Broadcom ASF Management Console for Windows
===========================================

$Archive: /Source/BCM5700/asf/MgmtCon/readme.txt $
$Revision: 4 $
$Date: 7/18/05 2:06p $
$Author: Swindell $


ASF Management Console Background
---------------------------------
This program is a replacement for the Broadcom AsfNetMon application and
should be used for all future ASF testing and verification in the Broadcom
network controller group. It supports all the features of AsfNetMon, has far
fewer bugs, conforms more closely to the ASF specification, and supports
ASF 2.0 (secure management).


ASF Background
--------------
The ASF (Alert Standard Format) defines methods for remote management and
control of systems in OS-absent environments.

The Remote Management and Control Protocol (RMCP), defined as part of the
ASF 1.0 protocol specification, provided no security mechanisms to protect
desktop systems from unauthorized remote management. An ASF 1.0 managed
client listens for RMCP messages on UDP port 623.

The ASF 2.0 protocol specification introduced the RMCP Security-Extensions
Protocol (RSP) to provide authentication and integrity services for remote
management. The secure RMCP protocol defined in ASF 2.0 listens for secure
RMCP messages on UDP port 664.


About ASF 2.0
-------------
There are 2 supported authenticated user "roles" for ASF 2.0 remote
management: Operator and Administrator. The implication is that authenticated
Administrators may have more "rights" than authenticated Operators, but that
determination is actually made by the individual that configures the Security
Policy of the managed client. It's actually possible for an Administrator to
have fewer rights than an Operator, if the Security Policy is configured as
such.

The non-destructive RMCP commands (e.g. ping, capabilities request, and system
state request) can be sent to an ASF 2.0 managed client using a
"Bypass Session" which provides no authentication or integrity. However, the
"Remote Control" commands (i.e. Reset, PowerUp, PowerDown, and PowerReset)
will usually require an authenticated ("open") secure session with the proper
"rights" to execute these commands depending on the configured "Remote
Capabilities" of the managed client.


You Will Need
-------------
ASF testing requires a minimum of two computers:

1. A managed client with an ASF-enabled Broadcom Ethernet network controller.
   This PC should be tested in both OS-present and OS-absent states.

2. A management console with any Ethernet network controller, running ASF
   Management Console software (presumably the Broadcom ASF Management Console
   for Windows).


Installation
------------
No "installation" of the Broadcom ASF Management Console is required other
than executing the AsfMgmtCon.exe file. If you have existing Windows Registry
Keys with AsfNetMon settings, it will use those settings for the managed
client IP address history and the default managed client IP address.

Any changes to the application form's size or position, the ASF 2.0 security
settings, most checkboxes, and the managed client's IP address (and IP history)
are automatically saved to the Windows registry when the application is
shutdown and automatically restored when the application is later run on the
same system.

In order for the Management Console to be able to receive Platform Event Traps
(a.k.a. "Alerts" or "Events"), you must have Windows SNMP Services installed
and running. 


Ports
-----
If you have a firewall between the management console and the managed client,
you may need to open or forward the following ports:

UDP 623 (RMCP)
UDP 664 (Secure RMCP)
UDP 162 (SNMP Trap)

An Broadcom ASF-enabled network controller transmits PET events from UDP port
1026.


Configuration
-------------
The "Settings" tab allows adjustment of RMCP time-out and maximum log line
values. These settings do not normally require any modification.

The "Security" tab (only visible when the "Secure Management" checkbox is
checked on the "Manage" tab) allows the user to configure the security-related
parameters (user name, keys, etc.).

In order for the Management Console to be able to receive Platform Event Traps
(a.k.a. "Alerts" or "Events") from a managedc client, that client must be
configured to transmit alerts to the IP address of the management console
system.


Managing a Client
-----------------
The "Manage" tab has all the controls required for management of an ASF
"managed client". Enter the IP address of the client you wish to manage in the
"Managed Client (IP Address)" edit box or pick one from the IP address history
drop down box. To add an IP address to the history, hit the ENTER key while
editing the IP address. To remove an IP address, hit the DELETE key.

To send a management (RMCP) command to the managed client, select the desired
command from the "Management Command" combo box and click the "Send" button.
To send the same command repeatedly to the client, check the "Repeat" checkbox
and enter the repeat count, with an optional "Delay" (in milliseconds) between
each command/response sequence. You may also turn off the logging and status/
cursor indications to increase the number of commands that may be sent over a
period of time, attempting to saturate the client with commands.

To quickly send a single management command to the managed client, use one of
the toolbar buttons for: Ping, Capabilities Request, System State Request,
Reset, Power Up, Power Down, or Power Reset.

The Reset, Power Up, and Power Reset commands have optional "Boot Options"
associated with them. The parameters of these "Boot Options" are configured
with the "Boot Options" tab. Note: Not all managed clients support all the
possible boot option values; use the "Capabilities Request" command to query
which boot options are supported by the managed client.

In order to create an authenticated session with a client using ASF 2.0, you
must enter the security parameters in the "Security" tab and either click the
"Authenticate" button or send the Management "Authentication" command from the
"Manage" tab (effectively the same thing).


Secure Sessions
---------------
Once a session is open, you may use any remote control commands that require a
successfully-authenticated secure session.

If a session is not "closed", it will eventually time-out (effectively
closing itself). If the system loses AC power, any open sessions will be
effectively closed. A Broadcom ASF-enable network controller supports a
maximum of 2 simultaneous secure sessions. For these reasons, secure sessions
should not be left open any longer than necessary.

You may use the "Abort Session" button on the "Security" tab to force the
management console to "forget" about a currently open secure session.

/* End of File */