Server operations

What is BMC in server hardware? The out-of-band management chip explained

What is BMC in server hardware? The Baseboard Management Controller is a small computer on the motherboard with its own processor, memory, firmware and network port that runs whenever the server has power. IPMI and Redfish are protocols for talking to it; iDRAC and iLO are vendor names for it.

By Toplink product teamPublished 9 min read

So what is BMC in server hardware? BMC stands for Baseboard Management Controller: a dedicated management chip on the server motherboard with its own processor, memory, firmware and network port. It runs whenever the server has power, even when the host is switched off or the operating system has crashed, and it lets you power the machine on and off, read sensors, see the screen and mount an ISO from anywhere on the network. IPMI and Redfish are protocols for talking to a BMC; iDRAC, iLO and XClarity Controller are vendor names for the same kind of chip.

What kind of chip is a BMC?

A BMC is essentially a small computer soldered onto the server motherboard, entirely separate from the host CPU, memory and disks:

Component Details
Processor An ARM system-on-chip, most often from ASPEED or Nuvoton. The ASPEED AST2500 is a single-core ARM11 at 800 MHz; the AST2600 is a dual-core Cortex-A7 at 1.2 GHz with a Cortex-M3 coprocessor; Nuvoton’s NPCM7xx is a dual-core Cortex-A9
Memory Its own DDR memory, typically a few hundred MB up to 1 GB
Firmware storage SPI flash of a few tens of MB holding the BMC firmware; some boards carry a second flash chip for redundancy
Network A dedicated RJ45 management port, or a sideband (NC-SI) connection that shares one of the host’s onboard NICs
Display controller ASPEED BMCs double as the motherboard’s integrated graphics, so the host’s video output is captured inside the BMC itself. That is why remote KVM can show the BIOS screen

BMC firmware is usually a stripped-down Linux and comes from one of three places: the server vendor’s own stack (Dell iDRAC, HPE iLO), the commercial AMI MegaRAC stack used by white-box and many smaller vendors, or the open-source OpenBMC project hosted by the Linux Foundation and used by hyperscalers and some OEMs.

A set of dedicated connections links the BMC to the host, each providing one capability:

Interface Connected to Capability
LPC or eSPI (KCS channel) Host chipset In-band IPMI: ipmitool inside the OS works without a password
I2C, SMBus, PMBus Temperature sensors, power supplies, FRU EEPROM, memory SPD Sensor readings, PSU status, board serial numbers
PECI CPU CPU temperature
Video capture Host graphics output Remote KVM screen
USB Host USB controller Emulated keyboard and mouse, virtual CD-ROM and USB drive
UART Host serial port Serial-over-LAN (SOL)
GPIO, PWM, tachometer Power button, reset line, fans, LEDs Power on and off, hard reset, fan speed control, locator LED

Separate power and a separate network port

Why the BMC keeps running when the host is off

A server power supply has two outputs. The main rails feed the CPU, memory and disks and switch off when the host shuts down; the standby rail stays live as long as AC power is connected. The BMC runs from standby power, so:

  • Host powered off (ACPI S5): the BMC is running and can power the host on remotely;
  • Operating system crashed: the BMC is unaffected, because it does not depend on the host CPU;
  • Power cord unplugged or PDU outlet switched off: the BMC loses power too and can do nothing.

The BMC draws only a few watts and uses none of the host’s CPU or memory, which is why it can sit on standby for years.

Dedicated or shared network port

A BMC reaches the network in one of two ways. The factory default varies by vendor and can be changed in the BIOS or in the BMC’s own settings:

Mode Cabling Advantages Drawbacks
Dedicated A separate RJ45 port on the board, cabled to a management switch Management traffic is physically separate from production traffic; a failed or rate-limited production NIC does not affect management One more switch port and one more cable per server
Shared (NC-SI sideband) The BMC borrows one of the host’s production NICs; two MAC addresses appear on one cable Saves ports and cabling If the production port is shut down, moved to another VLAN or cut off for non-payment, the BMC disappears with it

Data centers normally use the dedicated port on a separate management VLAN, isolated from customer traffic. When a server is provisioned, the BMC gets an address from a dedicated IPMI address block that is managed apart from public IP space.

BMC vs IPMI vs Redfish

The most common confusion is “what is the difference between BMC and IPMI?” In one sentence: the BMC is hardware; IPMI and Redfish are protocols for talking to that hardware.

BMC IPMI Redfish
What it is The management chip on the motherboard and its firmware A platform management interface specification A REST-based management API specification
Who defines it Each server and motherboard vendor Intel, Dell, HP and NEC; version 1.0 in 1998, 2.0 in 2004 DMTF; version 1.0 in 2015
Transport — Out of band over RMCP+ (UDP port 623); in band over KCS and other system interfaces JSON over HTTPS, under /redfish/v1/
Common tools Vendor web interface ipmitool, FreeIPMI curl, redfishtool, vendor CLIs such as racadm and ilorest
Status Present in every server Universally supported; no major revision since 2.0 Where new features land; modern BMCs support both

A single BMC normally exposes all three entry points at once: the vendor’s web interface for people, IPMI for scripts and management systems, and Redfish for newer automation tooling. Anything ipmitool can do, Redfish can generally do too, and it returns structured data, such as a complete inventory of disks, NICs and firmware versions.

What vendors call their BMC

Vendor BMC name Notes
Dell iDRAC Licensed as Basic, Express, Enterprise and Datacenter
HPE iLO Standard and Advanced licenses
Lenovo XClarity Controller (XCC) Standard, Advanced and Enterprise licenses
Cisco CIMC / IMC —
Supermicro BMC / IPMI Out-of-band BIOS updates and similar features need an SFT-OOB-LIC license
Huawei iBMC Older models used iMana
Fujitsu iRMC —
White-box and others AMI MegaRAC, OpenBMC Interface and features depend on the firmware stack

Watch the licensing. Dell, HPE and Lenovo put the graphical remote console and virtual media behind higher license tiers; the base tier usually only shows status and controls power. When buying used or white-box servers, confirm that the license ships with the machine, or you will have a BMC whose console will not open. Tier names and included features change, so check the vendor’s current documentation.

What the BMC can do in each host state

Host state The BMC can The BMC cannot
AC power on, host off Power the host on; read temperatures, voltages and fan speeds; read the System Event Log (SEL) and FRU data; set the next boot device; mount virtual media; on some models update BIOS and firmware out of band Show the OS screen, since the host is not running
Host on, OS hung Show the current screen over KVM; hard reset or power off; send an NMI to force a crash dump; watch serial output over SOL Shut down gracefully, which needs the OS to answer the ACPI signal
Host on, no OS installed Install an OS from virtual media or by setting PXE boot; drive the BIOS through KVM —
Power cord unplugged or PDU outlet off Nothing Everything; only a remotely switchable PDU can restore power

Working with a BMC from the command line

Common ipmitool commands

The commands below run on any Linux system with ipmitool installed. Run inside the server’s own OS (in band) they need no address or password; from another machine (out of band) add -I lanplus -H <address> -U <user> -P <password>.

# Load the IPMI drivers before in-band use
modprobe ipmi_si
modprobe ipmi_devintf

# The BMC's own details: firmware version, manufacturer ID, supported features
ipmitool mc info

# Network settings of the management port (channel is usually 1; some models use 2 or 8, check the vendor docs)
ipmitool lan print 1

# Give the BMC a static address
ipmitool lan set 1 ipsrc static
ipmitool lan set 1 ipaddr 10.0.0.10
ipmitool lan set 1 netmask 255.255.255.0
ipmitool lan set 1 defgw ipaddr 10.0.0.1

# Board FRU data (model, serial number) and temperature sensors
ipmitool fru print 0
ipmitool sdr type Temperature

# Power state and the hardware event log
ipmitool chassis power status
ipmitool sel list

# List BMC users, then reset a password by user ID
ipmitool user list 1
ipmitool user set password 2 'NewPassword'

# Blink the chassis locator LED for 60 seconds to find the machine in the rack
ipmitool chassis identify 60

# Cold-reset a hung BMC; the host keeps running
ipmitool mc reset cold

The same information is available over Redfish as JSON:

# List this server's managers (the BMC) and system resources
curl -k -u admin:'password' https://10.0.0.10/redfish/v1/Managers/
curl -k -u admin:'password' https://10.0.0.10/redfish/v1/Systems/

Resource IDs under Managers vary by vendor (iDRAC uses iDRAC.Embedded.1, many others use 1), so list the collection first and then follow the links.

Troubleshooting

  • BMC unresponsive, web interface will not load: run ipmitool mc reset cold from inside the OS first. If in-band access is also dead, the only option is to remove AC power from the server, wait about 30 seconds and reconnect it so the BMC restarts from standby power. This is a side effect of separate power: rebooting the host never reboots the BMC.
  • No link light on the management port: check whether the BMC is set to dedicated or shared mode. Many “cannot reach the BMC” cases are a cable in the dedicated port while the setting says shared.
  • Lost password: reset it in band with ipmitool, which needs no old password, or with the vendor tool (Dell racadm, HPE hponcfg).
  • Wrong timestamps: SEL entries use the BMC’s clock. Set it with ipmitool sel time set or configure NTP in the web interface.
  • Old firmware: BMC firmware has had a number of publicly disclosed vulnerabilities, and the BMC has full control of the server. Update to the vendor’s current release before racking, then check periodically.

The security rules are the same as for IPMI: keep the management port off the internet, change default passwords, and allow access only from the management system and jump hosts. The IPMI guide covers this in more detail.

Where the BMC fits in a management system

For hundreds or thousands of servers from different vendors, the BMC is how a management system reaches inside each machine. In Toplink DCIM you record each server’s BMC address, username and password; from then on remote power control, boot device selection, ISO mounting and the VNC console all happen in the browser, and the remote console is tuned for iDRAC, iLO, iBMC, Supermicro and XClarity BMCs (see IPMI remote management). BMC address blocks are typed as IPMI in IP address management and assigned separately from public space; hardware model templates record whether a model supports IPMI and which console type it uses; and an unresponsive BMC can be reset remotely from the admin panel, or by customers themselves in the self-service portal.

FAQ

What is the difference between BMC and BIOS?

BIOS (or UEFI) is firmware that runs on the host CPU at power-on to initialize hardware and boot the OS; it stops when the host is off. The BMC is a separate system on its own chip that keeps running while the host is off, can power it on remotely, show the BIOS screen and, on some models, update the BIOS out of band.

Do desktop PCs or workstations have a BMC?

Consumer motherboards normally do not. Some workstation boards and all server-class boards do. Some business desktops offer similar remote management through Intel AMT, but that is not a BMC.

Where do I find the default BMC username and password?

Check the label on the chassis or the pull-out tag first: most servers shipped in recent years use a random factory password printed there, while older models used a vendor-wide default. Either way, change it before the BMC touches a management network, and follow the vendor documentation for your model.

How do I update BMC firmware?

Upload the firmware package through the vendor's web interface, or push it with Redfish or the vendor's CLI; some vendors also support updating from within the OS. Do not cut power during the update. The BMC reboots itself afterwards and the host normally keeps running, but follow the vendor's procedure.

See how it works in your data center.

Start with a product demo and map out your next step.

View pricing
Hotline 400-112-2951

Let’s talk about your IDC

Scan with WeChat to book a product demo or request a trial.

Toplink WeCom contact QR code

Save this code or scan it with WeChat / WeCom

Or call
400-112-2951
Telegram
@TopLink88