What is BMC in server hardware? The out-of-band management chip explained
What is BMC in server hardware? The Baseboard Management Controller is a small computer on the motherboard with its own processor, memory, firmware and network port that runs whenever the server has power. IPMI and Redfish are protocols for talking to it; iDRAC and iLO are vendor names for it.
So what is BMC in server hardware? BMC stands for Baseboard Management Controller: a dedicated management chip on the server motherboard with its own processor, memory, firmware and network port. It runs whenever the server has power, even when the host is switched off or the operating system has crashed, and it lets you power the machine on and off, read sensors, see the screen and mount an ISO from anywhere on the network. IPMI and Redfish are protocols for talking to a BMC; iDRAC, iLO and XClarity Controller are vendor names for the same kind of chip.
What kind of chip is a BMC?
A BMC is essentially a small computer soldered onto the server motherboard, entirely separate from the host CPU, memory and disks:
| Component | Details |
|---|---|
| Processor | An ARM system-on-chip, most often from ASPEED or Nuvoton. The ASPEED AST2500 is a single-core ARM11 at 800 MHz; the AST2600 is a dual-core Cortex-A7 at 1.2 GHz with a Cortex-M3 coprocessor; Nuvoton’s NPCM7xx is a dual-core Cortex-A9 |
| Memory | Its own DDR memory, typically a few hundred MB up to 1 GB |
| Firmware storage | SPI flash of a few tens of MB holding the BMC firmware; some boards carry a second flash chip for redundancy |
| Network | A dedicated RJ45 management port, or a sideband (NC-SI) connection that shares one of the host’s onboard NICs |
| Display controller | ASPEED BMCs double as the motherboard’s integrated graphics, so the host’s video output is captured inside the BMC itself. That is why remote KVM can show the BIOS screen |
BMC firmware is usually a stripped-down Linux and comes from one of three places: the server vendor’s own stack (Dell iDRAC, HPE iLO), the commercial AMI MegaRAC stack used by white-box and many smaller vendors, or the open-source OpenBMC project hosted by the Linux Foundation and used by hyperscalers and some OEMs.
A set of dedicated connections links the BMC to the host, each providing one capability:
| Interface | Connected to | Capability |
|---|---|---|
| LPC or eSPI (KCS channel) | Host chipset | In-band IPMI: ipmitool inside the OS works without a password |
| I2C, SMBus, PMBus | Temperature sensors, power supplies, FRU EEPROM, memory SPD | Sensor readings, PSU status, board serial numbers |
| PECI | CPU | CPU temperature |
| Video capture | Host graphics output | Remote KVM screen |
| USB | Host USB controller | Emulated keyboard and mouse, virtual CD-ROM and USB drive |
| UART | Host serial port | Serial-over-LAN (SOL) |
| GPIO, PWM, tachometer | Power button, reset line, fans, LEDs | Power on and off, hard reset, fan speed control, locator LED |
Separate power and a separate network port
Why the BMC keeps running when the host is off
A server power supply has two outputs. The main rails feed the CPU, memory and disks and switch off when the host shuts down; the standby rail stays live as long as AC power is connected. The BMC runs from standby power, so:
- Host powered off (ACPI S5): the BMC is running and can power the host on remotely;
- Operating system crashed: the BMC is unaffected, because it does not depend on the host CPU;
- Power cord unplugged or PDU outlet switched off: the BMC loses power too and can do nothing.
The BMC draws only a few watts and uses none of the host’s CPU or memory, which is why it can sit on standby for years.
Dedicated or shared network port
A BMC reaches the network in one of two ways. The factory default varies by vendor and can be changed in the BIOS or in the BMC’s own settings:
| Mode | Cabling | Advantages | Drawbacks |
|---|---|---|---|
| Dedicated | A separate RJ45 port on the board, cabled to a management switch | Management traffic is physically separate from production traffic; a failed or rate-limited production NIC does not affect management | One more switch port and one more cable per server |
| Shared (NC-SI sideband) | The BMC borrows one of the host’s production NICs; two MAC addresses appear on one cable | Saves ports and cabling | If the production port is shut down, moved to another VLAN or cut off for non-payment, the BMC disappears with it |
Data centers normally use the dedicated port on a separate management VLAN, isolated from customer traffic. When a server is provisioned, the BMC gets an address from a dedicated IPMI address block that is managed apart from public IP space.
BMC vs IPMI vs Redfish
The most common confusion is “what is the difference between BMC and IPMI?” In one sentence: the BMC is hardware; IPMI and Redfish are protocols for talking to that hardware.
| BMC | IPMI | Redfish | |
|---|---|---|---|
| What it is | The management chip on the motherboard and its firmware | A platform management interface specification | A REST-based management API specification |
| Who defines it | Each server and motherboard vendor | Intel, Dell, HP and NEC; version 1.0 in 1998, 2.0 in 2004 | DMTF; version 1.0 in 2015 |
| Transport | — | Out of band over RMCP+ (UDP port 623); in band over KCS and other system interfaces | JSON over HTTPS, under /redfish/v1/ |
| Common tools | Vendor web interface | ipmitool, FreeIPMI | curl, redfishtool, vendor CLIs such as racadm and ilorest |
| Status | Present in every server | Universally supported; no major revision since 2.0 | Where new features land; modern BMCs support both |
A single BMC normally exposes all three entry points at once: the vendor’s web interface for people, IPMI for scripts and management systems, and Redfish for newer automation tooling. Anything ipmitool can do, Redfish can generally do too, and it returns structured data, such as a complete inventory of disks, NICs and firmware versions.
What vendors call their BMC
| Vendor | BMC name | Notes |
|---|---|---|
| Dell | iDRAC | Licensed as Basic, Express, Enterprise and Datacenter |
| HPE | iLO | Standard and Advanced licenses |
| Lenovo | XClarity Controller (XCC) | Standard, Advanced and Enterprise licenses |
| Cisco | CIMC / IMC | — |
| Supermicro | BMC / IPMI | Out-of-band BIOS updates and similar features need an SFT-OOB-LIC license |
| Huawei | iBMC | Older models used iMana |
| Fujitsu | iRMC | — |
| White-box and others | AMI MegaRAC, OpenBMC | Interface and features depend on the firmware stack |
Watch the licensing. Dell, HPE and Lenovo put the graphical remote console and virtual media behind higher license tiers; the base tier usually only shows status and controls power. When buying used or white-box servers, confirm that the license ships with the machine, or you will have a BMC whose console will not open. Tier names and included features change, so check the vendor’s current documentation.
What the BMC can do in each host state
| Host state | The BMC can | The BMC cannot |
|---|---|---|
| AC power on, host off | Power the host on; read temperatures, voltages and fan speeds; read the System Event Log (SEL) and FRU data; set the next boot device; mount virtual media; on some models update BIOS and firmware out of band | Show the OS screen, since the host is not running |
| Host on, OS hung | Show the current screen over KVM; hard reset or power off; send an NMI to force a crash dump; watch serial output over SOL | Shut down gracefully, which needs the OS to answer the ACPI signal |
| Host on, no OS installed | Install an OS from virtual media or by setting PXE boot; drive the BIOS through KVM | — |
| Power cord unplugged or PDU outlet off | Nothing | Everything; only a remotely switchable PDU can restore power |
Working with a BMC from the command line
Common ipmitool commands
The commands below run on any Linux system with ipmitool installed. Run inside the server’s own OS (in band) they need no address or password; from another machine (out of band) add -I lanplus -H <address> -U <user> -P <password>.
# Load the IPMI drivers before in-band use
modprobe ipmi_si
modprobe ipmi_devintf
# The BMC's own details: firmware version, manufacturer ID, supported features
ipmitool mc info
# Network settings of the management port (channel is usually 1; some models use 2 or 8, check the vendor docs)
ipmitool lan print 1
# Give the BMC a static address
ipmitool lan set 1 ipsrc static
ipmitool lan set 1 ipaddr 10.0.0.10
ipmitool lan set 1 netmask 255.255.255.0
ipmitool lan set 1 defgw ipaddr 10.0.0.1
# Board FRU data (model, serial number) and temperature sensors
ipmitool fru print 0
ipmitool sdr type Temperature
# Power state and the hardware event log
ipmitool chassis power status
ipmitool sel list
# List BMC users, then reset a password by user ID
ipmitool user list 1
ipmitool user set password 2 'NewPassword'
# Blink the chassis locator LED for 60 seconds to find the machine in the rack
ipmitool chassis identify 60
# Cold-reset a hung BMC; the host keeps running
ipmitool mc reset cold
The same information is available over Redfish as JSON:
# List this server's managers (the BMC) and system resources
curl -k -u admin:'password' https://10.0.0.10/redfish/v1/Managers/
curl -k -u admin:'password' https://10.0.0.10/redfish/v1/Systems/
Resource IDs under Managers vary by vendor (iDRAC uses iDRAC.Embedded.1, many others use 1), so list the collection first and then follow the links.
Troubleshooting
- BMC unresponsive, web interface will not load: run
ipmitool mc reset coldfrom inside the OS first. If in-band access is also dead, the only option is to remove AC power from the server, wait about 30 seconds and reconnect it so the BMC restarts from standby power. This is a side effect of separate power: rebooting the host never reboots the BMC. - No link light on the management port: check whether the BMC is set to dedicated or shared mode. Many “cannot reach the BMC” cases are a cable in the dedicated port while the setting says shared.
- Lost password: reset it in band with ipmitool, which needs no old password, or with the vendor tool (Dell racadm, HPE hponcfg).
- Wrong timestamps: SEL entries use the BMC’s clock. Set it with
ipmitool sel time setor configure NTP in the web interface. - Old firmware: BMC firmware has had a number of publicly disclosed vulnerabilities, and the BMC has full control of the server. Update to the vendor’s current release before racking, then check periodically.
The security rules are the same as for IPMI: keep the management port off the internet, change default passwords, and allow access only from the management system and jump hosts. The IPMI guide covers this in more detail.
Where the BMC fits in a management system
For hundreds or thousands of servers from different vendors, the BMC is how a management system reaches inside each machine. In Toplink DCIM you record each server’s BMC address, username and password; from then on remote power control, boot device selection, ISO mounting and the VNC console all happen in the browser, and the remote console is tuned for iDRAC, iLO, iBMC, Supermicro and XClarity BMCs (see IPMI remote management). BMC address blocks are typed as IPMI in IP address management and assigned separately from public space; hardware model templates record whether a model supports IPMI and which console type it uses; and an unresponsive BMC can be reset remotely from the admin panel, or by customers themselves in the self-service portal.
FAQ
What is the difference between BMC and BIOS?
BIOS (or UEFI) is firmware that runs on the host CPU at power-on to initialize hardware and boot the OS; it stops when the host is off. The BMC is a separate system on its own chip that keeps running while the host is off, can power it on remotely, show the BIOS screen and, on some models, update the BIOS out of band.
Do desktop PCs or workstations have a BMC?
Consumer motherboards normally do not. Some workstation boards and all server-class boards do. Some business desktops offer similar remote management through Intel AMT, but that is not a BMC.
Where do I find the default BMC username and password?
Check the label on the chassis or the pull-out tag first: most servers shipped in recent years use a random factory password printed there, while older models used a vendor-wide default. Either way, change it before the BMC touches a management network, and follow the vendor documentation for your model.
How do I update BMC firmware?
Upload the firmware package through the vendor's web interface, or push it with Redfish or the vendor's CLI; some vendors also support updating from within the OS. Do not cut power during the update. The BMC reboots itself afterwards and the host normally keeps running, but follow the vendor's procedure.