Users Guide

Group Manager uses mDNS to discover other iDRACs on the network and sends encrypted packets for normal inventorying,
monitoring and management of the group using the link local IP address. Using IPv6 link local networking means that the Group
Manager ports and packets will never leave the local network or be accessible to external networks.
Ports (Specific to Group Manager unique functionality does not include all iDRAC ports) are:
5353 (mDNS)
443 (webserver) - configurable
5670 (Multicast group communication)
C000 -> F000 dynamically identifies one free port for each member to communicate in the group
Best networking practices
Groups are intended to be small and on the same physical link local network.
It is recommended to use the dedicated iDRAC network port for enhanced security. Shared LOM is also supported.
Additional network considerations
Two iDRACs that are separated by a router in the network topology are considered to be on separate local networks and cannot
be joined in the same iDRAC local group. Meaning, if the iDRAC is configured for dedicated NIC settings, the network cable
connected to iDRAC dedicated port in the rear of the server must be under a local network for all relevant servers.
If the iDRAC is configured for shared LOM network settings, the shared network connection used by both server host and
IDRAC need to be connected under a local network for Group Manager to detect and onboard those servers into a common
group. IDRACs configured with a mix of dedicated and shared LOM mode NIC settings could also be on-boarded into a common
group, if all the network connections do not pass through a router.
Manage Logins
Use this section to Add New User, Change User Password and Delete User from the Group.
Group jobs including Manage Logins are one time configurations of the servers. Group manager uses SCP and jobs to make any
changes. Every iDRAC in the group owns an individual job in its job queue for each Group Manager job. Group Manager does not
detect changes on member iDRACs or lock member configurations.
NOTE: Group jobs does not configure or override the lockdown mode for any specific iDRAC.
Leaving a group does not change local user or change settings on a member iDRAC.
Add a New User
Use this section to create and add a new user profile on all the servers in that group. A group job would be created to add the
user to all servers in that group. The status of group job can be found at GroupManager > Jobs page.
NOTE:
By default iDRAC is configured with a local administrator account. You can access further information for each
parameter with local administrator account.
For more information see, Configuring user accounts and privileges.
Table 36. New User Options
Option Description
New User Information Allows you to provide the new user's information details.
iDRAC Permissions Allows you to define the user's role for future usage.
Advanced User Settings Allows you to set (IPMI) user privileges and helps you to
enable SNMP.
NOTE: Any member iDRAC with system lockdown enabled, that is part of the same group returns an error that the user
password was not updated.
iDRAC 9 Group Manager 185