LINUXOR.SK ... open source notes ...

Balabit - IPMI of node B (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from IPMI out-of-band management

The three IPMI pages of the SCB appliance in datacenter B that my design document names as differing from node A: Alerts, Network and SSL Certification (as recorded, the SSL Certification sentence is word for word node A's). The design says that every other page is identical to node A and documents only these; for the rest see IPMI of node A.

ItemValue
WhereIPMI web interface of node B, https://dc1-b-ablb001m.mgmt.example.net/, 10.11.23.29
Appliancedc1-b-ablb001, SCB T-10 in datacenter B, node of the site 1 cluster dc1-s-xblb001
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.1.2
Differences from node AAlert subject, MAC address, host name, IPv4 address and gateway, IPv6 address; the SSL Certification sentence is the same as node A's, with the same dates

The answers

ini
# Page / Field = value, as configured on dc1-b-ablb001 (IPMI), from the design document v0.5, chapter 7.1.2

Alerts > Alert 1 / Alert Level = Warning and Above
Alerts > Alert 1 / Destination Address = 010.011.019.033 & scb_mail_group@ad.example.net
Alerts > Alert 2 … 16 / Alert Level = Disable All
Alerts > Alert 2 … 16 / Destination Address = 000.000.000.000 & NULL
Alerts > Alert 1 (detail) / Event Severity = Warning
Alerts > Alert 1 (detail) / Destination IP = 010.011.019.033
Alerts > Alert 1 (detail) / Email Address = scb_mail_group@ad.example.net
Alerts > Alert 1 (detail) / Subject = dc1-b-ablm001 - Alert
Alerts > Alert 1 (detail) / Message = NULL

Network > BASIC SETTINGS / MAC ADDRESS = 0c-c4-7a-00-00-02
Network > BASIC SETTINGS / HOSTNAME = dc1-b-ablb001m.mgmt.example.net
Network > BASIC SETTINGS / USE THE FOLLOWING IP ADDRESS = Yes
Network > IPv4 SETTINGS / IP ADDRESS = 010.011.023.029
Network > IPv4 SETTINGS / SUBNET MASK = 255.255.255.000
Network > IPv4 SETTINGS / GATEWAY = 10.11.23.254
Network > IPv4 SETTINGS / DNS = 10.11.16.145
Network > IPv6 SETTINGS / DHCPv6 STATELESS = Yes
Network > IPv6 SETTINGS / ADDRESS LIST = 2001:db8:b1:0ff3:0016:0000:00e7:0001/64
Network > IPv6 SETTINGS / DNS SERVER IP = 2001:db8:a1:c0b::f:1
Network > OTHER SETTINGS / VLAN = Disabled
Network > OTHER SETTINGS / VLAN ID = 0
Network > OTHER SETTINGS / LAN INTERFACE = Dedicate
Network > OTHER SETTINGS / RMCP PORT = 623

SSL Certification / Signed by = internal certification authority
SSL Certification / Valid from = 7/19/2017
SSL Certification / Valid to = 7/20/2018

As for node A, the SSL Certification page is a sentence in the design, and the field names Signed by, Valid from and Valid to are mine.

AnswerWhat it means
IP ADDRESS 010.011.023.029, GATEWAY 10.11.23.25410.11.23.29 in the out-of-band network of datacenter B, 10.11.23.0/24, VLAN 12
ADDRESS LIST 2001:db8:b1:0ff3:…The logical network table of the design gives 2001:db8:a1:ff3::/64 to datacenter B and 2001:db8:b1:ff3::/64 to datacenter A. The two IPMI pages have it the other way round: node A has an a1 address, node B a b1 address. One of the two places is wrong; nothing in the material says which
DNS 10.11.16.145Only the Infoblox of datacenter A, on both nodes; the second Infoblox 10.11.18.145 is the NTP server, not a DNS server, on the BMCs
Subject dc1-b-ablm001 - AlertThe older name of the module, as on node A

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
IPMI of node B in its own out-of-band networkThe vendor's caution applies unchanged: IPMI only on well-protected, separated management networks with restricted accessibility; see IPMI of node A for the rest
← solutionz