
Hardware Management Console Best Practices
- 14 -
4 Security
Physical security of the HMC is a customer responsibility. The HMC should be
located in a secure room, if possible. Usually, because of its proximity to the
servers it manages, the HMC will be located in a secured data center. However,
when that is not possible, there are ways of providing additional protection
against unauthorized physical access. These protections are mainly provided by
changes in the BIOS settings on the Intel chip that powers the HMC:
• Change the startup device settings in BIOS to prevent the use of a
Recovery CD or diskette to boot into single-user mode.
• Assign a power-on password in BIOS to prevent unauthorized changes to
BIOS settings.
• Unattended start mode can be set in BIOS to allow the HMC to reboot
without the power-on password following restoration of power after an
unplanned outage. However, the keyboard and mouse at the local console
will remain locked until the power-on password is entered.
4.1 Network Security
The HMC must be properly networked to perform its server management
functions. The private or service network is used to communicate with FSPs, and
the open network is used to collect serviceable events from managed servers and
to dynamically reallocate resources. A network is also the means by which
remote administrators access and manage the HMC itself.
Two versions of the Web-based System Manager (WebSM) client code (for
Windows 2000 and later or Linux) reside on the HMC and are downloadable
using a browser as follows:
http://<HMC_hostname>/remote_client.html
To download the client package from the HMC, the user is required to enter a
valid HMC user ID and password. Once the WebSM client package has been
installed, the user can connect to the HMC by:
• Entering wsm <hmc_hostname>
if the user is on a remote Linux
system, or
• Double clicking on the WebSM remote client icon on the Windows
desktop
A login dialog is then displayed to prompt the user for an id and password.
Komentáře k této Příručce