Configuration Management Plug-in - Overview

This section is applicable to the following editions of IT360 - Professional Edition, Enterprise Edition (Probes only) and MSP Edition (Probes only).

The below topics are discussed here:

  1. Introduction
  2. Features
  3. Limitations
  4. Integrating Standalone Device Expert with IT360
  5. Enabling SSL mode for the Plugin

1. Introduction

The Configuration Management plug-in in IT360 is a comprehensive solution for easy network change and configuration management. It offers multi-vendor network device configuration, continuous monitoring of configuration changes, notifications on respective changes, detailed operation audit and trails, easy and safe recovery to trusted configurations, automation of configuration tasks and insightful reporting.

This plug-in effectively manages network devices such as switches, routers, firewalls, wireless access points, integrated access devices etc., from multiple vendors. It imports the network devices from IT360 and builds up an inventory database, thus enabling IT administrators to take control of configuring the devices from a central console. The added advantage of this Configuration Management plug-in is that it eliminates the need to re-configure users and mail servers and allows the inbuilt configurations in IT360 to be used.

2. Features

Top

3. Limitations

3.1 General:

  1. Enterprise Search is not supported for this plug-in.
  2. Shared probe concept is not supported for this plug-in.
  3. The Configuration Management widgets will not be shown in Central server.

3.2 Rebranding-specific:

  1. Customer / Partner level rebranding is not supported; only Global level (MSP level) rebranding is supported.
  2. In case of Professional and Enterprise editions, you need to carry out a specific procedure to enable rebranding. Contact it360-eval@manageengine.com for the same.
  3. While installing the plugin in a setup that is already rebranded, you need to re-submit the rebranding form, for the changes to take effect in the NCM tables and images.
  4. Always restart the Network module, to get instant effect of the updated rebranding data in the Configuration Management plug-in UI.

Top

4. Integrating Standalone Device Expert with IT360

Instead of installing the Configuration Management plug-in newly, you can also integrate an existing Standalone Device Expert setup with IT360. For that you need to follow the below procedure:

4.1 Prerequisite:

The Standalone Device Expert should be upgraded to the version supported by IT360 or above. 

4.2 Data Backup:

  1. Stop the standalone Device Expert service. 

  2. Execute the backupDB.bat script available under the '<DeviceExpert_Home>\bin' directory to start the data backup.

  3. Once the backup is over, a zip file (latest), say 140109-1444.zip will be created under the '<DeviceExpert_Home>/Backup' directory.

4.3 Data Restore:

  1. Stop the IT360-Networks service. 

  2. Execute the restoreDB.bat script available under the '<IT360_ Home>\networks\ncm\bin' directory, with the backup file name as 'argument'. (provide the absolute path of the backup file). 

i.e., execute the following in the command prompt: <IT360_Home>\networks\ncm\bin>restoreDB.bat <Backup_path>\140109-1444.zip(provide the latest zip file) 

e.g., <IT360_Home>\networks\ncm\bin>restoreDB.bat <DeviceExpert_Home>\Backup\140109-1444.zip (provide the latest zip file) 

  1. Start IT360-Networks service.

Top

5. Procedure to Enable SSL mode for Configuration Management Plug-in

5.1 Circumstances to enable SSL mode in Configuration Management plug-in:

  1. If IT360 (Professional / Enterprise Probe) is installed in HTTPs mode and NCM plugin is installed before the Networks module start-up, follow the below steps to enable SSL mode for NCM Plugin.

  2. If IT360 is enabled with HTTPs mode and NCM plugin is integrated with it, keep the Networks module down, perform the below steps and then start the Networks module.

  3. While importing third party SSL Certificate into IT360, with the Configuration Management plug-in installed in it; make sure the Networks module is down and follow the below steps to enable SSL mode for the Plugin.

5.2 Steps Required:

  1. Copy it360.keystore file from <IT360Home>/networks/conf/ to <IT360Home>/networks/ncm/conf/.

  2. Change the Connector tag in server.xml available under <IT360Home>/networks/ncm/conf/ as given below:

<Connector SSLEnabled="false" URIEncoding="UTF-8" acceptCount="100" clientAuth="false" debug="0" disableUploadTimeout="true" enableLookups="false"keystoreFile="conf/server.keystore" keystorePass="RGV2aWNlRXhwZXJ0"maxSpareThreads="15" maxThreads="150" minSpareThreads="5" port="6060" redirectPort=""scheme="http" secure="false" sslProtocol="TLS" useBodyEncodingForURI="true"/>

<Connector SSLEnabled="true" URIEncoding="UTF-8" acceptCount="100" clientAuth="false" debug="0" disableUploadTimeout="true" enableLookups="false"keystoreFile="conf/it360.keystore" keystorePass="it-360" maxSpareThreads="15" maxThreads="150" minSpareThreads="5" port="6060" redirectPort="" scheme="https" secure="true" sslProtocol="TLS" useBodyEncodingForURI="true"/>

Params
Value in HTTP Mode
Value in HTTPs Mode
SSLEnabled false true
keystoreFile conf/server.keystore conf/it360.keystore
keystorePass RGV2aWNlRXhwZXJ0 it-360
scheme http https
secure false true
  1. Change the following properties in system_properties.conf available under <IT360Home>/networks/ncm/conf/:
opm.trustStore=../../conf/OpManager.truststore
opm.trustStorePassword=opmanager
opm.trustStore=../conf/it360.keystore
opm.trustStorePassword=it-360
  1. Create it360.cer file that needs to be imported into cacerts. Command to convert it360.keystore file into it360.cer file is given below. Execute this under <IT360Home>/jre/bin:

    Commandkeytool.exe -export -alias it360 -storepass it-360 -file it360.cer -keystore ..\..\networks\ncm\conf\it360.keystore
    Output of command : Certificate stored in file <it360.cer>

  2. Import the certificate generated in the above step [it360.cer] into cacerts using the below command. Execute this under <IT360Home>/jre/bin.

    Command: keytool.exe -import -keystore ..\lib\security\cacerts -alias it360 -file it360.cer -storepass changeit -noprompt
    Output of command: Certificate was added to keystore
In case of a NAT enabled setup, first execute the above steps, followed by these steps.

Top



Copyright © 2013, ZOHO Corp. All Rights Reserved.