Providing Out-of-Band Connectivity to Mission-Critical IT Resources

Free Yourself from Vendor Lock-in!

Back in the early and mid-2000’s the race was on to implement an out-of-band infrastructure (OOBI) to provide access and control to all your IT assets in the data center via a separate management network. Isolating device management to a separate management network was, and still is a great practice. Having the ability to remotely connect to a device in the data center via an isolated network, allows users to perform various tasks such as Reboot, Power off, Power on, run a specific script, provision, test, etc. of specific devices, without impacting the production network processing. Another benefit (among many) is being able to connect to a failed production network device and bring it back in service via remote access and management. Reduces recovery time. Minutes can mean millions when it comes to a production IT outage. The faster you can respond, the less it costs.

Currently, and some 10 years ago, implementing an OOBI required various hardware appliances to be installed in your network to provide access to the device. Serial Console Servers, KVM/IP Switches, Intelligent and Controllable Rack PDU’s, etc… which you need to purchase and install in your data center. 1000’s of dollars were, and still are being spent on the purchase and implementation of these appliances. Why? Because that’s how you do it. Buy more management appliances and add them to your existing infrastructure as you grow. In an attempt to keep up with new technologies like Service Processors (IPMI, ILO, Drac, CIMC, etc) and the explosion of Virtualization, the manufactures have addressed this by creating another appliance for you to buy, add to your rack and network, just to facilitate the access and control to the Service processors and Virtual Machines. These solutions also require periodic updates or upgrades to the vendor specific management software, which was developed (for what was available at the time) over 10 years ago, and based on the use of appliances (sell you more hardware). Not what’s available now.

 

 

 

 

 

 

 

 

Today, Virtualization and Service processors are aggressively being adopted in data centers. This greatly reduces the need for expensive, rack cluttering, and heat generating KVM/IP Switches, and perhaps, in some cases, reduced the need for expensive rack PDU’s. Quite a cost savings. But still not enough. Most all OOBI management solutions require additional hardware appliances in order to consolidate and provide access to the Service Processor or Virtual Machine infrastructure. Again, this method of implementing an OOBI came about 10 years ago and required hardware components (KVM/IP, Serial Console, Intelligent Rack PDU’s, Service Processor, and virtual Machine consolidators) in order for it work. And let’s not forget the vendor specific management tools that are useless without the presence of vendor specific appliances and don’t integrate with equivalent competitor products. For example, Console Servers from different vendors. As a result, you, the users are locked in to a specific vendor technology and method of OOBI management. To frame this differently, suppose your company purchases a company which standardized on an OOBI from vendor A. You’re standardized on vendor B. How do you handle this? Maintain both solutions until you can replace one with the other. Buy more hardware from your preferred OOBI manufacturer to replace the hardware from the other manufacturer. Either way, it’s costly and locking you into a specific vendor OOBI technology and method.

So, what can you do? Continue to expand your OOBI infrastructure from a specific vendor with outdated methods and solutions, OR, you could implement a vendor neutral OOBI software-only management solution that provides the same, if not better, secure access and control to devices from both Vendor A and B without having to add additional hardware appliances. Now you can have OOB connectivity and management of your Physical and Virtual infrastructures as it grows, and expands via whatever vendor/s products you decide to use. In fact, you could use a combination of Vendor A, B, C, and D’s OOB appliances to rebuild a best of breed OOBI. Let Freedom Ring. No more OOBI vendor lock-in.

From the team that gave us the Linux Break Safe Console Server, Managed Rack PDU’s, and put IPMI in Service processors, comes the world’s first Software-Only, Vendor Neutral Access and Control solution for the management of both Physical and Virtual (VMware and Kernel Virtualization) IT device Infrastructures, regardless of manufacturer. “NodeGrid Manager” is the first software-only solution for Access and Control that doesn’t require any additional hardware components to provide access and control to your existing OOBI, regardless of manufacturer. NodeGrid Manager’s agnostic approach to device management allows you to take advantage of your existing hardware OOBI without regard for manufacturer, or the addition of expensive KVM/IP, or service processor and virtual machine consolidator hardware appliances. As a byproduct, NodeGrid Manager frees you from vendor lock-in. NodeGrid provides the same user experience regardless of device and manufacturer via a common UI and standardized feature and command stack across the entire infrastructure. User experience is the same for Server, Storage, Network, Power, and Virtual Machine (VMware and Kernel Virtualization) infrastructure regardless of manufacturer.

If it hasn’t already happened, there will come a time when your existing OOBI starts letting you down. When that happens, turn to ZPE Systems NodeGrid Manager for relief. NodeGrid Manager Delivers a true vendor-neutral experience in OOBI management. Oh, and did we mention you don’t have to add expensive vendor specific proprietary appliances to manage your physical and virtual IT infrastructure.

 

 

Free your OOBI now from vendor lock-in. Stay ahead of technology changes and growth with NodeGrid Manager. The world’s first, Software-Only, Vendor-Neutral Access and Control Solution for both Physical and Virtual IT Infrastructures, that simply and easily works, and scales to meet your needs.

See for yourself.

The fastest way to learn more – Email us at sales@zpesystems.com (or call +1 510 298 3022) to schedule a chat or request a demo.

The Future of IT Infrastructure Management is Here

ZPE Systems – The Future of IT Infrastructure Management

You might not know us, but you do.

We designed and engineered OOBI appliances that are deployed in the world’s largest data centers. We are a group of technologists with more than 100+ years of cumulative experience in the remote console management business, with many patents granted. Now we’re putting our century of experience to work to make your job even easier. Welcome to the simpler, faster, more cost effective software-defined future of IT Infrastructure Management.

Did you know that the team who brought you the world’s first Linux Break safe Console Servers, coded the firmware for Rack PDUs and put IPMI inside of big name servers, is now delivering a Vendor Neutral software solution to access and control both Physical and Virtual IT assets? It’s true.

NodeGrid Manager is the industry’s first and only pure software solution on the market today that allows you to access and control Servers, Networks, Storage, Virtual Machines, Rack PDUs, UPSs and more from a single interface without the addition of any hardware appliances, while taking advantage of your existing infrastructure.

NodeGrid customers are reducing the number of management tools they need to buy, learn, use, and maintain. You too can save time responding to outages faster, helping to improve service levels. Save money on training and maintenance costs associated with vendor specific management tools. These are just a few of the many benefits NodeGrid provides. NodeGrid takes advantage of your existing access and control hardware and supplements data center visualization and monitoring tools.

Ready to take your infrastructure management to the next level? Schedule a live online demo of NodeGrid to learn how we’re changing the way physical and virtual infrastructures can, and should be managed, now and in the future.

Thanks in advance for joining us on this exciting journey into the future of software-defined infrastructure. We look forward to hearing from you.

Avoid Future ShellShock Type Attacks

ShellShock UNIX Bash Bug – Introduction

You’ve heard about the ShellShock Unix Bash “ghost user” exploit at least 13 times by now. This discovery of a hurtful secret within a deep, trusted friendship (ubiquitous reliance upon generally stable Open Source software) reminds us that IT Security is like any long-term relationship – constantly evolving.

Did you and your colleagues have a fire drill this week reacting to the ShellShock news? If it felt like one over the past week, where everybody ran around patching servers and semi-anxiously diagnosed what else might be vulnerable, then you’ve come to the right triage center. ZPE Systems provides a solution which helps sysadmins avoid the ShellShock bug’s malicious ghost users in the first place. Feeling lucky?


Lucky or Forward Thinking?

Enterprise INFOSEC admins who already had NodeGrid Manager installed before this latest problem merely had to patch one user portal. After this, said admins were able to leisurely patch the thousands of systems safely nestled behind NodeGrid Manager at their own pace. In fact, they could wait until Christmas and feel quite zen, although we don’t recommend it. Just because you can do something doesn’t mean you should. Our existing customers are already benefiting from NodeGrid’s intrinsic built-in Firewall capabilities.

This “Firewall capability” of NodeGrid Manager isn’t something we’ve trumpeted much before. By placing NodeGrid in front of all your devices, you effectively firewall user access to your varied, globally distributed IT assets. Widespread damage by users is highly reduced in a NodeGrid environment. Upon login to NodeGrid, users are authenticated against your existing enterprise AD/LDAP database for access. Then, users are further authorized based on their existing profiles with specific access rights to specific IT assets. No user will have direct access to every shell in the house without your explicit authorization.


Your Way, the Right Way

In this way, Joe, a senior engineer within the IT Security team, only has access to specific switches, routers, servers and smart PDU infrastructure to which he is authorized. Joe’s world consists of only those machines to which he is authorized access to from within NodeGrid. He won’t have access to or even see Marketing VMs, Development storage and server hardware or Finance servers and switches. Joe is protected, and his colleagues in other departments are also protected.


Another Use Case:

  • Samuel’s “internal and trusted” corporate Dell laptop has been hacked/infected by a Shellshock type attack.
  • Sam’s laptop tries to connect to NodeGrid without encrypted user credentials – is unceremoniously blocked – and can’t hack the rest of the network.
  • Multiple layers of NodeGrid security prevent collateral damage.

NodeGrid can help to improve the security and reduce the exposure to vulnerabilities by allowing network separation between critical systems and the users. NodeGrid’s “FireTrail” secure tunneling through Firewalls feature explicitly limits IT asset exposure to outside elements. Users receive secure locked-down access to authorized devices behind sensitive Firewalls without ever needing to know Firewall credentials. Deploying NodeGrid is almost like having two extra Firewalls.

 

 

Illustration of NodeGrid’s FireTrail secure tunneling IT asset protection feature.

 

 

In a NodeGrid managed device scenario, there is no direct connection to the bash of the target managed devices. NodeGrid works as the entry point, redirecting authorized users to a secondary network connection established exclusively between NodeGrid and your target managed devices. Also, by limiting the access availability to the serial console port of managed devices or access only within the management network (not production), sysadmins can improve the security of critical devices.


Get the Protection You Need Right Now

If you’d like to be doubly protected from future ShellShock bash bug type attacks, or any other attacks on your infrastructure based upon compromised user logins or exposed IT assets, contact us today. As you know, NodeGrid can act as a second firewall, or moat, around your IT castle — either in front of your existing firewall appliance or behind it.

 

In celebration of Halloween this month, we continue to offer terrifyingly good weekly demo sessions in person and via Webex. Register now to watch an overview of NodeGrid and learn how it can help save your IT bacon. You’re also welcome to download an evaluation copy of NodeGrid.

We look forward to helping enterprises and the global Internet become more secure and stable places to conduct business.

Warm wishes,

Kenneth Ott

Partnership Development

Kenneth Ott is Partnerships Manager at ZPE Systems and began using shell accounts in the late ’90s. He conducts initial consultations with organizations seeking simplified IT infrastructure management options. Outside of work, Kenneth enjoys hiking and camping throughout California.

Are Your Infrastructure Management Practices Still Valid In Today’s Data Center?

ZPE Systems – Nodegrid Data Center

I believe we will all agree that when it comes to technology, “Change is Constant”. Nowhere in the history of time has anything changed as fast as technology over a shorter period.

As a byproduct of this, we‘ve come to accept and expect computing, networking, storage, software, and just about all forms of technology to change sooner rather than later. Manufacturers usually find ways to make things “Cheaper, Smaller, Faster, and COOLER” (CSFC) than the previous version or idea, and we will (without a doubt) have to have it. This has become an everyday part of our life. Don’t believe me?

How about all the loyal iOS lovers that camp out in front of big box stores for 2 weeks prior to the release of the next “I Whatever” device? Or the “Black Friday” campers, who start lining up when the news breaks about being the first in line to get (1 of 3 available) 65” Super HD everything all in one home theater entertainment center with supersonic sound that gets 10k stations and any movie ever made all converted to 3D (no glasses required)? Don’t laugh! You know who you are. There’s a geek lurking in all of you somewhere.

So what does that have to do with Infrastructure Management? I first wanted to point out how we’ve come to accept and expect changes in technology, and how far people will go to get the latest techno gadget they believe will (in some way) improve their lives. A new feature, faster processor, more storage, faster network, improved this and that, etc. The point is, we accept, make plans for, and seek out technology changes that we believe (for whatever reason) will somehow improve our lives. We want it, are convinced we need it, and will sometimes go to extremes to get it, despite how insignificant it very well may be weeks or months later.

In IT, we all want the latest CSFC Servers, Network Gear, Storage Devices, Virtualization, Etc. These pieces of the technology pie will (in some way) improve our lives and the lives of others until the next CSFC device or piece of software comes along. Once we get it, we’ll put it in play and manage it (along with all the other generations of CSFCs from different manufacturers we have living in our data centers) using the same old tired management practices we‘ve been using for who knows how long. So why is that a problem?

It’s not–if trying to manage 100s to 1000s of Physical and Virtual IT Assets from different manufacturers, via multiple vendor specific management tools is not a problem for you.

Quite frankly, I say it’s a problem. Why? Because you have all these Servers, Network, Storage and Virtualized environments from different manufacturers and different generations, and you’re still trying to manage them using older management tools and methods. Just as IT technology changes, so should the management practices you have in play.

Up until now, the promise of having a single standardized infrastructure management solution that provides access and control to your CSFCs from different manufacturers and generations of Physical and Virtual IT Assets, didn’t exist. Variations are out there, but for the most part you still rely on the management tools provided by the respective manufacturer. This can, and does create a number of un-necessary problems.

For example, you most likely use a different tool to access and control servers from different manufacturers via Serial Console or the Service Processor. Each are different. You also probably have a different solution for accessing and controlling Network equipment, storage, and power from various manufacturers. And another access and control solution for your Virtual Environment. So here is where I have to say, WHY ISN’T this a problem? How is it cost effective to learn, maintain and use so many different solutions to access and control your infrastructure, when 1 or 2 would be sufficient? Everyone across the infrastructure would have the same interface and normalized command stack in which to access and control the entire Physical and Virtual landscape. This just makes too much sense right?

Having a single Access and Control solution that reduces the number of vendor specific tools you have to learn, use, and maintain, greatly simplifies the whole infrastructure management conundrum. Less tools, greater results and more savings. Who would have thought this could happen?

I’m no rocket surgeon, but when I think of being able to significantly reduce the number of management tools I have, need to learn, maintain, and use to control 100s–1000s of CSFCs, I’m thinking It might be time to get in line. Having a single solution that will do the work of many is a great benefit. It helps save time and money, reduces training costs and user mistakes, enhances compliancy, and improves security and troubleshooting challenges, just to name a few more.

All teams (Server, Network, Storage, Virtualization, and NOC) would all be operating from the same play book. Interfaces would be the same, commands would be the same, and predictably, the results would all be the same. Better Infrastructure Management with less risk and cost. Is this for real and available? Yes it is.

So I’ll leave you with these last thoughts and calls to action. If you’re in IT, and you use multiple solutions instead of one to manage 100s – 1000s of physical and virtual devices, you don’t have to camp out in line for 2 weeks to make a change that will immediately (today) start improving your life and the lives of others. You can do it right now (today). You can make a change (today) that delivers immediate and long lasting results to your data center infrastructure management practices. The technology exists (right now) that will make the lives of your Server, Network, Storage, Virtual, and NOC teams a whole lot easier.

Hope you had fun reading this and that you’ll make the move (right now) to find out (today) how simplifying your Physical and Virtual Infrastructure management can be as easy as breathing. Out With the Old, In With the New. I’m happy to share details. All you have to do is ask (today, now, this minute). Don’t wait any longer.

Good luck, and I trust you’ll make it a priority (right now) to upgrade your Physical and Virtual Infrastructure management tools and practices.

Data Center IT Challenges

I recently came across a survey of 400+ IT Execs and DC Managers regarding the efficiency of their Data Centers, and what they believe would help them make improvements.

In general the survey uncovered some interesting challenges. I’ll focus on two. “Daily Distractions” and “Adequate Physical and Virtual Machine Management.”

NodeGrid Manager™ addresses data center IT challenges with Software Defined Infrastructure and a uniform user interface for managing access and power control of all hardware and VMs.

Daily Distractions

It states that IT departments (in general) spend an average of 32 hours per week dealing with roughly 16 unexpected IT issues like “Network Slowdowns and Outages”, “Equipment Failures”, “Technology Upgrade Requests” and “Availability and Capacity Issues”, all taking about 2 hours and 20 minutes each to resolve. These issues shift IT managers’ focus away from planned projects and higher level future planning activities, and each issue required roughly “9” or so staff members to help resolve. I’m not sure I buy or understand the need for 9 staff members, but that was the result in the survey.

Adequate Physical and Virtual Machine Infrastructure Management

The survey also pointed out that 75% of the IT managers surveyed felt they lacked the proper “Physical and Virtual Infrastructure Management Tools” and adequate training on the use of these Tools. The survey also pointed out that 71% believed if they had proper tools and training, their efficiency and productivity would improve by 30%. A total of 71% also felt their overall risk would shrink considerably.

These are some interesting numbers since one of the first and foremost requirements of any IT manager should be to have management solutions and training on their use in place from the get go. I can only assume this is not the case here, or the solution(s) they do have in place, don’t meet their current requirements or are difficult to understand and use.

ZPE Provides Secure Access and Control of Physical and Virtual Infrastructures

So I leave you with this request: if you can relate to this survey, and have issues with your current “Physical and Virtual Machine Management Tools”, I would love to speak with you about what might (arguably) be the easiest and most complete “Physical and Virtual Machine Management Solution” you’ve ever seen: “NodeGrid Manager” Software Defined Infrastructure from ZPE Systems.

 

Sign up for a free demonstration of NodeGrid Manager and learn how we’re changing “Physical and Virtual Machine Infrastructure Management” for the better. We’re delivering what others only claim they can do. Experience NodeGrid Manager for yourself.

Cheers!

– Kevin

Five Reasons To Use Software Defined Access Control

Five reasons to consider Nodegrid Manager ™ for Managing Access to Your Organization’s Data Center Assets


1. Nodegrid Manager Makes Life Easy

You’ve got a laundry list of virtual and physical multi-vendor assets (of all types) all over the globe and no simple one screen, identical user interface solution for providing appropriate sysadmin/user access and full power control to them all. This didn’t exist until now.

ZPE Systems is now delivering a secure one-screen access and control solution that provides just that. One Screen for your Data Center of Everything ™. Yes, we provide secure In-Band and Out-of-Band user access for practically everything – VMware and KVM VMs, Cisco and Juniper routers, OpenGear, Raritan, Digi, and Avocent console servers, APC/Schneider PDUs and UPS devices, HP, IBM, Dell, Cisco, and Supermicro servers, storage from EMC and NetApp… you name it, we most likely provide secure access to it.

 

 


2. Nodegrid Manager Delivers “Everything You Need in a Screen”

  • Enterprise AD/LDAP access to all your data centers’ assets – give the right people access to the right device (both physical and virtual)
  • Mouse-Keyboard-Screen (MKS) access to all your VMware VMs and virtual appliances
  • DeviceURL Direct URL device bookmark for MKS, Console, Web or Tunnel.
  • Power on/off control – not simply rebooting live machines. Nodegrid turns on cold ones too.
  • Cloud Clustering™ – easy cloud clustering with elastic search capability for large or distributed environments.
  • FireTrail Secure Tunneling – give users secure tunnel access to all their appropriate devices (and ports) across data centers and through firewalls. All port forwarding happens inside of a secure Nodegrid tunnel. At no time do you need to punch holes in or provide users with credentials to any firewalls. Users only see the devices and ports they are authorized to see.

 

 


3. Nodegrid Manager Saves you Time, Money, and Trouble

See our Use Cases to find out how – and get cool implementation ideas for Nodegrid Manager in disparate environments. We’re adding new cases each month!


4. Schedule your Exclusive Personalized Demo today

We want you to get to know Nodegrid Manager, and truly experience vendor freedom – It’s liberating!


5. Cloud Cluster Management

Free one month trial. Our software defined solution grows with your needs – without breaking a sweat. Request your trial license copy now.

We’d like to know how you’re currently handling secure access of your data center assets today. Send us an email info@zpesystems.com or give us a call. We’d like to discuss how we can help you simplify data center access management.

– The ZPE Team