Passer au contenu principal
  • Passer des commandes rapidement et facilement
  • Afficher les commandes et suivre l’état de votre expédition
  • Profitez de récompenses et de remises réservées aux membres
  • Créez et accédez à une liste de vos produits
  • Gérer vos sites, vos produits et vos contacts au niveau des produits Dell EMC à l’aide de la rubrique Gestion des informations de l’entreprise.

iDRAC9 Security Configuration Guide

PDF

Network Security Configuration

iDRAC provides optional networking interfaces that can be used for connection and management. As a security best practice, it is recommended to disable networking interfaces that are unused.

The following configurations are recommended for network security:

  • iDRAC Nic Select – Dedicated
  • iDRAC VLAN – enabled
  • USB Management Port — Disabled
  • iDRAC Managed: USB SCP — Disabled
  • Pass-through State — Disabled
  • Pass-through Mode — USB NIC
  • IP Blocking Enabled
  • IP Filtering Enabled
  • Auto Discovery Disabled or if Auto Discovery is necessary set to DNS
Table 1. Network Configurations from Web Interface and RACADM
Feature iDRAC Web Interface RACADM

Nic Selection

iDRAC Settings > Connectivity > Network > Network Settings > NIC Selection - Dedicated

racadm set idrac.nic.selection 1

VLAN

iDRAC Settings > Connectivity > Network > VLAN Settings > Enable VLAN ID - Enabled

iDRAC Settings > Connectivity > Network > VLAN Settings > VLAN ID - <ID Number>

racadm set idrac.nic.vlanenable 1

racadm set idrac.nic.vlanID <ID Number>

USB Management Port

iDRAC Settings > Settings > Management USB Settings - Disabled

racadm set

idrac.usb.PortStatus 0

Pass-through State

iDRAC Settings > Connectivity > OS to iDRAC Pass-through - Disabled

racadm set idrac.OS-BMC.AdminState 0

Pass-through Mode

iDRAC Settings > Connectivity > OS to iDRAC Pass-through - USB NIC

racadm set idrac.OS-BMC.PTMode 1

Ip Blocking

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Enabled – Enabled

racadm set idrac.IPBlocking.BlockEnable 1

Ip Blocking Fail Count

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Fail Count – 3

racadm set iDRAC.IPBlocking.FailCount 3

IP Blocking Fail Window

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Fail Window – 60

racadm set iDRAC.IPBlocking.FailWindow 60

IP Blocking Penalty Time

iDRAC Settings > Connectivity > Advanced Network Settings > IP Blocking Penalty Time – 60

racadm set iDRAC.IPBlocking.PenaltyTime 60

IP Range Filtering

iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Enabled - Enabled iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Address – <IP of Management Station>

iDRAC Settings > Connectivity > Advanced Network Settings > IP Ranges > IP Range Subnet – <Management Subnet Mask>

racadm set idrac.IPBlocking.RangeEnable 1

racadm set idrac.IPBlocking.RangeAddr <IP of Management Station>

racadm set idrac.IPBlocking.RangeMask < Management Subnet Mask>

Auto Discovery

iDRAC Settings > Connectivity > Network > iDRAC Auto Discovery > Auto Discovery – Disabled

racadm set idrac.autodiscovery.EnableIPChangeAnnounce 0


Évaluez ce contenu

Précis
Utile
Facile à comprendre
Avez-vous trouvé cet article utile ?
0/3000 characters
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez indiquer si l’article a été utile ou non.
  Les commentaires ne doivent pas contenir les caractères spéciaux : <>()\