Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

iDRAC9 Security Configuration Guide

PDF

Network Security Configuration

iDRAC provides optional networking interfaces that can be used for connection and management. As a security best practice, it is recommended to disable networking interfaces that are unused.

The following configurations are recommended for network security:

  • iDRAC Nic Select – Dedicated
  • iDRAC VLAN – enabled
  • USB Management Port — Disabled
  • iDRAC Managed: USB SCP — Disabled
  • Pass-through State — Disabled
  • Pass-through Mode — USB NIC
  • IP Blocking Enabled
  • IP Filtering Enabled
  • Auto Discovery Disabled or if Auto Discovery is necessary set to DNS
Table 1. Network Configurations from Web Interface and RACADM
Feature iDRAC Web Interface RACADM

Nic Selection

iDRAC Settings > Connectivity > Network > Network Settings > NIC Selection - Dedicated

racadm set idrac.nic.selection 1

VLAN

iDRAC Settings > Connectivity > Network > VLAN Settings > Enable VLAN ID - Enabled

iDRAC Settings > Connectivity > Network > VLAN Settings > VLAN ID - <ID Number>

racadm set idrac.nic.vlanenable 1

racadm set idrac.nic.vlanID <ID Number>

USB Management Port

iDRAC Settings > Settings > Management USB Settings - Disabled

racadm set

idrac.usb.PortStatus 0

Pass-through State

iDRAC Settings > Connectivity > OS to iDRAC Pass-through - Disabled

racadm set idrac.OS-BMC.AdminState 0

Pass-through Mode

iDRAC Settings > Connectivity > OS to iDRAC Pass-through - USB NIC

racadm set idrac.OS-BMC.PTMode 1

Ip Blocking

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Enabled – Enabled

racadm set idrac.IPBlocking.BlockEnable 1

Ip Blocking Fail Count

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Fail Count – 3

racadm set iDRAC.IPBlocking.FailCount 3

IP Blocking Fail Window

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Fail Window – 60

racadm set iDRAC.IPBlocking.FailWindow 60

IP Blocking Penalty Time

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Penalty Time – 60

racadm set iDRAC.IPBlocking.PenaltyTime 60

IP Range Filtering

iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Enabled - Enabled iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Address – <IP of Management Station>

iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Subnet – <Management Subnet Mask>

racadm set idrac.IPBlocking.RangeEnable 1

racadm set idrac.IPBlocking.RangeAddr <IP of Management Station>

racadm set idrac.IPBlocking.RangeMask < Management Subnet Mask>

Auto Discovery

iDRAC Settings > Connectivity > Network > iDRAC Auto Discovery > Auto Discovery – Disabled

racadm set idrac.autodiscovery.EnableIPChangeAnnounce 0


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\