APC UPS Data Center & Enterprise Solutions Forum
Schneider, APC support forum to share knowledge about installation and configuration for Data Center and Business Power UPSs, Accessories, Software, Services.
Posted: 2021-06-30 01:56 AM . Last Modified: 2024-03-11 12:19 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 01:56 AM . Last Modified: 2024-03-11 12:19 AM
So I have a number of SmartUPS units with AP9630 NMC's, and today I was testing upgrading them from v5.1.7 to v6.5.6. I tried it on 2, and while the upgrade was successful, I am having issues with the web console in 6.5.6 that I was not having in 5.1.7 - even though I am accessing the web interface on a local network, my company has a proxy that is load balanced over 4 servers I have to go through, and the UPC sees me as connecting from one of these IPs rather than my own. It seems that after I log in, when I click any link in the interface and the proxy URL sends me through a different server than it did when I logged in, then the web interface will make me re-authenticate. This will give a new session key, so even if the next click takes me back to the last server, I get asked to authenticate again. The end result is it feels like I have to enter my username & password for every link I click on in the web interface. You can see from the attached screenshot that in less than a minute, I had to authenticate 4 times and got 4 different session keys.
Is there anyway to change the security settings to not be so strict? Or any suggestions that do not involve changes on the side of the proxy?
Unfortunately getting group policy updated to allow this IP range to bypass the proxy is something that is a lot easier said than done, as that is handled by a different team behind loads of fun bureaucratic red tape. Truthfully it'd just be easier to downgrade my 2 I tested the update on and leave the rest at 5.1.7. Considering 25% of my UPS's have AP9617 nmc's running 3.7.2 and can't be upgraded, maybe I should just leave it...
Any help is appreciated!
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 01:56 AM . Last Modified: 2024-03-11 12:19 AM
Hi,
Unfortunately I think this is going to be a problem. I was thinking that maybe disabling the "require authentication cookie" setting may help under Web configuration but I refreshed myself on what it exactly does by reading this FAQ: http://www.apc.com/us/en/faqs/FA235784
As it explains at the bottom, even without the cookie setting I was thinking of, the NMC is looking for the session ID and remote IP to match at a bare minimum to prevent session hijacking and there is no way to modify this logic or behavior for this particular (understandable) situation
*Edit* if you do decide to downgrade, which I understand why you'd want to (but still don't recommend based on bug fixes, security updates, new features, etc), please make sure to read this FAQ about upgrade/downgrade and caveats: http://www.apc.com/us/en/faqs/FA167693
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 01:56 AM . Last Modified: 2024-03-11 12:19 AM
Hi,
Unfortunately I think this is going to be a problem. I was thinking that maybe disabling the "require authentication cookie" setting may help under Web configuration but I refreshed myself on what it exactly does by reading this FAQ: http://www.apc.com/us/en/faqs/FA235784
As it explains at the bottom, even without the cookie setting I was thinking of, the NMC is looking for the session ID and remote IP to match at a bare minimum to prevent session hijacking and there is no way to modify this logic or behavior for this particular (understandable) situation
*Edit* if you do decide to downgrade, which I understand why you'd want to (but still don't recommend based on bug fixes, security updates, new features, etc), please make sure to read this FAQ about upgrade/downgrade and caveats: http://www.apc.com/us/en/faqs/FA167693
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.