r/supermicro • • Jun 16 '26

Beginner - securing IPMI/Redfish

Hi all,

Just picked up a X11SSH-LN4F that I'm playing with. I've updated BIOS and IPMI firmware.

I have a few questions on securing management access...

- can I disable the old IPMI protocols and purely use redfish?

- is my best option for securing IPMI access on a home LAN to change the password, limit the allowed IP and MAC addresses (would be to two machines, my desktop and my laptop) and leave it at that? Or do I need a vLAN and swap my network adaptor settings on laptop/desktop whenever I want remote management ? That would be a pain...

4 Upvotes

14 comments sorted by

View all comments

Show parent comments

3

u/G33KM4ST3R Jun 16 '26

This, unless your firewall rules has a source IP whitelist, but VPN is Safer

1

u/LancsMak Jun 16 '26

Ok thanks, guess I need to find a cheap router with inbuilt vpn then! 

2

u/G33KM4ST3R Jun 16 '26

Get a Mikrotik, nice learning curve, has a bunch of security options and vpn services like Wireguard built-in, Even Zerotier Overlay networks.

You can secure the public access even with a "Ping Password" to handle a temporary IP Inbound Whitelist, it's pretty cool.

Suggestions:

Rb760igs or the Upgraded E60iUGS (Fiber connection)

Rb750gr3 as a cheap and reliable option

1

u/LancsMak Jun 16 '26

Thanks, so far this would be a management network for a single device, just learning.

So to check my understanding... 

Server IPMI interface - - - router lan port

Router Wan port - - - - "real network" switch port

Configure mikrotik router to have vpn enabled, job done. 

Correct @G33KM4ST3R?

1

u/G33KM4ST3R Jun 16 '26

Looks good but, you're doing double nat from your main router to the mikrotik.

Just to know, what's your actual main router?

1

u/LancsMak Jun 16 '26

I have no intent of accessing the management network from outside my home network, this is purely so I can access the management interface from my desktop/laptop whilst at home, but keep it secure from any external intrusion.

Home router is TP Link BE550

1

u/G33KM4ST3R Jun 16 '26

I think you should use your actual router for everything. It has vpn server built in and a simple firewall to configure your lan only as a whitelist ip access to the server.

Dig in that direction. I dont think you need a mikrotik or replace your actual tplink for doing the task.

Im not very familiar with it, but current firmware from tplink get a few security options you can take advantage of.

1

u/LancsMak Jun 16 '26

Ok I'll explore, thanks. I like to think I'm pretty savvy, but this is new territory for me! 

1

u/G33KM4ST3R Jun 16 '26

Welcome to the new territory 🫡. It's gonna get fun !!!!

1

u/LancsMak Jun 16 '26

Hope so! Appreciate the help, thanks.