LINUXOR.SK ... open source notes ...

Balabit - IPMI configuration with ipmitool

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from IPMI out-of-band management

note<IPMI-IP>, <IPMI-netmask> and <gateway-IP> are placeholders in my notes, not values. The values of site 1 are in the table below. The notes also give the vendor's command for the 1000d and 10000 appliances; it is not for a T-10 and is left out of the fence.

The commands that give the IPMI module (BMC) of an SCB appliance its static address and make it use the dedicated IPMI port, run from the appliance itself before the module is reachable over the network, followed by the change of the factory password in the IPMI web interface.

ItemValue
WhereThe boot shell of the SCB appliance: log in on the local console (or over SSH) as root, then Shells > Boot shell in the menu (the notes call it the "IPMI menu")
Run asroot
Appliancesdc1-a-ablb001 and dc1-b-ablb001, SCB T-10
Firmware at the timeThe notes do not say; the site 1 cluster ran 5 LTS (5.0.3) when the design was written
SourceMy notes "Configuring the IPMI interface and create debug bundle from GUI and CLI"
Not in itThe output of ipmitool lan print; the notes did not keep it

The commands

As root in the boot shell of each appliance: show the LAN settings of the BMC, switch it to a static address, set address, netmask and gateway, make it use the dedicated interface, and show the result on channel 1.

bash
$ ipmitool lan print
$ ipmitool lan set 1 ipsrc static
$ ipmitool lan set 1 ipaddr <IPMI-IP>
$ ipmitool lan set 1 netmask <IPMI-netmask>
$ ipmitool lan set 1 defgw ipaddr <gateway-IP>
$ ipmitool raw 0x30 0x70 0xc 1 0
$ ipmitool lan print 1
CommandWhat it does
lan set 1 ipsrc staticChannel 1 is the LAN channel of the BMC. The notes give ipsrc dhcp as the alternative; site 1 used static addresses
lan set 1 ipaddr, netmask, defgw ipaddrFor site 1: 10.11.15.29, 255.255.255.0, 10.11.15.254 on node A and 10.11.23.29, 255.255.255.0, 10.11.23.254 on node B, from the IPMI Network pages in node A and node B
raw 0x30 0x70 0xc 1 0The vendor's command "on the N1000, T1, T4, and T10 appliances" to use the dedicated Ethernet interface. As I understand it, it is a SuperMicro OEM command (LAN interface: 0 = dedicated); the IPMI Network page shows the result as LAN INTERFACE Dedicate. The notes give ipmitool raw 0x30 0x70 0xc 1 1 0 for the 1000d and 10000 appliances
lan print 1Prints the settings again; then the notes say "Use a browser to connect to the reported network address"

The last step was in the web interface, "change password only for first configuration": log in with the factory credentials of the BMC, Configure > Users, select ADMIN, Modify User, change the password and save with Modify. The new password is not in the notes. ADMIN stayed the only local user of the module.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
ipmitool lan set 1 … from the boot shellSPS 9.0 documents the IPMI network settings only through the console menu ("Configuring the IPMI from the console") and from the BIOS after a lost IPMI password; it does not document ipmitool
ipmitool raw 0x30 0x70 0xc 1 0 to select the dedicated portNot checked against a SuperMicro source. The 9.0 guide says the IPMI looks for network interfaces during boot, so the dedicated IPMI port must be connected before the appliance is powered on
← solutionz