LOM port management for SDX 9200 and SDX 17000
Prerequisites
-
Physical or console access to NetScaler.
-
Network connectivity to the LOM port (direct or switched).
-
Device serial number (required for initial authentication).
-
Planned IP addressing scheme for the LOM network segment.
-
Administrative access credentials.
-
Web browser with HTML5 support (Chrome, Firefox, Edge, or Safari).
-
Standard HTTPS (port 443) network access to the LOM IP address.
Initial network access
Default LOM settings
| Parameter | Default Value |
|---|---|
| IP Address | 192.168.1.3 |
| Subnet Mask | 255.255.255.0 |
| Default Gateway | 192.168.1.1 |
| Username | nsroot |
| Password | Device serial number (case-sensitive) |
Network connection methods
-
Connect a laptop Ethernet port to the LOM interface using a crossover cable.
-
Set the laptop static IP address to
192.168.1.10with a subnet mask of255.255.255.0.
-
Connect the LOM interface and a management workstation to the same network switch.
-
Ensure that both devices are in the
192.168.1.0/24broadcast domain.
Configure LOM by using the GUI
Initial login and password change
-
Open a web browser
-
Type
https://192.168.1.3. -
Accept the self-signed SSL certificate warning that appears in the browser.
-
-
Authenticate with default credentials
-
Enter
nsrootas the Username. -
Enter the device serial number as the password (note: this is case-sensitive).
-
Click Login.
-
-
Mandatory password changeOn the first login, the system enforces a password change for security.
-
Current Password: Enter the device serial number.
-
New Password: Enter a password that meets the complexity requirements shown on the page.
-
Confirm Password: Re-enter the new password.
-
Click Submit to save.
-
nsroot account and your newly created password.
Network configuration
-
Navigate to Settings > Network IP Settings > LAN Interface (eth0).
-
Enter the following details:
-
IPv4 Address
-
IPv4 Subnet
-
IPv4 Gateway
-
-
Click Save. The Baseboard Management Controller (BMC) takes approximately 30 seconds to apply changes and then disconnects your current session.
-
Verify connectivity by pinging the new LOM IP address by using the following command from your management workstation:
ping <New_LOM_IP_Address> -
Access the LOM interface using the new IP address:
https://<new_LOM_IP_address> -
Log using
nsrootand updated password.
System lockdown mode restriction
Symptoms of lockdown mode
-
Error Messages: Insufficient privilege (code 8000).
-
Notifications: You do not have permission to view this content.
-
GUI Behavior: Settings menu items appear grayed out or are completely inaccessible.
Affected functions
-
Network configuration changes.
-
User management and password operations.
-
LOM firmware updates.
-
Field Replaceable Unit (FRU) data modifications.
Configure LOM by using the CLI (IPMI tool)
ipmitool commands.
Access requirements
-
Serial console connection
-
SSH session (if a network is configured)
-
Direct access or monitor access
shell to enter the FreeBSD environment.
System lockdown management
-
Check Status:
ipmitool raw 0x34 0x81(00=Disabled (Configuration changes allowed),01=Enabled (Read-only mode active)). -
Disable Lockdown:
ipmitool raw 0x34 0x81 0x0.This command enables full read-write access to all BMC configuration interfaces. -
Enable Lockdown:
ipmitool raw 0x34 0x81 0x1.This command restricts all BMC interfaces to read-only access for enhanced security.
Static IP configuration
-
Set the IP address source to static: Change the interface mode to disable DHCP and prepare the interface for static IP assignment using the following command:
ipmitool lan set 1 ipsrc static -
Assign the IP address: Specify the static IP address for the LOM interface using the following command:
ipmitool lan set 1 ipaddr <LOM_IP_Address>Example:ipmitool lan set 1 ipaddr 192.0.2.255 -
Assign the Subnet mask: Define the subnet mask for the LOM network segment using the following command:
ipmitool lan set 1 netmask <Subnet_Mask>Example:ipmitool lan set 1 netmask 255.255.255.0 -
Configure the default gateway: Specify the gateway address for routing traffic outside the local segment using the following command:
ipmitool lan set 1 defgw ipaddr <Gateway_IP>Example:ipmitool lan set 1 defgw ipaddr 192.0.2.255 -
Reset or reboot the BMC to apply changes:
ipmitool bmc reset coldThe BMC requires approximately 120 seconds to fully initialize after a reset.
Verify configuration
Display current LOM network settings
ipmitool lan print 1
Test network connectivity
ping <new_LOM_IP_address>
https://<new_LOM_IP_address>
User password management
-
List current usersRun the following command to display all configured LOM user accounts with their user IDs:
ipmitool user list 1Example output:ID Name Callin Link Auth IPMI Msg Channel Priv Limit 1 nsroot false false false NO ACCESS 2 false false true ADMINISTRATOR 3 true false false NO ACCESS Note:The defaultnsrootaccount has a User ID of2. -
Change user passwordRun the following command to change the password for the
nsrootaccount (User ID2):ipmitool user set password <user_ID> <new_LOM_password>Where:-
<user_ID>is the appropriate user ID (typically 2 for nsroot account). -
<new_LOM_password>is the new password.
Example:ipmitool user set password 2You are prompted to enter the new password interactively.Alternative (Non-Interactive):ipmitool user set password 2 NewSecurePassword123Note:The system prompts for the new password interactively. Enter the password when prompted. -
LOM factory reset
ipmitool raw 0x32 0x66
-
All settings revert to defaults (192.168.1.3/24).
-
All passwords reset to the device serial number.
-
System Lockdown mode resets to enable, by default.
-
SSL certificates reset to self-signed defaults.
-
All user configurations and custom settings are erased and restored back to factory defaults.
Remote system power control
Power on procedure
-
Pre-startup verificationBefore initiating power-on, verify the following conditions:
-
Power supplies are connected and operational.
-
Network infrastructure is available and stable.
-
Environmental conditions are within an acceptable range (temperature, airflow).
-
No hardware alerts or critical warnings are active.
-
-
Access power controlNavigate to the power control interface, LOM Web UI > Dashboard > Power Control.
-
Run power on
-
Select Power On from the available power control actions.
-
Review the confirmation dialog.
-
Click Perform Action to initiate the startup sequence.
-
-
Monitor startup processObserve the following indicators during system boot:
-
The power LED changes from off to solid green.
-
The system completes POST (Power-On Self-Test).
-
Network interfaces initialize and link up.
-
The operating system loads and becomes accessible.
-
Graceful shutdown procedure
-
Pre-Shutdown verificationConfirm the following conditions before initiating a shutdown:
-
No critical operations are in progress.
-
All active user sessions are canceled.
-
Configuration changes are saved.
-
Backup operations are complete.
-
-
Access power controlNavigate to the power control interface, LOM Web UI > Dashboard > Power Control.
-
Initiate ACPI shutdown
-
Select ACPI Shutdown from the power control actions.
-
Review the confirmation dialog.
-
Click Perform Action to initiate the graceful shutdown.
The ACPI Shutdown option sends a graceful shutdown signal to the operating system, allowing all services to exit. -
-
Monitor shutdown processObserve the following indicators during system shutdown:
-
The operating system begins the shutdown sequence.
-
Network interfaces go offline.
-
System services exit gracefully.
-
The power LED changes from green to off.
Note:Allow adequate time for a complete shutdown before initiating any power-on operations. -
Troubleshooting
Cannot access the default IP address
https://192.168.1.3.
-
The workstation is not configured with the correct IP address.
-
Network cable is not connected properly.
-
Layer 2 switching issue or VLAN mismatch.
-
BMC is not fully initialized after system boot.
-
Verify workstation IP configuration: Use
ipconfig(Windows) orifconfig/ip addr(Linux/macOS). -
Verify physical cable connection: Ensure the cable is plugged into the dedicated LOM port.
-
Check link status: Verify the LED on the LOM port is active.
-
Wait for initialization: Allow up to 5 minutes after system boot for the BMC to initialize.
-
Direct Connection: Try a direct crossover cable connection if a switched network issue is suspected.
Login fails with default credentials
nsroot and the serial number.
-
Incorrect serial number entry (passwords are case-sensitive).
-
The password was previously changed from the default.
-
The user account is locked due to multiple failed attempts.
-
Verify serial number: Check the physical label or device documentation.
-
Check case-sensitivity: Ensure the serial number is entered exactly as displayed.
-
Clear browser data: Clear the browser cache and cookies, then retry.
-
Account Lockout: Wait 15 minutes if the account is locked, then retry.
-
Factory Reset: Perform a factory reset if the password is lost and cannot be recovered.
BMC not responding after configuration
-
An invalid IP address or subnet mask is entered.
-
The network gateway is unreachable from the new IP address.
-
IP address conflicts with another device on the network.
-
BMC requires additional time for initialization.
-
Wait for initialization: Allow a full 120 seconds for BMC network initialization.
-
Check for conflicts: Verify that no other device on the network segment is using the same IP address.
-
Test connectivity: Attempt to
pingthe new IP address from a management workstation. -
Revert to default: Try connecting to the original default IP address (
192.168.1.3) if the new IP address fails. -
Factory Reset: Perform a factory reset if the BMC remains completely inaccessible.
Best practices for LOM configuration and management
Security best practices
Password policy
-
Change default passwords: Update the default credentials immediately after the first login.
-
Complexity requirements: Use strong passwords with a minimum of 8 characters.
-
Character variety: Include a mix of uppercase letters, lowercase letters, numbers, and special characters.
-
Rotation: Rotate passwords regularly according to your organizational security policy.
-
Uniqueness: Avoid using common words or device-specific information (such as serial numbers) in passwords.
System lockdown
-
Production readiness: Enable System Lockdown mode in all production environments.
-
Maintenance window: Disable lockdown only when configuration changes are explicitly required.
-
Re-enablement: Re-enable lockdown immediately after completing maintenance tasks.
Access logging
-
Audit logging: Enable audit logging for all administrative actions to maintain a clear history of changes.
-
Regular reviews: Regularly review access logs for any signs of unauthorized attempts.
-
Alerting: Implement alerting mechanisms for failed authentication attempts.
SSL/TLS configuration
-
Certificate replacement: Replace the default LOM self-signed SSL certificate with certificates from a trusted multi-tier CA root chain.
-
Chain validation: Implement proper certificate chain validation.
-
Protocol version: Use minimum TLS 1.2 protocol.
-
Monitoring: Configure appropriate monitoring for certificate expiration.
Power control best practices
-
Prioritize graceful shutdowns: Use graceful shutdown procedures whenever possible to prevent data corruption and service disruption.
-
Observe power cycle delays: Wait a minimum of 30 seconds between power-off and power-on operations.
-
Maintain documentation: Document all power control actions in change management or maintenance logs.
-
Schedule operations: Coordinate all power operations with established maintenance Windows to minimize impact.
-
Ensure redundant access: Maintain alternative access methods (such as serial console or iKVM) while power cycling the system.
-
Verify system state: Always verify the system's operational state both before and after performing power operations.