Launch pricing: every plan costs 30% less than the cheapest offshore competitor we track. See the benchmarkEvery plan 30% under the cheapest offshore host

Knowledge base · Dedicated servers

Using IPMI and the KVM console on a dedicated server

Reach your dedicated server's IPMI console, mount an ISO, control power, enter the BIOS and reinstall the OS, then keep the BMC secure and fix console problems.

Updated 5 min read

In this guide

  • IPMI gives you the screen, keyboard, power control and virtual media even when the operating system is down.
  • The login details are on your server's page in the client area; access is restricted to the IP addresses you ask us to allow from that page.
  • Change the password at first login and never expose the management interface to the public internet.
  • Prefer the HTML5 console; older Java consoles need OpenWebStart and some extra setup.
Dedicated servers8 sections
All guides
On this page
  1. What IPMI and the KVM console are
  2. Access the IPMI interface
  3. Mount an ISO with virtual media
  4. Power control
  5. Enter the BIOS or UEFI setup
  6. Reinstall the operating system
  7. Keep the BMC secure
  8. Troubleshooting

Every dedicated server comes with IPMI or an equivalent KVM console. It is your way in when SSH is not: during an operating system install, after a bad network change, or when the server does not boot.

What IPMI and the KVM console are

The mainboard carries a baseboard management controller (BMC), a small separate computer with its own firmware and network port. It runs whenever the server has power, even if the operating system has crashed or is not installed. IPMI is the protocol for talking to it; the web interface adds a remote console, often called KVM over IP (keyboard, video, mouse). The BMC gives you:

  • a remote console that shows the screen from power-on, including the BIOS and boot menus;
  • virtual media, to boot the server from an ISO file on your computer;
  • power control: on, off, reset and graceful shutdown;
  • hardware sensors and an event log for temperatures, fans, power supplies and memory errors.

Menus differ between vendors; this guide uses generic names.

Access the IPMI interface

  1. Find the IPMI address, username and password on your server's page in the client area.
  2. On the same page, under Server actions, request Allow my IP on the IPMI console with the public IP address you will connect from. Access to the IPMI interface is restricted to the addresses you asked for; the request shows as done once yours is allowed.
  3. Open https://IPMI_ADDRESS in your browser. Expect a certificate warning: BMCs use self-signed certificates.
  4. Log in and change the password right away (see Keep the BMC secure).

If your public IP changes, as it can on home, mobile and VPN connections, send the new one the same way before you connect.

Where IPMI over LAN is enabled, you can also use ipmitool from your allowed IP. Read the password into a variable so it stays out of your shell history:

read -rs IPMI_PASSWORD
export IPMI_PASSWORD
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power status

The -E option reads the password from IPMI_PASSWORD; the examples below use the same options.

Mount an ISO with virtual media

  1. Open the remote console from the IPMI web interface.
  2. In the console's virtual media menu, attach an ISO file from your computer as a virtual CD/DVD drive.
  3. Restart the server and pick the virtual drive in the one-time boot menu (often F11), or set it as the next boot device:
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis bootdev cdrom options=efiboot
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power cycle

Leave out options=efiboot if the server boots in legacy BIOS mode. The ISO streams from your computer, so large images install slowly. Prefer a small network installer, such as Debian's netinst image, and keep the console open until the installation finishes: closing it usually disconnects the drive.

Power control

ActionWhat happensipmitool keyword
Graceful shutdownSends an ACPI signal and the OS shuts down cleanlysoft
Power onStarts the serveron
ResetHard reset without cutting powerreset
Power cycleCuts power, then switches it back oncycle
Power offCuts power immediatelyoff

From the command line, put the keyword at the end:

ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power soft

Enter the BIOS or UEFI setup

Open the console, restart the server and press the setup key while the vendor logo shows, usually Del or F2. Browser consoles sometimes miss short key presses, so press the key repeatedly, or tell the BMC to boot straight into setup:

ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis bootdev bios
ipmitool -I lanplus -H IPMI_ADDRESS -U IPMI_USER -E chassis power cycle

Changing the boot order is safe. Leave three things alone unless you know why: the BMC's own network settings (a wrong value cuts off your IPMI access), the onboard network cards, and the storage controller mode (switching between AHCI and RAID can make the installed system unbootable).

Reinstall the operating system

Before you wipe the old system, note its IP address, netmask and gateway:

ip -br addr
ip route
  1. Mount the installer ISO and boot from it, as described above.
  2. Partition the disks. On servers with two NVMe or SSD drives, use software RAID 1 (mdadm) or a ZFS mirror, so one failed drive does not take the system down. On the storage servers, install the system on the SSD and build the hard drives into a separate data pool, for example RAID 6 or RAIDZ2.
  3. Configure the network with the values you noted.
  4. Install the SSH server and set a strong password or, better, an SSH key.
  5. Detach the ISO, reboot into the new system and log in over SSH. Then follow the hardening guide.

If you get stuck, open a ticket from the Support page of the client area with your server's IP address.

Keep the BMC secure

  • Change the password at first login. Use a long, unique password from a password manager; some BMCs limit length or special characters.
  • Never expose the BMC to the public internet. IPMI 2.0 lets anyone who can reach the BMC request a password hash for offline cracking (CVE-2013-4786), and CISA listed an authentication bypass in AMI MegaRAC firmware (CVE-2024-54085) as actively exploited in June 2025. That is why access is restricted to your IP.
  • Allow only an address you control. A shared address, such as the exit of a commercial VPN, lets everyone behind it reach your BMC.
  • Log out and close the console when you are done.
  • Avoid extra BMC accounts: each one is another password to guess.

Troubleshooting

The IPMI page does not load

Check that your current public IP is one you asked us to allow (Server actions on your server's page). If the BMC stops responding, restart it from the server's operating system; this restarts only the management controller, not the server:

apt install -y ipmitool
modprobe ipmi_devintf
ipmitool mc reset cold

Lost the IPMI password? As root on the server, list the BMC users, then set a new password for yours (replace 2 with its ID). ipmitool prompts for the new password:

ipmitool user list 1
ipmitool user set password 2

HTML5 console problems

  • Black screen: the server may be off, or the operating system has blanked the display. Check the power status, then press a key.
  • Nothing opens: allow pop-ups for the IPMI address in your browser.
  • Mouse pointer out of line: switch the mouse mode between absolute and relative in the console settings.
  • Wrong characters: the console and the server may assume different keyboard layouts. Match them, or type passwords with the console's virtual keyboard.
  • Virtual media drops: keep the console tab in the foreground, stop your computer from sleeping and use a smaller ISO.

Java console on older BMCs

Older firmware starts the console by downloading a .jnlp file, which needs Java Web Start. Java 11 and later no longer include it, so install OpenWebStart, an open-source replacement, and open the file with it. If Java blocks the console, add https://IPMI_ADDRESS to its exception site list. If it still fails on old TLS versions, ask by ticket whether an HTML5 console is available.

Stuck on a step?

Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under 12 hours. For every other server, use the Server actions on its page, the guides and the network status page.

Welcome back

Sign in to manage your servers and your balance.

No KYCHuman check by Cloudflare TurnstileNo tracking