Providing Out-of-Band Connectivity to Mission-Critical IT Resources

Home » Archives for August 2022

CIOs: Tempos difíceis estão chegando. 3 Resoluções diretivas para sobreviver ao inverno da Recessão e Lockdowns

TemposDificies

O índice da bolsa de valores Dow caiu mais de 1000 pontos nesta última sexta-feira de agosto. O mesmo efeito ocorreu em todas as bolsas de valores do mundo. Companhias como Apple, Vale, Google e Netflix reduziram o número de contratações para este ano. Para CIOs, a mensagem é clara: tempos difíceis estão chegando e a recessão poderá vir junto.

Podemos considerar que as receitas das empresas estão ligadas aos serviços digitais e à qualidade da infraestrutura de TI. Em termos simples, rede fora do ar significa queda em receita. Então, quando a economia desacelera, as contratações são reduzidas e aumenta o trabalho das equipes de TI. Os CIOs precisam descobrir como “fazer mais com menos” para manter os mesmos níveis de serviço. Na realidade, todos esperam que o TI mantenha e suporte a estrutura mesmo durante um Apocalipse Zumbi.

Hoje, líderes estão se preparando para estes desafios que estão visíveis no horizonte, sem mencionar riscos de retorno de covid, entre outros. A preocupação é a mesma: manter a rede de dados e comunicações confiáveis, seguras e operando.

Os líderes estão inseguros sobre o futuro.

A incerteza está crescendo nestes dias por conta de possíveis abalos operacionais, como os que ocorreram no início da pandemia em 2020, impulsionada por duas possibilidades:

  • Recessão, a qual os economistas estão prevendo como possível, mais do que apenas um aumento de inflação nos Estados Unidos e no mundo. Isso irá forçar os líderes a congelar contratações e serem obrigados a manter as redes de dados operando com pessoal reduzido.
  • A volta da Covid, que pode incorrer em novos lockdowns com milhões de casos em todo o mundo. Reduzindo a população ativa devido a contaminação de covid. Proporcionalmente teremos menos especialistas, técnicos de campo e de manutenção em atividade, incorrendo em quedas de serviços e queda de receita. Ao CIO perguntarão como ele planeja aumentar a receita de primeira linha, apesar da recessão, com número limitado de funcionários e dificuldade de locomoção. Isso significa que ele precisará de respostas sólidas para três perguntas críticas que surgirão em sua próxima reunião do conselho.

Três perguntas para ajudar os CIOs a sobreviverem aos “Tempos Turbulentos”.

Se eu não posso contratar, como eu posso manter o SLA de nossos serviços de TI internos e para os clientes?

A quantidade de processos e trabalho do time de TI está crescendo exponencialmente desde a mudança de centralizado (ou no escritório) para descentralizado (home office). Existe uma grande quantidade de equipamentos distribuídos por vários Data Centers e escritórios remotos, desde servidores, roteadores, gateways, sensores, infraestrutura de estruturas inteligentes, aplicações de usuários, e claro, firewalls. Além disso, estão levando conteúdo para computação de borda/edge e estruturas de redes 5G que irão necessitar de mais micro e nano datacenters que devem ser mantidos, geralmente remotamente. E com o time de TI já reduzido e carregado de atividades do dia a dia, como gerenciamento de configurações, troubleshooting e recuperação de equipamentos, ficará cada vez mais difícil e estressante receber funções e trabalhos adicionais nestes períodos.

Se o time de TI não consegue acessar fisicamente o equipamento, como manter a disponibilidade?

Como observado no início da pandemia de Covid, as companhias tiveram dificuldades para normalizar a operação das redes até conseguir habilitar todos para um trabalho remoto. Porém, muitas companhias não estavam preparadas e ainda sofrem os efeitos disso. Em um artigo reportado em 2021 sobre empresas de TI, a prioridade era permitir trabalho remoto, porém, 66% delas não estavam conseguindo suportar as atividades e o nível de serviço neste ambiente de trabalho remoto.

As empresas de TI devem estar preparadas para acomodar trabalho flexível para o futuro com qualidade, mas isso normalmente implica em ter pessoal no local, parceiros de serviços, e soluções remotas que inflam os custos operacionais. Desconsiderando lockdowns, acesso físico já é um desafio quando os equipamentos se encontram em locais remotos ou de acesso perigoso ou difícil.

Será que seremos capazes de estar em “compliance” e manter os sistemas seguros?

Muitas quebras de segurança ocorrem, não porque não existem patches ou upgrades, mas porque instalando estes patches podemos incorrer em outros problemas desconhecidos. Muitas empresas continuam rodando softwares muito antigos e sem updates de revisão. Ao mesmo tempo, esperam que estas vulnerabilidades não vão ser exploradas e acabam gerando penalidades e multas para as empresas não preparadas. Em termos gerais, os sistemas sobrevivem sem upgrades, e as vulnerabilidades aumentam com o tempo. A mudança pode trazer perigos que ninguém está disposto a correr sob o risco de não conseguir restabelecer o serviço. Este problema aumenta em caso de menor equipe on-site e acesso ou deslocamento restrito.

Grandes empresas de tecnologia conseguiram resolver este desafio.

As grandes empresas de tecnologia sempre conseguem despontar durante as crises e emergir mais fortes. Como? Porque elas compreendem que precisam dar poderes as áreas de TI para se prepararem para estes desafios que sempre ocorrem. De acordo com o Gartner, o melhor jeito de se preparar é investindo na transformação digital do ambiente de trabalho. Mas o que quer dizer exatamente isso? Como CIO, você tem uma grande distribuição de equipe para abraçar toda a infraestrutura. Com isso, fica difícil definir os passos estratégicos e táticos. Respondendo as três questões abaixo, seu time de TI saberá como conseguir se preparar.

O Grande Segredo das Grandes: Plano para Automação de Rede.

Muito melhor do que tentar descobrir ou inventar a sua própria estratégia de resiliência, existe um modelo que as grandes empresas de tecnologia usam durante os períodos recessivos. Ele é composto de duas soluções que podem ser combinadas inteligentemente, que incluem:

  • Um nível de orquestração da rede de dados, que serve como meio de automação básico, intermediário e entreprise das tarefas de TI.
  • Um nível de automação de infraestrutura, que permite aos engenheiros de suporte executarem remotamente gerência e serviços de automação que normalmente requerem presença física no site.

Existem mais de 10 componentes de automação e orquestração requeridos para efetivamente implementar esta modelagem da automação de rede. Mas os times de TI já estão acostumados com estes modelos e processos. Isso inclui atividades como controle de versão de sistemas, orquestração, pre-stagging de servidores, conectividade out of band e controle de alimentação de energia, entre outros.

Mas a parte mais importante está na modelagem, respondendo a três questões que vão aparecer durante as reuniões de diretoria, e definem exatamente como atingir a resiliência e confiabilidade da rede.

Se eu precisar congelar as contratações, conseguiremos manter os serviços de TI confiáveis?

Resposta: Nível de Orquestração – Isso é fundamental para reduzir as atividades manuais de TI, mas a maioria das companhias está relutante em usar automação porque eles não têm as ferramentas apropriadas que podem ajudá-los em se recuperar em caso de erros catastróficos. A chave para isso é possuir o nível de orquestração colocado no topo do nível de automação de infraestrutura.

Isso irá ajudar a diminuir o trabalho do time de TI e servir como um gatilho de segurança contra erros de automação.

Se TI não consegue acessar o equipamento fisicamente, como manter a disponibilidade?

Resposta: Nível de Automação de Infraestrutura – Gerência fora da banda IP (Out-of-band /OOB) é um componente crucial deste nível. OOB não é uma tecnologia nova, porém disponibiliza serviços permitindo aos engenheiros de TI terem uma completa presença virtual muito além do padrão de acesso na porta serial. As novas funcionalidades do OOB são detalhadas no modelamento, e incluem acesso adicional 4G/5G ou WIFI, com QoS & SD-WAN, múltiplos tipos de interfaces para se conectar em todos os equipamentos dos sites, e controlar logicamente as portas de alimentação permitindo executar um ciclo remoto desliga/liga.

Seremos capazes de estar em “compliance” e manter as atualizações de segurança em dia?

Resposta: Níveis de Infraestrutura de Orquestração e Automação trabalhando juntos para atingir as necessidades, automaticamente instalando updates de segurança e patches em toda a infraestrutura de redes.

Fazendo isso, garante que o time de TI possa verificar as configurações antes e depois delas serem implementadas, sem precisar de pessoal no local. Com os scripts e controles de alimentação OOB os engenheiros podem fazer o update de SW dos equipamentos remotamente para manter o “compliance”, mesmo em arquiteturas de rede distribuídas. Performando esta função via Out of Band (OOB), remove-se a ansiedade em se usar automação, pois patches com comportamentos estranhos podem ser desinstalados e trazer a infraestrutura ao estado online anterior.

Blueprint

Inscreva-se para receber este Plano.

Grandes companhias de tecnologia usam e provaram que este modelo é efetivo. Nós, da ZPE Systems, estamos customizando este documento com nossa engenharia para que você consiga explorar todos os componentes, junto com os diagramas de referência de implementações reais que ajudaram grandes companhias durante os períodos de crise.

Inscreva-se e receba este documento.

Data Center Orchestration with Gen 3 OOB for Digital Services Providers

ata center orchestration
Large digital service providers face some unique data center and network management challenges. Customers and shareholders expect 24/7, high-speed access to these services from anywhere in the world. The scale and complexity of their infrastructure, combined with their highly distributed, global network architectures, can make it difficult for administrators to meet those expectations. In this article, we’ll discuss how data center orchestration with Gen 3 out-of-band (OOB) management helps digital service providers achieve the reliability their customers demand while reducing expenses and complexity.

Use case: Data center orchestration with Gen 3 out-of-band for digital service providers

The businesses in this use case provide digital services at a very large scale. They need to ensure constant availability and reliability because that’s what their customers expect, and it’s what their competitors promise. Some examples of large digital service providers include:

   Music or video streaming services
   Stock trading applications
   Online banking portals
   Cloud compute services
   SASE and SSE vendors
   Internet service providers (ISPs) and telecom companies
   Internet exchanges
   Storage as a Service providers

These companies typically host their resources in private data centers or colocation facilities, so they have total control over the hardware and infrastructure. Because of the extremely large scale of their operations, they need to deploy, maintain, and administer many machines. And, since they typically provide global services, they have a large, complex, and highly-distributed network architecture.

There are several major pain points for network administrators in this environment. First, they need to maintain constant access to remote infrastructure, even during network outages. Second, they need the ability to scale up their infrastructure on-demand by quickly deploying new machines with the correct configurations. Finally, they need to be able to monitor, manage, and optimize their complex network architectures.

Let’s look at how these pain points are solved using data center orchestration with Gen 3 OOB.

1. Constant availability

People expect 100% uptime from their digital services, which is why it’s always major news when a big provider like Netflix goes down. To try and achieve constant availability, these vendors typically use their own hardware in private data centers and colocation facilities rather than relying on public cloud hosting. They host their infrastructure in many different facilities around the world, both for redundancy and to ensure peak performance for globally distributed customers.

Between hiring freezes and staff cuts at major companies like Apple, Google, and Netflix, many of these companies don’t have enough technical staff to maintain a physical presence in all of these data centers. Instead, their administrators and engineers access this infrastructure remotely, using tools like serial consoles, KVM switches, and jump boxes to connect to devices in the rack. However, if they lose network access to the management device due to an ISP outage, hardware failure, or configuration mistake, they’re left without a way to remotely recover. That means they need to either dispatch a technician from their home office or pay for costly on-site managed services from their hosting facility. Either way, valuable time and money are wasted on travel and other logistics.

Out-of-band management solves this problem by providing an alternative path to remote network infrastructure. Data center orchestration solutions with Gen 3 OOB use a secondary network connection (typically a cellular modem) that is dedicated to management and troubleshooting. That means administrators can configure, troubleshoot, and orchestrate remote infrastructure even when the primary network connection is offline or overloaded with production traffic. This gives digital service providers the ability to recover from outages and other issues much faster, bringing them closer to their goal of 24/7 availability.

2. Scalability

Large digital service providers need to serve millions of customers who may live all over the globe. They also need to meet sudden spikes in demand without limiting the performance of their product. That means they need to deploy lots of machines to many different facilities, often very quickly. Plus, they need to do so without configuration mistakes, as these could delay deployment, create security vulnerabilities, or even require a truck-roll to fix.

Since deployments need to happen quickly, accurately, and repeatedly, that makes them a prime candidate for automation. There are two primary technologies used to automate data center deployments: zero touch provisioning (ZTP) and Infrastructure as Code (IaC). A Gen 3 OOB data center orchestration tool enables both.

Zero touch provisioning gives administrators the ability to deploy device configurations to remote hardware over a network connection. Earlier generations of OOB data center solutions often included ZTP for devices within a specific vendor’s ecosystem, but Gen 3 tools are vendor-agnostic. That means administrators can remotely deploy an entire data center of mixed-vendor solutions without risking security breaches and the potential for opening a backdoor through pre-staging or on-site configuration. Plus, Gen 3 OOB provides a dedicated network to use in the provisioning process, so if there’s an issue with the configuration that takes the new device offline, administrators can still remotely recover.

IaC decouples a device’s configuration from the underlying hardware, turning it into software code that’s executed according to programmatic playbooks. Gen 3 OOB data center orchestration solutions support automation through IaC, either by integrating with third-party IaC platforms or by directly hosting playbooks. This allows administrators to apply DevOps best practices to infrastructure configurations, for example running automated tests to verify the quality and security of the code before deployment. IaC also reduces the time and complexity involved in configuring new devices, because scripts are easily reusable and can be deployed as many times as needed.

Through automation technologies like ZTP and IaC, Gen 3 OOB data center orchestration platforms allow digital service providers to scale their infrastructure quickly and efficiently. Automation also reduces the risk of human error, which reduces the chances that rapid scaling will cause service interruptions.

3. Network complexity

Large digital service providers have complex and distributed network architectures. They may have dozens or even hundreds of remote sites connected to the WAN, each of which may have different vendor hardware, bandwidth requirements, and security risks. Plus, there are many thousands of users accessing those resources from all over the world. In this kind of environment, manual network management is too time-consuming and prone to error.

Once again, automation is key to overcoming this challenge. Network automation is enabled in much the same way as infrastructure automation—by implementing software abstraction to decouple the management plane from the underlying hardware. This is known as software-defined networking (SDN) or, in the case of WAN architectures, software-defined wide area networking (SD-WAN). Digital service providers use SD-WAN to virtualize their distributed networks, employing software network controllers and APIs to route and load-balance traffic.

The right data center orchestration solution centralizes management of the entire SD-WAN architecture, giving administrators a single pane of glass from which to monitor and control the virtual network. Gen 3 OOB platforms are vendor-neutral, which means they can dig their hooks into all of the various hardware and software solutions that make up an SD-WAN infrastructure. They enable end-to-end automation of network management workflows and provide orchestration capabilities to automate the deployment and execution of those automated workflows. This makes it possible for digital service providers to manage their highly complex network architectures efficiently while maintaining optimal performance.

Gen 3 OOB data center orchestration with Nodegrid

The need for constant availability, easy scalability, and efficient network management is what brings many major digital service providers to ZPE Systems. The Nodegrid data center orchestration platform is the first Gen 3 out-of-band solution that enables end-to-end automation and complete vendor freedom.

The Nodegrid Serial Console Plus (NSCP) is a high-density serial console for large-scale and hyperscale data centers and includes features such as 5G/4G LTE cellular OOB and network failover to ensure 24/7 remote access. Built on the open, Linux-based Nodegrid OS, the NSCP supports integrations with your choice of third-party solutions, or you can directly host your automation, security, and SD-WAN applications on the device itself. Plus, the ZPE Cloud management software provides a centralized, web-based orchestration platform from which to deploy, monitor, and control your entire network architecture.

ZPE is here to help!

Still want to learn more about the Nodegrid Gen 3 data center orchestration platform for large digital service providers?

Contact Us

CIOs: 3 Boardroom Questions to Survive Winter Recession & Lockdowns

Winter is Approaching
The Dow recently posted decreases of 1,300 and 1,000 points within weeks of each other. Companies including Apple, Google, and Netflix have slowed hiring this year or outright cut staff. For CIOs, the message is clear: Winter is coming, and so is a recession.

We all know that company revenue is directly tied to IT infrastructure and the digital services it provides. In the simplest terms: network down, revenue down. So when economic downturns lead to hiring freezes and increasing workloads for IT, CIOs need to figure out how to ‘do more with less’ in order to maintain service levels. The reality is that we’d still expect IT to fulfill our support tickets even during the zombie apocalypse.

Today, business leaders are gearing up for the possibility of such challenges looming larger on the horizon, not to mention the potential for more covid lockdowns and other disruptions. No matter the reason, the expectation remains the same – keep networks reliable and secure.

Business leaders are uncertain about the coming winter

Business leaders are growing uncertain about the coming winter months because of the potential for more major operational shakeups, like those that occurred at the start of the coronavirus pandemic in 2020. This uncertainty stems from two looming possibilities:

As CIO, your peers will ask how you plan to increase top line revenue despite the winter recession, limited staff numbers, and potential lockdowns. This means you’ll need solid answers to three critical questions that will come up at your next board meeting.

3 Questions to Help CIOs Survive the Winter Recession

If we need to freeze hiring, can we continue to fulfill SLAs for internal & external digital services?

The IT workload has grown exponentially since infrastructure moved from centralized to decentralized. There’s just too much infrastructure scattered in so many data centers, colocations, and branch offices — from servers and routers, to branch gateways, remote sensors, smart building infrastructure, user experience monitoring applications, and firewalls. On top of this, pushing workloads to edge compute and 5G will inevitably lead to more micro and nano data centers that need to be maintained. Your IT teams are already struggling to keep up with everyday operations like configuration management, troubleshooting, and recovering down equipment. Now imagine how much stress they’ll endure if they’re unable to get additional help due to hiring freezes or pandemic lockdowns.

If staff can no longer physically access equipment, can we maintain IT availability?

As we saw at the beginning of the Covid pandemic, companies scrambled to find ways to accommodate normal operations while shifting staff to a fully digital workplace. But many companies were unprepared and are still struggling to adapt. In fact in 2021, IT organizations reported that their highest priority was to improve digital work for employees, but 66% said they didn’t have the capabilities to support the needs of remote and hybrid work. IT organizations must be prepared to accommodate flexible work well into the future, but this typically means employing a mix of local smart hands, third party service providers, and remote management solutions that significantly inflate operating costs. Despite any potential lockdowns, physical access can already be challenging when equipment resides at remote locations that are costly, inconvenient, or downright dangerous to access.

Will we be able to stay in compliance and keep up with security patches?

Many security breaches occur not because patches don’t exist, but because installing these patches might lead to unforeseen breakages. Some IT teams still run software that’s years old and several major revisions outdated. Meanwhile, these teams can only hope that vulnerabilities won’t be exploited and lead to business incurring regulatory fines or penalties. In a nutshell, systems go unpatched and grow more vulnerable as time goes on, because teams are afraid to risk breakages that they can’t easily recover from. This problem will only worsen when hiring is put on hold and physical site access is restricted.

Big tech has it figured out

Big tech companies have thrived on recessions and often come out stronger. How? Because they understand that they must empower their IT organizations during economic downturn. According to Gartner, there’s no better way to do this than to invest in digital transformation. But exactly what digital investments do these companies make? As CIO, you have such a large and distributed IT organization to wrap your arms around, that it’s difficult to define the practical steps you need to take. When answering these three key questions, your IT and executive teams will need to know: “How do you plan to accomplish this?”

Use big tech’s secret: The Network Automation Blueprint 

The network automation blueprint is made up of four major building blocks that create a management network design pattern to accommodate hyperautomation. These building blocks are:

  • IT/OT production infrastructure: This includes servers, switches, routers, and common production equipment.
  • Automation infrastructure: This is a truly independent network that enables automation to reach the production infrastructure in an out-of-band fashion.  Customers call this the double-ring network. This layer often uses a combination of serial console and Ethernet connections, and also includes staging jump boxes, local storage, TFTP source of truth, and version control systems.
  • Orchestration and automation systems: This is where the desired outcome and playbooks are sourced from. The key is that the orchestration reaches the production systems through the independent out-of-band network to achieve the desired outcome.
  • AI Ops infrastructure: This layer receives rich information from observability platforms to make reactive and predictive decisions at scale. Using machine learning and artificial intelligence, this layer learns the network’s normal behaviors and pushes changes through the orchestration and automation layer.

This blueprint is the reference architecture validated to successfully implement Gartner’s definition of hyperautomation, as well as meet the Open Networking User Group (ONUG) Orchestration and Automation recommendations. This blueprint gives you the necessary layers to confidently answer the three questions that will come up during your boardroom meeting, and outlines the practical steps required to achieve IT resilience. Here’s how it answers these questions:

If we need to freeze hiring, can we continue providing reliable IT services?

By separating the automation infrastructure from the production network, teams can build hyperautomated environments while having a safe way to recover from errors. Despite having limited staff and/or a virtual workforce, teams can develop their automation pipelines to reduce workloads and meet SLAs.

If staff can no longer physically access equipment, can we maintain IT availability?

With the network automation blueprint, teams get a management network design pattern that ties into all of their solutions. This means they get a full virtual presence to manage SD-WAN, firewalls, switches, servers, routers, and their entire stack. The blueprint also calls for running automation locally so workloads can be carried out despite connectivity problems. These allow teams to maintain their sites and availability across distributed architectures.

Will we be able to stay in compliance and keep up with security patches?

Automating via out-of-band means teams no longer need anxiety about the dreaded Friday night upgrade. Instead of running outdated software and configurations because “if it ain’t broke, don’t fix it,” teams can ensure the integrity of updates before pushing them live. This allows them to take advantage of the latest software releases, close security gaps, and maintain compliance.

Meeting customer expectations for always-on digital services is a major challenge for any enterprise. That’s why it’s important for CIOs to empower their teams with hyperautomation and automate as many processes as possible. The network automation blueprint gives you the reference architecture that’s been validated by big tech as the safe way to build hyperautomated environments. This blueprint is now available just in time to help organizations prepare for the looming winter recession.

Blueprint

Get the Network Automation Blueprint now

Now is the time to prepare for winter, and you can start laying the groundwork for hyperautomation. Click the button below to download the network automation blueprint. You’ll see the same network architecture used by Big Tech, now tailored to help any size company provide reliable digital services.

 

Opengear CM7100 Alternative Options

Opengear CM Alternative Options

The Opengear CM series console servers provide out-of-band (OOB) management of data center infrastructure so that network administrators can access and control remote equipment from one centralized interface. Like other OOB serial consoles, the CM series gives admins an alternative path to remote infrastructure that doesn’t rely on the production LAN, WAN, or ISP network.

The CM7100 series is EOL as of the 31st of March, 2023, with an end-of-sale date of the 30th of September 2023 – click here to see a full list of affected product SKUs.

Opengear’s recommended replacement is the CM8100. Like the 7100, this is a traditional console server solution, which means it has gaps in its OOB capabilities due to vendor lock-in, limited automation support, and a lack of hardware security.

In this blog, we’ll discuss Opengear’s replacement solution as well as Opengear alternatives that deliver greater availability, functionality, and security.

Disclaimer: This comparison was written by a 3rd party in collaboration with ZPE Systems using data gathered from publicly available data sheets and admin guides, as of 4/28/2023.

Please email us if you have corrections or edits, or want to review additional attributes: Matrix@zpesystems.com

Table of Contents

Opengear CM7100 overview

The Opengear CM7100 is a line of OOB console servers for data centers and large enterprise deployments. The CM7100 comes with 16, 32, 48, or 96 managed RJ45 serial ports and dual USB 2.0 managed console ports. OOB management and network failover are provided via dual LAN ports or dual LAN/SFP ports.

The CM7100 is primarily used in data center deployments to provide centralized remote control and OOB access. With the CM7100 now EOL, Opengear recommends migrating to the CM8100 series. Let’s take a look at the features, specifications, and limitations of the Opengear CM8100 before discussing some alternative options.

Looking for replacement options for other discontinued serial consoles and branch routers? Try:

 

Opengear replacement options: CM8100

The CM8100 is Opengear’s newest console server for large data center and enterprise deployments. The CM8100 comes with 16, 32, or 48 managed serial ports and 2 managed USB ports in a 1RU form factor, or up to 96 ports in 2RU. Like the other CM models, the 8100 does not come with cellular or WI-Fi options, so it provides OOB and failover on dual Ethernet/SFP interfaces.

All CM models use Opengear’s Smart OOBTM, which includes automatic port discovery and VLAN support. However, the CM series does not support cellular access for OOB or failover. Further automation capabilities include zero-touch provisioning (ZTP), Opengear NetOps modules, and support for Ruby, Perl, and Bash.

On the security side, the CM8100 offers IPSec & OpenVPN, Secure Shell (SSHv2), Trusted Platform Module 2.0 (TPM 2.0), and advanced authentication via TACACS+, Kerberos, RADIUS, and more. However, none of the CM models support SAML 2.0, which makes it difficult to implement Zero Trust principles on the OOB management network.

Opengear CM8100 Features & Tech Specs

Notable Serial Console Features

• SSH direct to consoles

• Keystroke logging

• Multiple concurrent sessions

• Automatic device name discovery

OOB Managed Interfaces

• 16, 32, 48 ports (1RU)

• 96 ports (2RU)

Hardware

• 1.6 GHz Dual-Core ARM Cortex-A9 SoC CPU

• Dual Ethernet for OOB/Failover

Automation

• Opengear NetOps modules

• API access

• Docker support

• Python

• Perl and bash support

• ZTP

• SNMP-Standard MIBs

Automation for End Devices

ZTP

Guest OS

• Docker support

Power Management

• Control PDU outlets via serial, USB, and Ethernet

• Supports 100+ power vendors’ equipment

Hardware Security

• TPM 2.0

• Embedded firewall

Form Factor

Fixed 1RU or 2RU

Opengear CM limitations

While the CM8100 offers some improvements over the CM7100, it still falls short of delivering Gen 3 OOB console server functionality in the following ways.

The Opengear CM solution suffers from:

OOB inflexibility

While the CM7100 and CM8100 both provide OOB management access and network failover, they’re only available via dual Ethernet/SFP interfaces. None of the CM-series console servers come with options for cellular, Wi-Fi, or dial-up modem access. That means something like a regional network outage or data center LAN issue could potentially cut off access to both the OOB and production network.

Vendor lock-in

The Linux-based OS is programmable and extensible, but Opengear’s Lighthouse management software is not truly vendor-neutral. That means your hardware and software integration capabilities will be limited to specific supported solutions. For enterprises with hybrid, distributed, and multi-vendor infrastructures, this limitation could leave gaps in management and orchestration coverage. 

Limited automation

The CM8100 offers more automation capabilities than the 7100, but there are still limitations. For example, Lighthouse is required for ZTP and other automation capabilities, but it only extends to certain supported end-devices, which means you’ll need to manually configure, provision, and deploy the rest of your infrastructure–or stay within Opengear’s ecosystem, which limits your vendor freedom.

Lack of security

Opengear added embedded TPM 2.0 security to the new CM8100 line to make the hardware more secure. However, the CM series does not include additional hardware security like geofencing, BIOS protection, or UEFI secure boot. This increases the risk that a stolen or compromised console server could be used to provide cybercriminals with unrestricted access to your OOB management network.

Both the Opengear CM7100 and CM8100 are 2nd generation serial console servers. That means they provide OOB management access as well as some automation functionality to simplify individual network management workflows. However, due to a lack of alternative OOB/failover interfaces, vendor lock-in, limited automation integrations, and minimal hardware security, the CM series falls short of the end-to-end automation and security required for a Gen 3 OOB solution.

CM7100 migration options from ZPE Systems

The Nodegrid solution from ZPE Systems is the world’s first Gen 3 OOB management platform. With a wide range of serial console servers and integrated branch services routers to choose from, three models in particular serve as direct replacements for the EOL Opengear CM7100: the Nodegrid Serial Console Plus (NSCP), the Nodegrid Serial Console S Series, and the Nodegrid Net Services Router (NSR).

Nodegrid Serial Console Plus (NSCP)

The high-density Nodegrid Serial Console Plus comes in 16, 32, 48, and 96 serial RJ45 port configurations as well as providing 2 USB 3.0 ports for a total of 98 managed devices on a single 1RU device. That makes the NSCP a direct replacement for 96-port CM7100 devices – to get the same number of ports on the CM8100, you’ll need a 2RU device that uses more rack space.

Nodegrid Serial Console S Series

The Nodegrid S series, which comes in 16, 32, or 48-port configurations, uses auto-sensing ports to provide seamless management of modern, legacy, and mixed-vendor infrastructure. The S Series serial console switch is the perfect legacy modernization solution because it allows you to extend automation to end devices that otherwise wouldn’t support it.

Nodegrid Net Services Router (NSR)

The Nodegrid Net Services Router is an all-in-one branch network solution that delivers out-of-band management, SD-WAN capabilities, and more in a single box. The NSR has a modular design so you can add extra terminal server capabilities, more storage or processing power, or extra GbE Ethernet ports to create a completely customized solution.

All Nodegrid boxes deliver OOB access and network failover via built-in 5G/4G LTE cellular and Wi-Fi, so you get 24/7 availability even during LAN and ISP outages. These devices run the open, Linux-based Nodegrid OS with full support for integrated NetDevOps automation solutions like Ansible, Chef, Docker, and Puppet. Nodegrid provides a separate control plane for OOB and automation, making it the ideal solution for a wide variety of business use cases, including

  • Extending automation to any environment or device
  • Enabling Zero Trust Network Access (ZTNA)
  • Increasing OOB & failover flexibility
  • Helping organizations become AI-ready

In addition, the vendor-neutral, web-based ZPE Cloud orchestration solution can dig its hooks into any Nodegrid-connected infrastructure, regardless of vendor, location, or private cloud provider. This gives you a single pane of glass from which to monitor and manage your on-premises, remote, and/or cloud-based infrastructure. Nodegrid’s vendor-agnostic platform enables true end-to-end automation and hyperautomation of enterprise networks.

Plus, Nodegrid includes robust hardware security features like BIOS protection, TPM 2.0, geofencing, and UEFI Secure Boot. The embedded, stateful firewall provides functionality such as multi-site IPSec VPN, advanced authentication, selectable cryptographic protocols and cyber suite levels, and Zero Trust 2FA and SAML 2.0.

 

Nodegrid NSCP

Nodegrid S Series

Nodegrid NSR

Notable Serial Console Features

• SSH direct to consoles

• Keystroke logging

• Logging to ZPE Cloud, NFS, Local

• Alert on cable disconnects

• Text pattern match with scriptable actions

• Multiple concurrent sessions

• Automatic device name discovery

• Session sharing for collaboration

• IP address per serial port

• Secure session logout enforcement

• Power control hotkey on serial port

• Configurable icon per serial port

• SSH direct to consoles

• Keystroke logging

• Logging to ZPE Cloud, NFS, Local

• Alert on cable disconnects

• Text pattern match with scriptable actions

• Multiple concurrent sessions

• Automatic device name discovery

• Session sharing for collaboration

• IP address per serial port

• Secure session logout enforcement

• Power control hotkey on serial port

• Configurable icon per serial port

• SSH direct to consoles

• Keystroke logging

• Logging to ZPE Cloud, NFS, Local

• Alert on cable disconnects

• Text pattern match with scriptable actions

• Multiple concurrent sessions

• Automatic device name discovery

• Session sharing for collaboration

• IP address per serial port

• Secure session logout enforcement

• Power control hotkey on serial port

• Configurable icon per serial port

OOB Managed Interfaces

• 16, 32, 48, 96 ports (1RU)

• 16, 32, 48 ports

• Up to 5 x 16-port RJ-45 Serial modules

Hardware

• Intel X86, 64-bit CPU optimized for running VMs and automation tools

• Dual-SIM 5G/4G/LTE, Wi-Fi, and V.02 modem for OOB/Failover

• Intel X86, 64-bit CPU optimized for running VMs and automation tools

• Dual-SIM 5G/4G/LTE, Wi-Fi, and V.02 modem for OOB/Failover

• Intel X86, 64-bit CPU optimized for running VMs and automation tools

• Dual-SIM 5G/4G/LTE, Wi-Fi, and V.02 modem for OOB/Failover

Automation

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

Automation for End Devices

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

• ZPE Cloud

• Chef

• Docker

• Puppet

• Python

• Ruby

• ShellScript

• Node.js JavaScript

• Redhat Ansible

• KVM Hypervisor

Guest OS

• VMs, Docker, Kubernetes, LXC

• VMs, Docker, Kubernetes, LXC

• VMs, Docker, Kubernetes, LXC

Power Management

• Supports major power strips manufacturers

• Power management integrated with serial session (escape sequence in the serial session or power buttons in web serial session)

• Power control of VMs

• Access rights for users & user groups

• Supports major power strips manufacturers

• Power management integrated with serial session (escape sequence in the serial session or power buttons in web serial session)

• Power control of VMs

• Access rights for users & user groups

• Supports major power strips manufacturers

• Power management integrated with serial session (escape sequence in the serial session or power buttons in web serial session)

• Power control of VMs

• Access rights for users & user groups

Hardware Security

• TPM 2.0

• Encrypted solid-state disk

• UEFI BIOS with protection

• Secure Boot (signed OS

• Geofencing

• TPM 2.0

• Encrypted solid-state disk

• UEFI BIOS with protection

• Secure Boot (signed OS

• Geofencing

• TPM 2.0

• Encrypted solid-state disk

• UEFI BIOS with protection

• Secure Boot (signed OS

• Geofencing

Form Factor

Fixed 1RU

Fixed 1RU

Modular 1RU

The Nodegrid Gen 3 OOB solution is an Opengear alternative that delivers 24/7 availability, end-to-end automation, Zero Trust Security, and complete vendor freedom.

Watch a free Nodegrid demo to see a Gen 3 OOB serial console solution in action. Watch Now

Opengear CM7100 migration SKUs:

Opengear CM7100 EOL SKU

In Scope Features

ZPE Replacement Product

CM7116-2-SAC

CM7116-2-DAC

16 Serial ports, OOB management

Fixed Form Factor:

ZPE-NSCP-T16R-STND-SAC

ZPE-NSC-T16S-STND-SAC

ZPE-NSCP-T16R-STND-DAC

ZPE-NSC-T16S-STND-DAC

Modular Form Factor:

ZPE-NSR-816-DAC with 1 x 16 port serial module 1 x ZPE-NSR-16SRL-EXPN

CM7132-2-DAC

32 Serial ports, OOB management

Fixed Form Factor:

ZPE-NSCP-T32R-STND-DAC

ZPE-NSC-T32S-STND-DAC

Modular Form Factor:

ZPE-NSR-816-DAC with 2 x 16 port serial module 2 x ZPE-NSR-16SRL-EXPN

CM7148-2-SAC

CM7148-2-DAC

48 Serial ports, OOB management

Fixed Form Factor:

ZPE-NSCP-T48R-STND-SAC

ZPE-NSC-T48S-STND-SAC

ZPE-NSCP-T48R-STND-DAC

ZPE-NSC-T48S-STND-DAC

Modular Form Factor:

ZPE-NSR-816-DAC with 3 x 16 port serial module 3 x ZPE-NSR-16SRL-EXPN

CM7196A-2-DAC

96 Serial ports, OOB management

ZPE-NSCP-T96R-STND-DAC

Ready to replace your EOL Opengear CM7100 with a Gen 3 out-of-band serial console solution?

Call ZPE Systems today at 1-844-4ZPE-SYS for a special trade-in promotion. Contact US

ZPE Cloud – Silver Peak and Palo Alto Networks Edge Deployment

Want to know how to set up a Silver Peak appliance and Palo Alto Networks firewall? In our latest video, Director of Solution Engineering Rene Neumann walks you through how to easily create an edge platform using the Nodegrid Gate SR and ZPE Cloud.

This hardware and cloud platform gives you:

SD-WAN capabilities, allowing you to simultaneously connect to Ethernet, fiber, and cellular
Enterprise-class firewall, allowing you to secure all traffic into and out of your edge site

These Silver Peak and Palo Alto templates are available to all customers, and make it easy to deploy and configure virtual machines necessary for edge sites.

Get a hands-on demo

Want to see how easy this is to deploy in your environment? Click the button below to set up a one-on-one demo with Rene himself.