All guides
Getting started
VPS
- VPS operating systems
- VPS snapshots and
off-site backups - How to host your own VPN on a VPS with WireGuard
- How to run a Tor relay, bridge or onion service on a VPS
- How to
self-host BTCPay Server on a VPS - How to run a Bitcoin or Monero node on a VPS
Dedicated servers
- Using IPMI and the KVM console on a dedicated server
- Choosing a RAID layout for your dedicated server
Windows RDP
Windows Server 2019 , 2022 or 2025 vsWindows 10 and 11 for RDP- How to connect to a Windows RDP server from any device
GPU servers
Security
On this page
Every dedicated server comes with IPMI or an equivalent KVM console. It is your way in when SSH is not: during an operating system install, after a bad network change, or when the server does not boot.
What IPMI and the KVM console are
The mainboard carries a baseboard management controller (BMC), a small separate computer with its own firmware and network port. It runs whenever the server has power, even if the operating system has crashed or is not installed. IPMI is the protocol for talking to it; the web interface adds a remote console, often called KVM over IP (keyboard, video, mouse). The BMC gives you:
- a remote console that shows the screen from
power-on , including the BIOS and boot menus; - virtual media, to boot the server from an ISO file on your computer;
- power control: on, off, reset and graceful shutdown;
- hardware sensors and an event log for temperatures, fans, power supplies and memory errors.
Menus differ between vendors; this guide uses generic names.
Access the IPMI interface
- Find the IPMI address, username and password on your server's page in the client area.
- On the same page, under Server actions, request Allow my IP on the IPMI console with the public IP address you will connect from. Access to the IPMI interface is restricted to the addresses you asked for; the request shows as done once yours is allowed.
- Open
in your browser. Expect a certificate warning: BMCs usehttps://IPMI_ADDRESSself-signed certificates. - Log in and change the password right away (see Keep the BMC secure).
If your public IP changes, as it can on home, mobile and VPN connections, send the new one the same way before you connect.
Where IPMI over LAN is enabled, you can also use ipmitool
read -rs IPMI_PASSWORD
export IPMI_PASSWORD
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power status
The -EIPMI_PASSWORD
Mount an ISO with virtual media
- Open the remote console from the IPMI web interface.
- In the console's virtual media menu, attach an ISO file from your computer as a virtual CD/DVD drive.
- Restart the server and pick the virtual drive in the
one-time boot menu (often F11), or set it as the next boot device:
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis bootdev cdrom options=efiboot
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power cycle
Leave out options=efiboot
Power control
| Action | What happens | ipmitool keyword |
|---|---|---|
| Graceful shutdown | Sends an ACPI signal and the OS shuts down cleanly | soft |
| Power on | Starts the server | on |
| Reset | Hard reset without cutting power | reset |
| Power cycle | Cuts power, then switches it back on | cycle |
| Power off | Cuts power immediately | off |
From the command line, put the keyword at the end:
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power soft
Enter the BIOS or UEFI setup
Open the console, restart the server and press the setup key while the vendor logo shows, usually Del or F2. Browser consoles sometimes miss short key presses, so press the key repeatedly, or tell the BMC to boot straight into setup:
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis bootdev bios
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power cycle
Changing the boot order is safe. Leave three things alone unless you know why: the BMC's own network settings (a wrong value cuts off your IPMI access), the onboard network cards, and the storage controller mode (switching between AHCI and RAID can make the installed system unbootable).
Reinstall the operating system
Before you wipe the old system, note its IP address, netmask and gateway:
ip -br addr
ip route
- Mount the installer ISO and boot from it, as described above.
- Partition the disks. On servers with two NVMe or SSD drives, use software
RAID 1 (mdadm) or a ZFS mirror, so one failed drive does not take the system down. On the storage servers, install the system on the SSD and build the hard drives into a separate data pool, for exampleRAID 6 or RAIDZ2. - Configure the network with the values you noted.
- Install the SSH server and set a strong password or, better, an SSH key.
- Detach the ISO, reboot into the new system and log in over SSH. Then follow the hardening guide.
If you get stuck, open a ticket from the Support page of the client area with your server's IP address.
Keep the BMC secure
- Change the password at first login. Use a long, unique password from a password manager; some BMCs limit length or special characters.
- Never expose the BMC to the public internet.
IPMI 2.0 lets anyone who can reach the BMC request a password hash for offline cracking (CVE-2013-4786 ), and CISA listed an authentication bypass in AMI MegaRAC firmware (CVE-2024-54085 ) as actively exploited inJune 2025 . That is why access is restricted to your IP. - Allow only an address you control. A shared address, such as the exit of a commercial VPN, lets everyone behind it reach your BMC.
- Log out and close the console when you are done.
- Avoid extra BMC accounts: each one is another password to guess.
Troubleshooting
The IPMI page does not load
Check that your current public IP is one you asked us to allow (Server actions on your server's page). If the BMC stops responding, restart it from the server's operating system; this restarts only the management controller, not the server:
apt install -y ipmitool
modprobe ipmi_devintf
ipmitool mc reset cold
Lost the IPMI password? As root on the server, list the BMC users, then set a new password for yours (replace 2 with its ID). ipmitool prompts for the new password:
ipmitool user list 1
ipmitool user set password 2
HTML5 console problems
- Black screen: the server may be off, or the operating system has blanked the display. Check the power status, then press a key.
- Nothing opens: allow
pop-ups for the IPMI address in your browser. - Mouse pointer out of line: switch the mouse mode between absolute and relative in the console settings.
- Wrong characters: the console and the server may assume different keyboard layouts. Match them, or type passwords with the console's virtual keyboard.
- Virtual media drops: keep the console tab in the foreground, stop your computer from sleeping and use a smaller ISO.
Java console on older BMCs
Older firmware starts the console by downloading a .jnlphttps://IPMI_ADDRESS
Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under