When it comes to Veeam Hardened Repository Server, we hopefully talk about a dedicated hardware server. Because of the high secure implementation of this feature it makes perfect sense to disable any additional attack surface. So it is highly recommended to disable platforms like HPE ilO and Dell iDRAC.
On the other side, it is essential to monitor this piece of hardware. IMHO it is important not to open any incoming network ports for monitoring. Means, monitoring (agent, script, deamon, ...) should open a port from within the host to in external instance like mail-server, SNMP-host, syslog-server, … and closes it afterwards. Otherwise a service - most probably with root-permissions - is running and open for external access.
So how did you implement hardware monitoring?