Intel® Active Management Technology v4.0Administrator's GuideOverviewProduct OverviewOperational ModesSetup and Configuration OverviewProvisionin
Intel ME Features ControlThe ME Features Control menu contains the following configuration selection.Manageability Feature SelectionWhen you select th
16. For IDE Redirection, select Enabled and then press <Enter>.
Secure Firmware Update is the next option. The default setting is Enabled.
17. Skip Set PRTC.
Idle Timeout is the next option. The default setting is 1. This timeout is applicable only when a WoL option isselected for Intel ME ON in Host Sleep
18. Select Return to Previous Menu, and then press <Enter>.
19. Select Exit, and then press <Enter>.
20. Press <y> when the following message appears:Are you sure you want to exit? (Y/N):
21. After the computer restarts, turn off the computer and disconnect the power cable. The computer is now in setup state and is ready for deployment
Back to Contents PageSystem DeploymentOnce you are ready to deploy a computer to a user, plug the computer into a power source and connect it to the n
Back to Contents PageOperating System DriversWithin the operating system, two drivers must be installed to remove unknown devices in the Device Manage
You can use this option to determine which manageability feature is enabled.ASF — Alert Standard Format. ASF is a standardized corporate assets manage
Back to Contents PageIntel AMT WebGUIThe Intel® AMT WebGUI is a Web browser-based interface for limited remote computer management. The WebGUI is ofte
Back to Contents PageAMT Redirection OverviewIntel® AMT makes it possible to redirect serial and IDE communications from a managed client to a managem
Back to Contents PageTroubleshootingThis page describes a few basic troubleshooting steps to follow if problems are experienced with the Intel® AMTcon
Bad ME memory configurationDIMM A is located beneath the keyboard. For instructions on accessing this slot, refer to the system documentation.Back to
Back to Contents PageUSB Setup and ConfigurationThe default console package provided is the Dell™ Client Management (DCM) application. This section pr
Click the <+> to expand the Intel AMT Getting Started section.
Click the <+> to expand the Section 1. Provisioning section.
Click the <+> to expand the Basic Provisioning (without TLS) section.
Select Step 1. Configure DNS.The notification server with an out-of-band management solution installed must be registered in DNS as "ProvisionSer
Click Test on the DNS Configuration screen to verify that DNS has the ProvisionServer entry and that it resolves to thecorrect Intel setup and configu
menu loads.The power package selected determines when the ME is turned ON. The default power package is Mobile: ON in S0. The enduser administrator ca
The IP address for the ProvisionServer and Intel SCS are now visible.
Select Step 2. Discovery Capabilities.
Verify that the setting is Enabled. If Disabled, click the check box next to Disabled and click Apply.
Select Step 3. View Intel AMT Capable Computers.
Any Intel AMT capable computers on the network are visible in this list.
Select Step 4. Create Profile.
Click the plus symbol to add a new profile.
On the General tab the administrator can modify the profile name and description along with the password. Theadministrator sets a standard password fo
The Network tab provides the option to enable ping responses, VLAN, WebUI, Serial over LAN, and IDE Redirection. If youare configuring Intel AMT manua
The Power Policy tab has configuration options to select the sleep states for Intel AMT as well as an Idle Timeout setting.It is recommended that Idle
Back to Contents PageAMT Configuration MenuAfter you completely configure the Intel® Management Engine (ME) feature, you must reboot before configurin
Select the icon with the arrow pointing out to Export Security Keys to USB Key.
Select the Generate keys before export radio button.
Enter the number of keys to generate (depends on the number of computers that need to be provisioned). The default is 50.The Intel ME default password
Insert the previously formatted USB device into a USB connector on the Provisioning Serverr.Click the Download USB key file link to download setup.bin
a. Click Save in the File Download dialog box.b. Verify the Save in: location is directed to the USB device. Click Save.c. Click Close in the Downl
Close the Export Security Keys to USB Key and drive explorer windows to return to the Altiris Console.Take the USB device to the computer, insert the
Once complete, turn off the computer and move back to the management server.Select Step 6. Configure Automatic Profile Assignments.
Verify that the setting is enabled. In the Intel AMT 2.0+ dropdown, select the profile created previously. Configure the othersettings for the environ
Select Step 7. Monitor Provisioning Process.
The computers for which the keys were applied begin to appearing in the system list. At first the status is Unprovisioned,then the system status chang
TCP/IPAllows you to change the following TCP/IP configuration of Intel AMT.Network interface – ENABLE** / DISABLED If the network interface is disable
Select Step 8. Monitor Profile Assignments.
The computers for which profiles were assigned appear in the list. Each computer is identified by the FQDN, UUID, andProfile Name columns.
Once the computers are provisioned, they are visible under the Collections folder in All configured Intel AMT computers.
Back to Contents Page
Current Provisioning Mode – Displays the current provisioning TLS Mode: None, PKI, or PSK. This configuration isonly shown in Enterprise Provision Mod
change the active status of the certificate press the <+> key. To delete the hash press the <del> key. To addanother key press the <ins
Remote Configuration Enable/DisableThe selectable options are Enable and Disable. If Remote Configuration is disabled, the menu options underneath are
The Manage Certificate Hash screen has several keyboard controls available to you to manage the hashes on the computer.The following keys are valid wh
Change the active state of this hash? (Y/N)prompt. Answering yes to this question toggles the active state of the currently selected certificate hash.
Back to Contents PageOverviewIntel® Active Management Technology (Intel AMT) allows companies to easily manage their networked computers in thefollowi
Un-provisionThe Un-Provision option allows you to reset the Intel AMT configuration to factory defaults. There are two types of un-provision:Full Un-p
SOL/IDE-RUsername and Password – DISABLED** / ENABLED This option provides the user authentication for SOL/IDER session. If the Kerberos protocol is u
Password PolicyThere are two passwords present for the firmware. The MEBX password is the password that is entered when a user isphysically at the sys
Secure Firmware UpdateThis option allows you to enable/disable secure firmware updates. Secure firmware update requires an administrator username and
Set PRTCEnter PRTC in GMT (UTC) format (YYYY:MM:DD:HH:MM:SS). Valid date range is 1/1/2004 – 1/4/2021. Setting PRTC value isused for virtually maintai
Idle TimeoutUse this setting to define the ME WOL idle timeout. When this timer expires, the ME enters a low-power state. This timeoutonly takes affec
Intel AMT in DHCP Mode Settings ExampleThe table below shows a basic field settings example for the Intel AMT Configuration menu page to configure the
The table below shows a basic field settings example for the Intel AMT Configuration menu page to configure the computerin static mode. The computer r
Back to Contents PageMEBx DefaultsThe table below lists all the default settings for the Intel® Management Engine BIOS Extension (MEBx).Password admin
Anytime Secure Firmware UpdateDisabled Enabled * Set PRTC blank Idle Timeout Timeout Value (0x0-0xFFFF) 1*Default setting**May ca
Back to Contents PageOperational ModesIntel® AMT can be set up for either Enterprise or Small and Medium Business operational modes (also called provi
Back to Contents PageSetup and Configuration Methods OverviewAs discussed in the Setup and Configuration Overview section, the computer has to be conf
Back to Contents PageConfiguration ServiceThis section discusses Intel® AMT setup and configuration using a USB storage device. You can set up and loc
Back to Contents PageMEBx Interface (Enterprise Mode)The Intel® Management Engine BIOS Extension (MEBx) is an optional ROM module that Intel provides
One uppercase letterOne lowercase letterA numberA special (nonalphanumeric) character, such as !, $, or ; excluding the :, ", and , characters.)T
6. Press <y> when the following message appears:System resets after configuration change. Continue (Y/N).
Intel ME State Control is the next option. The default setting for this option is Enabled. Do not change this settingto Disabled. If you want to disab
7. Select Intel ME Firmware Local Update. Press <Enter>.8. Then, select either Enabled or Disabled, and press <Enter>.The default settin
9. Select Intel ME Features Control, and then press <Enter>.
Manageability Feature Selection is the next option. This feature sets the platform management mode. The defaultsetting is Intel AMT.Selecting the None
10. Select Return to Previous Menu, and then press <Enter>.
Back to Contents PageSetup and Configuration OverviewThe following is a list of important terms related to the Intel® AMT setup and configuration.Setu
11. Select Intel ME Power Control, and then press <Enter>.
Intel ME ON in Host Sleep States is the next option. The default setting is Mobile: ON in S0.
12. Select Return to Previous Menu, and then press <Enter>.
13. Select Return to Previous Menu, and then press <Enter>.
14. Exit the MEBx Setup and save the ME configuration.The computer displays an Intel ME Configuration Complete message and then restarts. After the M
4. Select Host Name, and then press <Enter>.5. Type in a unique name for this Intel AMT machine, and then press <Enter>.Spaces are not a
6. Select TCP/IP. Press <Enter>.7. Press <n>when the following message appears:[DHCP Enable] Disable DHCP (Y/N)
8. Type the domain name into the Domain name field.
9. Select Provision Model from the menu, and then press <Enter>.10. Press <n>when the following message appears:[Enterprise] change to S
11. Select Setup and Configuration from the menu, and then press <Enter>.
Back to Contents PageThe act of setting up and configuring Intel® AMT is known as provisioning. There are two methods of provisioning a computerwith E
12. Select Current Provisioning Mode to display the current mode, and then press <Enter>.The current provisioning mode is displayed. Press <
13. Select Provisioning Record from the menu, and then press <Enter>.The screen displays the provision PSK/PKI record data of the computer. If
14. Select Provisioning Server from the menu, and then press <Enter>.
15. Type the provisioning server IP in the Provisioning server address field and press <Enter>.The default setting is 0.0.0.0. This default set
16. Type the port in the Port number field and press <Enter>.The default setting is 0. If left at the default setting of 0, the Intel AMT attem
17. Select TLS PSK from the menu, and then press <Enter>.
18. Set PID and PPS is the next option.The PID and PPS can be input manually or by using a USB key once the SCS generates the codes.This option is fo
Skip the Delete PID and PPS option. This option returns the computer to factory defaults. See the "Return to Default"section for more inform
20. Select TLS PKI from the menu, and then press <Enter>.
21. Select Remote Configuration Enable/Disable from the menu, and then press <Enter>.This option is Disabled by default and can be Enabled if t
Back to Contents PageMEBx Settings OverviewThe Intel® Management Engine BIOS Extension (MEBx) provides platform-level configuration options for you to
22. If Enabled, refer to steps 19 through 21. If not Enabled, skip to step 22.
Manage Certificate Hashes option is the next option. Four hashes are configured by default. Hashes can be deletedor added per customer needs.
23. Select Set FQDN from the menu, and then press <Enter>.24. Type the FQDN of the provisioning server in the text field and press <Enter&g
25. Select Set PKI DNS Suffix from the menu. Press <Enter>.26. Type the PKI DNS Suffix in the text field and press <Enter>.
27. Select Return to Previous Menu, and press <Enter>.
28. Select Return to Previous Menu, and then press <Enter>.This returns you to the Intel AMT Configuration menu.
Skip the Un-Provision option. This option returns the computer to factory defaults. See the "Return to Default"section for more information
29. Select SOL/IDE-R, and then press <Enter>.
30. Press <y> when the following message appears:[Caution] System resets after configuration changes. Continue: (Y/N).
User name & Password31. Select Enabled and then press <Enter>.This option allows you to add users and passwords from the WebGUI. If the opt
Intel AMT ConfigurationChange Intel ME PasswordThe Intel ME Configuration and Intel AMT Configuration menus are discussed on the following pages. Firs
32. For Serial Over LAN (SOL/IDE-R), select Enabled and then press <Enter>.
33. For IDE Redirection<, select Enabled and then press <Enter>.
Secure Firmware Update is the next option. The default setting is Enabled.
Skip Set PRTC.
Idle Timeout is the next option. The default setting is 1. This timeout is applicable only when a WoL option is selectedfor enabling ME for the Enterp
34. Select Return to Previous Menu, and then press <Enter>.
35. Select Exit, and then press <Enter>.
36. Press <y> when the following message appears:Are you sure you want to exit? (Y/N):
The computer restarts. Turn off the computer and disconnect the power cable. The computer is now in setup state andis ready for deployment.Back to Con
Back to Contents PageMEBx Interface (SMB Mode)The Intel® Management Engine BIOS Extension (MEBx) is an optional ROM module that Intel provides to Dell
Back to Contents PageME Configuration MenuTo reach the Intel® Management Engine (ME) Platform Configuration page, follow these steps:1. Under the Man
A numberA special (nonalphanumeric) character, such as !, $, or ; excluding the :, ", and , characters.)The underscore ( _ ) and spacebar are val
7. Press <y> when the following message appears:System resets after configuration change. Continue (Y/N).
Intel ME State Control is the next option. The default setting for this option is Enabled. Do not change this settingto Disabled. If you want to disab
8. Select Intel ME Firmware Local Update and then press <Enter>.9. Select either Enabled or Disabled, and then press <Enter>.The default
10. Select Intel ME Features Control, and then press <Enter>.
Manageability Feature Selection is the next option. This feature sets the platform management mode. The defaultsetting is Intel AMT. Selecting the Non
11. Select Return to Previous Menu, and then press <Enter>.
12. Select Intel ME Power Control, and then press <Enter>.
Intel ME ON in Host Sleep States is the next option. The default setting is Mobile: ON in S0.
13. Select Return to Previous Menu and then press <Enter>.
When enabled, the ME State Control option lets you disable ME to isolate the ME computer from the main platform whiledebugging a field malfunction. Th
14. Select Return to Previous Menu, and then press <Enter>.
15. Exit the MEBx Setup and save the ME configuration.The computer displays an Intel ME Configuration Complete message and then restarts. After the M
4. Select Host Name, and then press <Enter>. 5. Type in a unique name for this Intel AMT machine, and then press <Enter>.Spaces are not
6. Select TCP/IP, and then press <Enter>.7. Press <n> when the following message appears:[DHCP Enable] Disable DHCP (Y/N)
8. Type the domain name into the field.
9. Select Provision Model from the menu, and then press <Enter>.10. Press <y> when the following message appears:[Enterprise] change to
11. Skip the Un-Provision option. This option returns the computer to factory defaults. See the "Return to Default"section for more informa
13. Press <y> when The following message appears:[Caution] System resets after configuration changes. Continue: (Y/N)
14. Select Enabled for Username & Password, and then press <Enter>.This option allows you to add users and passwords from the WebGUI. If th
15. For Serial Over LAN, select Enabled and then press <Enter>.
Comentários a estes Manuais