Howto disable IPMI failover to LAN1 on Supermicro X10SLM-F

Status
Not open for further replies.

idlecycle

Cadet
Joined
May 15, 2016
Messages
3
Hi all.

I'm about to start a fresh FreeNAS 9.10 installation. I've got a X10SLM-F motherboard. This board, like many Supermicros, has a dedicated IPMI ethernet interface as well as two LAN interfaces. Until today I tought it would be safe to simply unplug the IPMI cable. However, it will silently fallback to LAN1 if there's no cable plugged into the IPMI connector!

The quick reference guide that came with the board lists jumper JPB1, which "enables or disables BMC" (IPMI). But in the board's user manual there's no mention of JPB1. I was able to locate where the jumper should be on the board, but there's no socket soldered on - just the bare contacts - and I didn't dare shorting the two pins.

The BIOS contains a section for the IMPI configuration ("BMC Network Configuration"). There I found the option "IPMI LAN Selection", which controls this behavior. It is preconfigured to "Failover" (here's a related question about that). Unfortunately, the setting is grayed out and I can't change it (I'm using BIOS v3.0, perhaps I have to update to v3.0a?).

I've setup stronger passwords on the IPMI admin login already, but I would rather not have IPMI exposed to my LAN either way. Right now the easiest workaround is probably to plug in only LAN2, but I'm really curious if somebody knows how to properly configure the board.



P.S.: I originally posted the same question on serverfault.com earlier today, but it doesn't seem to get much love over there.
 

maglin

Patron
Joined
Jun 20, 2015
Messages
299
Keep your IPMI plugged in. I don't see why you wouldn't want this. If you don't have enough ports on your switch get another switch. You can get some older 1G switches for under $50 now.


Sent from my iPhone using Tapatalk
 

idlecycle

Cadet
Joined
May 15, 2016
Messages
3
Hi Maglin

Well, firstly I don't really need it. Secondly, IPMI has history of really serious security vulnerabilities. My board came with v1.37 preinstalled, which has known issues. I've subsequently updated to the latest version, but I have little confidence that everything is completely secured now. So I prefer leaving it air-gapped - but that's just me.

Anyway I figured out how to do it. You can change the setting in the BMC tab of IPMIView. I suppose it's also possible to do it with the ipmitool, but I'm not familiar enough with it.
 
Last edited:

JDCynical

Contributor
Joined
Aug 18, 2014
Messages
141
IPMI has history of really serious security vulnerabilities
True. However, if someone with less than honorable intentions can even reach the interface, I would think you have bigger problems than an IPMI interface with potential secure holes, just saying...
 

idlecycle

Cadet
Joined
May 15, 2016
Messages
3
I agree completely with you Justin. This is just my humble little home NAS we're talking about here. If it were in an enterprise setting I'd firewall it off or put in a separate VLAN, and enable access restrictions in IPMI itself or whatever else is best practice.
But at home I like unplugging and not worrying about it :D
 
Status
Not open for further replies.
Top