This chapter provides a summary of the steps required to prepare your site for installation and configuration of the Sun N1 System Manager1.2 system, and security issues you need to consider when preparing your site for the first-time installation of the Sun N1 System Manager software.
If you are going to upgrade an existing installation of the N1 System Manager, see Chapter 2, Upgrading the Sun N1 System Manager Software and Provisionable Server Management Agents, in Sun N1 System Manager 1.2 Installation and Configuration Guide.
The following diagram provides a high-level overview of the tasks required to prepare a site for Sun N1 System Manager1.2 installation.
Summaries of each of the above tasks are provided in the following list.
Determine system requirements
This task involves the following actions:
Inventory the equipment you want to use with the Sun N1 System Manager
Compare the inventory to the system requirements, and if desired, purchase additional equipment
Determine which server you will use as the management server and which operating system you will install on the management server
Determine which servers you will use as provisionable servers and, based on the total, determine your switch requirements
References:
Map network
This task involves the following actions:
Determine the IP addressing scheme for the management, provisioning, and data networks.
Whether you will use a single-switch configuration in which all connections are on a single switch, or a two-switch configuration, in which the management network is isolated on one switch and the data and provisioning networks are on the second switch.
Determine the VLAN assignments
References:
Connect the hardware based on the information and decisions you have made in the preceding steps.
Install and configure an operating system on the management server
This task can be performed at the same time as provisionable server preparation.
References:
Prepare the provisionable servers
This task involves the following actions:
Assign IP addresses to the management port of each provisionable server
Set up the provisionable server management processor account credentials where applicable
References:
Provisionable server hardware documentation
The following list provides general security considerations that you should be aware of when you are using the N1 System Manager:
The JavaTM Web Console that is used to launch the N1 System Manager's browser interface uses self-signed certificates. These certificates should be treated with the appropriate level of trust by clients and users.
The terminal emulator applet that is used by the browser interface for the serial console feature does not provide a certificate-based authentication of the applet. The applet also requires that you enable SSHv1 for the management server. For certificate-based authentication or to avoid enabling SSHv1, use the serial console feature by running the connect command from the n1sh shell.
SSH fingerprints that are used to connect from the management server to the provisioning network interfaces on the provisionable servers are automatically acknowledged by the N1 System Manager software. This automation might make the provisionable servers vulnerable to “man-in-the middle” attacks.
The Web Console (Sun ILOM Web GUI) autologin feature for Sun Fire X4100 and Sun Fire X4200 servers exposes the server's management processor credentials to users who can view the web page source for the Login page. To avoid this security issue, disable the autologin feature by running the n1smconfig utility. See Configuring the N1 System Manager System in Sun N1 System Manager 1.2 Installation and Configuration Guide for details.