MeshCentral only pushes CIRA through an on-host agent, so this mirrors its amtmanager.js sequence directly over the LAN: trust MeshCentral's root, add the MPS (username = 16-char meshid prefix), a periodic policy, BIOS+OS user-initiated connections and a random environment-detection domain. Idempotent, with a read-only state report. Enumerate uses Enumerate+Pull (AMT 16 ignores OptimizeEnumeration; caught by a positive control that first read 0 instances of a class that has one). Applied to nh3-pve's AMT 2026-10-02 alongside MeshCentral mpsPass and an ana-gw VIP/policy for 4433; the AMT does not dial out yet (static IP).
3.7 KiB
3.7 KiB
pfi-tacticalrmm
Tactical RMM (remote monitoring + management) server at the Anaheim colo.
Network
- LAN IP: 10.250.50.57
- SSH:
lkraven@pfi-tacticalrmm
Infrastructure
- Hypervisor:
pfi-pve(VMID 111) - Type: Linux VM
- Site: Anaheim (PFI colo)
Role
TacticalRMM — open-source RMM platform. Monitors and manages endpoints, pushes patches, runs scripts, etc.
MeshCentral (bundled with TacticalRMM) — facts checked 2026-10-02
- Runs natively (
meshcentral.service, usertactical,/meshcentral), Node 18.20.8, MeshCentral 1.2.0, postgres-backed. Public athttps://rmm-mesh.phasefinal.com(nginx terminates TLS,tlsOffload), MPS (Intel AMT CIRA) atrmm-mesh.phasefinal.com:4433. 2FA is NOT forced (force2factorunset). - HYBRID since 2026-10-02 0812 (Prime: "hybrid, make it so").
settings.WANonlyset false (backupconfig.json.bak-20261002-hybrid); the log says "Hybrid (LAN + WAN) mode". All 14 connected agents came back. nh3-pve's AMT is inPFI-AMTasnh3-pve-amt(10.100.250.61, TLS, admin): MeshCentral reached it at once (AMT 16.1.25, activated, power on), so the old-TLS worry did not apply. ⚠ The path still runs through nh3-scale (CT 107 ON nh3-pve): with nh3-pve down, this AMT is unreachable from here. KVM needs an active iGPU output: the NanoKVM serves today; fit the 1080p dummy plug before it moves. - Phone-home (CIRA) plumbing, 2026-10-02 (Prime go):
settings.mpsPassset (vaultedpfi-tacticalrmm/meshcentral-mpspass; without it the MPS checked only the 16-char username). FortiGate ana-gw: serviceMeshCentral-MPS-4433, VIPmps-to-tacticalrmm(38.120.12.46:4433 → 10.250.50.57) and policy 76 (wan1→servers, accept) — 4433 verified open from the internet, 4434 closed as a control. The AMT side isscripts/amt-cira-setup.py. ⚠ nh3-pve's AMT took every setting but does NOT dial out: it is on a STATIC IP, and Intel's CIRA guidance says static IP does not work (environment detection keys on DHCP option 15). Open decision: move it to DHCP (the UDM reservation already pins 10.100.250.61). - Before 2026-10-02:
"WANonly": true(TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS "Add Intel AMT computer":meshuser.jsline 2682,if (args.wanonly == true) return;. No error, no event. LAN-mode AMT needsWANonlyfalse (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM'supdate.shonly touches the compression keys ofconfig.json, so a WANonly change survives updates. - Device groups:
TC2-MacMini(agent group),PFI-AMT(mtype 1, Intel AMT only; created by Prime 2026-10-02, empty). 24 devices visible to Prime's account, 7 of them report Intel AMT. - CLI access:
meshctrl.json this host with Prime's login token, vaultedpfi-tacticalrmm/meshcentral-login-token(one line:username: ~t:… password: …). Example:sudo -n -u tactical node /meshcentral/node_modules/meshcentral/meshctrl.js listdevicegroups --url wss://rmm-mesh.phasefinal.com --loginuser <u> --loginpass <p>. Feed the credentials over stdin; never put them in a file or a log.
Backup coverage
- VM-image: ✅ vzdump on pfi-pve (daily)
- File-level restic: ❌ not yet configured
TacticalRMM state (Postgres DB with inventory + automation history, MeshCentral config, agent registrations) is critical if used in production. Worth setting up app-consistent DB dumps + file-level restic if it's the primary management plane.
Refresh state
scripts/refresh-server-info.sh pfi-tacticalrmm
Discovered via
scripts/discover-fortigate.sh 10.250.250.1 on 2026-04-21 —
FortiGate DHCP lease (MAC ba:fa:65:f6:46:25).