- Preface
- Overview
- Installing the Server Operating System or Hypervisor
- Managing the Server
- Managing Storage Using RAID
- Viewing Server Properties
- Viewing Server Sensors
- Managing Remote Presence
- Managing User Accounts
- Configuring Network-Related Settings
- Configuring Communication Services
- Managing Certificates
- Configuring Platform Event Filters
- Firmware Management
- Viewing Faults and Logs
- Server Utilities
- Diagnostic Tests
- Index
Configuring Network-Related Settings
This chapter includes the following sections:
- CIMC NIC Configuration
- Configuring Common Properties
- Configuring IPv4
- Configuring the Server VLAN
- Network Security Configuration
- Configuring Network Analysis Module Capability
- NTP Settings Configuration
CIMC NIC Configuration
CIMC NICs
Two NIC modes are available for connection to the CIMC.
NIC Mode
The CIMC network settings determine which ports can reach the CIMC. The following network mode options are available, depending on your platform:
-
Dedicated—A connection to the CIMC is available through the management Ethernet port or ports.
-
Shared LOM—A connection to the CIMC is available through the LAN On Motherboard (LOM) Ethernet host ports and through the router's PCIe and MGF interfaces. 
Note
In shared LOM mode, all host ports must belong to the same subnet.
![]() Note | Dedicated mode is not applicable to the EHWIC E-Series NCE. |
NIC Redundancy
The CIMC network redundancy settings determine how NIC redundancy is handled:
The available redundancy modes vary depending on the selected network mode and your platform.
Configuring CIMC NICs
Use this procedure to set the NIC mode and NIC redundancy.
You must log in as a user with admin privileges to configure the NIC.
This example configures the CIMC network interface:
Server# scope cimc
Server /cimc # scope network
Server /cimc/network # set mode shared_lom
Server /cimc/network *# commit
Server /cimc/network #
Configuring Common Properties
Use common properties to describe your server.
You must log in as a user with admin privileges to configure common properties.
| Command or Action | Purpose |
|---|
This example configures the common properties:
Server# scope cimc
Server /cimc # scope network
Server /cimc/network # set hostname Server
Server /cimc/network *# commit
Server /cimc/network #
Configuring IPv4
You must log in as a user with admin privileges to configure IPv4 network settings.
| Command or Action | Purpose | |||
|---|---|---|---|---|
| Step 1 | Server# scope cimc |
Enters CIMC command mode. | ||
| Step 2 | Server /cimc # scope network |
Enters CIMC network command mode. | ||
| Step 3 | Server /cimc/network # set dhcp-enabled {yes | no} |
| ||
| Step 4 | Server /cimc/network # set v4-addr ipv4-address |
Specifies the IP address for the CIMC. | ||
| Step 5 | Server /cimc/network # set v4-netmask ipv4-netmask |
Specifies the subnet mask for the IP address. | ||
| Step 6 | Server /cimc/network # set v4-gateway gateway-ipv4-address |
Specifies the gateway for the IP address. | ||
| Step 7 | Server /cimc/network # set dns-use-dhcp {yes | no} |
Selects whether the CIMC retrieves the DNS server addresses from DHCP. | ||
| Step 8 | Server /cimc/network # set preferred-dns-server dns1-ipv4-address |
Specifies the IP address of the primary DNS server. | ||
| Step 9 | Server /cimc/network # set alternate-dns-server dns2-ipv4-address |
Specifies the IP address of the secondary DNS server. | ||
| Step 10 | Server /cimc/network # commit |
Commits the transaction to the system configuration. | ||
| Step 11 | Server /cimc/network # show [detail] |
(Optional) Displays the IPv4 network settings. |
This example configures and displays the IPv4 network settings:
Server# scope cimc
Server /cimc # scope network
Server /cimc/network # set dhcp-enabled no
Server /cimc/network *# set v4-addr 10.20.30.11
Server /cimc/network *# set v4-netmask 255.255.248.0
Server /cimc/network *# set v4-gateway 10.20.30.1
Server /cimc/network *# set dns-use-dhcp-enabled no
Server /cimc/network *# set preferred-dns-server 192.168.30.31
Server /cimc/network *# set alternate-dns-server 192.168.30.32
Server /cimc/network *# commit
Server /cimc/network # show detail
Network Setting:
IPv4 Address: 10.20.30.11
IPv4 Netmask: 255.255.248.0
IPv4 Gateway: 10.20.30.1
DHCP Enabled: no
Obtain DNS Server by DHCP: no
Preferred DNS: 192.168.30.31
Alternate DNS: 192.168.30.32
VLAN Enabled: no
VLAN ID: 1
VLAN Priority: 0
Hostname: Server
MAC Address: 01:23:45:67:89:AB
NIC Mode: dedicated
NIC Redundancy: none
Server /cimc/network #
Configuring the Server VLAN
You must be logged in as admin to configure the server VLAN.
| Command or Action | Purpose | |
|---|---|---|
| Step 1 | Server# scope cimc |
Enters CIMC command mode. |
| Step 2 | Server /cimc # scope network |
Enters CIMC network command mode. |
| Step 3 | Server /cimc/network # set vlan-enabled {yes | no} |
Selects whether the CIMC is connected to a VLAN. |
| Step 4 | Server /cimc/network # set vlan-id id |
Specifies the VLAN number. |
| Step 5 | Server /cimc/network # set vlan-priority priority |
Specifies the priority of this system on the VLAN. |
| Step 6 | Server /cimc/network # commit |
Commits the transaction to the system configuration. |
| Step 7 | Server /cimc/network # show [detail] |
(Optional) Displays the network settings. |
This example configures the server VLAN:
Server# scope cimc
Server /cimc # scope network
Server /cimc/network # set vlan-enabled yes
Server /cimc/network *# set vlan-id 10
Server /cimc/network *# set vlan-priority 32
Server /cimc/network *# commit
Server /cimc/network # show detail
Network Setting:
IPv4 Address: 10.20.30.11
IPv4 Netmask: 255.255.248.0
IPv4 Gateway: 10.20.30.1
DHCP Enabled: yes
Obtain DNS Server by DHCP: no
Preferred DNS: 192.168.30.31
Alternate DNS: 192.168.30.32
VLAN Enabled: yes
VLAN ID: 10
VLAN Priority: 32
Hostname: Server
MAC Address: 01:23:45:67:89:AB
NIC Mode: dedicated
NIC Redundancy: none
Server /cimc/network #
Network Security Configuration
Network Security
The CIMC uses IP blocking as network security. IP blocking prevents the connection between a server or website and certain IP addresses or ranges of addresses. IP blocking effectively bans undesired connections from those computers to a website, mail server, or other Internet servers.
IP banning is commonly used to protect against denial of service (DoS) attacks. The CIMC bans IP addresses by setting up an IP blocking fail count.
Configuring Network Security
Configure network security if you want to set up an IP blocking fail count.
You must log in as a user with admin privileges to configure network security.
| Command or Action | Purpose | |
|---|---|---|
| Step 1 | Server# scope cimc |
Enters CIMC command mode. |
| Step 2 | Server /cimc # scope network |
Enters CIMC network command mode. |
| Step 3 | Server /cimc/network # scope ipblocking |
Enters IP blocking command mode. |
| Step 4 | Server /cimc/network/ipblocking # set enabled {yes | no} |
Enables or disables IP blocking. |
| Step 5 | Server /cimc/network/ipblocking # set fail-count fail-count |
Sets the number of times a user can attempt to log in unsuccessfully before the system locks that user out for a specified length of time. The number of unsuccessful login attempts must occur within the time frame specified in the IP Blocking Fail Window field. Enter an integer between 3 and 10. |
| Step 6 | Server /cimc/network/ipblocking # set fail-window fail-seconds |
Sets the length of time, in seconds, in which the unsuccessful login attempts must occur in order for the user to be locked out. Enter an integer between 60 and 120. |
| Step 7 | Server /cimc/network/ipblocking # set penalty-time penalty-seconds |
Sets the number of seconds the user remains locked out if they exceed the maximum number of login attempts within the specified time window. Enter an integer between 300 and 900. |
| Step 8 | Server /cimc/network/ipblocking # commit |
Commits the transaction to the system configuration. |
This example configures IP blocking:
Server# scope cimc Server /cimc # scope network Server /cimc/network # scope ipblocking Server /cimc/network/ipblocking # set enabled yes Server /cimc/network/ipblocking *# set fail-count 5 Server /cimc/network/ipblocking *# set fail-window 90 Server /cimc/network/ipblocking *# set penalty-time 600 Server /cimc/network/ipblocking *# commit Server /cimc/network/ipblocking #
Configuring Network Analysis Module Capability
You must log in with admin privileges to perform this task.
| Command or Action | Purpose | |
|---|---|---|
| Step 1 | Server# scope cimc |
Enters CIMC command mode. |
| Step 2 | Server /cimc # scope network |
Enters CIMC network command mode. |
| Step 3 | Server /cimc/network # scope nam |
Enters Network Analysis Module (NAM) command mode. |
| Step 4 | Server /cimc/network/nam # set enabled yes |
Enables the NAM capability. To disable the NAM capability, use the set enabled no command. |
| Step 5 | Server /cimc/network/nam # show detail |
Verifies that the NAM capability is enabled or disabled. |
This example configures the common properties:
Server# scope cimc
Server /cimc # scope network
Server /cimc/network # scope nam
Server /cimc/network/nam # set enabled yes
Server /cimc/network/nam # show detail
Network Analysis Module:
Enabled: yes
NTP Settings Configuration
NTP Settings
By default, when CIMC is reset, it synchronizes the time with the host. With the introduction of the Network Time Protocol (NTP) service, you can configure CIMC to synchronize the time with an NTP server. The NTP server does not run in CIMC by default. You must enable and configure the NTP service by specifying the IP or DNS address of at least one server or a maximum of four servers that function as NTP servers or time source servers. When you enable the NTP service, CIMC synchronizes the time with the configured NTP server. The NTP service can be modified only through CIMC.
![]() Note | To enable the NTP service, it is preferable to specify the IP address of a server rather than the DNS address. |
Configuring NTP Settings
You must log in with admin privileges to perform this task.
| Command or Action | Purpose | |
|---|---|---|
| Step 1 | Server# scope cimc |
Enters CIMC command mode. |
| Step 2 | Server /cimc # scope network |
Enters CIMC network command mode. |
| Step 3 | Server /cimc/network # scope ntp |
Enters NTP command mode. |
| Step 4 | Server /cimc/network/ntp # set enabled yes |
Enables the NTP service. To disable the NTP service, use the set enabled no command. |
| Step 5 | Server /cimc/network/ntp # set [server-1 | server-2 | server-3 | server-4] ip-address or domain-name |
Configures the IP address or domain name for the specified server to act as an NTP server or the time source server. You can configure a maximum of four servers. |
| Step 6 | Server /cimc/network/ntp # show detail |
Displays whether the NTP service is enabled and the IP address or domain name of the NTP servers. |
This example configures NTP settings:
Server# scope cimc Server /cimc # scope network Server /cimc/network # scope ntp Server /cimc/network/ntp # set enabled yes Server /cimc/network/ntp # set server-1 10.50.171.9 Server /cimc/network/ntp # set server-2 time.cisco.com Server /cimc/network/ntp # show detail NTP Service Settings: Enabled: yes Server 1: 10.50.171.9 Server 2: time.cisco.com Server 3: Server 4:
Feedback