Docu 69327
Docu 69327
Docu 69327
Dell believes the information in this publication is accurate as of its publication date. The information is subject to change without notice.
THE INFORMATION IN THIS PUBLICATION IS PROVIDED “AS-IS.“ DELL MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND
WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. USE, COPYING, AND DISTRIBUTION OF ANY DELL SOFTWARE DESCRIBED
IN THIS PUBLICATION REQUIRES AN APPLICABLE SOFTWARE LICENSE.
Dell, EMC, and other trademarks are trademarks of Dell Inc. or its subsidiaries. Other trademarks may be the property of their respective owners.
Published in the USA.
Dell EMC
Hopkinton, Massachusetts 01748-9103
1-508-435-1000 In North America 1-866-464-7381
www.DellEMC.com
2 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CONTENTS
Preface 5
Chapter 1 Introduction 7
Benefits of ESRS..........................................................................................8
About remote service options.......................................................................8
Operational description............................................................................... 10
Chapter 5 Troubleshooting 31
ESRS cannot be enabled............................................................................ 32
ESRS reported a connection issue..............................................................33
Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration 3
CONTENTS
4 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Additional resources
DANGER
WARNING
CAUTION
NOTICE
Note
Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration 5
Additional resources
6 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CHAPTER 1
Introduction
This chapter introduces you to the EMC Secure Remote Services (ESRS) feature.
Topics include:
l Benefits of ESRS................................................................................................. 8
l About remote service options.............................................................................. 8
l Operational description.......................................................................................10
Introduction 7
Introduction
Benefits of ESRS
The embedded ESRS feature in Unity deployments provides a highly secure, remote
connection between your EMC Unity environment and EMC. A connection that, once
made, can unlock a wide range of benefits and services like:
l Automated health checks.
l 24x7 predictive wellness monitoring.
l Remote issue analysis and diagnosis.
l An enhanced Online Support experience with actionable, real-time data-driven
insight into your global EMC environment through the MyService360 dashboard.
l Remote delivery of EMC’s service and support.
l CloudIQ, a software-as-a-service cloud management dashboard that provides
intelligent analytics about performance, capacity, and configuration for health-
based reporting and remediation. ESRS must be enabled on your storage system
to send data to CloudIQ.
Note
Before you can configure ESRS, you must specify valid support credentials.
Centralized ESRS
Centralized ESRS runs on a gateway server. When you select this option, your storage
system is added to other storage systems in an ESRS cluster. The cluster resides
behind a single common (centralized) secure connection between Support Center
servers and an off-array ESRS Gateway. The ESRS Gateway is the single point of
entry and exit for all IP-based ESRS activities for the storage systems associated with
the gateway.
The ESRS Gateway is a remote support solution application that is installed on one or
more customer-supplied dedicated servers. The ESRS Gateway functions as a
communication broker between the associated storage systems, Policy Manager
(optional) and proxy servers (optional), and the Support Center. Connections to the
Policy Manager and associated proxy servers are configured through the ESRS
Gateway interface along with add (register), modify, delete (unregister), and querying
status capabilities that ESRS clients can use to register with the ESRS Gateway.
8 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Introduction
For more information about ESRS Gateway and Policy Manager, go to the ESRS
product page on Online Support (https://Support.EMC.com).
To configure your storage system to use Centralized ESRS, you only need to provide
the IP address of the ESRS Gateway and ensure that port 9443 is open between the
gateway and the storage system. Also, ensure that port 443 is open (outbound) for
network traffic.
Note
Storage systems can only be added to the ESRS Gateway from Unisphere. If the
storage system is added from the gateway server, it will appear to be connected, but
will not successfully send system information.
Note
Integrated ESRS runs directly on the storage system. When you select this option,
you set up the storage system to use a secure connection between itself and the
Support Center. You can select one of the following remote service connectivity
options for Integrated ESRS:
l Outbound/Inbound, which is the default, from the storage system to the Support
Center and from the Support Center to the storage system for remote access
using https.
l Outbound only from the storage system to the Support Center using https.
When you select the Outbound/Inbound option, the storage system sets up a secure
connection between itself and the Support Center. This option enables remote service
connectivity capabilities for remote transfer to and remote transfer from the Support
Center with the storage system. Configure the connection from the storage system to
a Policy Manager (optional) and any associated proxy servers (optional) through
either Unisphere or the CLI.
When you select the Outbound only option, the storage system sets up a secure
connection between itself and the Support Center. This option enables remote service
connectivity capability for remote transfer to the Support Center from the storage
system.
To configure the storage system to use Integrated ESRS, you must:
1. Specify valid support credentials, otherwise, you cannot perform an ESRS
readiness check or configure ESRS.
2. Run a readiness check (optional, but highly recommended).
3. If you skipped the readiness check, accept the license agreement for the feature.
4. Run the network check.
Note
Several ports need to be allowed by your firewall/network setting for the network
check and ESRS functionality. Ports 443 and 8443 are required for outbound
connections while ports 80 and 443 are required for inbound connections. Also, if
the settings that appear for the global proxy server need to be changed, edit the
settings then run the network check.
5. For Outbound/Inbound remote service connectivity, you must specify the required
customer contact data for the storage system if it has not been specified. This
step is not applicable to Outbound only remote service connectivity.
6. Request an access code for verification through email (an extra level of
authentication) and submit the access code for validation to continue the ESRS
enabling process.
7. Check the status of the system's ESRS connection to the Support Center.
8. For Outbound/Inbound remote service connectivity, configure the Policy Manager
(if an additional layer of security is required). The Policy Manager requires port
8090 (default) or the customer-specified port to be open for outgoing traffic. If it
is configured to use SSL, port 8443 must be open.
9. Specify whether to send data to CloudIQ.
When Outbound only is the current ESRS configuration on the storage system, you
can modify the proxy server information, if applicable, and change the remote service
connectivity option to Outbound/Inbound. Changing the remote service connectivity
option to Outbound/Inbound also requires you to specify the customer contact data
for the storage system if it has not been specified and, if required, to configure the
Policy Manager.
When Outbound/Inbound is the current ESRS configuration on the storage system,
you can modify the proxy server information, if applicable, and the contact and system
information. However, you cannot change the remote service connectivity option from
Outbound/Inbound to Outbound only, that change is not supported.
Operational description
The ESRS feature provides an IP-based connection that enables Support to receive
error files and alerts from your storage system, and to perform remote
troubleshooting resulting in a fast and efficient time to resolution.
Note
It is strongly recommended that you enable the ESRS feature to accelerate problem
diagnosis, perform troubleshooting, and help speed time to resolution. If you do not
enable ESRS, you may need to collect system information manually to assist Support
with troubleshooting and resolving problems with your storage system. ESRS must be
enabled on the system for data to be sent to CloudIQ.
10 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Introduction
Operational description 11
Introduction
12 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CHAPTER 2
Requirements and Configuration
This chapter describes the requirements for the ESRS feature and provides an
operational description of the feature. The chapter also describes the processes to
provision the feature.
Topics include:
NOTICE
If you use DHCP to assign IP addresses to any ESRS components (ESRS Gateway
servers, Policy Manager servers, or managed devices), they must have static IP
addresses. Leases for the IP addresses that those devices use cannot be set to expire.
It is recommended that you assign static IP addresses to those devices you plan to
have managed by ESRS.
Note
14 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Requirements and Configuration
l Network traffic (HTTPS) must be permitted on port 9443 between the Unity
system and the ESRS Gateway server. Also, network traffic over port 443 is
required for ESRS functionality.
l The ESRS gateway server operating environment must be version 3.12.00.04 or
later.
NOTICE
Never manually add or remove a Unity system from an ESRS Gateway server. Only
add or remove a storage system from a gateway server with the Unisphere ESRS
configuration wizard.
Note
Full-access support is only provided to customers that have direct Online Support.
Note
Limited-access account privileges are sufficient for registering and licensing storage
systems. However, you cannot configure ESRS for a storage system based on an
account that has only Limited-access privileges.
Required Description
Information
Relationship with Indicate whether your organization is a partner, supplier, or customer
EMC of EMC products.
Required Description
Information
Site ID (Location) Select an existing Site ID (if one has already been created for your
organization) or select your organization from a database of
organization profiles.
Note
The email address associated with the initial Limited-access account becomes the
business email domain associated with the new customer profile.
Note
You must specify valid support credentials (user name and password associated with
an active Online Support account with Full-access privileges) before you can
configure ESRS.
16 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Requirements and Configuration
Note
Note
18 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CHAPTER 3
Configure Remote Support using Unisphere
This chapter describes the processes to provision the ESRS feature using the
Unisphere interface.
Topics include:
Option Description
Integrated Before the readiness check runs, the ESRS end user license
(physical agreement (ESRS EULA) must be accepted. After the
deployments license agreement is accepted, click Next to run the check.
only)
Note
20 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Configure Remote Support using Unisphere
Option Description
Centralized— Specify the Network Address of the ESRS Gateway
Monitor with a server that is used to connect to the EMC enterprise
Centralized ESRS and ensure that port 9443 is open between the
configuration Gateway server and the storage system.
Integrated— This feature may not be available in your
Monitor with this implementation. You must go through the Configure
storage system's ESRS process and accept the ESRS EULA. You can
integrated ESRS select whether to have Outgoing only or Outbound/
client (physical Inbound connectivity with your remote service provider
deployments only) and whether to send data to CloudIQ. Use of the Policy
Manager and proxy servers is optional and only
applicable when you select Integrated ESRS with
Outbound/Inbound connectivity. Once selected, you
can configure a Policy Manager and Proxy Server
settings.
Note
Note
If the Status remains as Transitioning and does not change after several minutes (the
time it should take to test connectivity), contact Online Support.
Note
If the license agreement was accepted during running of the Readiness check
before you configure ESRS, the license agreement does not appear again.
2. Run a Network check. If a proxy server has been configured for the storage
system, you can make changes, if necessary, by clicking the pencil icon beside
Connect Through a Proxy Server and filling in the appropriate information in
the dialog box that appears.
Note
Changes made on this page apply to the global proxy settings for the storage
system.
When you submit the Network Check page and the server details have been
entered, network tests are performed to check connectivity between the device
and the core node. If you selected Integrated ESRS with Outbound/Inbound
connectivity, the back-end Global Access Servers (GAS) are also included in
the network tests. The network connectivity from ESRS to all the required
back-end servers is checked. If the tests are unsuccessful, which means the
device is unable to connect to some or all of the back-end servers, the results
are displayed at the top of the wizard page. If this is the case, verify that the
appropriate firewall hosts and ports (443 and 8443) are open to the back-end
servers. All tests must be successful. You are responsible for resolution of proxy
server and firewall issues that impact connectivity to the ESRS infrastructure.
3. Verify the Customer Contact Data information. (This verification only appears
and is applicable when you have selected Integrated ESRS with Outbound/
Inbound connectivity. )
To add or change Customer Contact Data information, click the pencil icon
beside Contact Information and fill in the appropriate information in the dialog
box that appears. This information is required to proceed with the ESRS
configuration. Ensure that this information is accurate. Support will use this
information to respond to your support issues.
4. Go through the email verification process.
This step adds an extra level of authentication and helps to ensure that you are
the correct user and authorized to enable ESRS on the storage system.
22 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Configure Remote Support using Unisphere
5. (Optional, only applicable when you have selected Integrated ESRS with
Outbound/Inbound connectivity.) If your storage system will use a Policy
Manager to set authorization permissions, select Policy Manager and fill in the
appropriate information for the Policy Manager. If the Policy Manager will use a
Proxy Server, select Use Proxy Server for Policy Manager and fill the
appropriate information for the Proxy Server. If you will not be using a Policy
Manager, go to step 6.
The Policy Manager dialog box appears. If you are using Policy Manager, it
must be installed and operational. It is recommended that the SSL strength be
High.
6. (Optional) To enable CloudIQ, select Send data to CloudIQ.
CloudIQ can be enabled or disabled after completing ESRS configuration from
Settings > Support Configuration > CloudIQ.
Once ESRS is successfully configured, the relevant certificates are installed,
ESRS is provisioned and registered on the Support Center, and the Results
page appears.
7. Check the Overview panel on the Service page (Dashboard > System >
Service) to see the status of the ESRS connection.
Note
If the Status appears to remain as Transitioning and does not change after several
minutes (the time it should take to test connectivity), contact Support.
Note
The Policy Manager can be configured or changed after configuring ESRS by clicking
Edit on the Settings > Support Configuration > EMC Secure Remote Services
page.
Proxy Server and filling in the appropriate information in the dialog box that
appears.
n The Verify Contact Information and System Location information panel in
the ESRS wizard is enabled with an edit option (pencil icon) beside both
Contact Information and System information. System information can be
updated with the exception of the Site ID number.
n You can change the ESRS type from Integrated (Outboung/Inbound) to
Centralized and specify the applicable information.
24 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CHAPTER 4
Configure Remote Support using CLI
This chapter describes the processes to provision the ESRS feature using the
UEMCLI. For full documentation of these and related commands, see the Unisphere
Command Line Interface User Guide.
Topics include:
Qualifier Description
-enableSupportProxy Specifies whether to enable or re-enable,
or disable the proxy server. Valid values
are:
l yes
l no
Note
Example:
uemcli -u <adminUser> -p <password> -sslPolicy accept /sys/
support/config set -supportProxyAddr 10.0.0.1 -supportProxyPort
1080 -supportProxyUser user1 -supportProxyPasswd password123 –
supportProxyProtocol http
26 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Configure Remote Support using CLI
Qualifier Description
-location Specify an updated location name.
-contactEmail Specify the new contact email address for the
system.
-contactPhone Specify the new contact phone number for the
system.
-contactMobilePhone Specify the new contact mobile phone number for
the system.
-contactFirstName Specify the new contact first name for the
system.
-contactLastName Specify the new contact last name for the system.
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
info set -contactFirstName Zach -contactLastName Arnold -
contactEmail [email protected] -contactPhone 1233456789 -
location here -contactMobilePhone 987654321
3. Set the support credentials:
Format:
/sys/support/account set -user <value> {-passwd <value>|-
passwdSecure}
Action qualifiers:
Qualifier Description
-user Specify the user name of the support account.
-passwd Specify the new password of the support account.
-passwdSecure Specifies the password in secure mode - the user will be
prompted to input the password.
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/account set -user user1 -passwd Password123
4. Accept the ESRS End User License Agreement (EULA):
Format:
/sys/support/esrsi set -acceptEula yes
Example:
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/esrsi set -type twoWay
6. Check the network connectivity from the Integrated ESRS client to the EMC
servers:
Format:
/sys/support/esrsi checkNetwork
Note
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/esrsi checkNetwork
7. Request an access code for Integrated ESRS. This access code is emailed to
the email account user. The access code is only valid for 30 minutes.
Format:
/sys/support/esrsi requestAccessCode
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/esrsi requestAccessCode
8. Validate access code and review site information:
Format:
/sys/support/esrsi validateAccessCode -accessCode <value>
Action qualifiers:
Qualifier Description
-accessCode Specifies the access code that was received by email from
the IT service base.
Note
Example:
uemcli -u Local/joe -p MyPassword456! /sys/support/esrsi
validateAccessCode -accessCode 2216789
9. Enable Integrated ESRS:
Format:
28 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Configure Remote Support using CLI
Qualifier Description
-enable Specifies whether to enable or disable the ESRS. Valid values
are:
l yes
l no
Note
Note
Note
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/esrsi set -enable yes
10. Optionally, configure the Policy Manager and policy proxy server attributes:
Format:
/sys/support/esrsi/policymgr set [-enable {yes|no} ] [-
address <value> ] [-port <value>] [-protocol {http|https}]
[sslStrength {high|medium|low}] [-enableProxy { yes|no}]
[-proxyAddr <value>] [-proxyPort <value>] [-proxyUser
<value> {-proxyPasswd <value>|-proxyPasswdSecure}] [-
proxyProtocol {http|socks}]
Action qualifiers:
Qualifier Description
-enable Specifies whether to enable or disable the ESRS policy
manager. Valid values are:
l yes
l no
Qualifier Description
Note
Note
Example:
uemcli -u Local/joe -p MyPassword456! -sslPolicy accept /sys/
support/esrsi/policymgr set -enable yes -address 10.0.0.2 -port
1080 -protocol http -sslStrength high -enableProxy yes -
proxyAddr 10.0.0.3 -proxyPort 1080 -proxyUser user2 -
proxyPasswdSecure -proxyProtocol http
30 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
CHAPTER 5
Troubleshooting
The service command svc_esrs_ve allows the user to perform basic tasks on ESRS
VE, such as checking the status of the service and network or cleaning up the
configuration. For more information, refer to the EMC Unity™ Service Commands
Technical Notes document.
This chapter provides information about the probable causes of problems that you
may encounter when enabling and running the ESRS feature and the recommended
actions to take to resolve them.
Topics include:
Troubleshooting 31
Troubleshooting
Note
You may have provided valid login credentials Verify your Site ID number is on Online
but the credentials are not associated with Support:
your Site ID where the storage system is
1. Log in to Online Support with your
located. A Site ID is created in Support
credentials.
systems for each location within your
organization where EMC products have been 2. Select Service Center.
installed.
3. On the Service Center page, below the
Sites and Contracts area, click
Administer a Site.
4. Ensure that the site where the storage
system is installed is listed in the My Sites
area.
32 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration
Troubleshooting
Note
A Policy Manager is configured but is not Check that the Policy Manager is online. From
reachable. Unisphere, go to Settings > Support
Configuration > EMC Secure Remote
Service and verify that the Policy Manager
protocol, port, and network name/IP address
settings are configured correctly.
A system configured with the ESRS Confirm that port 9443 is open to allow REST
centralized implementation has problems with API calls from the storage system to the
HTTP keep-alive and does not appear to be ESRS Gateway.
connected.
34 Unity All Flash, Unity Hybrid, UnityVSA 4.3 Secure Remote Services Requirements and Configuration