Utilizing management network for secured configuration and platform management
A network connection device having a security processor exchanges data traffic between a data network and a host computer via a network port. Security management data is exchanged exclusively between the security processor and a management network via a management network connectivity port that is inaccessible to the data traffic.
1. A method for isolating security management data in a network, comprising the steps of:
connecting a host computer to a network connection device having a network port, access to a management network connectivity port, a sideband interface and a security processor;
connecting a baseboard management controller to the sideband interface, wherein the management network connectivity port is disposed in the baseboard management controller;
exchanging data traffic on a first path that extends between a data network and the host computer via the network port of the network connection device;
isolating security and network configuration functions of the network connection device from the host computer by exchanging security management data relevant to the security and network configuration functions between the security processor and a management host on a management network via a second path that extends from the security processor to the management host via the management network connectivity port;
directing the second path from the management network connectivity port to the security processor via the sideband interface; and
with the baseboard management controller producing traffic directed to the sideband interface for configuring the security processor.
2. The method according to claim 1 , wherein the management network connectivity port is integral with the network connection device.
3. The method according to claim 1 , wherein the security processor performs encryption and decryption of the data traffic.
4. The method according to claim 1 , wherein the security processor manages an access control list.
5. An apparatus, comprising:
a network interface device comprising:
a network port, configured for connection to a data network so as to exchange data traffic between the data network and a host computer on a first path;
a sideband interface; and
a security processor configured to control security and network configuration functions of the network interface device;
a baseboard management controller connected to the sideband interface;
a management network connectivity port in the baseboard management controller that is connectable to a management network, and operative for exchanging security management data relevant to the security and network configuration functions between the security processor and a management host on the management network via a second path that extends from the security processor to the management host via the management network connectivity port, wherein the basement management controller is operative for producing traffic directed to the sideband interface for configuring the security processor; and
a switch in the baseboard management controller that provides access for the security management data to the security processor on the second path via the sideband interface and operative to separate the security management data from traffic related to the host computer.
6. The apparatus according to claim 5 , wherein the baseboard management controller comprises:
a control interface for communicating with the host computer.
7. The apparatus according to claim 5 , wherein the security processor performs encryption and decryption of the data traffic.
8. The apparatus according to claim 5 , wherein the security processor manages an access control list.