ops(nh3-pve): AMT phones home to MeshCentral (CIRA); AMT on DHCP; LAN management now dark by design

This commit is contained in:
vh
2026-10-02 09:06:24 -07:00
parent 9bcb9417fb
commit 1a2d763de4
4 changed files with 21 additions and 5 deletions
+7 -3
View File
@@ -33,9 +33,13 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
`pfi-tacticalrmm/meshcentral-mpspass`; without it the MPS checked only the 16-char username). FortiGate
ana-gw: service `MeshCentral-MPS-4433`, VIP `mps-to-tacticalrmm` (38.120.12.46:4433 → 10.250.50.57) and
policy 76 (wan1→servers, accept) — 4433 verified open from the internet, 4434 closed as a control. The AMT
side is `scripts/amt-cira-setup.py`. ⚠ nh3-pve's AMT took every setting but does NOT dial out: it is on a
STATIC IP, and Intel's CIRA guidance says static IP does not work (environment detection keys on DHCP
option 15). Open decision: move it to DHCP (the UDM reservation already pins 10.100.250.61).
side is `scripts/amt-cira-setup.py`. **nh3-pve's AMT phones home since 0859** after moving it from static IP
to DHCP (Intel: CIRA does not work on a static IP; the FortiGate sniffer had shown zero attempts before).
The CIRA entry is `nh3-pve-amt` (the old LAN entry was removed). Two things it needed: the AMT
credentials set on the device (`changedevice` intelamt user/pass) and `intelamt.tls` = 1. Then a
MeshCentral restart re-ran its AMT manager, which logged in at once (16.1.25, power on). ⚠ MeshCentral
1.2.0 `amtmanager.js` picks TLS-vs-not over CIRA with `boundPorts.indexOf('16992')` used as a boolean
(−1 is truthy), so a TLS-only AMT can be tried without TLS. Set `tls` explicitly as above.
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's