69.7 Starting Remote Management Operations Using ConsoleOne

The Remote Management Agent starts automatically when the managed workstation boots up. The remote operator can initiate a Remote Management session in any of the following ways:

69.7.1 Initiating a Directory-Based Remote Management Session

You can initiate directory-based Remote Management using either of the following methods:

From the Workstation Object

The following table lists the directions for initiating a Remote Management session.

Table 69-1 Initiating a Remote Management Session

Remote Management Session

To Initiate

Remote Control

Right-click the managed workstation, then click Actions > Remote Control.

Remote View

Right-click the managed workstation, then click Actions > Remote View.

File Transfer

Right-click the managed workstation, then click Actions > File Transfer.

Remote Execute

Right-click the managed workstation, then click Actions > Remote Execute.

Diagnostics

Right-click the managed workstation, then click Actions > Diagnostics.

Remote Wake Up

Right-click the managed workstation, then click Actions > Remote Wake Up.

Remote Audit

Right-click the managed workstation, then click Actions > Remote Audit.

From the User Object

  1. In ConsoleOne, right-click a user object.

    The selected user must be logged in to at least one managed workstation before Directory-Based Remote Management is initiated.

  2. Click Remote Management.

  3. In the Remote Management dialog box:

    1. Select the IP address of the managed workstation which you want to remotely manage.

      If the user has logged into the eDirectory through the Middle Tier, the list of IP addresses contains the IP address of the Middle Tier. To filter this address, in the ConsoleOne_installation_directory\1.2\bin\drishtitype.ini file, add the XTierServerAddresses property and specify the Middle Tier IP addresses. For example, XTierServerAddresses = Middle_Tier_IP_address1, Middle_Tier_IP_address2, ...

    2. Select a Remote Management operation which you want to perform on the selected managed workstation.

    3. Select Directory-Based, then click OK.

69.7.2 Initiating a Password-Based Remote Management Session

NOTE:There is a known security vulnerability in using Password-Based authentication. We recommend you to use the Directory-Based authentication. For more information on the vulnerability in using Password-Based authentication, see TID 7006557 in the Novell Support Knowledgebase

Before initiating the Password-based Remote Management, make sure that the following prerequisites are met:

Table 69-2 Prerequisites to Initiate a Password-based Remote Management

Is the managed workstation registered in eDirectory and imported as an eDirectory workstation object?

Has an eDirectory user logged at the managed workstation?

To initiate a Password-Based Remote Management Session

Yes

Yes

  • The Enable Password-Based Remote Management option in the Remote Control policy of the managed workstation object must be enabled.

  • The Enable Password-Based Remote Management option in the user object’s Remote Management property page must be enabled.

  • The workstation user must have a password set on the managed workstation.

Yes

No

  • The Enable Password-Based Remote Management option in the Remote Control policy of the managed workstation object must be enabled.

  • The workstation user must have a password set on the managed workstation.

No

Yes

  • The workstation user must have a password set on the managed workstation.

No

No

  • The workstation user must have a password set on the managed workstation.

You can initiate Password-Based Remote Management using either of the following methods:

From the ConsoleOne Menu

  1. In ConsoleOne, click Tools > Remote Management > Windows.

  2. In the Remote Management dialog box:

    1. Enter or select the IP address or DNS name of the managed workstation with which you want to initiate a Remote Management session.

    2. Enter the password set by the workstation user on the managed workstation.

    3. Select a Remote Management operation that you want to perform on the selected managed workstation.

From the User Object

  1. In ConsoleOne, right-click a user object.

    The selected user must be logged in to at least one managed workstation before Password-Based Remote Management is initiated.

  2. Click Remote Management.

  3. In the Remote Management dialog box:

    1. Select the IP address of the managed workstation which you want to remotely manage.

      If the user has logged into the eDirectory through the Middle Tier, the list of IP addresses contains the IP address of the Middle Tier. To filter this address, in the ConsoleOne_installation_directory\1.2\bin\drishtitype.ini file, add the XTierServerAddresses property and specify the Middle Tier IP addresses. For example, XTierServerAddresses = Middle_Tier_IP_address1, Middle_Tier_IP_address2, ...

    2. Select a Remote Management operation that you want to perform on the selected managed workstation.

    3. Click Password.

    4. Enter the password set by the workstation user on the managed workstation.

    5. Click OK.

69.7.3 Initiating Remote Management Session from the Remote Management Agent

If the managed workstation is configured behind dynamic NAT, the managed workstation cannot be accessed from the management console but the management console can be accessed from the managed workstation. To resolve this problem:

  1. The user at the managed workstation must initiate a request for a Remote Management session to the remote operator by using the Request Session option.

    IMPORTANT:Before initiating a Remote Management session from the Remote Management Agent, the remote operator must make sure that ConsoleOne is running on the management console.

    To request a session, the user at the managed workstation must do the following:

    1. Right-click the Remote Management Agent icon.

    2. Select Request Session.

    3. Specify the IP address or the DNS name of the management console.

    4. Select the Remote Control or Remote View operation from the drop-down list.

    5. Click OK.

  2. The Remote Management Listener listens to the request and notifies the remote operator about it. The remote operator must accept the request and provide the following credentials for the request in the Select Authentication Mode dialog box:

    1. Select the Directory option for directory-based authentication.

      or

      Select the Password option for password-based authentication.

    2. If the password-based authentication is selected, enter the password for authentication.

    3. Click OK.

Operating in the Terminal Server Environment

The first instance of ConsoleOne receives the request when a session request is initiated from a managed server to the management console running on a terminal server. None of the ConsoleOne instances receive the session request until all ConsoleOne instances on the session where ConsoleOne was launched for the first time are closed. To receive the session request, ConsoleOne must be launched again on any terminal session.