background image

Intel

®

 Active Management Technology v6.0

Administrator's Guide

Overview

Product Overview

Out of Box Experience

Operational Modes

Setup and Configuration Overview

 

Menus and Defaults

MEBx Settings Overview

ME General Settings

AMT Configuration

Intel Fast Call for Help

ME General Settings

AMT Configuration

Setup and Configuration

Methods Overview

Configuration Service--Using a USB Device

Configuration Service--USB Device Procedure

System Deployment

Operating System Drivers

 

 

Management

Intel AMT Web GUI

AMT Redirection (SOL/IDE-R)

AMT Redirection Overview

 

Intel Management and

Security Status Application

Intel Management and Security Status

Application

 

Troubleshooting

Troubleshooting

 

 

If you purchased a DELL™ n Series computer, any references in this document to Microsoft

®

 Windows

®

 operating systems

are not applicable.

Information in this document is subject to change without notice.

© 2010 Dell Inc. All rights reserved.

Reproduction of these materials in any manner whatsoever without the written permission of Dell Inc. is strictly forbidden.

Trademarks used in this text: Dell, Latitude, and the DELL logo are trademarks of Dell Inc.; Intel is a registered trademark of Intel Corporation in

the U.S. and other countries; Microsoft and Windows are either trademarks or registered trademarks of Microsoft Corporation in the United States

and/or other countries.

Other trademarks and trade names may be used in this document to refer to either the entities claiming the marks and names or their products.

Dell Inc. disclaims any proprietary interest in trademarks and trade names other than its own.

April 2010     Rev. A00

Summary of Contents for OptiPlex 980 - Desktop

Page 1: ... a DELL n Series computer any references in this document to Microsoft Windows operating systems are not applicable Information in this document is subject to change without notice 2010 Dell Inc All rights reserved Reproduction of these materials in any manner whatsoever without the written permission of Dell Inc is strictly forbidden Trademarks used in this text Dell Latitude and the DELL logo ar...

Page 2: ...tures Benefits Out of band OOB access Allows remote management of platforms regardless of system power or operating system state Remote troubleshooting and recovery Significantly reduces desk side visits increasing the efficiency of IT technical staff Proactive alerting Decreases downtime and minimizes repair times Computer Requirements The computer referred to in this document consists of the Int...

Page 3: ...ies Setup and Quick Reference Guide Intel AMT overview with link to the Dell Technology Guide Dell Technology Guide High level Intel AMT overview setup provisioning and support Backup media Firmware and critical drivers are available on the Resource CD See the Administrator Guide for detailed information about Intel AMT The guide is posted on the Web and is available with the computer manuals on s...

Page 4: ...MEBx Enabled can be disabled at a later time Legacy Redirection Mode Controls FW listening for incoming redirection connections Disabled Enabled if feature enabled in Intel MEBx Disabled set to Enabled to work with Legacy SMB consoles NOTE KVM is supported only with integrated graphics CPU The system should be in the integrated graphics mode Perform manual configuration using the following steps 1...

Page 5: ...ree setup and configuration states SCS Factory default state Setup state Provisioned state The factory default state is a fully un configured state in which security credentials are not yet established and Intel AMT capabilities are not yet available to management applications In the factory default state Intel AMT has the factory defined settings The setup state is a partially configured state in...

Page 6: ...e of two ways The key can be manually typed into the MEBx The SCS can create a list of custom keys and put them onto a specially formatted USB thumb drive Then each AMT computer retrieves a custom key from the specially formatted USB thumb drive during BIOS boot as detailed in the Configuration Service section of this document Back to Contents Page ...

Page 7: ...are NOT going to be committed to ME NVM Accessing the MEBx Configuration User Interface The MEBx configuration user interface can be accessed on a computer through the following steps 1 Turn on or restart your computer 2 When the blue DELL logo appears press F12 immediately and select MEBx If you wait too long and the operating system logo appears continue to wait until you see the Microsoft Windo...

Page 8: ... before changing any feature configuration options When an IT administrator first enters the Intel MEBx configuration menu with the default password he or she must change the default password before any feature can be used The new password must include the following elements Eight characters no more than 32 One uppercase letter One lowercase letter A number A special non alphanumeric character suc...

Page 9: ......

Page 10: ...CP IP Settings Wired LAN IPv4 Configuration DHCP Mode IPv4 Address Default Gateway Address Preferred DNS Address Alternate DNS Address Previous Menu Wired LAN IPv6 Configuration IPv6 Feature Selection IPv6 Interface ID Type IPv6 Address IPv6 Default Router Preferred DNS IPv6 Address Alternate DNS IPv6 Address Previous Menu Wireless LAN IPv6 Configuration IPv6 Feature Selection IPv6 Interface ID Ty...

Page 11: ...rm State Control Option Description Enabled Enable the Management Engine on the platform Disabled Disable the Management Engine on the platform NOTE Disabling the Intel ME does not really disable it It causes the Intel ME code to be halted at an early stage of the Intel ME s booting so that the system has no traffic originating from the Intel ME on any of the buses This is not intended to be norma...

Page 12: ... This option determines when the user is allowed to change the Intel MEBx password through the network NOTE The Intel MEBx password can always be changed via the Intel MEBx user interface Description of these options ...

Page 13: ...he network interface Anytime The Intel MEBx password can be changed through the network interface at any time Network Setup Under the Intel ME Platform Configuration menu select Network Setup and press Enter The Intel ME Platform Configuration menu changes to the Intel ME Network Setup page Network Name Settings Under the Intel ME Network Name Settings select Intel ME Network Name Settings and pre...

Page 14: ...2 Domain Name Under the Intel ME Network Name Settings select Domain Name and press Enter A domain name can be assigned to the Intel AMT machine 3 Shared Dedicated FQDN ...

Page 15: ...DN that is the HostName DomainName is shared with the host and identical to the operating system machine name or dedicated to the Intel ME Option Description Dedicated The FQDN domain name is dedicated to ME Shared The FQDN domain name is shared with the Host 4 Dynamic DNS Update Under the Intel ME Network Name Settings select Dynamic DNS Update and press Enter ...

Page 16: ... the firmware will assume its old implementation where the firmware used DHCP option 81 for DNS registration but did not directly update DNS using the DDNS update protocol For selecting Enabled for Dynamic DNS Update it is required that the Host Name and Domain Name are set Option Description Enabled The Dynamic DNS Update Client in FW is enabled Disabled The Dynamic DNS Update Client in FW is dis...

Page 17: ...t should be set according to corporate DNS scavenging policy Units are minutes A value of 0 disables periodic update The value set should be equal or greater than 20 minutes The default value for this property is 24 hours 1440 minutes 6 TTL 1 Under the Intel ME Network Name Settings select TTL and press Enter 2 Type the desired time in seconds and press Enter ...

Page 18: ...ork Setup page TCP IP Settings 1 Under the Network Setup menu select TCP IP Settings and press Enter 2 The Intel ME Network Name Settings menu changes to the Intel Network Setup page The Intel Network Setup menu changes to the TCP IP Settings page NOTE The Intel MEBx has menus for Wireless IPv6 but no menu for wireless IPv4 When the Intel MEBx starts it will check for the wireless interface to mak...

Page 19: ...he TCP IP Settings menu changes to the Wired LAN IPv4 Configuration page ENABLED If DHCP Mode is enabled TCP IP settings will be configured by a DHCP server More options will be displayed on the screen Select ENABLED and press Enter no additional steps are required DHCP mode enabled ...

Page 20: ...t DISABLED and press Enter If you disable DHCP more options will be displayed DHCP mode disabled 2 IPv4 Address Select IPv4 Address and press Enter Type the IPv4 Address in the address column and press Enter ...

Page 21: ...ask Address and press Enter Type the Subnet Mask Address in the address column and press Enter 4 Default Gateway Address Select Default Gateway Address and press Enter Type the Default Gateway Address in the address column and press Enter ...

Page 22: ...red DNS Address and press Enter Type the Preferred DNS Address in the address column and press Enter 6 Alternate DNS Address Select Alternate DNS Address and press Enter Type the Alternate DNS Address in the address column and press Enter ...

Page 23: ...with the host operating system To enable Dynamic DNS registration for IPv6 addresses a dedicated FQDN must be configured NOTE The Intel ME network stack supports a multi homed IPv6 interface Each network interface can be configured with the following IPv6 addresses 1 One link local auto configured address 2 Three auto configured global addresses 3 One DHCPv6 configured address 4 One statically con...

Page 24: ...ation is allowed 2 IPv6 Interface ID Type Under the Wired LAN IPv6 Configuration select IPv6 Interface ID Type and press Enter The auto configured IPv6 address consists of two parts the IPv6 Prefix set by the IPv6 router is the first part and the interface ID is the second part 64 bits each ...

Page 25: ...Intel ID The IPv6 Interface ID is automatically generated using the MAC address Manual ID The IPv6 Interface ID is configured manually Selecting this type requires that the Manual Interface ID is set with a valid value 3 IPv6 Address Under the Wired LAN IPv6 Configuration select IPv6 Address and press Enter Type the IPv6 Address and press Enter ...

Page 26: ...4 IPv6 Default Router Under the Wired LAN IPv6 Configuration select IPv6 Default Router and press Enter Type the IPv6 Default Router and press Enter 5 Preferred DNS IPv6 Address ...

Page 27: ...d DNS IPv6 Address and press Enter Type the Preferred DNS IPv6 Address and press Enter 6 Alternate DNS IPv6 Address Under the Wired LAN IPv6 Configuration select Alternate DNS IPv6 Address and press Enter Type the Alternate DNS IPv6 Address and press Enter ...

Page 28: ...nges to the TCP IP Settings menu Wireless LAN IPv6 Configuration Under the TCP IP Settings select Wireless LAN IPv6 Configuration and press Enter The TCP IP Settings menu changes to the Wireless LAN IPv6 Configuration page 1 IPv6 Feature Selection Under the Wireless LAN IPv6 Configuration select IPv6 Feature Selection and press Enter ...

Page 29: ...art and the interface ID is the second part 64 bits each Option Description Random ID The IPv6 Interface ID is automatically generated using a random number as described in RFC 3041 This is the default Intel ID The IPv6 Interface ID is automatically generated using the MAC address Manual ID The IPv6 Interface ID is configured manually Selecting this type requires that the Manual Interface ID is se...

Page 30: ...ess Enter The Wireless LAN IPv6 Configuration menu changes to the TCP IP Settings menu Unconfigure Network Access 1 Under the Intel ME Platform Configuration menu select Unconfigure Network Access and press Enter NOTE This will cause Intel ME to transition to the PRE provisioning state ...

Page 31: ...2 Select Y to unconfigure 3 Select Full Unprovisioning and press Enter ...

Page 32: ... Setup and Configuration Under the Intel ME Platform Configuration menu select Automated Remote Setup and Configuration and press Enter The Intel ME Platform Configuration menu changes to the Automated Remote Setup and Configuration page ...

Page 33: ...rovisioning Mode Under Automated Setup and Configuration select Current Provisioning Mode and press Enter Current Provisioning Mode Displays the current provisioning TLS Mode None PKI or PSK Provisioning Record ...

Page 34: ...his suffix to the FQDN in the Configuration Server s client certificate A value of 1 indicates that the DNS suffix was configured and the firmware matched it against the DNS suffix in the Configuration Server s client certificate Host Initiated Indicates whether the setup and configuration process was initiated by the host No indicates that the setup and configuration process was NOT host initiate...

Page 35: ...Remote Setup and Configuration menu changes to the Intel Remote Configuration page Start Configuration Under the Intel Remote Configuration menu select Start Configuration and press Enter If Remote Configuration is not activated Remote configuration cannot occur To activate enable remote configuration select Y ...

Page 36: ...and Configuration page Provisioning Server IPv4 IPv6 Under the Intel Automated Setup and Configuration menu select Provisioning Server IPv4 IPv6 and press Enter 1 Type the provisioning server address and press Enter 2 Type the provisioning server port number and press Enter The port number 0 65535 of the Intel AMT provisioning server The default port number is 9971 ...

Page 37: ...uration menu select Provisioning Server FQDN and press Enter Type the FQDN of the provisioning server and press Enter FQDN of the provisioning server mentioned in the certificate PKI only This is also the FQDN of the server that AMT sends hello packets to for both PSK and PKI ...

Page 38: ...omated Remote Setup and Configuration menu changes to the Intel TLS PSK Configuration page This submenu contains the settings for TLS PSK configuration settings Set PID and PPS Under the Intel TLS PSK Configuration menu select Set PID and PPS and press Enter Type PID and press Enter Type PPS and press Enter ...

Page 39: ...000 0000 0000 0000 will not change the setup configuration state If this value is used the setup and configuration state will remain Not started Deleting PID and PPS Under the Intel TLS PSK Configuration menu select Delete PID and PPS and press Enter This option deletes the current PID and PPS stored in Intel ME If the PID and PPS were not entered previously the Intel MEBx will return an error mes...

Page 40: ...o the Intel Remote Configuration page Remote Configuration Under the Intel Remote Configuration menu select Remote Configuration and press Enter Enabling Disabling Remote configuration will cause a partial un provision if the setup and configuration server is In process Option Description Disabled Remote configuration is disabled Only Remote Configuration and Previous Menu items are visible Enable...

Page 41: ...PKI DNS Suffix Under the Intel Remote Configuration menu select PKI DNS Suffix and press Enter Type the PKI DNS Suffix and press Enter Manage Hashes ...

Page 42: ...dding customized hash Please see the next section below The Manage Certificate Hash screen provides keyboard controls for managing the hashes on the system The following keys are valid when in the Manage Certificate Hash menu Key Description Escape Exits from the menu Insert Adds a customized certificate hash to the system Delete Deletes the currently selected certificate hash from the system Chan...

Page 43: ...ate hash Type the hash name up to 32 characters When you press Enter you are prompted to enter the certificate hash value The Certificate hash value is a hexadecimal number for SHA 1 it is 20 bytes for SHA 2 it is 32 bytes If the value is not entered in the correct format the message Invalid Hash Certificate Entered Try Again is displayed When you press ...

Page 44: ...h as follows Yes The customized hash will be marked as active No Default The customized hash will add to the EPS but will not be active Deleting a Hash When the Delete key is pressed in the Manage Certificate Hash screen the following screen is displayed NOTE A certificate hash that is set to Default cannot be deleted ...

Page 45: ...ging the Active State When the key is pressed in the Manage Certificate Hashes screen the following screen is displayed Answering Y toggles the active state of the currently selected certificate hash Setting a hash as active indicates that the hash is available for use during PSK provisioning Viewing a Certificate Hash When the Enter key is pressed in the Manage Certificate Hash screen the followi...

Page 46: ...enu Under the Intel Remote Configuration menu select Previous Menu and press Enter The Intel Remote Configuration menu changes to the Intel Automated Setup and Configuration page FW Update Settings Under the Intel ME Platform Configuration menu select FW Update Settings and press Enter The Intel ME Platform Configuration menu changes to the FW Update Settings page ...

Page 47: ... Enabled option is selected the IT admin is able to update the Intel ME firmware locally via the local Intel Management Engine interface or via the local secure interface This local firmware update does not require an administrator user name and password Therefore once the local update is complete this setting is automatically set to Disabled by the Intel ME firmware This option must be set to Ena...

Page 48: ...ser name and password are not supplied the firmware cannot be updated When the Secure Firmware Update feature is enabled the IT administrator can update the firmware using the secure method Secure firmware updates are performed via the LMS driver Previous Menu Under the FW Update Settings menu select Previous Menu and press Enter The FW Update Settings menu changes to the Intel ME Platform Configu...

Page 49: ...taining PRTC during the power off G3 state Type PRTC in GMT UTC format YYYY MM DD HH MM SS and press Enter Power Control Under the Intel ME Platform Configuration menu select Power Control and press Enter The Intel ME Platform Configuration menu changes to the Intel Power Control page ...

Page 50: ...ins in the M off state until a command is sent to the ME After this command has been sent the Intel ME will transition to an M0 or M3 state and will respond to the next command that is sent A ping to the Intel ME will also cause the Intel ME to go into an M0 or M3 state The Intel ME takes a short time to transition from the M off state to the M0 or M3 state During this time Intel AMT will not resp...

Page 51: ...time that the Intel ME is allowed remain idle in M3 before transitioning to the M off state NOTE If the Intel ME is in M0 it will NOT transition to M off Previous Menu Under the Intel ME Platform Configuration menu select Previous Menu and press Enter The Intel ME Power Control menu changes to the Intel ME Platform Configuration page Information on this page provided by Intel ...

Page 52: ... default gateway and domain name Explaining these terms is beyond the scope of this document The Intel AMT Configuration page appears Below are quick links to the various sections Manageability Feature Selection SOL IDER Username and Password SOL Redirection Mode Previous Menu KVM Configuration KVM Feature Selection User Opt in Opt in Configurable from remote IT Previous Menu Previous Menu The Int...

Page 53: ...name and Password Under the SOL IDER page select Username and Password and press Enter This option provides the user authentication for SOL IDER session If Kerberos is used this option should be set to DISABLED The user authentication is handled through Kerberos If Kerberos is not used the IT administrator has the choice to enable or disable user authentication on SOL IDER session Option Descripti...

Page 54: ...onsole if the client system supports SOL If the system does not support SOL this value cannot enable it Option Description Enabled SOL is enabled Disabled SOL is disabled NOTE Disabling SOL does not remove this feature but only blocks it from being used IDER Under the SOL IDER page select IDER and press Enter ...

Page 55: ...If the client system does not support IDE R this value cannot enable it Option Description Enabled IDER is enabled Disabled IDER is disabled NOTE Disabling IDER does not remove this feature but only blocks it from being used Redirection Mode Under the SOL IDER page select Redirection Mode and press Enter ...

Page 56: ...ng the redirection ports The old SMB consoles before Intel AMT 6 0 which do not support opening the redirection ports function need to manually turn on the redirection port through this Intel MEBx option When selecting the mode the following message is displayed Option Description Disabled Legacy redirection Mode is disabled Default The port is left open at all times when redirection is enabled in...

Page 57: ...ration Under the Intel AMT Configuration page select KVM Configuration and press Enter The Intel AMT Configuration page changes to the KVM Configuration page KVM Feature Selection Under the IKVM Configuration page select KVM Feature Selection and press Enter Option Description Disabled Disable KVM Feature Enabled Enable KVM Feature NOTE Disabling KVM does not remove this feature but disables it KV...

Page 58: ...nt is not required for remote establishment of KVM session Local User Consent is required for remote establishment of KVM session Opt in Configurable from remote IT Under the IKVM Configuration page select Opt in Configurable from remote IT and press Enter ...

Page 59: ...in Policy Enables Remote User s ability to select User OPT IN Policy Previous Menu Under the KVM Configuration page select Previous Menu and press Enter The KVM Configuration page changes to the Intel AMT Configuration page Previous Menu Under the Intel AMT Configuration page select Previous Menu and press Enter The Intel AMT Configuration page changes to Main Menu page Information on this page pr...

Page 60: ...Fast Call for help can be started environment detection must be enabled This allows Intel AMT to determine if the system is within the corporate network This is configured through an ISV app 2 A remote connection policy must be created before an Intel Fast call for help can be initiated The policy for the BIOS initiated call does not need to be configured but another policy must exist before initi...

Page 61: ...ration Anytime Network Setup Network Name Settings Host Name blank Domain Name blank FQDN Dedicated Shared Dynamic DNS Disabled Enabled TCP IP Settings Wired LAN IPv4 Configuration DHCP Mode Disabled Enabled Wired LAN IPv6 Configuration IPv6 Feature Selection Disabled Enabled The configuration page is displayed only if enabled is selected IPv6 Interface ID Type Random ID Intel ID Manual ID IPv6 Ad...

Page 62: ... PPS blank Delete PID and PPS Y N TLS PKI Remote Configuration Disabled Enabled PKI DNS Suffix blank Manage Hashes FW Update Settings FW Update Settings Local FW Update Qualifier Always Open Never Open Restricted Secure FW Update Disabled Enabled Default setting May cause Intel AMT partial unprovision 1 Intel ME Platform State Control is only changed for Management Engine ME troubleshooting 2 Un p...

Page 63: ...User Opt in User Consent is not required for KVM session User Consent is required for KVM session Opt in Configurable from remote IT Disable Remote Control of KVM Opt In Policy Enable Remote Control of KVM Opt In Policy NOTE In order for KVM to work the requirement must be Clarkdale Arrandale CPU Default setting May cause Intel AMT partial unprovision 1 Intel ME Platform State Control is only chan...

Page 64: ...are completed using a file created by the configuration service saved to a USB mass storage device MEBx interface The IT administrator manually configures the Management Engine BIOS Extension MEBx settings on each Intel AMT ready computer The PPS and PID fields are completed by typing the 32 character and 8 character alphanumeric keys created by the configuration service into the MEBx interface TL...

Page 65: ...mputer BIOS detects the USB drive key If found the BIOS looks for a setup bin file at the beginning of the drive key Go to step 7 If no USB drive key or setup bin file is found then restart the computer Ignore the remaining steps 7 The computer BIOS displays a message that automatic setup and configuration will occur 1 The first available record in the setup bin file is read into memory The proces...

Page 66: ...SB storage device is required and must conform to the requirements listed in Configuration Service Using a USB Device NOTE The nature of management software is that it is not always dynamic or real time In fact sometimes if you tell a computer to do something such as to reboot you may just have to do it again before it will work 1 Format a USB device with the FAT16 file system and no volume label ...

Page 67: ...4 Click the to expand the Intel AMT Getting Started section ...

Page 68: ...5 Click the to expand the Section 1 Provisioning section ...

Page 69: ...6 Click the to expand the Basic Provisioning without TLS section ...

Page 70: ...7 Select Step 1 Configure DNS The notification server with an out of band management solution installed must be registered in DNS as ProvisionServer ...

Page 71: ...8 Click Test on the DNS Configuration screen to verify that DNS has the ProvisionServer entry and that it resolves to the correct Intel setup and configuration server SCS ...

Page 72: ...The IP address for the ProvisionServer and Intel SCS are now visible ...

Page 73: ...9 Select Step 2 Discovery Capabilities ...

Page 74: ...10 Verify that the setting is Enabled If Disabled click the checkbox next to Disabled and click Apply ...

Page 75: ...11 Select Step 3 View Intel AMT Capable Computers ...

Page 76: ...Any Intel AMT capable computers on the network are visible in this list ...

Page 77: ...12 Select Step 4 Create Profile ...

Page 78: ...13 Click the symbol to add a new profile ...

Page 79: ... the administrator can modify the profile name and description along with the password The administrator sets a standard password for easy maintenance in the future Select the manual radio button and type a new password ...

Page 80: ...n the MEBx The TLS Transport Layer Security tab provides the ability to enable TLS If enabled several other pieces of information are required including the certificate authority CA server name CA common name CA type and certificate template The ACL access control list tab is used to review users already associated with this profile and to add new users and define their access privileges ...

Page 81: ...tel AMT as well as an Idle Timeout setting It is recommended that Idle timeout is always set to 0 for optimal performance CAUTION The setting for the Power Policy tab can potentially impact a computer s ability to remain E Star 4 0 compliant 14 Select Step 5 Generate Security Keys ...

Page 82: ...15 Select the icon with the arrow pointing out to Export Security Keys to USB Key ...

Page 83: ...16 Select the Generate keys before export radio button ...

Page 84: ...er of computers that need to be provisioned The default is 50 18 The Intel ME default password is admin Configure the new Intel ME password for the environment 19 Click Generate Once the keys have been created a link appears to the left of the Generate button ...

Page 85: ... Server 21 Click the Download USB key file link to download setup bin file to the USB device The USB device is recognized by default save the file to the USB device NOTE If additional keys are needed in the future the USB device must be reformatted before saving the setup bin file to it ...

Page 86: ...a Click Save in the File Download dialog box b Verify the Save in location is directed to the USB device Click Save ...

Page 87: ...er window 22 Close the Export Security Keys to USB Key and drive Explorer windows to return to the Altiris Console 23 Take the USB device to the computer insert the device and turn on the computer The USB device is recognized immediately and you are prompted to Continue with Auto Provisioning Y N Press y ...

Page 88: ...Press any key to continue with system boot 24 Once complete turn off the computer and move back to the management server 25 Select Step 6 Configure Automatic Profile Assignments ...

Page 89: ...26 Verify that the setting is enabled In the Intel AMT 2 0 dropdown select the profile created previously Configure the other settings for the environment ...

Page 90: ...27 Select Step 7 Monitor Provisioning Process ...

Page 91: ...or which the keys were applied begin to appear in the system list At first the status is Unprovisioned then the system status changes to In provisioning and finally it changes to Provisioned at the end of the process ...

Page 92: ...28 Select Step 8 Monitor Profile Assignments ...

Page 93: ...The computers for which profiles were assigned appear in the list Each computer is identified by the FQDN UUID and Profile Name columns ...

Page 94: ...Once the computers are provisioned they are visible under the Collections folder in All configured Intel AMT computers ...

Page 95: ...Back to Contents Page ...

Page 96: ...The Hello message is transparent to the end user There is no feedback mechanism to tell you that the computer is broadcasting the message The SCS uses the information in the Hello message to initiate a Transport Layer Security TLS connection to the Intel AMT capable computer using a TLS Pre Shared key PSK cipher suite if TLS is supported The SCS uses the PID to look up the provisioning passphrase ...

Page 97: ...ilable on support dell com and on the ResourceCD under Chipset Drivers The driver is labeled Intel AMT SOL LMS Once the driver is obtained execute the file it unzips and prompts the user to continue the installation process Once you install the SOL LMS driver the PCI Serial Port entry becomes the Intel Active Management Technology SOL COM3 entry HECI Driver The Intel AMT Host Embedded Controller I...

Page 98: ... 168 2 1 16992 By default the port is 16992 NOTE Use port 16993 and https to connect to the Intel AMT WebUI on a computer that has been configured and set up in the Enterprise mode If DHCP is used then use the fully qualified domain name FQDN for the ME The FQDN is the combination of the host name and domain example http host_name 16992 or http system1 16992 4 The management computer makes a TCP c...

Page 99: ...console Similarly the management console may send serial data over the LAN connection that appears to have come through the client s serial port IDE Redirection Overview IDE Redirection IDER is capable of emulating an IDE CD drive a legacy floppy or an LS 120 drive over a standard network connection IDER enables a management machine to attach one of its local drives to a managed client over the ne...

Page 100: ...o describe the Intel Management and Security Status application for Intel AMT generation 6 x Click here for more information Intel Management and Security Status Application NOTE If the Intel Management and Security Status application starts automatically as a result of the user logging on to Windows the icon will be loaded to the notification area only if Intel AMT or Intel Standard Manageability...

Page 101: ...about 1 minute After un provisioning completes control is passed back to the Intel AMT Configuration screen Provisioning Server Set PID and PPS and Set PRTC options are available again because the computer is set to the default Enterprise Mode 2 Select Return to previous menu 3 Select Exit and then press y The computer restarts Firmware Flash Flash the firmware to upgrade to newer versions of Inte...

Reviews: