IPMI (Intelligent Platform Management Interface) is the protocol spoken by the BMC, the small management controller built into most server motherboards. The BMC has its own network port and power supply, so it lets you power a server on and off, read its hardware sensors and reach its console even when the operating system has crashed. In this tutorial you will install ipmitool on Ubuntu 24.04, connect to a BMC locally and over the network, control power and boot order, read sensors and the event log, open a Serial-over-LAN console and lock down the BMC user accounts.
Prerequisites
To follow this guide you need:
- A bare metal server with an IPMI 2.0 compatible BMC (Supermicro, Dell iDRAC, HPE iLO, Lenovo XClarity and most others). Virtual machines do not have a BMC.
- A management workstation or jump host running Ubuntu 24.04 LTS, with a non-root
sudouser. - The BMC's IP address, a BMC username and password, and network access from the workstation to UDP port 623 on the BMC.
Warningnever expose a BMC to the public internet. IPMI has a long history of serious vulnerabilities. Keep BMCs on an isolated management network or VPN and reach them from a jump host.
Step 1 - Installing ipmitool
ipmitool is in the Ubuntu repositories. Install it on the workstation you will manage servers from, and also on the managed server itself if you want local access:
sudo apt update
sudo apt install ipmitool
Check the version:
ipmitool -V
ipmitool version 1.8.19
Step 2 - Accessing the BMC locally from the server
When you are logged in to the server itself, ipmitool talks to the BMC through a kernel driver instead of the network, and needs no password. Load the drivers and make them load at boot:
sudo modprobe ipmi_devintf
sudo modprobe ipmi_si
printf 'ipmi_devintf\nipmi_si\n' | sudo tee /etc/modules-load.d/ipmi.conf
Check that the device exists and that the BMC answers:
ls /dev/ipmi*
sudo ipmitool mc info
/dev/ipmi0
Device ID : 32
Device Revision : 1
Firmware Revision : 1.73
IPMI Version : 2.0
Manufacturer Name : Super Micro Computer Inc.
...
Local access is the easiest way to find the BMC's network settings. Most BMCs use channel 1 for LAN:
sudo ipmitool lan print 1
IP Address Source : Static Address
IP Address : 10.10.0.21
Subnet Mask : 255.255.255.0
MAC Address : 3c:ec:ef:12:34:56
Default Gateway IP : 10.10.0.1
...
If the BMC has no address yet, you can set a static one from the server:
sudo ipmitool lan set 1 ipsrc static
sudo ipmitool lan set 1 ipaddr 10.10.0.21
sudo ipmitool lan set 1 netmask 255.255.255.0
sudo ipmitool lan set 1 defgw ipaddr 10.10.0.1
Step 3 - Connecting to a BMC over the network
Remote commands use the lanplus interface (IPMI 2.0 with RMCP+ encryption). Avoid the old lan interface (IPMI 1.5), which sends credentials without proper protection.
Passing the password with -P leaves it in your shell history and in the process list. Store it in a file only you can read and pass it with -f instead:
install -m 600 /dev/null ~/.ipmi-pass
nano ~/.ipmi-pass
Write only the password on the first line and save the file. Then run your first remote command, replacing your_bmc_ip and your_bmc_user:
ipmitool -I lanplus -H your_bmc_ip -U your_bmc_user -f ~/.ipmi-pass chassis status
System Power : on
Power Overload : false
Main Power Fault : false
Power Control Fault : false
Power Restore Policy : always-off
...
To keep the rest of the commands short, define a shell function in your session:
bmc() { ipmitool -I lanplus -H your_bmc_ip -U your_bmc_user -f ~/.ipmi-pass "$@"; }
Now bmc chassis status runs the same command as above. The examples below use bmc. To run them locally on the server instead, replace bmc with sudo ipmitool.
Step 4 - Controlling power and boot order
These are the commands you will use most when a server stops responding:
bmc chassis power status
Chassis Power is on
| Command | Effect |
|---|---|
bmc chassis power on | Powers the server on. |
bmc chassis power soft | Sends an ACPI shutdown signal, like a short press of the power button. The OS shuts down cleanly. |
bmc chassis power off | Cuts power immediately, like holding the power button. |
bmc chassis power cycle | Powers off, waits a moment and powers on again. |
bmc chassis power reset | Hard reset, like pressing the reset button. |
Always try soft first. off, cycle and reset do not give the OS a chance to flush data to disk.
To boot a server once from the network (for example to reinstall it through PXE) and then reset it:
bmc chassis bootdev pxe
bmc chassis power reset
The override applies only to the next boot. Other useful targets are disk, cdrom and bios (enter firmware setup). On UEFI systems add options=efiboot so the BMC requests a UEFI boot:
bmc chassis bootdev pxe options=efiboot
Change what the server does when power returns after an outage:
bmc chassis policy always-on
The valid values are always-on, always-off and previous.
Step 5 - Reading sensors and the event log
The BMC continuously reads temperatures, fan speeds, voltages and power supply status. List all sensors with their status:
bmc sdr elist
Filter by sensor type to get a quick view of what matters:
bmc sdr type Temperature
CPU1 Temp | 01h | ok | 3.1 | 48 degrees C
CPU2 Temp | 02h | ok | 3.2 | 51 degrees C
System Temp | 0Bh | ok | 7.1 | 29 degrees C
Peripheral Temp | 0Ch | ok | 7.2 | 38 degrees C
Other useful types are Fan, Voltage and Power Supply. To see the warning and critical thresholds the BMC uses for each sensor:
bmc sensor list
The System Event Log (SEL) records hardware events such as memory ECC errors, power supply failures, fan faults and chassis intrusion. It is the first place to look after an unexpected reboot:
bmc sel elist
1 | 09/21/2026 | 03:12:45 | Power Supply PS2 Status | Power Supply AC lost | Asserted
2 | 09/21/2026 | 03:14:02 | Power Supply PS2 Status | Power Supply AC lost | Deasserted
The SEL has limited space and some BMCs stop logging when it is full. Save it before clearing it:
bmc sel elist > sel-$(date +%F).txt
bmc sel clear
To read the hardware inventory (board model, serial numbers, power supplies):
bmc fru print
Step 6 - Using Serial-over-LAN
Serial-over-LAN (SOL) redirects the server's serial port through the BMC, so you get a text console over the network: firmware messages, the GRUB menu, kernel output and a login prompt. It works even when SSH is down.
First make Linux on the managed server send its console to the serial port. Which port the BMC redirects depends on the vendor, usually ttyS1 on Supermicro and Dell and ttyS0 on many others; check your BMC documentation. On the managed server, edit the GRUB defaults:
sudo nano /etc/default/grub
Set these lines, adjusting ttyS1 if needed:
GRUB_CMDLINE_LINUX="console=tty0 console=ttyS1,115200n8"
GRUB_TERMINAL="console serial"
GRUB_SERIAL_COMMAND="serial --unit=1 --speed=115200"
--unit=1 matches ttyS1; use --unit=0 for ttyS0. Apply the change and reboot:
sudo update-grub
sudo reboot
systemd starts a login prompt on the serial console automatically because it appears in the kernel command line.
On the workstation, check the SOL settings of the BMC and make sure the speed matches:
bmc sol info 1
Enabled : true
Force Encryption : true
Privilege Level : ADMINISTRATOR
Non-Volatile Bit Rate (kbps) : 115.2
Volatile Bit Rate (kbps) : 115.2
...
If the bit rate differs, set it with bmc sol set non-volatile-bit-rate 115.2 1 and bmc sol set volatile-bit-rate 115.2 1. Then open the console:
bmc sol activate
Press Enter to get a login prompt. To leave the session, type ~. (tilde, then period) at the start of a line. If you are connected to the workstation through SSH, type ~~. so the outer SSH session does not capture the escape sequence.
If a previous session was not closed properly, SOL refuses a new one with SOL payload already active on another session. Close the old session first:
bmc sol deactivate
Step 7 - Securing BMC users
Many BMCs ship with well-known default credentials. Review the user table on channel 1:
bmc user list 1
ID Name Callin Link Auth IPMI Msg Channel Priv Limit
1 true false false NO ACCESS
2 ADMIN false false true ADMINISTRATOR
3 true false false NO ACCESS
Create a personal administrator account in a free slot (3 in this example). When you omit the password, ipmitool prompts for it so it does not end up in your history:
bmc user set name 3 your_admin_user
bmc user set password 3
bmc channel setaccess 1 3 link=on ipmi=on callin=on privilege=4
bmc user enable 3
Privilege level 4 is Administrator. Allow the new user to use Serial-over-LAN:
bmc sol payload enable 1 3
Update your password file with the new password and test the account before touching the old one:
ipmitool -I lanplus -H your_bmc_ip -U your_admin_user -f ~/.ipmi-pass mc info
Once it works, disable the default account (slot 2 in the example) or at least change its password:
bmc user disable 2
Finally, make sure cipher suite 0 is not accepted. It allows logging in with any password. Look at the Cipher Suite Priv Max line of bmc lan print 1: the first character corresponds to cipher suite 0 and must be X (disabled). If it is not, disable cipher 0 in the BMC web interface or update the BMC firmware.
Troubleshooting
Error: Unable to establish IPMI v2 / RMCP+ session. Check that the username and password are right and that the user has IPMI access on the channel (bmc channel setaccess). Some older BMCs do not support ipmitool's default cipher suite 17; try -C 3:
ipmitool -I lanplus -C 3 -H your_bmc_ip -U your_bmc_user -f ~/.ipmi-pass chassis status
Could not open device at /dev/ipmi0. The local drivers are not loaded. Run sudo modprobe -a ipmi_si ipmi_devintf and check sudo dmesg | grep -i ipmi. If ipmi_si finds no interface, the machine has no BMC or it is disabled in the firmware.
Commands time out. UDP 623 is blocked between your workstation and the BMC, or the BMC itself is hung. From a local shell on the server, sudo ipmitool mc reset cold restarts the BMC (it does not affect the running OS and does not reset BMC settings).
SOL connects but shows nothing or garbage. The serial port or speed does not match. Try the other ttyS port in GRUB and make sure the kernel, GRUB and the BMC all use 115200.
Conclusion
You can now reach a server's BMC with ipmitool, power cycle it safely, change the boot device, read its sensors and event log, get a console through Serial-over-LAN and replace default BMC credentials. As next steps, collect IPMI sensor data centrally with Prometheus and the ipmi_exporter, script PXE reinstalls with chassis bootdev pxe, and keep your BMC firmware up to date, since many IPMI vulnerabilities are fixed only through firmware updates.
