Black Box kv1081a Calculating the mask for IP access control, Single locations, All locations

Page 82

Calculating the mask for IP access control

The IP access control function uses a standard IP address and a net mask notation to specify both single locations and ranges of addresses. In order to use this function correctly, you need to calculate the mask so that it accurately encompasses the required address(es).

Single locations

Some of the simplest addresses to allow or deny are single locations. In this case you enter the required IP address into the ‘Network/Address’ field and simply enter the ‘Mask’ as 255.255.255.255 (255 used throughout the mask means that every bit of the address will be compared and so there can only be one unique address to match the one stated in the ‘Network/Address’ field).

All locations

The other easy setting to make is ALL addresses, using the mask 0.0.0.0 As standard, the IP access control section includes the entry: +0.0.0.0/0.0.0.0 The purpose of this entry is to include all IP addresses. It is possible to similarly exclude all addresses, however, take great care not to do this as you instantly render all network access void. There is a recovery procedure should this occur.

Address ranges

Although you can define ranges of addresses, due to the way that the mask operates, there are certain restrictions on the particular ranges that can be set. For any given address you can encompass neighbouring addresses in blocks of either 2, 4, 8, 16, 32, 64, 128, etc. and these must fall on particular boundaries. For instance, if you wanted to define the local address range:

192.168.142.67 to 192.168.142.93

The closest single block to cover the range would be the 32 addresses from:

192.168.142.64 to 192.168.142.95.

The mask needed to accomplish this would be: 255.255.255.224

When you look at the mask in binary, the picture becomes a little clearer. The above mask has the form: 11111111.11111111.11111111.11100000

Ignoring the initial three octets, the final six zeroes of the mask would ensure that the 32 addresses from .64 (01000000) to .95 (01011111) would all be treated in the same manner. See Net masks - the binary explanation for details.

When defining a mask, the important rule to remember is:

There must be no ‘ones’ to the right of a ‘zero’.

For instance, (ignoring the first three octets) you could not use a mask that had 11100110 because this would affect intermittent addresses within a range in an impractical manner. The same rule applies across the octets. For example, if you have zeroes in the third octet, then all of the fourth octet must be zeroes.

The permissible mask values (for all octets) are as follows:

Mask octet

Binary

Number of addresses encompassed

255

11111111

1 address

254

11111110

2 addresses

252

11111100

4 addresses

248

11111000

8 addresses

240

11110000

16 addresses

224

11100000

32 addresses

192

11000000

64 addresses

128

10000000

128 addresses

0

00000000

256 addresses

If the access control range that you need to define is not possible using one address and one mask, then you could break it down into two or more entries. Each of these entries could then use smaller ranges (of differing sizes) that, when combined with the other entries, cover the range that you require.

For instance, to accurately encompass the range in the earlier example:

192.168.142.67 to 192.168.142.93

You would need to define the following six address and mask combinations in the IP access control section:

Network/address entry

Mask entry

 

192.168.142.67

255.255.255.255

defines 1 address (.67)

192.168.142.68

255.255.255.252

defines 4 addresses (.68 to .71)

192.168.142.72

255.255.255.248

defines 8 addresses (.72 to .79)

192.168.142.80

255.255.255.248

defines 8 addresses (.80 to .87)

192.168.142.88

255.255.255.252

defines 4 addresses (.88 to .92)

192.168.142.93

255.255.255.255

defines 1 address (.93)

®

   



81

Image 82
Contents ServSwitch CX Uno IP Contents Further information Index Many computers Global usersSAM formats ServSwitch CX Uno IP features front and rear What’s in the box What you may additionally needSingle unit rack brackets MountingDouble unit rack brackets Connections SAMTo connect the local user port Local userFrom video monitor From USB keyboard and mouse To connect the Global user IP network port ServSwitch CX Uno IP Front panelGlobal user IP network port IP network linkComputer system via SAM To connect a computer systemOutput lead from Power adapter Power in connectionTo connect the power supply Exceeds 40 degrees CentigradePower control port To connect and address the switch boxesSee also Cascading multiple unitsCascade tree Tips for successful cascading Connecting units in cascadeTo connect units in cascade Using cascaded computers Addressing computers in a cascadeIt is recommended that Second SAM in each pair is a Multiple video head connectionsUSB-type and that it is plugged Host computer port/channel Video off Remote switching controlCable from serial Control device Rear panel Configuration Overall initial configurationInitial configuration Menu layout To access the main menu HotkeysMain menu SecurityTo set an Admin password General security and configuration stepsTo enable general security Registering users and host computersWhat to do if the Admin password has been forgotten To clear a password and restore factory default settingsWhat is IP access control? Clearing IP access controlTo clear IP access control Full configuration by global user To configure the unit from a global user locationServSwitch CX Uno IP encryption settings Encryption settingsViewer encryption settings Networking issues Positioning ServSwitch CX Uno IP in the networkAddressing Placing ServSwitch CX Uno IP behind a router or firewallPort settings Firewall/router addressTo discover a DHCP-allocated IP address DNS addressingEnsuring sufficient security Placing ServSwitch CX Uno IP alongside the firewallPorts To configure the power sequences for each host computer Power switching configurationPower control sequences To control two or more ports simultaneouslyTo upgrade ServSwitch CX Uno IP models Upgrading ServSwitch CX Uno IP modelsRecovering from a failed upgrade To invoke backup/recovery modeAccessing the ServSwitch CX Uno IP Front panel indicatorsLocal user access Selecting a computerStandard hotkeys To select a computer using the Select Host menuWhen choosing Select Host menu here you can select computers by nameLogging in and out To select a computer using mouse buttonsTo select a computer using mouse buttons Advanced method To logConfirmation box To enable/disable the confirmation boxTo change banner colors or disable the banner Reminder bannerOrange dot indicators in the Select Host menu User preferences and functionsGlobal user access Global UserEnter the ServSwitch CX Uno IP address here and click OK Global user access via VNC viewerTo access via the VNC viewer To download the VNC viewerGlobal user access via web browser To access via your web browserWhen using the viewer window Using the viewer windowMenu bar Host selection ConfigureMouse pointers To select a hostAuto calibrate Access mode shared/privatePower switching Re-synchronize mouseControls Video Settings Enable Sun TranslationWhen entering codes Keyboard ControlIncreased by 50% when a slow link is detected Using automatic configurationsSetting the Threshold manually Custom Video Modes Advanced SettingsOverlap Capture If you need to enter a port number Viewer encryption settingsSupported web browsers Getting assistance TroubleshootingWhen logging on using VNC viewer, I cannot enter a username Techhelp@blackbox.co.ukAppendix 1 Local setup menus To access the local setup menusRestore Intellimouse Power ControlRestore Standard Mouse FunctionsReminder Color User PreferencesReminder Banner Screen SaverUser Timeout Mouse SwitchingSettings Disabled 2, 5, 10,15 or 20 Minutes Settings 1, 2, 5, 10, 30 Seconds, 1, 5, 10 MinutesSetup Options Settings Disabled, EnabledCompletely resets the ServSwitch CX Uno IP unit ConfigurationIP admin password, encryption settings, etc IP address, net mask, VNC port, etcUnit Configuration Network Configuration Settings 1200, 2400, 4800, 9600, 19200, 38400, 57600 Serial ConfigurationSettings Power Control, Sync Units Options PortReset Configuration To reset the ServSwitch CX Uno IP configurationTo access the remote configuration pages Appendix 2 Configuration pages via viewerMain configuration Logged on users User accounts Unit configuration Advanced unit configuration Time & date configuration IP Network Mask Network configurationIP Access Control IP GatewayTo reorder access control entries Setting IP access controlTo define a new IP access control entry To edit/remove access control entriesOptions Port Use Serial port configurationBaud Rate Add entry for unrecognized host Host configurationErase Host Configuration To create a new host entrySyslog Server IP Address Logging and statusTo copy and paste the log For further details To get hereLdap configuration Auto select Appendix 3 VNC viewer connection optionsColor/Encoding Preferred encodingInputs Enable all inputsDisable all inputs view-only mode CustomizeMisc Scale to Window Size ScalingNo Scaling Custom SizeIdentities Defaults ReloadDefaults Save Load / SaveAppendix 4 VNC viewer window options Encoding and color level Appendix 5 Browser viewer optionsSecurity IP addresses Appendix 6 Addresses, masks and portsNet masks Binary equivalent Net masks the binary explanationOperation with net mask Binary octet afterAll locations Calculating the mask for IP access controlSingle locations Address rangesSecurity issues with ports Ports9pin D-type female 4pin RJ9 Appendix 7 Cable and connector specificationsPower switch to power switch daisy chain cable SLAVE2 end 9pin D-type femalePermissible key presses Appendix 8 Hotkey sequence codesCreating macro sequences Appendix 9 Supported video modes Safety information General Public License LinuxEnd user licence agreement FCC Compliance Statement United States Radio Frequency EnergyEuropean EMC directive 89/336/EEC Canadian Department of Communications RFI statementCertification notice for equipment used in Canada Normas Oficiales Mexicanas NOM electrical safety statement Instrucciones de seguridad Index Server Access Module connection BlackBox subsidiary contact details Country Web Site/Email Phone Fax