On this page
What a management card actually is
A network management card is a self-contained embedded computer that slides into an expansion slot on the back of a UPS. It has its own Ethernet port and IP address, reads UPS data over the slot's internal interface, and offers that data to the network in several ways. Because it is powered by the UPS, it keeps working on battery and does not depend on any server staying up.
| Brand | Card family | Typical companion software |
|---|---|---|
| APC by Schneider Electric | Network Management Card (NMC 2 and NMC 3 generations) | PowerChute Network Shutdown |
| CyberPower | RMCARD series | PowerPanel Business (client role) |
| Eaton | Network-M2 and newer Network-M3 cards | Intelligent Power Protector and Intelligent Power Manager |
| Tripp Lite (by Eaton) | WEBCARDLX family | PowerAlert |
| Vertiv Liebert | IntelliSlot cards (for example the RDU101 family) | Vertiv's power management and shutdown software |
Some newer UPS models have a network port built in rather than a slot, and some offer cloud monitoring through the vendor. The concepts below apply to all of them.
What the card gives you
- Web interface for status, event logs, self-test scheduling, outlet group control and UPS settings.
- Alerts by email, syslog and SNMP traps, independent of any server.
- SNMP polling for monitoring systems such as Zabbix, LibreNMS, PRTG or Prometheus via an SNMP exporter.
- Shutdown signaling to client agents on each protected server.
- Environmental sensors on many cards: temperature and humidity probes in the rack.
- Outlet group control on UPS models that support switched outlet groups: remote reboot of a hung device, staggered power-on.
SNMP in five minutes
SNMP organizes values in a tree of numeric object identifiers (OIDs). A MIB file maps names to OIDs. For UPS units there are two layers:
- UPS-MIB, RFC 1628. A vendor-neutral standard under
1.3.6.1.2.1.33. Most cards implement at least part of it, so a generic monitoring template can read battery status, runtime and output source from any brand. - Vendor MIBs. Richer and brand specific, for example APC's PowerNet MIB. They expose details the standard omits, such as battery replacement dates, outlet groups and sensor probes.
| Object | OID | Meaning |
|---|---|---|
| upsBatteryStatus | 1.3.6.1.2.1.33.1.2.1.0 | 1 unknown, 2 normal, 3 low, 4 depleted |
| upsSecondsOnBattery | 1.3.6.1.2.1.33.1.2.2.0 | Seconds on battery; 0 when on mains |
| upsEstimatedMinutesRemaining | 1.3.6.1.2.1.33.1.2.3.0 | Runtime estimate in minutes |
| upsEstimatedChargeRemaining | 1.3.6.1.2.1.33.1.2.4.0 | Charge in percent |
| upsOutputSource | 1.3.6.1.2.1.33.1.4.1.0 | 3 normal, 5 battery, 4 bypass (other values defined) |
Testing from a Linux machine with the net-snmp tools:
# SNMPv2c, read-only community (replace with yours)
snmpget -v2c -c your-ro-community 192.168.50.5 1.3.6.1.2.1.33.1.2.3.0
snmpwalk -v2c -c your-ro-community 192.168.50.5 1.3.6.1.2.1.33
# SNMPv3 with authentication and privacy
snmpget -v3 -l authPriv -u monitor -a SHA -A 'auth-pass' -x AES -X 'priv-pass' \
192.168.50.5 1.3.6.1.2.1.33.1.4.1.0
Many cards ship with SNMP disabled or limited to specific managers. Enable the version you need and add your monitoring host's address to the card's access list before testing.
Using a card with Network UPS Tools
NUT's snmp-ups driver turns a card into a regular NUT UPS. A Linux box, NAS or hypervisor runs the driver and server, and every other machine follows it as a NUT client exactly as if the UPS were on USB.
# /etc/nut/ups.conf, SNMPv2c
[rackups]
driver = snmp-ups
port = 192.168.50.5
community = your-ro-community
snmp_version = v2c
mibs = auto
desc = "Rack UPS via management card"
# SNMPv3 variant
[rackups]
driver = snmp-ups
port = 192.168.50.5
snmp_version = v3
secLevel = authPriv
secName = monitor
authProtocol = SHA
authPassword = auth-pass
privProtocol = AES
privPassword = priv-pass
mibs = auto
Check with upsc rackups@localhost. If mibs = auto picks a generic mapping that lacks details, the driver documentation lists named mappings (such as apcc for APC or ietf for the standard MIB) you can set explicitly. Some Eaton cards also support XML-based drivers in NUT; check the hardware compatibility list for your card. Full NUT setup is covered in the NUT guide, and Proxmox-specific clients in Proxmox UPS shutdown.
Card or USB plus a NUT server?
| Situation | Better fit | Why |
|---|---|---|
| One to three machines, always-on NAS or server | USB plus NUT server | No extra hardware; NUT shares status to the rest |
| Rack with many servers or hypervisors | Card | No dependency on one host; vendor agents or NUT can all poll it |
| Existing SNMP monitoring system | Card | Standard UPS-MIB templates work out of the box |
| Need remote outlet reboot or rack temperature | Card | Outlet groups and sensor probes need the card |
| UPS has no expansion slot | USB plus NUT server | Cards only fit slotted models |
Rule of thumb: the card removes a single point of failure
With USB, the machine holding the cable is the oracle for everything else. If it crashes, hangs on an update, or is the first thing you shut down, every other machine is blind. A card has no such dependency and keeps reporting on battery. Our working threshold: once three or more important machines rely on one UPS, or any of them lack a sensible owner for the USB cable, a card starts to justify its cost.
Shutdown clients: how the signal reaches each server
The card never shuts anything down by itself. It publishes state, and each protected machine runs something that listens. There are two broad models:
- Vendor agents. Each server runs the vendor's network shutdown client, registered with the card. The card tells clients when to shut down and can wait for them before turning off outlet groups. These agents often integrate with hypervisor management (for example, migrating or shutting down VMs) and are the supported path for vendor support cases.
- One NUT server polling the card. A single Linux machine or NAS runs
snmp-upsand upsd; every other machine is a NUT secondary. This is brand-agnostic and fits mixed environments, but it reintroduces a dependency on that one poller.
Some environments use both: vendor agents on hypervisors, and NUT for everything else. That works as long as each machine has exactly one thing deciding when it shuts down.
Timing with outlet groups
UPS models with switchable outlet groups let the card turn groups off in sequence: for example, non-critical gear early in an outage to extend runtime for the core switch and storage. Coordinate the group turn-off delays with client shutdown times, so a group never goes dark while its servers are still stopping. Write the plan down in a short table alongside the rack documentation; it is the first thing anyone will need during an incident.
Securing the card
A management card is a networked device with the power to switch off your equipment. Treat it like any other infrastructure device.
- Change default credentials on first login. Cards historically shipped with well-known default usernames and passwords; newer firmware often forces a change.
- Disable what you do not use: SNMPv1, Telnet, FTP and plain HTTP where HTTPS and SSH are available.
- Do not use "public" or "private" as SNMP communities. Prefer SNMPv3 with authentication and privacy.
- Restrict access with the card's access list and put it on a management VLAN that ordinary clients and the internet cannot reach.
- Update firmware. UPS management interfaces, including major brands' cards, have had publicly disclosed vulnerabilities over the years. Check the vendor's security notices and CISA advisories periodically.
- Send logs off the card via syslog, so events survive a card reset.
Never expose a UPS card to the internet
Remote access belongs behind a VPN. A publicly reachable card is an open invitation for someone to turn your outlets off.
Physical and network checklist
- Plug the switch port that serves the card into a battery-backed circuit, or the card goes silent exactly when it matters.
- Give the card a static address or DHCP reservation so clients do not lose it.
- Set the card's clock via NTP, so event timestamps line up with server logs.
- Record the card's MAC address and firmware version with your rack documentation; see rack-mount UPS installation.
For a broader view of where cards fit among other tools, see the UPS software overview and UPS for a network rack.
Frequently asked questions
Do I need a network management card for my UPS?
Not if one machine owns the UPS by USB and shares status over the network with NUT, which covers most homes and homelabs. A card is worth it when the UPS feeds many servers, sits in a rack without an always-on host, needs alerts and logs independent of any server, or must be monitored by an existing SNMP system.
What is the difference between SNMP v1, v2c and v3 on a UPS card?
Versions 1 and 2c authenticate with a community string sent in plain text, so anyone on the network path can read it. SNMPv3 adds per-user authentication and optional encryption. Use v3 where your monitoring tools support it, and if you must use v2c, choose a non-default read-only community and restrict access by IP.
Can I put a CyberPower card in an APC UPS or the reverse?
No. Expansion slots are vendor specific and often differ between product generations of the same brand. Each card is compatible with a listed set of UPS families. Check the vendor's compatibility list for your exact model before buying, and be cautious with used cards that may need specific firmware.
How do servers shut down when the UPS has a network card?
Each server runs a client that listens to the card: vendor agents such as PowerChute Network Shutdown or PowerPanel Business client, or a NUT server polling the card with snmp-ups that other machines then follow as NUT clients. The card itself only signals; the client software on each server performs the shutdown.
Why does snmpwalk return nothing from my UPS card?
Common causes are SNMP disabled on the card (many ship with it off), the wrong version or community, an access list on the card that does not include your IP, or a firewall blocking UDP 161. Test with snmpget on a single UPS-MIB OID first, then widen to a walk.
Sources and further reading
- RFC 1628: UPS Management Information Base
- RFC 3414: User-based Security Model for SNMPv3
- Network UPS Tools: snmp-ups driver documentation
- APC by Schneider Electric: Network Management Card user guide and PowerNet MIB reference
- CISA advisories on UPS management interfaces (search the CISA site for UPS)