Tripp Lite B0930042E4U Owners Manual for B093- B097- and B098-Series Console S - Page 265

Force session privilege level. Can be CALLBACK, USER, OPERATOR, and ADMIN. Default is ADMIN.

Page 265 highlights

15. Advanced Configuration -H Remote server address. Can be IP address or hostname. This option is required for lan and lanplus interfaces. -I Selects IPMI interface to use. Supported interfaces that are compiled in are visible in the usage help output. -L Force session privilege level. Can be CALLBACK, USER, OPERATOR, and ADMIN. Default is ADMIN. -m Set the local IPMB address. The default is 0x20. There is no need to change this setting under normal operation. -o Select the OEM type to support. This usually involves minor hacks in place in the code to work around quirks in various BMCs from various manufacturers. Use -o list to see a list of current supported OEM types. -p Remote server UDP port to connect to. Default is 623. -P Remote server password is specified on the command line. If supported, it will be obscured in the process list. Note: Specifying the password as a command line option is not recommended. -t Bridge IPMI requests to the remote target address. -U Remote server username, default is NULL user. -v Increase verbose output level. This option may be specified multiple times to increase the level of debug output. If given three times, you will get hexdumps of all incoming and outgoing packets. -V Display version information. If no password method is specified, ipmitool will prompt the user for a password. If no password is entered at the prompt, the remote server password will default to NULL. Security The ipmitool documentation highlights several security issues that should be considered before enabling the IPMI LAN interface. A remote station has the ability to control a system's power state as well as the ability to gather certain platform information. To reduce vulnerability, it is strongly advised that the IPMI LAN interface only be enabled in trusted environments where system security is not an issue, where there is a dedicated secure management network, or access has been provided through a console server. It is strongly advised you should not enable IPMI for remote access without setting a password and that the password should not be the same as any other password on that system. When an IPMI password is changed on a remote machine with the IPMIv1.5 lan interface, the new password is sent across the network as clear text. This could be observed and then used to attack the remote system. As such, it is recommended that IPMI password management only be performed over IPMIv2.0 lanplus interface or the system interface on the local station. For IPMI v1.5, the maximum password length is 16 characters. Passwords longer than 16 characters will be truncated. For IPMI v2.0, the maximum password length is 20 characters. Passwords longer than 20 characters will be truncated. Commands help This can be used to get command-line help on ipmitool commands. It may also be placed at the end of commands to get option usage help. ipmitool help Commands: raw Send a RAW IPMI request and print response lan Configure LAN Channels chassis Get chassis status and set power state event Send pre-defined events to MC mc Management Controller status and global enables sdr Print Sensor Data Repository entries and readings sensor Print detailed sensor information 265

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288

265
15. Advanced Configuration
-H <address>
Remote server address. Can be IP address or hostname. This option is required for
lan
and
lanplus
interfaces.
-I <interface>
Selects IPMI interface to use. Supported interfaces that are compiled in are visible in the usage
help output.
-L <privlvl>
Force session privilege level. Can be CALLBACK, USER, OPERATOR, and ADMIN. Default is ADMIN.
-m <local_address>
Set the local IPMB address. The default is 0x20. There is no need to change this setting under
normal operation.
-o <oemtype>
Select the OEM type to support. This usually involves minor hacks in place in the code to work
around quirks in various BMCs from various manufacturers. Use
-o list
to see a list of current
supported OEM types.
-p <port>
Remote server UDP port to connect to. Default is 623.
-P <password>
Remote server password is specified on the command line. If supported, it will be obscured in the
process list.
Note:
Specifying the password as a command line option is not recommended.
-t <target_address>
Bridge IPMI requests to the remote target address.
-U <username>
Remote server username, default is NULL user.
-v
Increase verbose output level. This option may be specified multiple times to increase the level of
debug output. If given three times, you will get hexdumps of all incoming and outgoing packets.
-V
Display version information.
If no password method is specified, ipmitool will prompt the user for a password. If no password is entered at the prompt, the
remote server password will default to NULL.
Security
The ipmitool documentation highlights several security issues that should be considered before enabling the IPMI LAN
interface. A remote station has the ability to control a system’s power state as well as the ability to gather certain platform
information. To reduce vulnerability, it is strongly advised that the IPMI LAN interface only be enabled in trusted environments
where system security is not an issue, where there is a dedicated secure management network, or access has been provided
through a console server.
It is strongly advised you should not enable IPMI for remote access without setting a password and that the password should
not be the same as any other password on that system.
When an IPMI password is changed on a remote machine with the IPMIv1.5 lan interface, the new password is sent across
the network as clear text. This could be observed and then used to attack the remote system. As such, it is recommended that
IPMI password management only be performed over IPMIv2.0 lanplus interface or the system interface on the local station.
For IPMI v1.5, the maximum password length is 16 characters. Passwords longer than 16 characters will be truncated.
For IPMI v2.0, the maximum password length is 20 characters. Passwords longer than 20 characters will be truncated.
Commands
help
This can be used to get command-line help on
ipmitool
commands. It may also be placed at the
end of commands to get option usage help.
ipmitool help
Commands:
raw
Send a RAW IPMI request and print
response
lan
Configure LAN Channels
chassis
Get chassis status and set power state
event
Send pre-defined events to MC
mc
Management Controller status and global enables
sdr
Print Sensor Data Repository entries and readings
sensor
Print detailed sensor information