What is IP KVM? How KVM over IP works, its three forms and when you need one
What is IP KVM? Hardware that puts a computer's screen, keyboard and mouse on the network: it streams the video output to your browser and feeds your input back as USB. Because it works outside the OS, you can operate POST, the BIOS, installers and blue screens remotely.
What is IP KVM? An IP KVM is a small device that runs independently of the computer it controls and does three jobs. It captures the picture from the host’s graphics output, compresses it and streams it to your browser over the network. It turns the keys you type and the mouse movements you make in the browser into USB keyboard and mouse input for the host. And on many models it presents an ISO file from your own computer to the host as a USB optical drive. KVM stands for keyboard, video and mouse, and the IP prefix means it runs over an IP network, which is why you will also see it called KVM over IP, a network KVM or a remote KVM.
IP KVM vs remote desktop: what is the difference?
The first question most people ask is why you would need an IP KVM when remote desktop already exists. The answer is where each one runs:
| Remote desktop (RDP, VNC inside the OS, SSH) | IP KVM | |
|---|---|---|
| Where it runs | Software inside the host operating system | Separate hardware outside the host |
| Network port | The host’s own production NIC | The device’s own network port |
| Shows POST and the BIOS | No | Yes |
| Works after a blue screen, a hang or a broken network config | No | Yes |
| Can install an OS remotely | No | Yes, with virtual media |
| What the host needs | A running OS with the service enabled | A video output and a USB port |
In short, remote desktop is how you use a machine remotely while the operating system is healthy; an IP KVM is how you rescue it remotely when the operating system is not.
How KVM over IP works
Inside, an IP KVM is an embedded processor with video capture and USB device functions, plus a network port. It connects to the host through three signal paths, with power control as an optional fourth:
| Path | Direction | How it works | Connectors |
|---|---|---|---|
| Video | Host to you | Captures the VGA, HDMI or DisplayPort signal, digitizes and compresses it, and serves it through an HTML5 web console, VNC or a vendor client; onboard versions grab the picture inside the integrated graphics controller | VGA, HDMI, DP |
| Keyboard and mouse | You to host | Enumerates on the host as a USB HID keyboard and mouse and converts your browser key presses and pointer positions into HID reports | USB; PS/2 on older equipment |
| Virtual media | You to host | Enumerates as a USB optical drive or flash drive; whichever sector the host reads, the device fetches that part of the ISO from your computer over the network | USB |
| Power (optional) | You to host | A relay or optocoupler shorts the power and reset pins on the motherboard’s front-panel header, or the device triggers a switched PDU | ATX front-panel header, PDU |
Why the video stream has to be compressed
Do the arithmetic. At 1920 × 1080, 24-bit color and 60 frames per second, the uncompressed stream is 1920 × 1080 × 3 bytes × 60 ≈ 373 MB/s, or about 2.99 Gbps. That does not fit through a gigabit port, and even 1024 × 768 needs around 1.13 Gbps. Every IP KVM therefore compresses the picture, commonly with MJPEG, H.264 or a vendor-specific differential encoding that only sends the regions that changed. BIOS screens and text consoles barely change, so the bit rate stays low; scrolling through large amounts of log output or playing video pushes bit rate and latency up noticeably. That is why IP KVM suits system administration and is a poor fit for graphics work.
Absolute vs relative mouse mode
An IP KVM can emulate a mouse in two ways. In absolute mode the host believes it has an absolute pointing device such as a graphics tablet: wherever you click in the browser, the host cursor lands in the same place, with no drift. In relative mode it emulates an ordinary mouse and only reports how far the pointer moved, so if the host has mouse acceleration turned on, the remote and local cursors drift apart. Windows and mainstream Linux desktops generally support absolute mode, but some BIOS setup screens, older operating systems and installers only understand an ordinary mouse. If the cursor does not move or jumps around, switch the KVM to relative mode.
No monitor attached, no picture
At power-on a graphics card reads the attached monitor’s EDID data to learn which resolutions it supports. An external IP KVM has to emulate an EDID; otherwise some graphics cards decide that no monitor is connected and send no signal at all, or fall back to a very low resolution. When the remote screen is black, rule this out first, then check the cables and the input source.
Three forms of IP KVM: external switch, PCIe card and onboard BMC
All three let you see the screen and use the keyboard and mouse remotely. They differ in where they are installed, how many machines one unit covers and whether they can control power:
| External IP KVM (switch or single-port) | PCIe card | Onboard BMC (iKVM) | |
|---|---|---|---|
| Where it sits | In the rack or on a desk, cabled to the host | In a free PCIe slot inside the host | Soldered onto the server motherboard |
| Machines per unit | Switches commonly have 8, 16 or 32 ports; single-port models are one-to-one | One | One |
| Video source | The host’s graphics output | The card’s own display function, or a capture of the host’s output | The BMC’s integrated graphics |
| Power control | Switches usually have none and need a switched PDU; some single-port models have an ATX module | Yes, once wired to the front-panel header | Yes, and it can power on a host that is off |
| Hardware sensors and event log | No | Usually not; check the spec sheet | Yes |
| What the host needs | A video output and a USB port | A free PCIe slot, a USB port and the front-panel header | A motherboard with a BMC |
| Typical use | A rack of older machines in one place, network device consoles | Adding remote access to servers, workstations and PCs without a BMC, one at a time | Built into brand-name servers |
External KVM switches: many machines, few remote sessions
A rack-mount KVM switch brings the video and USB connections from many servers into one device. Usually each server gets an adapter module, often called a CIM (computer interface module) or dongle, which connects back to the switch over twisted-pair network cable. The advantage is that one device covers a whole rack. The catch is the number of remote channels: an entry-level model may have 16 ports but only one or two remote sessions, so only one or two servers can be viewed remotely at a time and the rest have to wait. Check the spec sheet of the exact model.
PCIe cards: a BMC on a separate board
A card-type IP KVM sits in a PCIe slot inside the host. In effect it packages the capabilities of a server BMC as a separate card: it has its own processor and network port, connects to a motherboard USB port to emulate the keyboard, mouse and virtual media, and connects to the front-panel header to control power. It is one-to-one, which makes it a practical way to add out-of-band management to machines without a BMC one by one, with no extra rack space and no external cabling.
Onboard BMC: the IP KVM built into brand-name servers
The virtual console in iDRAC, iLO, XClarity Controller (XCC) or iBMC is an IP KVM built into the server, with power control, sensors, an event log and standard management interfaces on top. A server with a working BMC normally does not need an external IP KVM as well, unless you want an emergency path that does not depend on the BMC. The IPMI guide explains what a BMC does beyond the console.
When do you need an IP KVM?
Work through these questions in order:
- The server has a BMC and its remote console works: you do not need one; use the BMC’s virtual console. Check the license first, because on some vendors’ base license the graphical console is missing or only works before the OS boots.
- The server has no BMC: older servers, PCs used as servers, workstations, NAS boxes and industrial PCs. When the operating system fails, someone has to go on site. This is the main use case for an IP KVM.
- The server has a BMC, but it is unreliable: old firmware that hangs regularly, or a management port that cannot be connected to the management network. Add an independent path for critical machines.
- You need to reach more than servers: serial consoles on switches and firewalls, or other equipment with a display output, can be brought together with a KVM that has serial modules or with a dedicated console server.
- You only need to power machines on and off, not see the screen: skip the IP KVM; Wake-on-LAN or a switched PDU will do the job.
Five things to check before you deploy one
- Video connector and resolution: does the host output VGA, HDMI or DisplayPort, what is the KVM’s maximum resolution and refresh rate, and does it need EDID emulation?
- USB connection: virtual media usually needs USB 2.0 or later, a rear port on the motherboard is more reliable than a front-panel extension cable, and USB boot must not be disabled in the BIOS.
- Power control: if you need to power machines on remotely, choose a model with ATX control or a card-type unit, or pair it with a switched PDU. Also make sure the KVM itself stays powered while the host is off.
- Concurrency and permissions: how many people can view at the same time, whether view-only and full-control access can be separated, and whether actions are logged.
- Network and security: an IP KVM has the same control as a local keyboard and mouse. Keep its management port on the management network, change the default password, apply firmware updates as the vendor releases them, and never expose it to the internet, just as you would treat a BMC.
How IP KVM fits into a data center
Most data centers run two kinds of machines side by side: brand-name servers with a BMC, and older machines or converted PCs without one. For the first kind, record the BMC address and credentials in Toplink DCIM and you can open a VNC console, power the server on and off and mount an ISO from the browser (see IPMI remote management). For the second kind, fit an IPMI remote management card to each machine. The Toplink Smart Control Card is the PCIe card form described above: once the USB and front-panel cables are connected, video, keyboard and mouse, power control and ISO mounting all work remotely, and because it gives the host a display function through the PCIe edge connector, machines without a separate graphics card still show a picture.
FAQ
Is IP KVM the same as KVM virtualization in Linux?
No. Linux KVM is the Kernel-based Virtual Machine, a virtualization technology. The KVM in IP KVM stands for keyboard, video and mouse and refers to hardware for operating a physical machine remotely; the two only share an acronym.
What is the difference between a KVM switch and an IP KVM?
A plain KVM switch lets one monitor, keyboard and mouse switch between several computers, and the operator has to be in front of it. An IP KVM digitizes the signals and sends them over the network, so you can work from anywhere. Rack-mount switches come in remote (IP) and local-only versions, so check the model before you buy.
Does an IP KVM need drivers on the host?
External units do not: to the host they look like a monitor plus a USB keyboard, mouse and optical drive, which the BIOS and operating system recognize with built-in generic drivers. If a card-type unit provides the host's display, the OS sees it as a graphics adapter and a generic display driver usually works; follow the vendor's documentation.