L2 Switch Out-of-Band Management NC-SI Alternative
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current out-of-band management systems using network controller sideband interface (NC-SI) are costly, require dedicated software, and lack capacity to handle denial of service (DOS) attacks and proper firewall implementation.
Innovation Solution
Implementing a level 2 (L2) capable switch that replaces the network controller, providing a standardized interface for out-of-band management without expensive hardware, and enhancing security through filtering and DOS attack prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NC-SI compatible network controllers are used for out-of-band management, then standardized interface and network access to host CPU are provided, but system cost increases and dedicated software installation is required
Solution Approach 1:
The patent uses a standard L2 switch that copies the essential networking functionality of NC-SI controllers. The switch replicates the standardized interface capabilities (MAC address filtering, VLAN support, network connectivity) using common, inexpensive hardware rather than specialized NC-SI controllers, thereby reducing cost while maintaining reliability.
Solution Approach 2:
The invention replaces expensive NC-SI compatible network controllers with inexpensive standard L2 switches. These standard switches are mass-produced, low-cost devices that provide sufficient functionality for out-of-band management without requiring dedicated software installations or specialized hardware features.
2Ease of operation
If NC-SI compatible network controllers are used for out-of-band management, then network access to host CPU via system bus is enabled, but firewall implementation and DOS attack prevention become difficult
Solution Approach 1:
The patent introduces a standard L2 switch as an intermediary device between the network and the BMC/host CPU. This switch acts as a security mediator that can filter traffic based on MAC addresses, implement VLAN segmentation, and prevent direct network access to management interfaces, thereby blocking DOS attacks and enabling firewall functionality while maintaining ease of network access.
Solution Approach 2:
The invention segments network traffic using VLANs and MAC address filtering on the L2 switch. By dividing network traffic into different virtual LANs and filtering based on MAC addresses, the system creates isolated management networks that are protected from external attacks while maintaining straightforward network access within authorized segments.
Data Source
AI summary
A system and a method for operating a plurality of information handling systems forming a network are provided. The system includes a host computer processing unit (CPU); a band management controller (BMC); and a switch having a first port coupled to the host CPU, a second port coupled to the BMC, and an external port coupled to a network; wherein the switch is configured to perform lookups and send an ingress traffic including an internet content to the host CPU, and to send the ingress traffic including a management content to the BMC accordingly. A computer program product including a non-transitory computer readable medium having computer readable and executable code for instructing a processor in a management unit for a plurality of information handling systems forming a network to perform a method using a system as above is also provided.


