Solved

Secure access to IPMI and vSphere from remote location

Posted on 2013-11-07
2
642 Views
Last Modified: 2013-11-14
I need some help brainstorming a good way to do this.

We are about to deploy a new server - a VMWare ESXi host which will run most of our internal company systems and services.

We have an entirely virtual company and everybody works remotely from home. We don't actually have an office of our own.

We DO rent the services of a "business incubator" - a shared office facility that is basically a receptionist and some shared boardrooms and meeting rooms. They happen to have a really nice 100MBPS internet connection, and that's where our server is going to be hosted.

Our server runs a virtual router - we have a pfSense VM which provides routing for the local area network available inside the host. All of the virtual machines are part of this virtual LAN, and the pfSense VM provides routing and VPN access to the network for our outside workers.

So workers VPN in to the pfSense router, and after that they can access the internal company network. I an also VPN into the network to administer servers via SSH, Remote Desktop etc.

This is great and all so long as everything is working, but on my end there's two low level management tasks I NEED to be able to do remotely, and securely:

1) Connecting to the host via vSphere, to manage virtual machines

2) The server itself has a SuperMicro motherboard with IPMI, and I can connect via IPMIVIEW over port 5900 and I can actually see the console of the physical server - very cool! This lets me see the sensors, power on/off the server, and come to the rescue when everything goes to hell and the server is down.


What's a good way to get remote access to these two services in a secure way? I'm a bit hesitant to just open it up to the Internet, and VPN access only works if the pfSense VM is actually functional - something I can't rely on if I'm trying to fix a broken server.


....... any ideas?
0
Comment
Question by:Frosty555
2 Comments
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 250 total points
ID: 39631729
You should put a box in front which will access control connections to your box. I have used mikrotik for remote access as they are (very) cheap but very powerfull (100mbits VPN traffic is NO problem).
0
 

Assisted Solution

by:ChadSeaton
ChadSeaton earned 250 total points
ID: 39644284
I would use a hardware solution. Two Mikrotik Routers (or Cisco if you want to spend more money) set up to do a VPN Tunnel between the two routers. Use IPSec to secure the tunnel between the two. Done.

This a "always on" VPN sollution.

Video on how to set this up:
http://gregsowell.com/?p=787
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
configuring snmp v2 or v3 on Cisco switches 2 49
Protectings Systems from Malicous Users 4 93
Structural Sanitization 4 39
SOHO Router with software VPN access 1 35
Outsource Your Fax Infrastructure to the Cloud (And come out looking like an IT Hero!) Relative to the many demands on today’s IT teams, spending capital, time and resources to maintain physical fax servers and infrastructure is not a high priority.
Is your computer hacked? learn how to detect and delete malware in your PC
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now