Skip to content

IPMI security is theater, my VLAN segmentation is what matters

Dedicated Servers by hankels 4 replies 270 views
#1

Been running 52 boxes across 3 providers (Contabo, OVHcloud, Vultr) and I never touch IPMI except when the NIC dies. Everything lives on a management VLAN with no gateway. Why obsess over BMC firmware when network isolation does the heavy lifting?

My math:

  • 52 servers
  • $8.50 avg per box for IPMI premium = $442/yr wasted
  • 0 breaches in 4 years

BMCs get CVEs weekly. I get sleep nightly.

Someone change my mind with numbers, not FUD.

seedbox, NAS, tape, and three offsite
#2

I have read a CVE since 2 days about VLAN hopping with double tagging... it is possible to do that? I dont know if my switch is vulnerable lol.

Vive la résistance... électrique
#3

Vlan hopping

#4

Double tagging works on anything not checking 802.1q native vlan. Took me 15 min on a lab switch from 2019. Your isolation is paint on glass...

#5

SNAPPED UP a RackNerd dedi last week with IPMI for $12/YR ARE YOU KIDDING but now im SCARED. @nedjoe what switch model was it? Need to check my rack at HostHatch

world record: 4min Arch install

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft