Intel AMT KVM: Accessing Multiple Servers Behind One Public IP Address

Bunkai

Reputable
Apr 6, 2015
3
0
4,510
I have to host multiple servers in a collocation center which is distant over 250 km. I need to have as good remote control over the servers as possible. In other words, I need to be able to access BIOS of the servers, be able to turn the servers ON or OFF, or to remotely re-install the Operating System.


For this purpose the relatively fresh Intel vPro AMT KVM technology is just optimal and cost effective. I can access just one server over the public IP address of that server.


What I do not know is, how to access multiple servers via Intel vPro KVM, if they all are behind one Public IP Address. Will technologies like IP Address Translation or Port Forwarding work for me? Could you advise please, how to configure the network so, that I would be able to access any of the servers on the network if of course they all support Intel vPro AMT (and KVM)?


Thank you in advance.
 
Solution
VPN into the local network. They likely have separate private IPs - in fact, it's generally standard practice for the KVM kit to be on a different network or subnet from the main network.

You seriously do not want to expose stuff like virtual KVMs or BIOS to the open net.
VPN into the local network. They likely have separate private IPs - in fact, it's generally standard practice for the KVM kit to be on a different network or subnet from the main network.

You seriously do not want to expose stuff like virtual KVMs or BIOS to the open net.
 
Solution

Bunkai

Reputable
Apr 6, 2015
3
0
4,510



Hi thank you for your answer. To be hones, I do not have too much information with hardware VPN. So far, all I have used was software VPN like LogMeIn Hamachi.

Let me therefore say in my own words what you meant to be sure I understand. I have to take the advantage of the Firewall VPN. I will create a software VPN between the Firewall and my PC. Through the firewall I will then be able to pick up any PC of my choice by selecting the private static IP address.

I have one more scenario. If I have only one server, at the beginning, I hoped, I could go with software firewall and not needing a separate firewall appliance. If I want to go in this direction, I simply have to either take the risk and open the ports needed for Intel KVM or purchase a separate firewall even for the only one server. Which direction should I go, please?