Server operations

What is HPE iLO? Remote management for ProLiant servers explained

HPE iLO (Integrated Lights-Out) is the BMC built into ProLiant servers: a separate chip with its own network port that lets you power the host on and off, see its screen and mount an ISO with nobody on site. What you can do depends on the iLO generation and the license.

By Toplink product teamPublished 13 min read

What is HPE iLO? iLO, short for Integrated Lights-Out, is the remote management controller built into HPE ProLiant servers. A “lights-out” data center is one with the lights off and nobody on site, and the name describes the job: managing a server without standing in front of it. Physically, iLO is a dedicated chip on the ProLiant motherboard, the server’s BMC, with its own processor, memory, firmware and network port (the RJ45 port labeled iLO on the back panel). It runs whenever the power cord is plugged in and does not depend on the host CPU or operating system. Out of the box the username is Administrator, the password is a random string printed on the pull-out tag at the front of the server, and the iLO port gets its address over DHCP.

What can HPE iLO do?

What you need The iLO feature
Power on, power off or restart remotely Virtual power button: Momentary Press, Press and Hold (forced power-off), Reset (warm reboot) and Cold Boot (power off, then on)
See the screen and use keyboard and mouse Integrated Remote Console, visible from POST and BIOS through to the running OS
Mount an ISO to install an OS Virtual Media, from a local file or from an image URL inside the data center
Check hardware health Health summary, temperature and fan sensors, the Integrated Management Log (IML)
Boot from the network or a virtual CD next time One-Time Boot, used together with PXE or virtual media
Get notified of hardware faults SNMP traps, email alerts, remote syslog
Script and automate IPMI, Redfish (RESTful API), the SSH command line, HPE’s iLOrest tool

There are four ways in: the web interface at https://<iLO address>, SSH to the iLO command line, IPMI over LAN, and the Redfish API. IPMI over LAN is disabled by default starting with iLO 5, so turn it on in the web interface’s access settings (Security → Access Settings on iLO 5) before ipmitool will connect. The SSH command line is the fallback when the web interface will not load. A typical session looks like this:

$ ssh [email protected]
</>hpiLO-> power              show the host's current power state
</>hpiLO-> power on           power the host on
</>hpiLO-> power reset        hard reset
</>hpiLO-> vsp                virtual serial port; press Esc, then ( to return

vsp shows the Linux serial console, provided the COM port mapped to the virtual serial port in the BIOS matches the kernel’s console= parameter; which ttyS device that is depends on the model, so check its documentation. It needs no graphical console, which makes it useful when the license restricts the console.

iLO 4 vs iLO 5 vs iLO 6: which generation do you have?

iLO generations track ProLiant generations, so the Gen number in the model name tells you which iLO you have:

Generation Servers Remote console Management interfaces Watch out for
iLO 2 / iLO 3 G5, G6 / G7 Mostly Java Web, SSH, IPMI, RIBCL scripts Only old TLS versions, so modern browsers often refuse the web interface; keep them running through the CLI and IPMI
iLO 4 Gen8, Gen9 .NET and Java clients; later firmware adds an HTML5 console (check the firmware release notes) Web, SSH, IPMI, RIBCL; RESTful API on later firmware IPMI over LAN on by default; used servers often carry very old firmware, so update to HPE’s latest iLO 4 release before connecting them
iLO 5 Gen10, Gen10 Plus HTML5 by default, plus .NET and Java Web, SSH, IPMI, Redfish Silicon Root of Trust verifies the firmware in hardware; IPMI over LAN off by default; security states such as High Security and FIPS
iLO 6 Gen11 HTML5 Mainly web, SSH, Redfish Same interface and security architecture as iLO 5; HPE has moved RIBCL and other legacy scripting interfaces to maintenance, and some platforms no longer support them

Gen12 servers ship with iLO 7; check HPE’s current documentation for the details. In day-to-day operations the generation matters in three places: whether the console needs a client installed, TLS and browser compatibility on old firmware, and whether automation should use RIBCL or Redfish. Write new scripts against Redfish. It is available from later iLO 4 firmware onward, but the older the generation, the fewer resources it implements, so work from what the API actually returns.

If all you have is an iLO address and you are not sure which generation sits behind it, ask Redfish. Passing only the username to -u makes curl prompt for the password, which keeps it out of your shell history:

curl -sk -u Administrator https://10.20.5.31/redfish/v1/Managers/1/ \
  | grep -oE '"(Model|FirmwareVersion)": *"[^"]*"'

Model comes back as iLO 4, iLO 5 and so on, and FirmwareVersion is the iLO firmware version. On old firmware without Redfish, run ipmitool -I lanplus -H 10.20.5.31 -U Administrator -a mc info and read the Firmware Revision line; -a also prompts for the password.

iLO Standard vs iLO Advanced: what the license unlocks

Every ProLiant has the iLO hardware; the license decides which features are switched on. All ProLiant servers ship with iLO Standard, and iLO Advanced needs a separately purchased license key. There are other tiers too, such as Essentials on some models and the Advanced Premium Security Edition, which adds security features on top of Advanced; check HPE’s documentation for which models each applies to. The split you deal with every day is Standard vs Advanced:

Feature iLO Standard (included) iLO Advanced
Web, SSH, IPMI and Redfish management Yes Yes
Remote power control, one-time boot Yes Yes
Health status, IML, iLO Event Log Yes Yes
Virtual serial port (vsp) Yes Yes
Graphical remote console Only from POST until the OS starts loading Always
Virtual media (local ISO or image URL) No Yes
Shared console sessions, boot and fault screen recording No Yes
Directory login (LDAP, Kerberos and others) No Yes
Email alerts, remote syslog No Yes

This is the usual split for iLO 4 and iLO 5. A few features have moved between tiers across generations and firmware versions, so check HPE’s current licensing guide before you buy.

The deciding question is simple: does this server need its screen while the OS is running, and does it need ISOs mounted remotely? On a Standard-only server, the console stops at a notice that a license is required as soon as the OS starts. If a customer reports that the OS will not boot, you can still watch POST; if they report a frozen system, you see nothing. ProLiant servers that are rented out or reinstalled remotely almost always need Advanced. Internal compute nodes installed over PXE can get by with Standard plus the virtual serial port.

To install a license:

  1. Log in to the web interface, open Administration → Licensing and check whether it says iLO Standard or iLO Advanced. Do this first on used servers and on machines returned by a previous customer.
  2. Enter the 25-character license key in the Activation Key field and click Install.
  3. The license takes effect immediately, normally without restarting iLO or the host. Open the remote console and confirm the screen stays visible while the OS runs.

HPE also offers time-limited evaluation licenses, which help in an emergency; check HPE for the term and how to request one.

How to use the iLO remote console

Taking iLO 5 as the example:

  1. Log in and click HTML5 under Integrated Remote Console on the Overview page, or launch it from Remote Console & Media in the left menu. HTML5 needs no client at all. The .NET client runs only on Windows, and the Java client needs Java Web Start and has plenty of compatibility problems, so avoid both when you can.
  2. The console’s power menu has Momentary Press, which acts like a short press of the power button and lets the OS shut down cleanly; Press and Hold, a long press that forces the power off; Reset, a warm reboot; and Cold Boot, which removes power and restores it, for when both the host and its devices are stuck.
  3. Watch the key prompts at the bottom of the POST screen: F9 opens System Utilities (BIOS and iLO settings), F10 starts Intelligent Provisioning (HPE’s deployment tool), F11 opens the one-time boot menu and F12 starts a network boot. If your browser swallows function keys, send them from the console’s keyboard menu or with hot keys.
  4. Send Ctrl+Alt+Del from the keyboard menu. Pressing it on your own keyboard triggers your own computer instead.

Three common problems:

  • The web interface loads but the console does not: usually a firewall that only allows port 443. The .NET and Java clients use TCP 17990 for the remote console and TCP 17988 for virtual media by default (both can be changed in iLO’s access settings), so open those as well. For the HTML5 console, check the port requirements in the documentation for your firmware.
  • The mouse pointer drifts away from the on-screen cursor: change the High Performance Mouse option in the remote console settings. Linux desktops and older Windows versions are sensitive to it.
  • The screen turns into a license notice once the OS boots: that is the Standard license limit described above, not a fault.

Mounting an ISO with iLO virtual media

Method Where the image lives Speed depends on Best for
Local ISO through the console The operator’s own computer Bandwidth from your computer to iLO; over the internet, a multi-gigabyte installer can take a long time to read Mounting a tools or driver disc now and then
Image URL (Scripted Media) An HTTP server on the data center network Bandwidth from iLO to that HTTP server Remote OS installs and bulk work

Local ISO: in the HTML5 console toolbar, click the disc icon, choose CD/DVD → Local *.iso file and pick the image. Restart from the power menu, press F11 at POST and choose the entry with Virtual CD in its name. Keep the browser tab open; closing it disconnects the image.

Image URL: go to Remote Console & Media → Virtual Media, enter an HTTP address such as http://10.20.0.5/iso/rocky-9.4-x86_64-dvd.iso under Scripted Media URL for CD/DVD, tick Boot on Next Reset, click Insert Media and restart the host. iLO pulls the image straight from the internal network instead of through your computer, which is much faster and more reliable. The management network iLO sits on must be able to reach that HTTP server.

The same steps work over Redfish, which is handy when you have several servers to do:

ILO=10.20.5.31
# List the virtual media device; on iLO 5, ID 2 is usually CD/DVD, confirm with MediaTypes
curl -sk -u Administrator https://$ILO/redfish/v1/Managers/1/VirtualMedia/2/
# Insert an ISO from the internal HTTP server
curl -sk -u Administrator -X POST -H 'Content-Type: application/json' \
  https://$ILO/redfish/v1/Managers/1/VirtualMedia/2/Actions/VirtualMedia.InsertMedia/ \
  -d '{"Image": "http://10.20.0.5/iso/rocky-9.4-x86_64-dvd.iso"}'
# Boot from the virtual CD on the next boot only
curl -sk -u Administrator -X PATCH -H 'Content-Type: application/json' \
  https://$ILO/redfish/v1/Systems/1/ \
  -d '{"Boot": {"BootSourceOverrideTarget": "Cd", "BootSourceOverrideEnabled": "Once"}}'
# Restart the host
curl -sk -u Administrator -X POST -H 'Content-Type: application/json' \
  https://$ILO/redfish/v1/Systems/1/Actions/ComputerSystem.Reset/ \
  -d '{"ResetType": "ForceRestart"}'

Each command prompts for the password; in a real script, use a Redfish session token instead. On a Standard-only server the InsertMedia call usually fails with a license error. In that case go through PXE: set the one-time boot target to Pxe and let the data center’s PXE service run the install.

Reading the iLO IML when hardware fails

iLO keeps three logs with different purposes, and it pays not to mix them up:

Log What it records Who reads it Location in the iLO 5 web interface
IML (Integrated Management Log) Host hardware events: memory, CPU, power, fans, temperature, drives, POST errors Operations staff troubleshooting and filing hardware tickets Information → Integrated Management Log
iLO Event Log Events in iLO itself: who logged in, which settings changed, which power actions ran Auditing, tracing a mistaken action Information → iLO Event Log
Active Health System Log Configuration and telemetry collected continuously in the background, exported as a binary .ahs file HPE support Information → Active Health System Log

How to read the IML:

  1. Sort by severity. Start with Critical and Caution; Informational entries are usually routine events such as power cycles and cleared logs.
  2. Read the component and location in the description. Memory events name the processor and DIMM slot, power supplies and fans give their number. Match them against the component map inside the chassis lid to find the physical part.
  3. Check the count and the last occurrence. An event whose Count keeps rising is an ongoing problem and more urgent than one that happened once.
  4. Mark entries as repaired after replacing the part (Mark as Repaired). Otherwise the health summary may keep showing a degraded state, and the next real fault is easy to miss.

What the common entries usually mean:

Keyword in the description Usually means First step
Memory, Corrected Memory Error Correctable errors on one DIMM have passed a threshold Note the slot and schedule a replacement before it turns into an uncorrectable error and a crash
Power Supply A power supply has failed or redundancy is lost Check the input cord and whether the matching PDU outlet is live before replacing the PSU
Fan A fan has failed or is running at the wrong speed Replace the fan and check whether temperature readings are already climbing
Temperature A temperature sensor has passed its threshold Check inlet temperature, blanking panels and hot/cold aisle separation, then the fans
Drive, Storage A drive or array has changed state Confirm in the array management tool which drive it is and whether the array is degraded
POST Error with a code An error found during power-on self-test Look up the code in HPE’s error message guide

When you open a hardware ticket, attach an export of the IML rather than a screenshot. From iLO 5 onward one Redfish call exports it; old firmware without $expand support needs each link under Members read in turn:

curl -sk -u Administrator "https://10.20.5.31/redfish/v1/Systems/1/LogServices/IML/Entries/?\$expand=." \
  | python3 -m json.tool > iml-10.20.5.31.json

The iLO Event Log lives at /redfish/v1/Managers/1/LogServices/IEL/Entries/ and is read the same way.

Managing iLO across a mixed server fleet

A data center running Gen8 through Gen10 side by side has iLO 4 and iLO 5 machines with different console clients, menu layouts and license states, and engineers end up looking up addresses and passwords one server at a time. Toplink DCIM brings these differences into one admin panel. The console adapter list in IPMI remote management covers iLO 2, iLO 4 and iLO 5: once a server’s iLO address and account are recorded, you power it on and off, set the next boot to PXE or an online ISO and open a VNC console in the browser, with no Java or .NET client to install. Every session is recorded automatically and can be played back at higher speed. For other iLO generations, check the adapter list before connecting them. After a server is rented out, customers handle reboots, reinstalls and rescue mode in the self-service portal, where risky actions such as reinstalls and rescue require a one-time code, so the iLO administrator account never has to leave your team. The remote console and virtual media are still governed by the iLO license, so check the Licensing page before handing a server over.

FAQ

How is iLO related to iDRAC and IPMI?

iLO, like Dell's iDRAC, is a vendor's name for its own BMC, with its own web interface, CLI and licensing. IPMI and Redfish are standard interfaces for talking to any BMC; recent iLO generations support both, so ipmitool and generic Redfish scripts can manage iLO as well.

Is it safe to put iLO on the internet?

No. iLO has full control of the server, and a web port or UDP 623 on a public address is scanned and brute-forced around the clock. Connect the iLO port to a separate management network that only jump hosts and management systems can reach, and come in over a VPN or jump host when you need remote access.

Does an iLO firmware update interrupt the server's workload?

No. The update restarts only iLO itself; the host and its OS keep running, while the remote console and monitoring drop out for a few minutes. Upload the HPE firmware file on iLO's firmware update page, and for very old firmware check HPE's release notes for whether you need to step through intermediate versions.

See how it works in your data center.

Start with a product demo and map out your next step.

View pricing
Hotline 400-112-2951

Let’s talk about your IDC

Scan with WeChat to book a product demo or request a trial.

Toplink WeCom contact QR code

Save this code or scan it with WeChat / WeCom

Or call
400-112-2951
Telegram
@TopLink88