ops(nh3-pve-2): AMT 21 configured (KVM, no-consent, listener) and phoning home to MeshCentral

This commit is contained in:
vh
2026-10-02 14:54:56 -07:00
parent e73adfe7ae
commit 34659ae9e7
2 changed files with 3 additions and 2 deletions
+2 -1
View File
@@ -35,7 +35,8 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
policy 76 (wan1→servers, accept) — 4433 verified open from the internet, 4434 closed as a control. The AMT
side is `scripts/amt-cira-setup.py`. **nh3-pve's AMT phones home since 0859** after moving it from static IP
to DHCP (Intel: CIRA does not work on a static IP; the FortiGate sniffer had shown zero attempts before).
The CIRA entry is `nh3-pve-amt` (the old LAN entry was removed). Two things it needed: the AMT
The CIRA entries are `nh3-pve-amt` (old LAN entry removed) and `nh3-pve-2-amt` (MS-03, AMT 21.0.6, from 2026-10-02 1449;
configured on DHCP from the start, so it phoned home the moment its environment detection was set). Two things it needed: the AMT
credentials set on the device (`changedevice` intelamt user/pass) and `intelamt.tls` = 1. Then a
MeshCentral restart re-ran its AMT manager, which logged in at once (16.1.25, power on). ⚠ MeshCentral
1.2.0 `amtmanager.js` picks TLS-vs-not over CIRA with `boundPorts.indexOf('16992')` used as a boolean