HP Integrity iLO 2 Operations Guide

Table Of Contents
Login After initial failed login attempts (default three), a delay of approximately
one second is imposed on the serial connection and the login banner
warnings are repeated. All other connection types are disconnected.
IMPORTANT: Ensure that physical access to the server is limited. Anyone can clear passwords
by pressing the iLO MP reset button for longer than four seconds.
NOTE: For greater security, HP recommends that iLO 2 management traffic be on a separate
dedicated management network that is configured to only allow limited access from selected secure
systems by designated system administrators. This acts as the first line of defense against security
attacks. A separate network enables you to physically and logically control which systems are
allowed to connect to the network and the iLO 2 LAN port.
Protecting SNMP Traffic
Because SNMP uses passwords, known as community strings, that are sent across the network in
clear text, you must enhance the network security when using SNMP traffic. To enhance network
security, do the following:
Reset the community strings (read only) with the same frequency and according to the same
guidelines as the administrative passwords. For example, select alphanumeric strings with at
least one uppercase letter, one numeral, and one symbol.
Set firewalls or routers to accept only specific source and destination addresses. For example,
you can allow inbound SNMP traffic into the host server only if it comes from one of the
predetermined management workstations.
TIP: Telnet sends data without encryption and is not a secure connection. HP recommends using
SSH instead of Telnet because SSH uses encryption.
To enable and disable Telnet access, use the SA command.
Security 25