Blog sidebar

Category

Recent Posts

How to Test Refurbished Server Hardware Properly
  • Aug 28, 2026
A refurbished server should be treated as enterprise hardware entering a new lifecycle, not as an appliance that only needs to power on. Knowing how...
Best Server Drives for RAID in Business Systems
  • Aug 26, 2026
A failed member drive is rarely the only storage problem in a server estate. The replacement must match the controller, carrier format, firmware expectations and...
Dell iDRAC Licensing Guide for Server Buyers
  • Aug 24, 2026
A Dell PowerEdge server can be fully operational while still being awkward to manage remotely. That distinction is where this Dell iDRAC licensing guide matters....
How to Configure HPE iLO on Gen9 and Gen10
In News

How to Configure HPE iLO on Gen9 and Gen10

An HPE server can be powered off, unreachable on the production network or sitting in a remote rack and still remain manageable through iLO. Knowing how to configure HPE iLO correctly gives administrators independent access for hardware health checks, remote console work, virtual media and power control. It also prevents a common avoidable problem: an iLO interface left on DHCP with default credentials and no defined ownership.

For refurbished HPE Gen9 and Gen10 platforms, the process is broadly consistent. Menu wording, firmware features and licence options vary by model and iLO generation, but the priorities do not: establish isolated management connectivity, apply current firmware, remove default access, and verify remote recovery before the server enters service.

Prepare the server and management network

Start with the physical connection. Most ProLiant systems provide a dedicated iLO Ethernet port, usually identified by an iLO or management marking. Connecting this to a separate management VLAN is preferable to using the shared production NIC arrangement. A dedicated port keeps out-of-band access available when host networking, NIC configuration or operating system services fail.

Shared network port mode can be appropriate where switch capacity or cabling is constrained, particularly in smaller installations. The trade-off is clear: iLO then depends on the selected host NIC and its associated network path. For business-critical or remotely hosted equipment, dedicated iLO connectivity is normally the safer design.

Before configuration, have the following information ready: the intended static IP address, subnet mask, default gateway, DNS servers, management VLAN details where applicable, NTP source, host name and the credentials or authentication method required by your organisation. Defining these beforehand avoids a partially configured controller being handed between teams.

Confirm the server has a supported, stable power supply and connect the iLO management port to the correct switch port. iLO remains active whenever standby power is present, so the server does not need to be switched on to complete basic network configuration.

How to configure HPE iLO from the server console

The most reliable initial method is the iLO Configuration Utility during POST. Reboot or power on the server, then press F8 when prompted for iLO configuration. On many Gen9 systems this opens the iLO 4 utility; Gen10 systems typically use iLO 5. If the prompt is missed, restart the server and try again rather than changing settings through the operating system.

Within the utility, first review the network settings. iLO is commonly set to obtain an address through DHCP by default. DHCP is useful for initial discovery, but it is not usually suitable as the long-term configuration unless your DHCP service provides reservations, documented DNS records and controlled lease management.

Set the network mode to static IPv4 where that matches your management policy, then enter the IP address, subnet mask and gateway. Apply the settings and record the address against the server serial number, rack position and asset record. It is worth doing this immediately: a labelled chassis and a current asset register reduce recovery time when a host is unavailable.

If your management network uses IPv6, configure it deliberately rather than leaving dual-stack services enabled by accident. IPv6 is entirely viable for iLO, but the address allocation, DNS registration, firewall rules and support procedures need to be in place. In estates managed primarily through IPv4, disabling unneeded protocols reduces the number of exposed services to monitor.

The F8 utility also lets you set or change the local Administrator password. Do this before connecting the controller to any wider management network. Do not retain the factory credential printed on the pull-out tag or chassis label, even on an isolated VLAN.

Complete configuration in the iLO web interface

Browse to the assigned iLO address using HTTPS. A certificate warning is normal on first connection because the controller presents a self-signed certificate. Verify that the address is the expected device before proceeding. Replace the default certificate later with one issued by your internal PKI or another trusted certificate authority where your management standards require it.

Sign in using the Administrator account and the new password. The first tasks should be administrative rather than operational. Set a meaningful server name, configure DNS search settings if used, and ensure the iLO date, time and timezone are accurate. Configure NTP rather than relying on manually set time. Accurate timestamps matter when correlating iLO event logs with switch, hypervisor, operating system and monitoring records.

Create named user accounts for administrators instead of sharing the built-in Administrator account. Assign only the permissions required. An operator who needs power and remote console access does not necessarily need authority to amend security settings, manage users or alter network configuration. Named accounts also provide more useful audit records.

Where Active Directory, LDAP or another central identity service is available, directory authentication can reduce local account administration. It depends on reliable DNS, time synchronisation and directory reachability from the management VLAN. Keep at least one protected local break-glass account, however. If directory services, routing or DNS fail during an incident, a local account may be the only route back into the server.

Apply security settings before production use

iLO is a high-value management interface. It can reset the host, mount installation media, expose a remote console and provide access to hardware inventory. Treat it with the same care as a firewall, hypervisor management interface or switching platform.

Use a long unique password for every local privileged account and store it in the organisation's approved password management system. Limit iLO access at the network layer to the administrator workstations, jump hosts, monitoring platforms and automation services that need it. A management VLAN alone is useful but is not a complete access control model.

Disable services that are not required. Depending on the iLO version and operational needs, this may include legacy web access, SSH, IPMI, SNMP or unused directory integration. Do not disable IPMI or SNMP simply as a blanket rule if existing monitoring, orchestration or data centre tooling depends on it. Establish the dependency first, then prefer authenticated, encrypted management methods where supported.

Review the security dashboard and configure the available login controls. Failed-login delay, account lockout thresholds and session timeouts should align with the wider IT security policy. Enable audit logging and, where available, forward events to a central logging or monitoring platform. An iLO event log stored only on the controller is helpful during a fault, but it is not a substitute for retained central records.

Update firmware and check licensing requirements

Before placing the host into service, check the iLO firmware version against your approved baseline. Refurbished equipment may arrive with a functional but older controller firmware revision. Updating can address security issues, browser compatibility problems and defects affecting remote console, storage reporting or sensor data.

Firmware should be sourced, approved and applied in line with your maintenance process. Read the release notes, confirm compatibility with the specific server generation and schedule a maintenance window where necessary. An iLO firmware update can restart the management controller, so remote access will be interrupted temporarily even if the host operating system continues to run.

iLO Standard covers core remote management functions, but advanced features may require an iLO Advanced licence. Requirements vary by generation and exact feature set. Remote graphical console capability, virtual media and enhanced power or directory functions are frequent reasons to check licensing before an urgent recovery event. Verify the installed licence and test the functions your support team expects to use, rather than discovering a limitation during an outage.

Test remote management while the server is healthy

Configuration is not complete when the login screen appears. From an approved management workstation, test a remote console session, confirm the server inventory and health status are visible, and check that event logs are recording correctly. If licensed and required, test virtual media with a small approved ISO image.

Test power controls carefully. In a production environment, use a planned maintenance period or a non-critical host. Confirm that iLO reports the correct power state and that a graceful shutdown route is understood before relying on forced power actions. Forced reset and power-off functions are valuable recovery tools, but they can cause filesystem or application damage if used as routine administration.

Finally, verify the configuration after a switch port change, firmware update or relocation. iLO issues are often caused by ordinary infrastructure changes: a port moved to the wrong VLAN, an address reused, a DNS record left stale or a certificate that has expired. Keeping iLO records alongside server configuration documentation makes these problems faster to isolate.

For Gen9 and Gen10 estates, iLO is not merely a convenience feature. It is the management path that can reduce hands-on intervention, shorten fault diagnosis and keep proven server hardware supportable for longer. Build it into the commissioning checklist, assign ownership and test it before the server is needed in anger.

YOU MAY ALSO LIKE

Category

Recent Posts

How to Test Refurbished Server Hardware Properly
  • Aug 28, 2026
A refurbished server should be treated as enterprise hardware entering a new lifecycle, not as an appliance that only needs to power on. Knowing how...
Best Server Drives for RAID in Business Systems
  • Aug 26, 2026
A failed member drive is rarely the only storage problem in a server estate. The replacement must match the controller, carrier format, firmware expectations and...
Dell iDRAC Licensing Guide for Server Buyers
  • Aug 24, 2026
A Dell PowerEdge server can be fully operational while still being awkward to manage remotely. That distinction is where this Dell iDRAC licensing guide matters....