Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

configure levels of access to web browser

EcoStruxure IT forum

Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results forย 
Showย ย onlyย  | Search instead forย 
Did you mean:ย 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT
  • EcoStruxure IT forum
  • configure levels of access to web browser
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Cory_McDonald
Admiral Cory_McDonald Admiral
124
Jef
Admiral Jef Admiral
108
gsterling
Captain gsterling Captain
71
APC_Steve
Captain APC_Steve Captain
62
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Solved Go to Solution
Back to EcoStruxure IT forum
Solved
DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

0 Likes
8
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

configure levels of access to web browser

Is there a way or configuration that I can configure on the DCE V7.2.0 for prohibit an user or group of user from accessing to browser for launch to devices?

Objetive:
The customer would like configure an group of user that can access the devices by internal web browser of DCE, an another group of user that can't do it.

(CID:116365234)

Labels
  • Labels:
  • Data Center Expert
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic

Accepted Solutions
DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

0 Likes
3
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

Hi Elivaldo da Silva Campos,

I also solved this problem and unfortunately the access control tools, built into the DCE server, did not help me.

My question is: is network access to monitoring devices from Private LAN carried out directly from clients PC or through a privateproxy embedded in the DCE server?

In the first case, I solved this problem by simply prohibiting network access by the external firewall to monitoring devices for users who should not have such access. But at the same time, they can monitor these devices without restrictions from the DCE WEB-console or from the DCE-client.

In the second case, I also used an external firewall, through which I allowed access to the DCE-server from Public LAN on port 80 (http) only to users, who must have via DCE privateproxy access to monitoring devices. And I allowed all other users on this external firewall to access the DCE server from Public LAN only on port 443 (https). On the DCE server, access to both the http (80) and https (443) protocols must be configured. This is in the first place. And secondly, on all monitoring devices from Private LAN it is necessary to configure access on port 80 (http). The https (443) protocol setting on the monitoring devices is possible, but not required. Thus, since access to monitoring devices from Private LAN is through the DCE privateproxy, which does not support working through the https protocol (this is its drawback, but for us this is an advantage ๐Ÿ˜€, we get an excellent access delimitation. Users, who do not need to have access to monitoring device interfaces have access to the DCE server only via the https protocol, but thus do not have access to the monitoring devices from either the DCE WEB-console or from the DCE client.

This is the solution I have been using successfully for several years.

With best regards.

(CID:116918078)

See Answer In Context

Reply

Link copied. Please paste this link to share this article on your social media post.

Replies 8
DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

0 Likes
2
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

Dear Elivaldo,

Struxureware Data Center Expert UI or Web browser access can be controlled by User and User Group authentication method. Therefore, please set the user password accordingly to provide an access to the UI and Web client of DCE. 

There is a video tutorial available on Managing Users and User Groups on StruxureWare Data Center Expert.

https://dcimsupport.apc.com/display/VIDEO/Managing+Users+and+User+Groups+on+StruxureWare+Data+Center...

Note: Device level access password also can be changed on the device web interface to prevent other users to access the device web interface. 

I hope it helps. 

Regards,

Bala

(CID:116917945)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

In response to DCIM_Support
0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:08 AM

Hi team, good morning,

Thanks so much your help.
The devices are installed on private lan of DCE.
I can not prevent this access only selecting the role "StruxureWare Data Center Expert Proxy"?
I tryed to several test with this objetive, but I don't got success.
I am understanding that this role don't have function... is it?

 

 

 

Best regards, thank you so much again!!

(CID:116921107)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

In response to DCIM_Support
0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:58 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

That's why, what you want to do can not be done on the DCE-server in principle. Therefore, I published a practical workaround. And it is not the only one. For example, you can still restrict access based on the group policies of MS AD, if authentication is done in this way on the DCE-server. But this is a completely different topic...

I am always glad to help.

(CID:116921111)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

0 Likes
3
1783
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

Hi Elivaldo da Silva Campos,

I also solved this problem and unfortunately the access control tools, built into the DCE server, did not help me.

My question is: is network access to monitoring devices from Private LAN carried out directly from clients PC or through a privateproxy embedded in the DCE server?

In the first case, I solved this problem by simply prohibiting network access by the external firewall to monitoring devices for users who should not have such access. But at the same time, they can monitor these devices without restrictions from the DCE WEB-console or from the DCE-client.

In the second case, I also used an external firewall, through which I allowed access to the DCE-server from Public LAN on port 80 (http) only to users, who must have via DCE privateproxy access to monitoring devices. And I allowed all other users on this external firewall to access the DCE server from Public LAN only on port 443 (https). On the DCE server, access to both the http (80) and https (443) protocols must be configured. This is in the first place. And secondly, on all monitoring devices from Private LAN it is necessary to configure access on port 80 (http). The https (443) protocol setting on the monitoring devices is possible, but not required. Thus, since access to monitoring devices from Private LAN is through the DCE privateproxy, which does not support working through the https protocol (this is its drawback, but for us this is an advantage ๐Ÿ˜€, we get an excellent access delimitation. Users, who do not need to have access to monitoring device interfaces have access to the DCE server only via the https protocol, but thus do not have access to the monitoring devices from either the DCE WEB-console or from the DCE client.

This is the solution I have been using successfully for several years.

With best regards.

(CID:116918078)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

In response to DCIM_Support
0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

Spezialist, good morning.


I understood that I can't prevent this access by DCE, but I need understand the funciton of "user roles" ==> "StruxureWare Data Center Expert Proxy", please, can you explained for me? 
Certainly the customer will do this question for me.

Best regards

(CID:116921095)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

In response to DCIM_Support
0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

Hi Elivaldo da Silva Campos,

It seems, that the DCE online help is somewhat outdated: I still could not understand, here is the Telnet access and what does it have to do with the SOCKS proxy? This is a question, primarily for DCE developers.

And now, in fact: the StruxureWare Central Proxy role is used, if you want to allow launch to the locally installed APC Adwanced View software from the DCE-client (and only). For example:


And this, in turn, gives access to the 80 (http) port (Telnet by default is disabled) of the NetBotz appliance (and only) in Private LAN via the built-in DCE-server SOCKS proxy (if it is of course enabled) through port 1080. For example:


I.e., if you sum up, the role StruxureWare Central Proxy allows you to access the NetBotz appliance (and only) in Private LAN and only from the DCE-client.

With best regards.

(CID:116921101)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

In response to DCIM_Support
0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2024-04-08 01:07 AM

spezialist, good morning,

 

Thank you so much, I appreciate your answer.

 

Best regards,

(CID:116921099)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2023-10-22 04:27 AM

0 Likes
0
1782
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2020-07-03 02:59 PM . Last Modified: โ€Ž2023-10-22 04:27 AM

superhero.png

This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.

Reply

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings ยฉ 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of