Jump to content

is IPMI on an old server safe to use?

I've got an old HP ProLiant ML350 G6 and It has a port for IPMI. I disabled it since I didn't need it, but it would be fun to try. 

but is it safe? 

She/Her

Link to comment
Share on other sites

Link to post
Share on other sites

Why won't it be safe? Unless you're going to access it from the internet. I'd put the IPMI on a different subnet. Get it a different IP to what you usually use.

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Abdul201588 said:

Why won't it be safe? Unless you're going to access it from the internet. I'd put the IPMI on a different subnet. Get it a different IP to what you usually use.

I guessed so because it's old software.. isn't it venerable?

She/Her

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, firelighter487 said:

I guessed so because it's old software.. isn't it venerable?

yea it normally is, but thats why you don't connect it to the full internet, just use your local network.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, firelighter487 said:

I guessed so because it's old software.. isn't it venerable?

Some older IPMI setups didn’t really have security in mind, such as HTTP only, easy to snoop on iKVM, and no security audits. Others are known to have significant vulnerabilities. Here are the known vulnerabilities for iLO2: https://www.cvedetails.com/vulnerability-list/vendor_id-10/product_id-27525/HP-Integrated-Lights-out-2-Firmware.html

 

The best practice is to seperate all your management interfaces (IPMI, switch IPs, etc) into a separate VLAN and subnet that is only accessible via a router or firewall that limits traffic to appropriate sources. This may be overkill but I suggest doing it if your router and switch(es) can do VLANs. Otherwise for a home lab, just don’t port forward to it from your WAN and it’ll probably be fine - you are relying on the security of the rest of the devices in the network.

Looking to buy GTX690, other multi-GPU cards, or single-slot graphics cards: 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, brwainer said:

Some older IPMI setups didn’t really have security in mind, such as HTTP only, easy to snoop on iKVM, and no security audits. Others are known to have significant vulnerabilities. Here are the known vulnerabilities for iLO2: https://www.cvedetails.com/vulnerability-list/vendor_id-10/product_id-27525/HP-Integrated-Lights-out-2-Firmware.html

 

The best practice is to seperate all your management interfaces (IPMI, switch IPs, etc) into a separate VLAN and subnet that is only accessible via a router or firewall that limits traffic to appropriate sources. This may be overkill but I suggest doing it if your router and switch(es) can do VLANs. Otherwise for a home lab, just don’t port forward to it from your WAN and it’ll probably be fine - you are relying on the security of the rest of the devices in the network.

i'm going to be replacing all of the cheap switches etc we use now with (old) decent switches. can you recommend me some good one's that are safe to use and that I can get for cheap second hand?

She/Her

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, firelighter487 said:

i'm going to be replacing all of the cheap switches etc we use now with (old) decent switches. can you recommend me some good one's that are safe to use and that I can get for cheap second hand?

Sorry, I haven’t been watching the second hand network equipment lately.

Looking to buy GTX690, other multi-GPU cards, or single-slot graphics cards: 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×