Skip to main content

Encapsulation management

When you manage Lenovo chassis and servers in Lenovo XClarity Administrator, you can configure Lenovo XClarity Administrator to change the firewall rules for the devices so that incoming requests are accepted only from Lenovo XClarity Administrator. This is referred to as encapsulation. You can also enable or disable encapsulation on chassis and servers that are already managed by Lenovo XClarity Administrator.

When enabled on devices that support encapsulation, Lenovo XClarity Administrator changes the device encapsulation mode to encapsulationLite, and changes the firewall rules on the device to limit incoming requests from only this Lenovo XClarity Administrator.

When disabled, the encapsulation mode is set to normal. If encapsulation was previously enabled on the devices, the encapsulation firewall rules are removed.

Attention
If encapsulation is enabled and XClarity Administrator becomes unavailable before a device is unmanaged, necessary steps must be taken to disable encapsulation to establish communication with the device. For recovery procedures, see lenovoMgrAlert.mib file and Recovering management with a CMM after a management server failure.
Note
  • Encapsulation is not supported on switches, storage devices, and non-Lenovo chassis and servers.

  • When the management network interface is configured to use the Dynamic Host Configuration Protocol (DHCP) and when encapsulation enabled, managing a rack server can take a long time.

For more information about encapsulation, see Enabling encapsulation.