Remote-access Guide

configure hmc remote access

by Adeline Becker Published 2 years ago Updated 1 year ago
image

  1. Enable remote operation In the navigation panel, click HMC Management, then click Remote Operation. Check the box to enable remote operation and click OK.
  2. Enable remote Web access in the firewall In the navigation panel, select HMC Management, and then click Change Network Settings. ...
  3. Ensure each user is enabled for remote access

Resolving The Problem
  1. Enable remote operation. In the navigation panel, click HMC Management, then click Remote Operation. ...
  2. Enable remote Web access in the firewall. In the navigation panel, select HMC Management, and then click Change Network Settings. ...
  3. Ensure each user is enabled for remote access.
Sep 22, 2021

Full Answer

How do I allow remote access to my HMC account?

In the navigation panel, select HMC Management, and then click Manage User Profiles and Access. Select the desired user profile and click the menu option User, Modify. On the Modify User dialog, click the User Properties... button. Check the box for Allow remote access via the web. Click OK, OK to save the change.

How do I enable SSH on the HMC?

SSH enabled on the HMC. 1. Select Management > System Configurations: 2a. To configure a new system, click New. Continue to Step 3. 2b. To update/add console configuration to an existing system, select the system and click Edit. Skip to Step 4: 3. Enter the System name. a. Enter the name of the IBM i OS system or partition.

How do I configure ACS to work with the HMC/FSM?

- The ACS client must have network connectivity to the HMC/FSM for TCP ports 2300 (unsecure console), 2301 (secure console), 22 (advanced options). - SSL console support requires JRE 7 or later. a. IBM i ACS 1.1.6 or later b. SSH enabled on the HMC. 1. Select Management > System Configurations: 2a. To configure a new system, click New.

What ports are open when remote access is enabled in HMC?

In V7R7.8 and later, a new port, 12443, is opened in the HMC firewall when "remote access" is enabled. For remote web browser connectivity to HMC V7R7.8.0 and later, this port must also be opened in any firewall that is between a remote client and the HMC.

image

How do I configure HMC console?

Before configuring the Hardware Management Console, verify that the requirements listed in the prerequisites section are met. Specify the HMC name to monitor remotely. Specify the SSH port number of the HMC to be monitored. The default port number is 22.

How do I enable SSH on HMC?

a) Select Users and Security > Systems and Console Security then click Enable Remote Command Execution. b) On the Remote Execution Options dialog, verify the Enable remote command execution by using the ssh facility check box is selected. If it is not, select the box, and click OK.

How do I access HMC command line?

On a local HMC, you can use the command line interface in a terminal window. To open a terminal window, use the Open Restricted Shell Terminal task from the HMC Management work pane. You must ensure that your script executions between SSH clients and the HMC are secure.

How do I log into HMC in AIX?

Click Log on and launch the Hardware Management Console web application. Log in to the HMC with the following default user ID and password: ID: hscroot. Password: abc123.

How do I check my HMC port status?

Verifying the RMC port for each partition From the HMC GUI, click HMC Management → Change Network Settings → LAN Adapter/Details → Firewall Settings, and then select Allow RMC.

How do I check my HMC file system?

Look at the filesystems of the HMC. Try using "proc", "mem" and "swap as well. Open a virtual console from the HMC. Exit by typing "~." (tilde dot) or "~~." (tilde tilde dot).

How do I start LPAR from HMC command line?

TO DEACTIVATE/SHUTDOWN A LPAR : # chsysstate -r lpar -m Server-9110-51A-SN066331D -o shutdown –immed -n server1.TO ACTIVATE/START A LPAR : # chsysstate -r lpar -m Server-9110-51A-SN066331D -o on -n server1 -f Profile_ name.TO REBOOT/RESTART A LPAR :

How do I log into IBM HMC?

You can long in to the Hardware Management Console (HMC) and choose which language you want to be displayed in the interface. Use the default User ID hscroot and password abc123 to log on to the HMC for the first time.

What is the default HMC access password?

Note: The default password for user admin is admin. If the admin password is also lost, contact an authorized service provider for information on how to reset both passwords.

What is HMC in AIX?

The HMC provides a graphical interface to control servers, including powering up and down, and setting up and managing partitions running on the managed servers. On AIX® or Linux partitions, this is accomplished through the HMC graphical user interface (GUI) and through the virtual terminal.

How do I get out of HMC console?

Hi, Use ~. (tilde dot) to exit the console.

How do I change my Hscroot password using CMD?

Perform the following steps:In the Navigation area, click HMC Management.In the Work area, click Change user profiles and access. ... Select hscroot to change the hscroot password or root to change the root password.Select User > Modify.Type the new password in the first field.More items...•

What is fastpath in HMC?

This section allows the user to configure the HMC managed system and partition associated with this server. This information is used by the Virtual Control Panel and Fastpath functions. Virtual Control panel allows a user to view and change the partition's virtual control panel settings including current SRC, IPL type, and attention light state. Fastpath allows the remote console to bypass the system and partition selection panels going direct to the desired partition console screen. Fastpath requires HMC 7.7.8 or later (with latest fixes).

Can HMC certificates be downloaded automatically?

The HMC certificate will be downloaded automatically.

Does HMC 5250 require SSH?

Note: SSH connectivity to the HMC is required. HMC 5250 Console Advanced options must be configured. The toolbar option cannot be saved/persisted; it must be enabled each session.

Laurence Chiu

We are replacing our zBC12 with a Z14 ZR1 which is DR machine. It will

Dana Mitchell

As far as firewall rules go, we can access SOO remotely so I'm looking back at some of my old firewall requests, and it looks like for a new HMC I requested ports 443,9960 and 2300 to be opened. But in the current doc, port 2300 is not referenced, so I don't recall what that was for.

Edgington, Jerry

Here is my "cheat sheet" for HMC ports and direction. However, I don't know if they have changed for z14 ZR1, but they work for z13s.

Laurence Chiu

OK an update. We haven't solved the remote access issue yet but the guys

Parwez

While I can't answer your specific Q. A general point - a HMC with 'lower' level of HMC code can't control/access System requiring a 'higher' level of HMC code. A HMC with higher level code e.g the z14 ZR1 HMC can access/control Systems all the way back to z10 EC and BC. If your zBC12 HMC is at level 2.12.1 then this could be the issue.

Jesse 1 Robinson

We replaced two z12s late last year with a z14 and a z13s. I didn't do the actual work, but all 'migratable' HMC data was copied over to the new CECs ahead of the push-pull swap out. This includes profile data and userids/passwords.

Jason Cai

I try to get the output of these mvs commands and save these output to a DSN.

How to connect a HMC to a network?

The first step is to make sure that the HMC is physically cabled to the network, so that it can talk to your network infrastructure. You can do this by looking behind the HMC box and noting whether there are one or two Ethernet cables plugged into the back of the PC. If there are two cables, the cables are probably plugged into side-by-side Ethernet ports on the back of the HMC ( eth0 and eth1 ). For a two cable setup, one cable is being used to connect the eth0 Ethernet port to your System i through the managed server’s Flexible Service Processor (FSP), and the second cable is probably being used to attach your PC to the network via the eth1 Ethernet port. If there is only one cable on the back of your box, it is only being used to connect the HMC to the System i FSP, and you will need to attach a second Ethernet cable from the eth1 port to a LAN switch or network hub residing on your network. This will complete the physical configuration to allow remote users to attach to your HMC over a network.

What is the port eth1?

IBM generally delivers its Hardware Management Console PCs with an additional network card that the system identifies as port eth1. Once configured on the network, eth1 can be configured to use the Web-based System Manager (WebSM) or to connect to one of the HMC system consoles on your network through a 5250 session using iSeries Access for Windows. I’ll cover WebSM (which allows you to run your HMC interface through a Web browser) in a future article. This week, I’ll concentrate on bringing up a system console on an HMC partition through the HMC’s Remote 5250 Console feature.

Can you start a 5250 session remotely?

You need to check and possibly configure the following items to make sure that the HMC will allow you to start a 5250 session for remotely accessing its system consoles.

How to log in to HMC?

The HMC will ask you to log in by using any valid HMC user ID and password. This is the same log in that you would use when you start the HMC. The most common login choice is to use the hscroot default user ID that is already configured on the HMC. If you’re not sure what the password is for the hscroot user, you can find it by checking out IBM’s Website that lists out the predefined passwords for the hscroot and root HMC user IDs.

How to start HMC Remote 5250?

Once you reach the HMC Remote 5250 Console Partition Selection screen, you will be prompted for the console and partition that you want to start the Remote 5250 Console for. For system console activation, you can select either a dedicated console (1=Connect dedicated) or a shared console (2=Connect shared). The difference is that a shared console can be used by another user with a 5250 emulator, and if you select option 2, you will be asked to enter a unique key that will also need to be entered by any other user who wants to take control of the shared remote console from you.

What language is on remote 5250?

You can select whichever language you want from a subfile of language choices that will be displayed on the screen. American English is listed as option 21 on this screen.

How to use Q#HMC?

Click on the Properties button on the screen and a Connection window will appear. Click on the dropdown box in the User ID signon information area of the screen, select Use default User ID, prompt as needed, and then enter the literal Q#HMC in the User ID field. Using Q#HMC is kind of a tricky dodge used by IBM in this configuration. The Q#HMC user ID isn’t actually used for security authentication when connecting to the HMC’s Remote 5250 console, but you need to designate Q#HMC in your PC5250 connection screen in order to establish a connection.

Can you remotely access partition system console?

And that’s all there is to remotely accessing a partition system console that resides on a Hardware Management Console PC. While these steps are relatively easy if everything is configured correctly, you can also check the resources at the bottom of the article if you are still having trouble connecting.

Can you change the HMC?

The main thing to consider is the connection method between the HMC and the frame (s). If you control it (via a private hub switch, direct connection, etc..), then you can change it at will. Otherwise, you may need to involve your network folks.

Can you change the address range on a P5 HMC?

If the 570 is the only frame connected to the p5 HMC and the HMC is a private DHCP server, you can change the address range to whatever you like on eth0 (under network settings), reboot the hmc (to activate the change), and then run mksysconn -o auto from a command line on the HMC. This will dynamically instruct the 570 to acquire a new address from the HMC. You will need to clean up any old addresses which were previously distributed by the HMC using rmsysconn.

image
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9