Remote Screen Administration
Remote SunScreen Administration is a SunScreen configuration
that consists of a Screen that is physically separate from the
Administration Station. The Screen can be both headless and keyboardless,
and can communicate with the Administration Station through a TCP/IP
interface that need not be exposed to the Internet (although it might
be exposed to the local network, depending on the topology you
use and your choice of Stealth or Routing mode). The communications
between the Screen and the Administration Station are encrypted with
SKIP.
Remote Administration can be used for:
-
A single Screen
-
A group of centrally managed Screens
If you use a remote Administration Station
for Centralized Management, you can
use one of the following scenarios:
-
The remote Administration Station connects the the Secondary Screens
without going through a firewall.
-
The remote Administration Station connects to the Secondary Screens
through a firewall.
Remote Administration without going through a firewall
If the remote Administration Station connects to the Secondary Screens
without going through a firewall, use Skiphost to enable access to
the Secondary Screens by giving it information about the SKIP ID for
the Secondary Screen.
Remote Administration through a firewall
If the remote Administration Station connects to the Secondary Screens
through a firewall, perform the following operations.
-
Enable access to the Secondary Screens by giving it information about the
SKIP ID for the Secondary Screen.
-
Allow SKIP service from the remote admin to the Secondary Screen on
each firewall.
-
Allow certificate discovery service from the remote Administration
Station to the Secondary Screen on each firewall through which the
Administration Station must communicate.
Note: If the firewall that the Administration Station goes through
is not SunScreen, the equivalent services must be allowed.
See also
Adding a Remote Administration
Station
Centralized Management