Robert,
Management ports are often sensitive and putting them on a separate
network prevents them from being accessed by snoopy users, network
scans, etc. There are some appliances (*cough* FastT *cough*) that
would die from DDOS when network scanned.
Unfortunately ASMI also has a poor history of using weak passwords. If
I can access your ASMI from a PC on your public LAN, and guess the IBM
default, I can turn off your server without warning.
I recommend SAN switches, SAN storage, and IPMI/FSP interfaces be on
separate networks. The HMC has built in support to run that on a
dedicated switch or a private nonrouted VLAN via DHCP.
Thanks.
On Wed, May 07, 2025 at 05:54:39PM +0000, Robert Berendt via IBM TechXchange Community wrote:
> So basically BMC is a rename of ASMI?
>
>
> If I log into my HMC and upgrade the firmware that way, doesn't that automatically upgrade the BMC also?
>
>
> I've never understood why the ASMI port needs to be on a separate network. I don't keep HR data, proprietary engineering drawings, strategic business plans, etc on a separate network. Why should the ASMI port be on a separate network?
>
>
> ------------------------------
> Robert Berendt IBMChampion
> Business Systems Analyst, Lead
> Dekko
> Fort Wayne
> ------------------------------
> -------------------------------------------
> Original Message:
> Sent: Wed May 07, 2025 01:48 PM
> From: Russell Adams
> Subject: What is BMC and do I care?
>
> BMC is the new FSP/ASMI. It's a cheap IPMI interface like whitebox
> Intel PC's use, instead of IBM's FSP. They are in use on the POWER10.
>
> You will upgrade the BMC firmware to update the system firmware from
> now on. It can be disruptive or concurrent just like the old FSP. Most
> of the time, it's basically the same.
>
> Be aware that the BMC account will silently fail with passwords over
> 19 characters. There is a 19 character limit (IPMI standard).
>
> Using IPMI is yet another reason to make sure your BMC port are on a
> separate network and not on the corporate LAN.
>
> Thanks.
>
> On Wed, May 07, 2025 at 05:41:55PM +0000, Robert Berendt via IBM TechXchange Community wrote:
> > I have had multiple Power systems for years. I've done numerous upgrades.
> >
> >
> > I used to have physical HMC's but now have vHMC's and would never go back to physical HMCs.
> >
> >
> > I'm familiar with ASMI and can log into that.
> >
> >
> > I hear talk of BMC but I'm not really sure what that is, or, if my setup would even use it. What is it?
> >
> >
> > I use my HMC to upgrade firmware on my Power systems. I keep firmware, vios, IBM i, HMC releases current and patched. Is BMC something to be concerned about too?
> >
> >
> > ------------------------------
> > Robert Berendt IBMChampion
> > Business Systems Analyst, Lead
> > Dekko
> > Fort Wayne
> > ------------------------------
> >
> >
> > Reply to Sender :
https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802175&SenderKey=3fd3d035-5ed4-4c4a-9c32-f5b55fdf51fd <https: community.ibm.com community user egroups postreply?groupid=6061&MID=802175&SenderKey=3fd3d035-5ed4-4c4a-9c32-f5b55fdf51fd>
> >
> > Reply to Discussion :
https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802175 <https: community.ibm.com community user egroups postreply?groupid=6061&MID=802175>
> >
> >
> >
> > You are subscribed to "HMC" as
Russell.Adams@AdamsSystems.nl <
russell.adams@adamssystems.nl>. To change your subscriptions, go to
http://community.ibm.com/community/user/preferences?section=Subscriptions. <http: community.ibm.com community user preferences?section=Subscriptions.> To unsubscribe from this community discussion, go to
https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=5ed81228-db5a-4c59-90a0-c36d8c6b0a77. <https: community.ibm.com higherlogic egroups unsubscribe.aspx?userkey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=5ed81228-db5a-4c59-90a0-c36d8c6b0a77.>
>
>
> ------------------------------------------------------------------
> Russell Adams
Russell.Adams@AdamsSystems.nl <
russell.adams@adamssystems.nl>
> Principal Consultant Adams Systems Consultancy
>
https://adamssystems.nl/ <https: adamssystems.nl>
>
>
> Original Message:
> Sent: 5/7/2025 1:42:00 PM
> From: Robert Berendt
> Subject: What is BMC and do I care?
>
>
> I have had multiple Power systems for years. I've done numerous upgrades.
>
> I used to have physical HMC's but now have vHMC's and would never go back to physical HMCs.
>
> I'm familiar with ASMI and can log into that.
>
> I hear talk of BMC but I'm not really sure what that is, or, if my setup would even use it. What is it?
>
> I use my HMC to upgrade firmware on my Power systems. I keep firmware, vios, IBM i, HMC releases current and patched. Is BMC something to be concerned about too?
>
>
> ------------------------------
> Robert Berendt IBMChampion
> Business Systems Analyst, Lead
> Dekko
> Fort Wayne
> ------------------------------
>
>
> Reply to Sender :
https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802179&SenderKey=3fd3d035-5ed4-4c4a-9c32-f5b55fdf51fd>
> Reply to Discussion :
https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802179>
>
>
> You are subscribed to "HMC" as
Russell.Adams@AdamsSystems.nl. To change your subscriptions, go to
http://community.ibm.com/community/user/preferences?section=Subscriptions. To unsubscribe from this community discussion, go to
https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=5ed81228-db5a-4c59-90a0-c36d8c6b0a77.------------------------------------------------------------------
Russell Adams
Russell.Adams@AdamsSystems.nlPrincipal Consultant Adams Systems Consultancy
https://adamssystems.nl/
Original Message:
Sent: 5/7/2025 1:55:00 PM
From: Robert Berendt
Subject: RE: What is BMC and do I care?
So basically BMC is a rename of ASMI?
If I log into my HMC and upgrade the firmware that way, doesn't that automatically upgrade the BMC also?
I've never understood why the ASMI port needs to be on a separate network. I don't keep HR data, proprietary engineering drawings, strategic business plans, etc on a separate network. Why should the ASMI port be on a separate network?
------------------------------
Robert Berendt IBMChampion
Business Systems Analyst, Lead
Dekko
Fort Wayne
------------------------------
Original Message:
Sent: Wed May 07, 2025 01:48 PM
From: Russell Adams
Subject: What is BMC and do I care?
BMC is the new FSP/ASMI. It's a cheap IPMI interface like whitebox
Intel PC's use, instead of IBM's FSP. They are in use on the POWER10.
You will upgrade the BMC firmware to update the system firmware from
now on. It can be disruptive or concurrent just like the old FSP. Most
of the time, it's basically the same.
Be aware that the BMC account will silently fail with passwords over
19 characters. There is a 19 character limit (IPMI standard).
Using IPMI is yet another reason to make sure your BMC port are on a
separate network and not on the corporate LAN.
Thanks.
On Wed, May 07, 2025 at 05:41:55PM +0000, Robert Berendt via IBM TechXchange Community wrote:
> I have had multiple Power systems for years. I've done numerous upgrades.
>
>
> I used to have physical HMC's but now have vHMC's and would never go back to physical HMCs.
>
>
> I'm familiar with ASMI and can log into that.
>
>
> I hear talk of BMC but I'm not really sure what that is, or, if my setup would even use it. What is it?
>
>
> I use my HMC to upgrade firmware on my Power systems. I keep firmware, vios, IBM i, HMC releases current and patched. Is BMC something to be concerned about too?
>
>
> ------------------------------
> Robert Berendt IBMChampion
> Business Systems Analyst, Lead
> Dekko
> Fort Wayne
> ------------------------------
>
>
> Reply to Sender : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802175&SenderKey=3fd3d035-5ed4-4c4a-9c32-f5b55fdf51fd
>
> Reply to Discussion : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6061&MID=802175
>
>
>
> You are subscribed to "HMC" as Russell.Adams@AdamsSystems.nl. To change your subscriptions, go to http://community.ibm.com/community/user/preferences?section=Subscriptions. To unsubscribe from this community discussion, go to https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=5ed81228-db5a-4c59-90a0-c36d8c6b0a77.
------------------------------------------------------------------
Russell Adams Russell.Adams@AdamsSystems.nl
Principal Consultant Adams Systems Consultancy
https://adamssystems.nl/
Original Message:
Sent: 5/7/2025 1:42:00 PM
From: Robert Berendt
Subject: What is BMC and do I care?
I have had multiple Power systems for years. I've done numerous upgrades.
I used to have physical HMC's but now have vHMC's and would never go back to physical HMCs.
I'm familiar with ASMI and can log into that.
I hear talk of BMC but I'm not really sure what that is, or, if my setup would even use it. What is it?
I use my HMC to upgrade firmware on my Power systems. I keep firmware, vios, IBM i, HMC releases current and patched. Is BMC something to be concerned about too?
------------------------------
Robert Berendt IBMChampion
Business Systems Analyst, Lead
Dekko
Fort Wayne
------------------------------
</https:></russell.adams@adamssystems.nl></https:></http:></russell.adams@adamssystems.nl></https:></https:>