LINUXOR.SK ... open source notes ...

Balabit - IPMI of node A (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from IPMI out-of-band management

note<LOCAL_UTC_OFFSET> is a placeholder for the time zone, and password_for_scb_mail was a placeholder already in my design document; neither is a value to copy. The page "LDAP" says No while the page "Active Directory" lists two role groups; the design does not show whether Active Directory authentication itself was switched on, see the table below.

Every page of the IPMI web interface (the SuperMicro BMC) of the SCB appliance in datacenter A as I recorded it in the design document: alerts, time, directory, network, SMTP, certificate, users, ports. The design says that it shows only what was changed from the defaults.

ItemValue
WhereIPMI web interface of node A, https://dc1-a-ablb001m.mgmt.example.net/, 10.11.15.29
Appliancedc1-a-ablb001, SCB T-10 in datacenter A, node of the site 1 cluster dc1-s-xblb001
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.1.1, "configuration from real implementation realized in production environment"
Node BThe same except Alerts, Network and SSL Certification: IPMI of node B
Not in itThe firmware version of the BMC, the Active Directory switch itself, the Configure > Users password (changed, not recorded)

The answers

ini
# Page / Field = value, as configured on dc1-a-ablb001 (IPMI), from the design document v0.5, chapter 7.1.1

Alerts > Alert 1 / Alert Level = Warning and Above
Alerts > Alert 1 / Destination Address = 010.011.019.033 & scb_mail_group@ad.example.net
Alerts > Alert 2 … 16 / Alert Level = Disable All
Alerts > Alert 2 … 16 / Destination Address = 000.000.000.000 & NULL
Alerts > Alert 1 (detail) / Event Severity = Warning
Alerts > Alert 1 (detail) / Destination IP = 010.011.019.033
Alerts > Alert 1 (detail) / Email Address = scb_mail_group@ad.example.net
Alerts > Alert 1 (detail) / Subject = dc1-a-ablm001 - Alert
Alerts > Alert 1 (detail) / Message = NULL

Date & Time / TIME ZONE = <LOCAL_UTC_OFFSET>
Date & Time / NTP ENABLE = Enable
Date & Time / PRIMARY NTP SERVER = 10.11.16.145
Date & Time / SECONDARY NTP SERVER = 10.11.18.145
Date & Time / DAYLIGHT SAVING TIME = No

LDAP / ENABLE LDAP AUTHENTICATION = No

Active Directory > Role Group 1 / Group Name = SCB_ADM_ORG
Active Directory > Role Group 1 / Group Domain = ad.example.net
Active Directory > Role Group 1 / Network Privilege = Administrator
Active Directory > Role Group 2 / Group Name = SCB_OPS_ORG
Active Directory > Role Group 2 / Group Domain = ad.example.net
Active Directory > Role Group 2 / Network Privilege = Operator
Active Directory > Role Group 3 … 5 / Group Name = ~
Active Directory > Role Group 3 … 5 / Group Domain = ~
Active Directory > Role Group 3 … 5 / Network Privilege = Reserverd
Active Directory > Role Group 1 (detail) / ROLE GROUP NAME = SCB_ADM_ORG
Active Directory > Role Group 1 (detail) / ROLE GROUP DOMAIN = ad.example.net
Active Directory > Role Group 1 (detail) / ROLE GROUP PRIVILEGE = Administrator
Active Directory > Role Group 2 (detail) / ROLE GROUP NAME = SCB_OPS_ORG
Active Directory > Role Group 2 (detail) / ROLE GROUP DOMAIN = ad.example.net
Active Directory > Role Group 2 (detail) / ROLE GROUP PRIVILEGE = Operator

RADIUS / ENABLE RADIUS = No

Mouse mode / MOUSE MODE = Set Mode to Absolute (Windows, Ubuntu, RH6.x later)

Network > BASIC SETTINGS / MAC ADDRESS = 0c-c4-7a-00-00-01
Network > BASIC SETTINGS / HOSTNAME = dc1-a-ablb001m.mgmt.example.net
Network > BASIC SETTINGS / USE THE FOLLOWING IP ADDRESS = Yes
Network > IPv4 SETTINGS / IP ADDRESS = 010.011.015.029
Network > IPv4 SETTINGS / SUBNET MASK = 255.255.255.000
Network > IPv4 SETTINGS / GATEWAY = 10.11.15.254
Network > IPv4 SETTINGS / DNS = 10.11.16.145
Network > IPv6 SETTINGS / DHCPv6 STATELESS = Yes
Network > IPv6 SETTINGS / ADDRESS LIST = 2001:db8:a1:0ff3:0016:0000:00e7:0001/64
Network > IPv6 SETTINGS / DNS SERVER IP = 2001:db8:a1:c0b::f:1
Network > OTHER SETTINGS / VLAN = Disabled
Network > OTHER SETTINGS / VLAN ID = 0
Network > OTHER SETTINGS / LAN INTERFACE = Dedicate
Network > OTHER SETTINGS / RMCP PORT = 623

Dynamic DNS / DYNAMIC UPDATE DISABLE = Yes
Dynamic DNS / ENABLE TSIG AUTHENTICATION = No

Remote session / VIRTUAL MEDIA ATTACH MODE = Auto Attach

SMTP / SMTP SSL AUTH = Yes
SMTP / SMTP SERVER = 10.11.19.33
SMTP / SMTP PORT NUMBER = 25
SMTP / SMTP USER NAME = scb_mail@ad.example.net
SMTP / SMTP PASSWORD = password_for_scb_mail
SMTP / SENDER’S ADDRESS = scb_mail@ad.example.net

SSL Certification / Signed by = internal certification authority
SSL Certification / Valid from = 7/19/2017
SSL Certification / Valid to = 7/20/2018

Users > User 1 / User Name = Anonymous
Users > User 1 / Network Privilege = Reserved
Users > User 2 / User Name = ADMIN
Users > User 2 / Network Privilege = Administrator
Users > User 3 … 10 / User Name = ~
Users > User 3 … 10 / Network Privilege = Reserved

Port > WEB PORT / Enabled = No
Port > WEB PORT / Value = 80
Port > WEB SSL PORT / Enabled = Yes
Port > WEB SSL PORT / Value = 443
Port > IKVM SERVER PORT / Enabled = Yes
Port > IKVM SERVER PORT / Value = 5900
Port > VIRTUAL MEDIA PORT / Enabled = No
Port > VIRTUAL MEDIA PORT / Value = 623
Port > SSH PORT / Enabled = No
Port > SSH PORT / Value = 22
Port > WSMAN PORT / Enabled = No
Port > WSMAN PORT / Value = 5985

IP Access Control / ENABLE IP ACCESS CONTROL = No

Fan mode / FAN MODE = Set Fan to Standard Speed

The SSL Certification page is a sentence in the design, not a table: the certificate "is signed by internal certification authority", was uploaded with its private key, and it is valid "from 7/19/2017 to 7/20/2018". The field names Signed by, Valid from and Valid to are mine.

AnswerWhat it means
Destination IP 010.011.019.033The SMTP virtual address 10.11.19.33 of the mail pair (see Network, DNS and firewall), written with leading zeros the way the BMC page shows it. IP ADDRESS 010.011.015.029 is 10.11.15.29 written the same way
Subject dc1-a-ablm001 - AlertThe older name of the IPMI module; the HOSTNAME on the Network page already uses the newer dc1-a-ablb001m
Role groups SCB_ADM_ORG, SCB_OPS_ORGThe same Active Directory groups that give administrator and operator rights on the SCB web interface. On the SuperMicro BMC, as I know it, Active Directory authentication has its own switch on the Active Directory page; the design lists the role groups but not that switch, and the LDAP switch is No
VLAN DisabledThe BMC sends untagged frames; the switch port is an access port in VLAN 12
LAN INTERFACE DedicateThe BMC uses its own IPMI port and not a shared LAN port; set with ipmitool raw 0x30 0x70 0xc 1 0, see the ipmitool commands
SMTP PORT NUMBER 25 with SMTP SSL AUTH YesThe design's table of out-of-band communications opens TCP 465 (SMTPS) from the IPMI modules to 10.11.19.33, not 25. Which of the two was right is not recorded
PortsOnly HTTPS (443) and the iKVM console (5900) are on; plain HTTP, SSH, virtual media and WS-Management are off
TIME ZONE <LOCAL_UTC_OFFSET>, DAYLIGHT SAVING TIME NoThe BMC keeps a fixed UTC offset without daylight saving; the design gives no reason
Valid to 7/20/2018The IPMI certificates in my certificate folder are newer: issued by the organisation's CA, valid from 2018-01-08 to 2019-01-08, see Certificates and keys

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
IPMI in the out-of-band network, reachable from "Any" on 443 and 5900The SPS 9.0 guide: the IPMI "has known vulnerabilities that One Identity cannot fix"; connect it "only … to well-protected, separated management networks with restricted accessibility"
VIRTUAL MEDIA PORT 623 offMatches SuperMicro's interim mitigation for CVE-2019-16649 and CVE-2019-16650 (plaintext authentication, weak encryption and authentication bypass in Virtual Media on X9 to H12 boards): block TCP port 623 and run BMCs on isolated networks. Whether a firmware fix exists for the X9 board was not confirmed
SSH PORT 22 offStill the right choice: even the BMC of the current 3000/3500 appliances offers 3des-cbc, diffie-hellman-group1-sha1, hmac-md5 and ssh-dss on its SSH port
The ports on the Port pageThe 9.0 guide lists the same IPMI ports and adds 161 (SNMP): 22, 80, 161, 443, 623, 5900, 5985

The appliance under this module is out of support (T-Series End of Support 2024-07-31), so no BMC firmware updates should be expected for it either; that is my conclusion, not a statement of the research.

← solutionz