LOM port management for MPX 9200 and MPX 17000
Prerequisites
-
Physical or console access to NetScaler.
-
Network connectivity to the LOM port (direct or switched).
-
Device serial number (required for initial authentication).
-
Planned IP addressing scheme for the LOM network segment.
-
Administrative access credentials.
-
Web browser with HTML5 support (Chrome, Firefox, Edge, or Safari).
-
Standard HTTPS (port 443) network access to the LOM IP address.
Initial network access
Default LOM settings
| Parameter | Default Value |
|---|---|
| IP Address | 192.168.1.3 |
| Subnet Mask | 255.255.255.0 |
| Default Gateway | 192.168.1.1 |
| Username | nsroot |
| Password | Device serial number (case-sensitive) |
Network connection methods
-
Connect a laptop Ethernet port to the LOM interface using a crossover cable.
-
Set the laptop static IP address to
192.168.1.10with a subnet mask of255.255.255.0.
-
Connect the LOM interface and a management workstation to the same network switch.
-
Ensure that both devices are in the
192.168.1.0/24broadcast domain.
Configure LOM by using the GUI
Initial login and password change
-
Open a web browser
-
Type
https://192.168.1.3. -
Accept the self-signed SSL certificate warning that appears in the browser.
-
-
Authenticate with default credentials
-
Enter
nsrootas the Username. -
Enter the device serial number as the Password (note: this is case-sensitive).
-
Click Login.
-
-
Mandatory password changeOn the first login, the system enforces a password change for security.
-
Current Password: Enter the device serial number.
-
New Password: Enter a password that meets the complexity requirements shown on the page.
-
Confirm Password: Re-enter the new password.
-
Click Submit to save.
-
nsroot account and your newly created password.
Network configuration
-
Navigate to Settings > Network IP Settings > LAN Interface (eth0).
-
Enter the following details:
-
IPv4 Address
-
IPv4 Subnet
-
IPv4 Gateway
-
-
Click Save. The Baseboard Management Controller (BMC) takes approximately 30 seconds to apply changes and then disconnects your current session.
-
Verify connectivity by pinging the new LOM IP address by using the following command from your management workstation:
ping <New_LOM_IP_Address> -
Access the LOM interface using the new IP address:
https://<new_LOM_IP_address> -
Log using
nsrootand updated password.
System lockdown mode restriction
Symptoms of lockdown mode
-
Error Messages: Insufficient privilege (code 8000).
-
Notifications: You do not have permission to view this content.
-
GUI Behavior: Settings menu items appear grayed out or are completely inaccessible.
Affected functions
-
Network configuration changes.
-
User management and password operations.
-
LOM firmware updates.
-
Field Replaceable Unit (FRU) data modifications.
Resolution
ipmitool commands. For information about how to disable lockdown, see System lockdown management section in the CLI section for lockdown management procedures.
Configure LOM by using the CLI (IPMI tool)
ipmitool commands.
MPX 17000 System Lockdown Mode (LOM Security Enhancement)
Access requirements
-
Serial console connection
-
SSH session (if a network is configured)
-
Direct access or monitor access
shell to enter the FreeBSD environment.
System lockdown management
-
Check Status:
ipmitool raw 0x34 0x81(00=Disabled (Configuration changes allowed),01=Enabled (Read-only mode active)). -
Disable Lockdown:
ipmitool raw 0x34 0x81 0x0.This command enables full read-write access to all BMC configuration interfaces. -
Enable Lockdown:
ipmitool raw 0x34 0x81 0x1.This command restricts all BMC interfaces to read-only access for enhanced security.
Static IP configuration
-
Set the IP address source to static: Change the interface mode to disable DHCP and prepare the interface for static IP assignment using the following command:
ipmitool lan set 1 ipsrc static -
Assign the IP address: Specify the static IP address for the LOM interface using the following command:
ipmitool lan set 1 ipaddr <LOM_IP_Address>Example:ipmitool lan set 1 ipaddr 192.0.2.255 -
Assign the Subnet mask: Define the subnet mask for the LOM network segment using the following command:
ipmitool lan set 1 netmask <Subnet_Mask>Example:ipmitool lan set 1 netmask 255.255.255.0 -
Configure the default gateway: Specify the gateway address for routing traffic outside the local segment using the following command:
ipmitool lan set 1 defgw ipaddr <Gateway_IP>Example:ipmitool lan set 1 defgw ipaddr 192.0.2.255 -
Reset or reboot the BMC to apply changes:
ipmitool bmc reset coldThe BMC requires approximately 120 seconds to fully initialize after a reset.
Verify configuration
Display current LOM network settings
ipmitool lan print 1
Test network connectivity
ping <new_LOM_IP_address>
https://<new_LOM_IP_address>
User password management
-
List current usersRun the following command to display all configured LOM user accounts with their user IDs:
ipmitool user list 1Example output:ID Name Callin Link Auth IPMI Msg Channel Priv Limit 1 nsroot false false false NO ACCESS 2 false false true ADMINISTRATOR 3 true false false NO ACCESS Note:The defaultnsrootaccount has a User ID of2. -
Change user passwordRun the following command to change the password for the
nsrootaccount (User ID2):ipmitool user set password <user_ID> <new_LOM_password>Where:-
<user_ID>is the appropriate user ID (typically 2 for nsroot account). -
<new_LOM_password>is the new password.
Example:ipmitool user set password 2You are prompted to enter the new password interactively.Alternative (Non-Interactive):ipmitool user set password 2 NewSecurePassword123Note:The system prompts for the new password interactively. Enter the password when prompted. -
LOM factory reset
ipmitool raw 0x32 0x66
-
All settings revert to defaults (192.168.1.3/24).
-
All passwords reset to the device serial number.
-
System Lockdown mode resets to enable, by default.
-
SSL certificates reset to self-signed defaults.
-
All user configurations and custom settings are erased and restored back to factory defaults.
Remote system power control
Power on procedure
-
Pre-startup verificationBefore initiating power-on, verify the following conditions:
-
Power supplies are connected and operational.
-
Network infrastructure is available and stable.
-
Environmental conditions are within an acceptable range (temperature, airflow).
-
No hardware alerts or critical warnings are active.
-
-
Access power controlNavigate to the power control interface, LOM Web UI > Dashboard > Power Control.
-
Run power on
-
Select Power On from the available power control actions.
-
Review the confirmation dialog.
-
Click Perform Action to initiate the startup sequence.
-
-
Monitor startup processObserve the following indicators during system boot:
-
The power LED changes from off to solid green.
-
The system completes POST (Power-On Self-Test).
-
Network interfaces initialize and link up.
-
The operating system loads and becomes accessible.
-
Graceful shutdown procedure
-
Pre-Shutdown verificationConfirm the following conditions before initiating a shutdown:
-
No critical operations are in progress.
-
All active user sessions are canceled.
-
Configuration changes are saved.
-
Backup operations are complete.
-
-
Access power controlNavigate to the power control interface, LOM Web UI > Dashboard > Power Control.
-
Initiate ACPI Shutdown
-
Select ACPI Shutdown from the power control actions.
-
Review the confirmation dialog.
-
Click Perform Action to initiate the graceful shutdown.
The ACPI Shutdown option sends a graceful shutdown signal to the operating system, allowing all services to exit. -
-
Monitor shutdown processObserve the following indicators during system shutdown:
-
The operating system begins the shutdown sequence.
-
Network interfaces go offline.
-
System services exit gracefully.
-
The power LED changes from green to off.
Note:Allow adequate time for a complete shutdown before initiating any power-on operations. -
Troubleshooting
Cannot access the default IP address
https://192.168.1.3.
-
The workstation is not configured with the correct IP address.
-
Network cable is not connected properly.
-
Layer 2 switching issue or VLAN mismatch.
-
BMC is not fully initialized after system boot.
-
Verify workstation IP configuration: Use
ipconfig(Windows) orifconfig/ip addr(Linux/macOS). -
Verify physical cable connection: Ensure the cable is plugged into the dedicated LOM port.
-
Check link status: Verify the LED on the LOM port is active.
-
Wait for initialization: Allow up to 5 minutes after system boot for the BMC to initialize.
-
Direct Connection: Try a direct crossover cable connection if a switched network issue is suspected.
Login fails with default credentials
nsroot and the serial number.
-
Incorrect serial number entry (passwords are case-sensitive).
-
The password was previously changed from the default.
-
The user account is locked due to multiple failed attempts.
-
Verify serial number: Check the physical label or device documentation.
-
Check case-sensitivity: Ensure the serial number is entered exactly as displayed.
-
Clear browser data: Clear the browser cache and cookies, then retry.
-
Account Lockout: Wait 15 minutes if the account is locked, then retry.
-
Factory Reset: Perform a factory reset if the password is lost and cannot be recovered.
BMC not responding after configuration
-
An invalid IP address or subnet mask is entered.
-
The network gateway is unreachable from the new IP address.
-
IP address conflicts with another device on the network.
-
BMC requires additional time for initialization.
-
Wait for initialization: Allow a full 120 seconds for BMC network initialization.
-
Check for conflicts: Verify that no other device on the network segment is using the same IP address.
-
Test connectivity: Attempt to
pingthe new IP address from a management workstation. -
Revert to default: Try connecting to the original default IP address (
192.168.1.3) if the new IP address fails. -
Factory Reset: Perform a factory reset if the BMC remains completely inaccessible.
Best practices for LOM configuration and management
Security best practices
Password policy
-
Change default passwords: Update the default credentials immediately after the first login.
-
Complexity requirements: Use strong passwords with a minimum of 8 characters.
-
Character variety: Include a mix of uppercase letters, lowercase letters, numbers, and special characters.
-
Rotation: Rotate passwords regularly according to your organizational security policy.
-
Uniqueness: Avoid using common words or device-specific information (such as serial numbers) in passwords.
System lockdown
-
Production readiness: Enable System Lockdown mode in all production environments.
-
Maintenance window: Disable lockdown only when configuration changes are explicitly required.
-
Re-enablement: Re-enable lockdown immediately after completing maintenance tasks.
Access logging
-
Audit logging: Enable audit logging for all administrative actions to maintain a clear history of changes.
-
Regular reviews: Regularly review access logs for any signs of unauthorized attempts.
-
Alerting: Implement alerting mechanisms for failed authentication attempts.
SSL/TLS configuration
-
Certificate replacement: Replace the default LOM self-signed SSL certificate with certificates from a trusted multi-tier CA root chain.
-
Chain validation: Implement proper certificate chain validation.
-
Protocol version: Use minimum TLS 1.2 protocol.
-
Monitoring: Configure appropriate monitoring for certificate expiration.
Power control best practices
-
Prioritize graceful shutdowns: Use graceful shutdown procedures whenever possible to prevent data corruption and service disruption.
-
Observe power cycle delays: Wait a minimum of 30 seconds between power-off and power-on operations.
-
Maintain documentation: Document all power control actions in change management or maintenance logs.
-
Schedule operations: Coordinate all power operations with established maintenance windows to minimize impact.
-
Ensure redundant access: Maintain alternative access methods (such as serial console or iKVM) while power cycling the system.
-
Verify system state: Always verify the system's operational state both before and after performing power operations.