So i am going to re-ip some devices in my network and am looking to make a proper OOB network. For things lke iDrac, ipmi, ups interface, and thinking about the proxmox interface as well.
on my L3 switch ill create the access list for certain machines on my network to gain access to that subnet and nothing else. but then i was thinking about it. if i do that then they will not have any internet access either. which is fine and what i ultimately want. but then how do you manage BIOS, firmware, and any general updates etc?
how are you guys/gals setting up the oob? are you even using one?
I run a completely separate switch for OOB, a separate vRouter in the firewall, with rules to allow those devices access to their update servers and nothing else
If the devices have a specific site they need for updates, I will usually allow the traffic to that site (or set of URLs/IPs) restricted to the ports/protocol needed (in the case of an ACL on a router/switch) or the application/port (in the case of a next gen firewall). But if there are a lot of potential destinations, I don't allow the traffic and instead download the needed files from a workstation and transfer them over.