Does an Intel server with RMM4 (IPMI BMC) need two IP addresses/cables?

I am managing a co-located server which has been rebooted and has not turned back on. It is in a data center and difficult to access, as such I am looking at Intel's RMM4 (compatible with the server board) as a solution.

Do I have to run two cables from the ISP's switch OR if there is a way to split a single cable? I assume that IPMI BMC needs to have it's own IP address?

Please note that the server is a computation server which is connected to a shared firewall and has a virtualized network (firewall + a virtual servers) and as such has one Ethernet cable connected to it.

Also, what are the security implications of IPMI BMC and how is it best to secure? I understand that Intel allows to limit access using IP addresses, is there anything else I should be aware of or do?

1
задан 17 March 2016 в 23:19
1 ответ

Ofhängeg vun der Plattform (zB, ech hunn dat mam Intel S2600GZ an ähnleche Systemer gesinn), kënnt Dir den RMM4 konfiguréieren fir eng vun den éischten zwee Onboard LAN Ports ze benotzen, oder den dedizéierten RMM4 Hafen.

Dës weisen sech als IPMI LAN Channels 1 - 3 un, déi éischt zwee sinn um Ethernet, déi lescht ass den dedizéierten Hafen.

Kuerz, Dir braucht nach ëmmer eng eenzeg IP Adress fir den RMM4 Controller, awer Dir kënnt komm ewech mat just engem Kabel.

WEI: Dir wëllt den RMM4 wierklech net op enger ëffentlecher konfrontéierter IP Adress lafen, wann Dir se vermeide kënnt, well e Kompromëss vun dësem kann einfach zu engem komplette Kompromiss vun Ärem Server resultéieren. (si hunn effektiv Remote Konsolenzugriff). Also wann dëst méiglech ass, wier Dir vill besser fir e Firewall-Gerät virum Server ze lafen, an den IPMI / RMM4 an de Server dozou ze verbannen, an dann e VPN ze benotzen fir den Zougang zu den RMM4 Management Interfaces ze kontrolléieren

0
ответ дан 4 December 2019 в 06:31

Теги

Похожие вопросы