HPE iLO 5 Initial Setup, Virtual Media & Remote Console - 夜莺博客

HPE iLO 5 Initial Setup, Virtual Media & Remote Console

HPE iLO 5 is the out-of-band management controller on ProLiant Gen10 and Gen10 Plus
servers, and it is the only way back into a machine whose OS will not boot. The initial setup
is short but has a few decisions that are expensive to change later — the network topology of
the management port, whether you set a static address or leave DHCP, and which licensing tier
you need for virtual media, the remote console and Redfish automation. This guide covers the
whole first-run sequence, then the day-to-day operations that matter: mounting an ISO,
attaching a virtual folder, launching the HTML5 console, and updating iLO firmware from the
command line.

Before You Start: Cabling and Addressing

iLO 5 has a dedicated RJ45 port and, on most Gen10 models, is also reachable through a
shared port. Juniper-style habits from switch management do not carry over here: iLO speaks
DHCP by default and its IPv4 DNS settings can be reset by firmware upgrades, so verify the
address after every major update rather than assuming it persisted.

  • Dedicated port — preferred. Put it on a management VLAN with an ACL that permits only your
    jump hosts.
  • Shared port — uses the LOM, with a VLAN tag if you configure one. Convenient in labs,
    riskier in production because the management plane rides the data plane.
  • iLO Direct (USB) — a recovery tool only. Use it when the network configuration is wrong,
    not as a primary access path.

Step 1: Reach the Default Interface

On a factory-fresh server the iLO IP is obtained by DHCP. Get it from the boot screen, from
DHCP leases, or from the physical iLO information tag on the server bezel — Gen10 and later
ship with a unique default password printed on that tag, replacing the old Administrator /
random-8-character
scheme.

# Quick reachability and identity check from your workstation
curl -sk https://ILO-IP/json/login_session -X POST \
  -H 'Content-Type: application/json' \
  -d '{"method":"login","user_login":"Administrator","password":"TAG-PASSWORD"}'

# Prefer the modern endpoint
curl -sk -u Administrator:'TAG-PASSWORD' https://ILO-IP/redfish/v1/Systems/1 | jq '.Model, .SerialNumber'

Step 2: Set a Static Address

Do this through the iLO web interface under Network > iLO Dedicated Network Port,
or at the console with the iLO 5 Configuration Utility (press F9 during POST). The web
interface is the more reliable path on Gen10 because the configuration utility's menu layout
varies between server models. HPE's own workflow is: prepare, connect iLO to the network, then
either run the configuration utility or complete setup in the web interface.

# Equivalent operation over the REST API / ilorest
ilorest login ILO-IP -u Administrator -p 'PASSWORD'
ilorest select ManagerNetworkProtocol.
ilorest set --href /redfish/v1/Managers/1/EthernetInterfaces/1 \
  IPv4StaticAddresses/1='{"Address":"10.0.9.21","SubnetMask":"255.255.255.0","Gateway":"10.0.9.1"}'
ilorest commit
ilorest logout

Step 3: Users, Licensing and Hardening

  • Create named accounts. Never leave a shared Administrator account in place.
  • Map directory authentication if you already run Active Directory or an LDAP directory
    through Security > Directory; group-based privilege mapping beats per-user
    accounts.
  • iLO Advanced unlocks the full virtual media set, directory integration, iLO Federation and
    the complete Redfish surface. Standard and Basic licences restrict the features you are most
    likely to want in an emergency — decide before the incident, not during it.
  • Disable IPMI over LAN (set /redfish/v1/Managers/1/Oem/Hpe/NetworkProtocol IPMILan=Disabled)
    unless a legacy tool genuinely needs it.

Step 4: Virtual Media and the Remote Console

Virtual media is what lets you reinstall a hypervisor in a remote rack. Two forms exist:
ISO/image mounting, and a virtual folder that exposes a directory from your workstation.

# Insert a CD/DVD image (iLO web UI: Virtual Media > Virtual CD/DVD)
ilorest rawpost /redfish/v1/Managers/1/VirtualMedia/2/Actions/VirtualMedia.InsertMedia \
  '{"Image":"http://fileserver.local/isos/VMware-ESXi-8.iso","Inserted":true,"WriteProtected":true}'

# Mount a local folder as a USB device over the network (iLO Advanced)
# Web UI: Virtual Media > Virtual USB > Attach, then choose "Local image file" or "Local folder"

For the remote console, the HTML5 console in iLO 5 needs no Java or ActiveX plugin and runs
in any modern browser. It gives you keyboard, mouse, virtual power, virtual media control and
the ability to capture a screenshot when a boot is failing. The text-based remote console
(TIRC) is worth knowing about, because it works over a slow link where the graphical console
will not render at all.

ssh Administrator@ILO-IP
# at the iLO CLI prompt
textcons          # switch the active session to the text console

Step 5: Firmware Baseline and Verification

ilorest serverinfo --firmware
ilorest flashfwpkg iLO5_2.90.fwpkg

# Alternative: the SPP / iLO firmware component via the web UI
#   Firmware & OS Software > Update Firmware > choose local file
# Always re-verify the version afterwards
ilorest serverinfo --firmware
curl -sk -u Administrator:'PW' https://ILO-IP/redfish/v1/Managers/1 | jq '.FirmwareVersion'

Remember that an iLO update restarts the management processor without touching the host.
Reconfigure static IPv4/IPv6 DNS afterwards if the release notes mention a network setting
change.

Operational Habits That Pay Off

  • Keep the iLO firmware inside your normal patch cycle. It is a permanently running Linux
    system with credentials to the host — a well-known target.
  • Alert, do not poll: configure iLO to forward SNMP traps and syslog to your monitoring
    platform and log pipeline (see Grafana Loki and Promtail log pipeline).
  • Use iLO Federation on Gen10 fleets to run group power actions and firmware updates across
    many servers at once instead of one console session per machine.
  • Document the iLO password tag location. In a rack of 40 servers, the information tag is
    faster than a password vault you cannot reach.

This complements iDRAC vs iLO vs IPMI: out-of-band server management and ipmitool BMC sensor, SEL and SOL operations — together they cover the three BMC platforms you will meet in most data centres.

原文链接:https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us