Thinkcentre M58p with Intel AMT White Paper
Total Page:16
File Type:pdf, Size:1020Kb
ThinkCentre M58p with Intel Active Management Technology First Edition (October 2008) Contents About this document . .v Intel ME configuration. .10 Intel AMT setup and configuration . .13 Driver description . .18 Chapter 1. Introduction to Intel vPro and Intel AMT technology . .1 Chapter 6. Web user interface . .19 Acronyms . .1 Access the Web user interface . .19 Provision the Intel AMT system . .19 Chapter 2. Lenovo ThinkCentre Logging onto the client system . .19 computer equipped with Intel AMT Function in Web user interface . .20 technology . .3 Appendix A. Two examples of Intel Chapter 3. ISV solution introduction . .5 AMT setup and configuration: SMB mode and enterprise mode . .23 Chapter 4. Main features of computers Intel AMT setup and configuration steps - SMB built with Intel AMT . .7 mode . .23 Intel AMT setup and configuration steps - Enterprise mode . .23 Chapter 5. Intel AMT setup and configuration based on Lenovo Appendix B. Default configuration ThinkCentre M58p . .9 values for Intel MEBx . .25 Associated Intel AMT setup and configuration in BIOS . .9 Intel MEBx setup and configuration . .10 Appendix C. Notices . .27 Entering MEBx configuration user interface. .10 Trademarks . .28 Changing Intel ME password . .10 iii iv ThinkCentre M58p with Intel AMT White Paper About this document ® This document provides information about the application of the Intel Active ® ® Management Technology (Intel AMT) for Lenovo ThinkCentre M58p desktop computers. It provides a step-by-step approach to successfully use the Intel AMT technology. This document is intended for trained IT professionals, or those responsible for deploying new computers throughout their organizations. The readers should have basic knowledge of network and computer technology, and be familiar with these terms: TCP/IP, DHCP, IDE, DNS, Subnet Mask, Default Gateway, and Domain Name. This document provides information about the following topics: Chapter 1, “Introduction to Intel vPro and Intel AMT technology,” on page 1: This ™ chapter provides a general introduction to the Intel vPro technology and Intel AMT technology. Chapter 2, “Lenovo ThinkCentre computer equipped with Intel AMT technology,” on page 3: This chapter describes the benefits of Intel vPro built-in computers. Chapter 3, “ISV solution introduction,” on page 5: This chapter provides detailed information on the ISV solution. Chapter 4, “Main features of computers built with Intel AMT,” on page 7: This chapter provides the main features of Intel vPro built-in computers. Chapter 5, “Intel AMT setup and configuration based on Lenovo ThinkCentre M58p,” on page 9: This chapter provides detailed instructions on how to configure the settings of Intel AMT. Chapter 6, “Web user interface,” on page 19: This chapter provides instructions on how to configure Intel AMT through web user interface. v vi ThinkCentre M58p with Intel AMT White Paper Chapter 1. Introduction to Intel vPro and Intel AMT technology ™ The Intel vPro technology is a business computer platform brand, enabling business computers with enhanced remote management capabilities. For computers built with Intel vPro technology, IT administrators can use a third party software to remotely collect inventory information, diagnose problems, and provide various services regardless of the system power state or operating system condition. Administrators can also isolate and protect individual computers and the network from threats quickly. The Intel AMT is part of the Intel Management Engine (ME), which is built into computers with Intel vPro technology. It is designed to provide remote management even to computers that are turned off or have an inoperable operating system as long as the system is connected to a power source and a network. Acronyms Acronym Description AMT Active Management Technology ASF Alert Standard Format CIRA Client Initiated Remote Access DHCP Dynamic Host Configuration Protocol DNS Domain Name Server FQDN Fully Qualified Domain Name FW Firmware HECI Host Embedded Controller Interface ICH I/O Controller Hub IDE-R Integrated Device Electronics Redirection ISV Independent Software Vendor LMS Local Manageability Service ME Management Engine MEBx Management Engine BIOS Extension MEI Management Engine Interface NAT Network Address Translation NVM Non-volatile Memory OEM Original Equipment Manufacturer PID/PPS Provisioning ID and Provisioning Pre-shared Key PKI Public Key Infrastructure PRTC Protected Real Time Clock PSK Pre-shared Key SMB Small and Medium Businesses SOL Serial-Over-LAN TCP Transmission Control Protocol 1 TLS Transport Layer Security UI User Interface VLAN Virtual Local Area Network ZTC Zero Touch Configuration 2 ThinkCentre M58p with Intel AMT White Paper Chapter 2. Lenovo ThinkCentre computer equipped with Intel AMT technology The following Lenovo business computers support the Intel AMT technology: ThinkCentre M55p, ThinkCentre M57p, and ThinkCentre M58p. ThinkCentre M55p supports Intel AMT 2.X. ThinkCentre M57p supports Intel AMT 3.X, and ThinkCentre M58p supports Intel AMT 5.0. ThinkCentre M58p computers with Intel AMT technology and supporting infrastructure enable IT administrators to better discover, restore, and protect the computers in order to deliver more efficient helpdesk service with less inconvenience and cost: v Discover: Intel AMT stores hardware and software information in nonvolatile memory. With built-in manageability, Intel AMT allows IT administrators to locate the assets, even when computers are powered off. v Restore: The built-in manageability of Intel AMT provides Out of Band (OOB) management capabilities to allow IT administrators to remotely recover systems even if the operating system is not operable. Alerting and event logging help IT administrators detect problems quickly to reduce downtime. v Protect: The Intel AMT System Defense feature enables better inbound protection by proactively blocking incoming threats, and reactively containing infected clients before they become critical and cause problems. ThinkCentre M58p also supports the Client Initiated Remote Access (CIRA) function. You can use this function through ISV applications. Client Initiated Remote Access (CIRA) allows client initiated, secure OOB communication to manageability console, including: v User initiated Call Home for help v Scheduled automated Call Home feature (no user input required) v TLS session established through client initiation 3 The following table shows the main features and benefits of the Intel AMT technology. Table 1. Features and Benefit Features Benefits OOB system access Allows remote management of platforms regardless of system power state or operating system state Remote Significantly reduces desk-side visits, and increases the efficiency troubleshooting and of IT technical staff recovery Proactive alerting Decreases downtime and minimizes time-to-repair Remote Hardware Increases speed and accuracy over manual inventory tracking, and asset tracking reduces asset accounting costs Third-party nonvolatile Increases speed and accuracy over manual inventory tracking, and storage reduces asset accounting cost 4 ThinkCentre M58p with Intel AMT White Paper Chapter 3. ISV solution introduction Intel AMT is designed as a building block and not a complete solution. This allows Original Equipment Manufacturers (OEMs) to incorporate Intel AMT technology into their client and server hardware platforms. Competent and authorized third-party applications will provide the management and security services that take advantage of the Intel AMT features, such as out-of-band access to asset information, event logs, hardware and software tables, and embedded capabilities. To ensure the usability and efficiency of our computers, Lenovo, as an OEM, is planning to develop complete solutions with Intel and leading third party security and enterprise management software vendors. Table 2. List of common third party management software ISV Application Microsoft Microsoft Systems Management Server 2003 Microsoft Microsoft System Center Configuration Manager LANDesk LANDesk Management Suite Altiris Altiris Real-Time System Manager 5 6 ThinkCentre M58p with Intel AMT White Paper Chapter 4. Main features of computers built with Intel AMT Computers built with Intel AMT version 2.0 or later (vPro technology) have the following features and improvements: v Remote Power Control – Power Down – Power Up – Power Reset – Power Cycle v Asset Management – E-Asset Tag – OOB HW Inventory v Integrated Device Electronics – Redirection (IDE-R) – Floppy Redirection – CD Redirection v Serial-Over-LAN (SOL) – Screen Redirection Based on Text – Keyboard Redirection – Network Redirection v Remote Reboot – Reboot from local HD – Reboot from local CD/DVD v Event Management – Event Alerting – Event Logging – Audit Log v Agent Presence v System Defense v Client Initiated Remote Access (CIRA) 7 8 ThinkCentre M58p with Intel AMT White Paper Chapter 5. Intel AMT setup and configuration based on Lenovo ThinkCentre M58p The Management Engine BIOS Extension (MEBx) is a separate BIOS from the normal system BIOS. It is an option ROM module provided by Intel. The MEBx enables you to configure settings that control the operation of the Management Engine (ME) that runs on the Intel AMT client, which must be set up and configured in a system before use. Intel ME is an isolated and protected computing resource. The Intel ME configuration should be completed through MEBx before use. All changes to the ME platform configuration settings are not cached in MEBx.