HOME LITERATURE Business Cases
ZoneRanger Integration with HP NNM Print

Tavve’s ZoneRanger appliance allows HP Network Node Manager to transparently reach into the DMZ over a single encrypted SSL Port.

ICMP and SNMP into the DMZ are sent over one port and SNMP traps are sent over this same encrypted SSL connection, allowing for one central NNM server to monitor internal and external (DMZ) devices.   One instance of snmpCollect can now poll all nodes into a central reporting database. SNMP traps and syslog messages are forwarded out of the DMZ to the NNM server over a single secure TCP port. Bi-directional NAT is possible with the ZoneRanger. This allows status polling of overlapping IP addresses with ICMP and SNMP. It also can be used to modify the source address of SNMP traps and syslog messages from nodes with duplicate IP addresses so that they appear unique.

In environments where NNM maps are not used, but rather “management by exception” is the rule, the ZoneRanger can be configured as a stand-alone status poller. This off loads the central NNM server and frees node licenses for deployment elsewhere in the enterprise. The ZoneRanger can perform auto-discovery using Tavve’s patented technology or to only poll nodes that are added to its database manually. Its status poller can use ICMP and/or SNMP to poll interfaces. There is also a TCP port poller for testing application availability. The syslog and trap receiver on the ZoneRanger can filter messages before forwarding them on to a central NNM or ITO server. Syslog messages can be converted to SNMP traps for processing with NNM on Windows.

 

How does ZoneRanger fit into your network?

What others are saying...

"Tavve has developed the ZoneRanger product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols."
Tavve: ZoneRanger 
Subraya Mallya
PrudentCloud.com


"Without a more secure approach to managing the protocols and tools that manage the network - including the 'trusted' internal network - enterprises may be exposing themselves to more risk than they realize."

Scott Crawford, CISSP, ISSAP, ISSMP
Senior Analyst, Enterprise Management Associates

"ZoneRanger effectively extends the reach of management applications to devices located beyond firewalls, eliminating the need for complicated firewall configurations, extensive agent deployments, or expensive application replication. ZoneRanger also provides security, acting as an application layer proxy firewall, inspecting and validating the traffic relayed between applications and devices.
Jim Doble, CISSP
CTO, Tavve