – those IP addresses and passwords are things you need at your fingertips on a moment’s notice – no time to search for them when something goes wrong.

Chances are, you’ve been through this nightmare scenario before: IT is notified of an issue.  The first course of action is to open the spreadsheet, locate the name of the server, and copy and paste its IP address, password and user name info. This can require opening and closing numerous browsers and applications – something that takes dozens of mouse clicks and many minutes – before a device can be found and accessed.  Once the device is located, you’ve got to fix the problem. You may go for an RDP session and fail, attempt a KVM-over-IP connection, or even worse – need to force a reboot through the PDU, each of which starts the copy and paste process all over again. This kind of downtime adds up. Over a typical shift, the wasted minutes can easily turn to wasted hours of valuable work time just searching for the right information.

What you need in order to safe guard your DCIM system, is a central access console, a singular control panel, where you can see and capably manage all of your computing resources no matter where they are physically located –from the network closet to an off-site data center to a co-location facility in another city or state. - But make sure to choose the right solution!

Here is a checklist you should use when selecting a remote access management (RAM) solution that will strategically fit your DCIM system in place. Ask yourself if the solution does all seven of these things:
  1. Supports a wide range of vendors: Select a solution that prevents vendor lock-in; make sure it supports all the equipment acquired over the years and offers the ability to add any brand of IT equipment – PDU, IP KVM switch, console server, or other network device in an unlimited array of vendor options.
  2. Integrates in-band and out-of-band access options: A seamless combination of the two means, even if the blue screen of death appears, crashed servers can be restarted and downtime minimized with one-click KVM over IP access from the same pane of glass used for everyday maintenance.
  3. Simplifies access: What makes a remote access solution truly powerful is a combination of one user interface, one url and one set of security rules.  When it comes to remote access management as part of DCIM, simplicity is king.
  4. Provides seamless access to power control: The only way to avoid disastrous mistakes like rebooting the wrong server is to have full control of the PDU from within the remote access management solution’s user interface.
  5. Maximizes tools that have already been deployed: Don’t throw out what works!  A must-have in remote access management is the ability for the IT staff to continue to use the existing remote access tools they find most effective and comfortable under a larger, more efficient and secure remote access umbrella.
  6. Overcomes implementation challenges: Look for a solution that can be installed in hours – not a month and not a week.
  7. Increases IT efficiency while maintaining security: Select a secure remote access solution that authenticates users with the organization’s own active directory, assigning user names and passwords created according to profile and task assignment.

What this all means is that Remote Access Management and Data Center Infrastructure Management are inextricably linked! Or in other words - if you don’t have a RAM, you really don’t have DCIM.

And if that’s not enough, just think how nice your wall will look without all those post-its on it...


Monday, December 05, 2011

What do slices of a hot Pizza have to do with DCIM?

No Data Center Infrastructure Management (DCIM) is complete without a Remote Access Management system in place!
The Full DCIM Pizza


Yes, you heard right. Now, you are probably asking, what does Remote Access Management have to do with DCIM?

The answer is - A lot! Today infrastructure equipment at all levels is becoming more important and more critical to the smooth operation of data centers, in other words, it has direct impact on lowering costs, tightening security and increasing efficiency. But DCIM is not only about monitoring and planning, it is also about managing all your access control tools and methods.

Remote Access Management (RAM) is one of the most vital slices of the DCIM ‘Pizza’ that is not getting the full attention it deserves. So let’s cut the chase and state it clearly: All other DCIM slices, as important as they may be, are compromised if you cannot manage the access to your data center infrastructure!

Think of the ordering process of a hot, sizzling family Pizza – the pictures on the website look awesome, you can practically “smell” the Pizza over the phone. The person taking your order is sweet and polite, you get all the flavors you asked for and you even get a special price for being such a nice guy, but – all this is worthless without a fast and reliable delivery that brings the Pizza hot and sizzling to your doorstep…  

So why don’t you take a closer look at your overall DCIM strategy and make sure that you have all the slices in place, and not missing the management of your remote access!

Monday, November 28, 2011

KVM over IP Switch or HP iLO? That’s the question – Or is it??


Posted by:
Tobias Silber
8 Points To Consider When Evaluating the Best Remote
Out-Of-Band Access Solution For Your Data Center.

Lately we have been getting a lot of questions from IT managers that are consolidating their data centers on the issue of an IP KVM switch versus a service processor. While IP KVM switches and embedded service processors, such as iLO from HP, often are looked upon as competitive, the reality is however much more complex. So let’s shed some light on what needs to be taken into consideration before deciding which (or both?) solution is right for your data center.

  • Local KVM Access: In the data center, certain situations can arise where you would need to have direct server access independent of potential network disruptions. - In other words, to have local access at the rack level. While iLO can be a good option for remote administration it does not provide local access at the rack. Only an IP KVM switch provides you with this important feature, allowing you to physically connect to multiple servers from one console, at the rack.
  • Centralized Server Management: By definition iLO is a one port solution, providing remote access to a single server. An IP KVM switch on the other hand can be connected to a bank of 10s or 100s of servers, providing for a tighter control and more efficient work flow.
  • Cost: In order to benefit from the iLO vKVM features, there is a licenses fee. While the license itself can be bought from $130, the true cost of using iLO can easily total over $400 per server when you include all the hidden costs. Compare this to the price per port of an IP KVM switch at $140-170 (including dongles/cable) – and you have easily saved a few thousand dollar per rack!
  • Ethernet Ports & Cabling: iLO requires the use of additional cabling and an additional Ethernet port at each server in order to be connected to the network. These requirements are translated into more routers and switch ports, which mean more money spent (part of the hidden cost).  This is in contrast to a KVM over IP switch that consolidates a large number of servers into one ethernet (or two, for redundancy) port.
  • IP addresses: Each server equipped with an iLO requires two unique IP addresses!one for the server and one for the iLO. This can dramatically increase the number of IP addresses the organization has to purchase (another hidden cost), and not all data center can meet this challenge. An IP KVM Switch on the other hand, centralized the remote management of up to 32 servers via a single IP address.
  • Performance: The KVM over IP video performance is superior to the iLO performance with a better video refresh rate at reduced bandwidth.  To benefit from the best mouse synchronization you need the best video resolutioin support. iLO supports up to 1280x1024 video resolution whereas an IP KVM Switch goes up to HD resolutions. Users of iLO are also limited in their choice of browsers, as it only support IE for Windows and Firefox for Linux in comparison to IP KVM users that can use a whole range of remote clients.
  • Ease of Operation: To install the IP KVM Switch you will only need to connect it to the servers, power up and assign to it an IP address. The time spent on configuring a single IP KVM switch in order to access 32 servers remotely is much less than the time you will need to setup 32 individual iLO servers. Think about the time difference when the need for a firmware upgrade arises!
  • Security: Another big aspect of keeping IP addresses to a minimum is data security. The less public IP addresses out there, the easier it is for IT to keep the lid tightly closed and avoid the horror of security breaches, just because there are so many IP addresses to look after.

...And just to summarize: IP KVM switches provide centralized remote access to servers, regardless of brand, generation or OS running, whereas iLO is only relevant for HP servers. This however does not necessarily make them competing technologies for out-of-band access, but rather the contrary - HP iLO is a good complementary solution to the KVM over IP Switch in the data center.

Sunday, November 22, 2009

11 Rules for IT Delivery Success

Kudos to the author, Thomas Hoffman, for not rounding up or down, but sticking to the number eleven.

His short, concise list of 11 Rules for IT Delivery Success are somewhat general. However, if applied consistently and thoroughly, these rules can be good guidelines for what needs to happen when new systems are introduced or old systems are upgraded.

The somewhat general nature of the rules can also be explained by the following bit of background:

“Because developers, operations staffers and engineers all work in different groups, ‘you need to have a way to establish parameters that everybody can work off of and understand what their expectations are,’ says Martin Gomberg [Senior Vice President and CIO, A&E Television Networks]. ‘We use this as a lens to measure every critical component.’ "

How close is this list to the one hanging on your wall?