Good morning, I know that best practice requires disconnecting out-of-band connections (HPE iLO, Dell iDRAC, Lenovo XCC, etc.) to reduce the attack surface and limit the ability to access the server, but there's still a need for notifications in the event of server hardware failures. I've read about camera-based monitoring with or without AI or similar, but that seems like an exaggeration.
I was wondering if a viable solution might be to connect the out-of-band card in "loopback" mode to one of the server's network cards. An SMTP service could be installed on the server to send emails (accepting emails only from out-of-band connections and only from that network card) and then configuring this SMTP server on the out-of-band card. This way, the out-of-band connection won't be reachable remotely, but you can still receive alert emails.
This would require the server to be able to use a second network card to send emails externally.
What do you think? Is this a no-brainer, or is it feasible if you follow security best practices?
If it's not a bad idea, is it possible to add an SMTP server to the ISO to manage this configuration?
Thanks everyone!
-
Maga84
- Novice
- Posts: 3
- Liked: 1 time
- Joined: Apr 01, 2024 10:15 pm
- Full Name: Fabio Magalini
- Contact:
-
Gostev
- former Chief Product Officer (until 2026)
- Posts: 33084
- Liked: 8168 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: Hardened repository notification from out-of-band
Good morning, we're working on adding proper integrations to enable safe and secure monitoring of our appliances with 3rd party software. There's extensive roadmap to cover all bases, and if I remember correct the team wants to start from adding Node Exporter and Syslog ASAP as these will be fairly simple to integrate quickly. Thanks
Who is online
Users browsing this forum: andreilight1, Bing [Bot], IvanK, Mildur and 53 guests