HMC The New Console on the Block John Still Objectives Console History Introducing the Hardware Management Console (HMC) Planning for HMC and i5 Guided Setup Wizard HMC Management Remote Access System Manager Security 2
Console History System 38 console built into the system unit 3 Console History Twinax 5250 console 20 feet from the system unit maximum 4
Console History PCs gain momentum 5250 emulation card allows PC to become system console Client access PC console iseries access operations console & Lan console 5 Introducing the HMC First introduced on the pseries A LINUX based PC appliance for eserver power5 Tied to specific PC hardware (xseries) Ships with embedded OS pre-loaded Closed and dedicated (can t install other software on it) Required for configuration & management of logical partitioning, capacity on demand and some maintenance functions 6
Introducing the HMC Create and maintain a LPAR environment. Display a virtual console session for each i5/os partition. Display or change control panel settings for each partition. Detect, report, and store changes in hardware conditions. Power managed systems on and off. Act as a service focal point for service representatives to determine an appropriate service strategy and enable service agent to call home to IBM. Activate additional resources on demand. The HMC can be disconnected, but you cannot perform any of the above functions. 7 Introducing the HMC Based on xseries server technology Minimum HMC configuration includes: 1 GB memory, 40 GB disk, DVD-RAM, 10/100/1000 Mbps Ethernet port, diskette drive, etc Selectable options for HMC s display, keyboard, etc (ordered separately) HMC connects to POWER5 service processor which has two dedicated HMC ports. The ports are Ethernet ports. (Different from the two generic 10/100/1000Mbps Ethernet LANs.) Standard HMC maintenance support is CRU. Suggest upgrading support to IBM On-Site Repair to be more consistent with POWER5 server s support agreement. 7310-CR2 (rack) HMC not used on earlier iseries servers non-hmc i5/os consoles are still supported High availability suggestion: attached two HMCs to critical Power5 servers for redundancy. 7310-C03 (desktop)
Introducing the HMC - Security HMC Security Granular User Access Controls Define Task and Resource Roles that define accessible lists of user tasks and resources (systems, partitions, etc) Assign roles to users to define their access rights For example, access could be limited to a single partition Network Security Firewall Controls Define which HMC network services should be accessible on which physical network interfaces For example, limit remote WebSM or SSH access to a single interface, or none Restricted Shell Provides access to supported HMC command line functions Accessible remotely through SSH enabled client Also accessible as a command prompt window on the HMC itself 9 Managed System with HMC Managed System i5/os Linux Partition 1 Partition 2 POWER Hypervisor Unassigned Resources Ethernet HMC Non-Volatile RAM Processors Memory I/O Slots LPAR Allocation Tables Service Processor Ethernet 10
Service Processor SP (Service Processor) or formerly FSP (Flexible Service Processor) Description: Controls base operations of the i5 system. It is powered up immediately when power is supplied. Defaults as DHCP client. Defaults if no address or range assigned within one minute: https://192.168.2.147 and https://192.168.3.147 Managed System can operate in the absence of the HMC. LPAR configuration resides in HMC and NVRAM. Maintenance PTFs required (via HMC or i5 OS Partition) 11 Typical Topology 12
Why the HMC? Already on the pseries why not the iseries Virtualization Why should operating systems have to worry about hardware A place to host advanced platform management applications regardless of what OS is loaded The ability to configure a server before the OS is loaded Provide virtual consoles (i5, AIX, LINUX) A common delivery vehicle IBM can deliver more functions, more quickly 13 Why the HMC? On an 8XX system your Primary Partition cost: At least.25 Processing Units recommended At least 1 DASD bay or sub bay At least 2 Disk drives At least 512 MB memory At least 1 IOP and 1 Disk IOA and 1 console IOA WAS a single point of failure P0 P1 P2 14
eserver Hardware Information Center On the internet Preferred On CD with your shipment Preloaded on the HMC For use once the initial setup and cabling steps have been completed, using either of the other two sources! http://publib.boulder.ibm.com/infocenter/eserver/v1r2s/en_us/index.htm 15 eserver Hardware Information Center 16
eserver Hardware Information Center Extensive Planning and How To documentation For the HMC, make sure you review these sections: Planning for the Hardware Management Console (HMC) Gathering required configuration settings HMC configuration checklist Going through these planning steps will make for a much smoother HMC installation it could save you hours! 17 HMC & Managed System LAN Topology HMC must connect to SP on Managed System Private Network or Open Network (or both) Separate connection to AIX or LINUX for DLPAR To Partitions Internal PCI Modem Network Ethernet Service Network Service Processor HMC Private LAN Service Processor 18
Remote Access to the HMC Limit 5 remote users Secure Shell (SSH) Client 4 SSH Access to HMC Commands Remotely Needs to be enabled from the HMC 3 WebSM Access through Windows/Linux/AIX Network ASMI HMC 2 Partition remote virtual terminal aka console via TN5250 1 Alternate (remote) HMC 5250 19 Additional ethernet requirements When running AIX ( AIX 5L 5.3 or higher ) or Linux partitions on an I5 server, the DLPAR ( dynamic movement of resources ) function for those partitions also requires an external LAN connection to the AIX or Linux partition. This second connection is not required for DLPAR in an I5/OS partition. To dynamically move resources in an AIX or Linux partition, the HMC must also be able to communicate to those partitions over a second LAN connection. The rack-mounted 7310-CR2 HMC has two ethernet ports built in. The first port connects to the HMC1 port on the server and the second port can be used to connect to the AIX or Linux partitions via a lan adapter in the partition or via virtual ethernet if the virtual ethernet can access the HMC over an external connection. The deskside 7310-CO3 requires a feature ethernet adapter because it has only one built-in ethernet port. This is now added by the configurator. Don t remove as it can t be MES d. 20
HMC Setup options Private Network port 1 (eth0) HMC = DHCP server (Managed Systems= DHCP client) Direct attach Single Managed System Attached through hub HMC (can add a 2 nd HMC) 1 or more Managed Systems (up to 16) Both i5 & p5 @ HMC 4.2 Port 1 & 2 identical 21 HMC Setup options Private Network Port 1 Redundant HMC: Synchronized with Primary HMC FSP is DHCP Client (default) FSP is DHCP Client (default) STRONG Suggestion : Connect the first HMC as a LOCAL HMC! 22
HMC Network options Open Network port 2 (eth1) Connect to managed systems through network To Local HMC Local HMC Port-a = DHCP server Port-b = DHCP client Remote HMC Port-a/b = DHCP client Direct to Managed System Port-a/b = DHCP client Note: The two ports on the HMC and the Managed System are equivalent Network 23 Rear View of HMC * You must set the voltage selector to the correct position for 115V. Default is 220V. 24
Rear View of HMC 7310-CR2 Rack mount rear view 25 Cabling a New HMC 26
Configuring the SP Connect AC Power As soon as AC power is applied, SP begins booting up. The control panel may show both C1xx and D1xx reference codes during SP Boot Note: power light flashes when system is powered off SP is now active powered off state 27 Service Processor Ports Default IP addresses for HMC Port on Service Processor (if not served address) HMC1 = 192.168.2.147 HMC2 = 192.168.3.147 (as @ May 12, 2004!) ======== HMC Port 1 ======== HMC Port 2 Model 520 Model 570 (Rack Mounted) 28
Change Service Processor IP Address in ASMI Service Processor communication configuration can be viewed and changed through ASMI Connect cable from PC to SP HMC port. Change IP addy on PC to same network segment. Power on SP (no HMC connected) https://192.168.2.147 for HMC1 https://192.168.3.147 for HMC2 You will see Managed Server (Service Processor) Sign in: admin/admin ORgeneral/general Case sensitive 29 ASMI Admin Password Change the password if this is the first time in. DO NOT LOSE IT! If you do, call IBM Support, who will manufacture a password that is valid for one day Or keep guessing! 30
Change Service Processor IP Address in ASMI If you forget the IP address you changed to in ASMI, follow these reset instructions: http://publib.boulder.ibm.com/infocenter/eserver/v1r2s/en_us/info/iphai/troubleshoot.htm 31 ASMI Important! Change the date and time systems have been shipping with a date of 1970? The firmware update policy defaults to the HMC recommend changing this to an i5 OS partition that is designated as a Service Partition 32
The Guided Setup Wizard Procedure to Setup a new HMC Follow instructions in the Information Center: 1. Cable and install HMC 2. Power on HMC 1. Managed server must remain Powered Off (unplugged) 3. Login as hscroot (default password- abc123) 4. Guided setup Wizard 1. Set Date & Time 2. Change pre-defined password <-- do not bypass 1. Hscroot = abc123, root = passw0rd 3. Create additional users (recommended) 4. Configure HMC network connections 5. Configure HMC to connect to service provider 5. Reboot HMC 6. Check HMC Software version 1. (Update if necessary) 7. Add Managed systems 33 The Guided Setup Wizard Accessing the Guided Setup Wizard Follow instructions in the Information Center: 1. Ensure that the managed system is not connected to a power source. 2. Press the power button on the HMC to turn it on. 3. Accept a license agreement 4. Select the locale you want. 5. Log in to the HMC using the following default user ID and password: -ID: hscroot - Password: abc123 6. Guided Setup splash screen appears. 34
The Guided Setup Wizard Guided Setup Splash Screen The customer may opt to deselect having this screen come up after The first use of the wizard. 35 The Guided Setup Wizard Guided Setup Launch Point You can run the wizard as many times as you want It is accessible from the main HMC interface. 36
Guided Setup wizard The Guided Setup Wizard 37 Guided Setup Date & Time 1 2 38
Guided Setup - Passwords 39 Guided Setup - Passwords This is the customer s tasks 40
Guided Setup - Checkpoint 41 Guided Setup Networking 42
Guided Setup Networking 43 Guided Setup Networking All i5 models are set up by IBM except the 520 (unless the 520 is an upgrade from an 8xx system) If an HMC is part of the deal, the IBM service rep will only configure the first ethernet port. The service rep will configure the port as a private network and a DHCP server The second HMC port will be configured by the customer 44
Guided Setup Networking Most setups will default the ethernet adapter media speed value 45 Guided Setup Networking In an IBM installation, the SSR will select private for the connection Except for the DHCP panel, other networking options that follow will not be shown, as they are for open networks Private is the default. 46
Guided Setup Networking Shown for private. 47 Guided Setup Networking Shown if no to DHCP server In most cases a second adapter on the HMC can be a DHCP client on the company s site LAN The customer would set this up; Considerations are located in the information center 48
Guided Setup Networking The default gateway provides access to the network to which the HMC will be connected 49 Guided Setup Networking On open networks, the customer can select which HMC applications are accessible to hosts or applications on the open network The following slide shows how the applications are selected: 50
Guided Setup Wizard - Firewall 51 Guided Setup DNS For open networks, the site domain name server IP addresses are entered here 52
Guided Setup 2 nd Ethernet 53 Guided Setup Domain Suffix Open networks also require the site domain name suffix if the domain name server is used 54
Guided Setup - Checkpoint 55 Guided Setup - Service Fields with asterisks are required. Complete entire form. 56
Guided Setup - Service Fields with asterisks are required. Complete entire form. 57 Guided Setup - Service Uncheck to enter a different address for the HMC, if appropriate This is the phone number used by support to connect to the system by modem Fields with asterisks are required. Complete entire form. 58
Guided Setup - Service Any or all options may be selected In an IBM installation, the SSR will set up the dial up from the local HMC 59 Guided Setup - Service 1 2 60
Guided Setup - Service 1 2 1 2 3 Click on the appropriate phone number Modem phone numbers are to be selected where possible, from the list on the HMC 4 5 Edit selected number if necessary. 6 61 Guided Setup - Service 62
Guided Setup - Service If the customer chooses and has a VPN connection, this option can be used. 63 Guided Setup Service 64
This option is available for I5/OS (OS/400 only) and would typically be set up by the customer. 65 Guided Setup Service 66
Optional, but strongly suggested. Guided Setup - Service This task relates this HMC with the customer s IBM ID. 67 Guided Setup - Service 1 2 68
Guided Setup - Service 69 Guided setup - Service The user should consult the documentation or use the defaults for Connection monitoring 70
Guided Setup - Completion 71 Guided Setup - Completion After clicking Finish on the guided setup wizard, it may take some time for processing. Successful Pending Failed For details of each task s completion status, click here. You can click Close at any time. The tasks will still run. 72
Plug in the Managed System Reboot the HMC Connect Ethernet cable from HMC port 1 to HMC1 port on the Managed System Plug the power cord into the Managed System The Managed System s Service Processor will boot up The HMC will assign an IP address to the Managed System The HMC will see the Managed System in a powered off state Activate the Managed System in Standby Mode Activate the Default Partition Make sure all system resources report in as operational 73 HMC GUI top-level navigation Manage HMC configuration, users, services,... Guide setup wizard and online documents Update your Licensed Internal Code Manage your servers and partitions Service tools to analyze and repair Set up security for remote GUI access 74
HMC Application GUI Menu Bar Tool Bar Content Pane Navigation Pane 75 Menu Bar - Help 76
HMC Application GUI From Server Management you manage your partitions 77 I5/OS V5R3 Logical Partitioning Interface on pre-power5 systems remains (service tools, iseries navigator) POWER5: IBM virtualization engine systems technologies include POWER Hypervisor Supports i5/os, AIX 5L* and Linux All OS/400 partitions require V5R3 Improve server utilization rates across multiple workloads Automatic processor balancing with uncapped partitions Improve fault tolerance and lower partition management costs Primary partition replaced by hardware management console (HMC) 78
LPAR Creation Wizard Default Type Partition type default is now based on system type (iseries, pseries or Linux) 79 Open a Terminal Window 80
Open a Terminal Window 81 Open a Terminal Window 82
Open a Terminal Window 83 Open a Terminal Window 84
Open a Terminal Window 85 HMC Application GUI Information Center is where you begin the setup wizard 86
HMC Application GUI From HMC Code Update you administer HMC code levels 87 HMC - Backup User preference files, user information, HMC platform-configuration files HMC log files You can save to DVD, remote system or remote site via FTP DVD media = DVD-RAM 88
HMC - Restore Restore from DVD or from remote server You must be part of superuser, operator or service rep 89 HMC - Schedule Backups 90
HMC Application GUI From Licensed Internal Code Updates you manage MS code 91 HMC Application GUI From HMC Users you manage HMC profiles and passwords 92
HMC Application GUI From HMC Configuration you manage access to your HMC 93 Enable Remote Options SSH to the HMC to do management tasks remotely HMC Management --> HMC Configuration -> Enable or Disable Remote Command Execution Remote access to LPAR virtual terminals (consoles) HMC Management --> HMC Configuration -> Enable or Disable Remote Virtual Terminal From PC: You need an SSH application like PuTTY 94
HMC Application GUI From Service Agent you manage your ET phone home 95 HMC Application GUI From Remote Support you manage SLINE access to your HMC 96
HMC Application GUI From Service Focal Point you manage your HMC hardware 97 Service and Support - options 1. Multiple partitions using the HMC to Dial out to the service provider 2. Multiple partitions using the Service Partition to contact the Service Provider via a VPN For VPN Firewall ports 500 *UDP and 4500 *UDP must be open 3. Multiple partitions using the Service Partition to contact the Service Provider via modem 98
Load WebSM Remote Client For Linux /MS Windows clients Access WebSM Remote Client application from HMC http://<hmc_hostname.domain>/remote_client.html http://<ip_addr_of_hmc>/remote_client.html Login as hscroot For WebSM Remote Client Choose InstallShield Setup.exe for Windows client wsmlinuxclient.exe for Linux client For WebSM Remote Client for Java Web Start Choose Java Web Start For AIX clients, load standard WebSM Available on Bonus Pack CD 99 WebSM Remote Client Comparison WebSM remote client: Available for Linux and Windows platforms Updates require that you uninstall the previous version and install the current version Installs via an InstallShield wizard You can select the installation loacation Installs in minutes 100
WebSM Remote Client Comparison WebSM remote client for Java Web Start: Available for Linux and Windows platforms Checks for updates every time it launches Downloads updates automatically if they are available Launches from the Java Web Start console Automatic update downloads may impact performance if you are not using a cable modem or DSL connection Requires and HTTP server 101 Getting the Client Point a web browser at the following URL http://hmchostname/remote_client.html http://<hmc_ip_addr>/remote_client.html Signon as hscroot and follow the links for either local install or java web start version and operating system (Windows or Linux). 102
HMC Remote Login via WebSM Windows WebSM icon on the desktop Type HMC s name and press Enter Wait for handshake process to finish Login 103 WebSM Logon Process 1 2 3 4 104
Almost as good as HMC GUI 105 Almost as good as HMC GUI Some tasks not performed using the remote client Determining the level of HMC code Updating the HMC code Restarting the HMC interface Configuring System Manager Security for certificate authority or viewing overview and status information 106
HMC Command Line Interface Restricted to a set of supported HMC commands Local Command Line Launched from a right-click menu option on the HMC desktop Remote Command Line Accessed through encryption-protected Secure Shell (SSH) Install SSH client on workstation Example: PuTTY ( freeware ) Command example lshwres - m managed system -r proc -- level sys 107 Using HMC Commands 108
TN5250 to create virtual terminal Be sure to use port 2300 IP address of open HMC port 109 Virtual Terminal JOHNS QINTER DSP01 LAN console that works 110
System Manager Security System Manager Security is an application on the physical HMC Used to set up SSL between HMCs and its clients Options Overview and Status Certificate Authority Define one HMC as Certificate Authority Generate keys and certificates Server Security Configure the HMC as a secure server Object Manager Security Switch between SSL to non-ssl communications (Service and Support) 111 System Manager Security Security Clent Security Server Encryption Decryption Internet Cleartext Cyphertext Cyphertext Cleartext Public Key Private Key Privacy Private Key Public Key Authentication/Non-Repudiation 112
Frame Management New function in the HMC Application GUI (HMC V4R3.2) The ability to work with hardware frames on Managed Systems Add frames Initialize frames Modify information about the frame Update frame information Resetting or removing a frame connection 113 HMC Good Practices Don t shutdown the HMC unless required You will not be able to dynamically change any resources You will not be able to log in remotely Backup the HMC Create some profiles other than hscroot & root Document all profiles and passwords Document Private Network IP addresses Check for fixes @ Fix Central (at least once a month) http://www-912.ibm.com/eserver/support/fixes/fcgui.jsp 114
Fix Central 115 Profiles & default passwords ASMI: 116
Education Ref: Web-based HMC Education Resource Link http://app-06.www.ibm.com/servers/resourcelink Password setup is required AS530 LPAR course 5 days in Rochester, MN 117 HMC Education 118
HMC Education 119 For more information: Johns@midrange.ca (905) 940-1814 (800) 668-6470 6470 120