[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Remote administration of a server



On Sun, 7 Aug 2005, Mitja Podreka wrote:

> I will have (I hope :-) no problems setting up the server, I've done that
> already. What I worry about is how to administer the server from China? Will I
> only lack the access to the reset button, or something more? Which software
> should I use for this? What should I take special care at?

If you're confortable with the command line (or prepared to become so) 
this is pretty easy.  You can administered the box through ssh without a 
problem.  I'm in Canada and administer boxes in various countries via ssh 
on a daily basis and have done so for many years.  Disable password access 
and root access via ssh and only allow assess to user accounts through PKI 
authentication.

You may need the console from time to time.  The best option if you can 
manage it is to setup a serial console.  The down side is this requires a 
2nd box controlled either by yourself or someone you trust implicitely.

With the serial console in place you can drop the box to single user mode, 
take if off the network, etc all from the other side of the world.  With a 
serial console the only things you lack are access to the BIOS and the 
reset button.  Some motherboards allow access to the BIOS through the 
serial console but this may be more expensive and is not a big deal IMHO.  
Simlarly 3rd party hardware is available to allow serial access to any 
BIOS but it is expensive.

Some housing facilities allow you to power cycle the box via a web 
interface.  This is useful if you accidentally halt the box.  As always, 
just be very careful when you are root.

Good luck,

Rob

-- 
Robert Brockway B.Sc.
Senior Technical Consultant, OpenTrend Solutions Ltd.
Ph: +1-416-669-3073 Email: rbrockway@opentrend.net http://www.opentrend.net
OpenTrend Solutions: Reliable, secure solutions to real world problems.
Contributing Member of Software in the Public Interest http://www.spi-inc.org



Reply to: