ops(nh3-pve): AMT phones home to MeshCentral (CIRA); AMT on DHCP; LAN management now dark by design
This commit is contained in:
@@ -56,7 +56,18 @@ not power back on by itself.
|
||||
vmbr0 members, so either cage works. **Never drop either port from the bridge**
|
||||
without checking which one has carrier (`ip -br link`). The bridge carries the
|
||||
I226-V's MAC `…:96:0d` because it is the first port listed.
|
||||
- **AMT: `https://10.100.250.61:16993`** (`nh3-pve-amt.nh3.internal`; Homepage
|
||||
- ⭐ **AMT PHONES HOME since 2026-10-02 0859 (Prime): use MeshCentral, not the LAN address.** The AMT holds a
|
||||
CIRA tunnel to `rmm-mesh.phasefinal.com:4433` (TacticalRMM's MeshCentral, group `PFI-AMT`, device
|
||||
`nh3-pve-amt`), which does not depend on nh3-pve or nh3-scale. MeshCentral logs in over the tunnel
|
||||
(AMT 16.1.25, power state read). Set up with `scripts/amt-cira-setup.py`; see
|
||||
`servers/pfi-tacticalrmm/README.md`.
|
||||
- ⚠ **The AMT is on DHCP now** (UDM reservation keeps `10.100.250.61`). Intel: CIRA does not work on a static IP.
|
||||
- ⚠ **LAN management is OFF while it is phoning home.** Once AMT decides it is "outside" (random
|
||||
environment-detection domain `21cade3bec8c`), `10.100.250.61:16993` stops answering, so
|
||||
`scripts/amt-wsman.py` from nh3-dev no longer reaches it. Manage it through MeshCentral; last resort
|
||||
is MEBx (Ctrl+P) through the NanoKVM. To go back to static, Put `amt-ethernet-static-revert.xml`
|
||||
(this dir) on `AMT_EthernetPortSettings` through MeshCentral or from MEBx.
|
||||
- **AMT (LAN, before 2026-10-02): `https://10.100.250.61:16993`** (`nh3-pve-amt.nh3.internal`; Homepage
|
||||
card *NH3-PVE-AMT* under Infra - NH3). Intel AMT 16.1.25, **Admin Control
|
||||
Mode**. User `admin`; the password is in the vault as `nh3-pve/amt-admin`.
|
||||
- **Static IP since 2026-09-25 2306:** `10.100.250.61/24`, gateway and DNS
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
<r:AMT_EthernetPortSettings xmlns:r="http://intel.com/wbem/wscim/1/amt-schema/1/AMT_EthernetPortSettings"><r:DHCPEnabled>false</r:DHCPEnabled><r:DefaultGateway>10.100.250.1</r:DefaultGateway><r:ElementName>Intel(r) AMT Ethernet Port Settings</r:ElementName><r:IPAddress>10.100.250.61</r:IPAddress><r:InstanceID>Intel(r) AMT Ethernet Port Settings 0</r:InstanceID><r:IpSyncEnabled>false</r:IpSyncEnabled><r:LinkIsUp>true</r:LinkIsUp><r:LinkPolicy>1</r:LinkPolicy><r:LinkPolicy>16</r:LinkPolicy><r:MACAddress>58-47-ca-76-96-0e</r:MACAddress><r:PhysicalConnectionType>1</r:PhysicalConnectionType><r:PhysicalNicMedium>1</r:PhysicalNicMedium><r:PrimaryDNS>10.100.250.1</r:PrimaryDNS><r:SharedDynamicIP>true</r:SharedDynamicIP><r:SharedMAC>true</r:SharedMAC><r:SharedStaticIp>false</r:SharedStaticIp><r:SubnetMask>255.255.255.0</r:SubnetMask></r:AMT_EthernetPortSettings>
|
||||
@@ -33,9 +33,13 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
|
||||
`pfi-tacticalrmm/meshcentral-mpspass`; without it the MPS checked only the 16-char username). FortiGate
|
||||
ana-gw: service `MeshCentral-MPS-4433`, VIP `mps-to-tacticalrmm` (38.120.12.46:4433 → 10.250.50.57) and
|
||||
policy 76 (wan1→servers, accept) — 4433 verified open from the internet, 4434 closed as a control. The AMT
|
||||
side is `scripts/amt-cira-setup.py`. ⚠ nh3-pve's AMT took every setting but does NOT dial out: it is on a
|
||||
STATIC IP, and Intel's CIRA guidance says static IP does not work (environment detection keys on DHCP
|
||||
option 15). Open decision: move it to DHCP (the UDM reservation already pins 10.100.250.61).
|
||||
side is `scripts/amt-cira-setup.py`. **nh3-pve's AMT phones home since 0859** after moving it from static IP
|
||||
to DHCP (Intel: CIRA does not work on a static IP; the FortiGate sniffer had shown zero attempts before).
|
||||
The CIRA entry is `nh3-pve-amt` (the old LAN entry was removed). Two things it needed: the AMT
|
||||
credentials set on the device (`changedevice` intelamt user/pass) and `intelamt.tls` = 1. Then a
|
||||
MeshCentral restart re-ran its AMT manager, which logged in at once (16.1.25, power on). ⚠ MeshCentral
|
||||
1.2.0 `amtmanager.js` picks TLS-vs-not over CIRA with `boundPorts.indexOf('16992')` used as a boolean
|
||||
(−1 is truthy), so a TLS-only AMT can be tried without TLS. Set `tls` explicitly as above.
|
||||
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
|
||||
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
|
||||
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's
|
||||
|
||||
Reference in New Issue
Block a user