nanog mailing list archives

Re: WaPo writes about vulnerabilities in Supermicro IPMIs


From: Jay Ashworth <jra () baylink com>
Date: Thu, 15 Aug 2013 22:36:28 -0400 (EDT)

----- Original Message -----
From: "Valdis Kletnieks" <Valdis.Kletnieks () vt edu>

Is anyone here stupid enough not to put the management interfaces
behind a firewall/VPN?

In most cases, this requires plugging in two separate ethernet cables
without wondering why you asked to be provisioned one IP address....

Hey; on my very first colo deploy, I was smart enough to put public, private
and ILO on separate VLANs.  Well, ok, I put ILO on the private VLAN, and
just put it in a disjoint network, but still... :-)

Cheers,
-- jra
-- 
Jay R. Ashworth                  Baylink                       jra () baylink com
Designer                     The Things I Think                       RFC 2100
Ashworth & Associates     http://baylink.pitas.com         2000 Land Rover DII
St Petersburg FL USA               #natog                      +1 727 647 1274


Current thread: