1.3 BMC, OOB and TPM setup

NCP-AII · System and Server Bring-up (31% of the exam) · Official objective: “Perform initial configuration of BMC, OOB, and TPM.”

Reaching the BMC safely, giving it an address, the ports it uses, Redfish and the TPM in the SBIOS.

Key points

  1. The BMC (baseboard management controller) is a small management computer in the server that works even when the OS is down. Redfish is a standard REST API for server management. The DGX H100 guide lists Redfish features including user accounts, BMC and SBIOS configuration, and power capping.

    What NVIDIA says (2)

    “Manage user accounts, privileges, and roles Manager sessions BMC configuration SBIOS configuration”

    — DGX H100/H200 User Guide: Redfish APIs Support

    “To manage the maximum power consumption on a system through power capping using Redfish API”

    — DGX H100/H200 User Guide: Managing Power Capping

  2. The BMC (baseboard management controller) is a small management computer in the server. It works even when the OS is down. When the network has no DHCP, you give the BMC a static IP address. ipmitool is the command-line tool for the BMC. NVIDIA's guide first prints the LAN settings, then sets the address source to static, then sets the address, netmask and gateway.

    What NVIDIA says (2)

    “You will need to do this if your network does not support DHCP.”

    — DGX H100/H200 User Guide: Using the BMC

    “Set the IP address source to static. $ sudo ipmitool lan set 1 ipsrc static”

    — DGX H100/H200 User Guide: Using the BMC

  3. OOB (out-of-band) management means managing a server over a separate network, not the one that carries user traffic. The BMC is the OOB entry point, so it must be protected. NVIDIA recommends a dedicated management network with firewall protection. If remote access is needed, use an isolated path such as a VPN.

    What NVIDIA says (3)

    “NVIDIA recommends that you connect the BMC port in the DGX H100/H200 system to a dedicated management network with firewall protection.”

    — DGX H100/H200 User Guide: Security

    “it should be accessed through a secure method that provides isolation from the internet, such as through a VPN server.”

    — DGX H100/H200 User Guide: Security

    “DGX OS Server software installs Docker Engine which uses the 172.17.xx.xx subnet by default”

    — DGX H100/H200 User Guide: Connecting to the DGX System

  4. The TPM (Trusted Platform Module) is a security chip that stores keys and measures the boot process. The SBIOS (system BIOS) is the firmware setup program you reach with Del or F2 at boot. NVIDIA says not to change SBIOS settings beyond its documents. Enabling the TPM is one of the documented changes.

    What NVIDIA says (3)

    “Here are some occasions where it might be necessary to reconfigure settings in the SBIOS:”

    — DGX H100/H200 User Guide: SBIOS Settings

    “Enabling the TPM and Preventing the BIOS from Sending Block SID Requests”

    — DGX H100/H200 User Guide: SBIOS Settings

    “press the Del or F2 key to enter the BIOS Setup Utility.”

    — DGX H100/H200 User Guide: SBIOS Settings

  5. IPMI (Intelligent Platform Management Interface) is the standard protocol that ipmitool uses to talk to a BMC. Over the network it uses RMCP+ on port 623. The web UI and Redfish use HTTPS on 443.

    What NVIDIA says (2)

    “443 Redfish Redfish https with auth 623 RMCP+ IPMI”

    — DGX H100/H200 User Guide: Using the BMC

    “443 | HTTPS | Web User Interface”

    — DGX H100/H200 User Guide: Using the BMC

  6. A REST API is a web interface driven by HTTP methods such as GET and PATCH. DMTF is the standards body behind Redfish. Redfish can read inventory and health, change BMC and SBIOS settings, and cap power.

    What NVIDIA says (2)

    “Redfish is DMTF’s standard set of APIs for managing and monitoring a platform.”

    — DGX H100/H200 User Guide: Redfish APIs Support

    “By default, Redfish support is enabled in the DGX H100/H200 BMC and the SBIOS.”

    — DGX H100/H200 User Guide: Redfish APIs Support

Key terms

Sample question

Which interface does the DGX H100 user guide document for managing BMC user accounts, SBIOS settings and power capping over the network?

Show the answer

Answer: The Redfish API on the BMC.

The BMC (baseboard management controller) is a small management computer in the server that works even when the OS is down. Redfish is a standard REST API for server management. The DGX H100 guide lists Redfish features including user accounts, BMC and SBIOS configuration, and power capping.

What NVIDIA says (2)

“Manage user accounts, privileges, and roles Manager sessions BMC configuration SBIOS configuration”

— DGX H100/H200 User Guide: Redfish APIs Support

“To manage the maximum power consumption on a system through power capping using Redfish API”

— DGX H100/H200 User Guide: Managing Power Capping

Practice 1.3 (6 questions) Full System and Server Bring-up guide

← 1.2 Network topologies for AI factories · 1.4 Firmware upgrades and fault detection →