background image

 

 
 

Intel® Desktop Boards 
DQ67SW, DQ67EP, DQ67OW

 

Intel® vPro™ Technology Setup and 
Configuration Guide  
 
 
 
 
 
 
 
 
 

September 2011 

Part Number:  G45734-001 

Summary of Contents for BX80623I52500

Page 1: ...Intel Desktop Boards DQ67SW DQ67EP DQ67OW Intel vPro Technology Setup and Configuration Guide September 2011 Part Number G45734 001 ...

Page 2: ...t further evaluation by Intel Intel Corporation may have patents or pending patent applications trademarks copyrights or other intellectual property rights that relate to the presented subject matter The furnishing of documents and other materials and information does not provide any license express or implied by estoppel or otherwise to any such patents trademarks copyrights or other intellectual...

Page 3: ...st Based Configuration 25 1 6 Fast Call for Help FCFH 25 1 7 KVM Remote Control 27 1 8 Intel Identity Protection Technology Intel IPT 29 1 9 BIOS Maintenance Mode 30 2 References 33 Figures Figure 1 Intel Desktop Boards POST Screen 7 Figure 2 BIOS Setup Main Menu 8 Figure 3 BIOS Setup Configuration Menu 9 Figure 4 BIOS Setup Configuration 9 Figure 5 BIOS Setup Security Menu 10 Figure 6 BIOS Setup ...

Page 4: ...ration 23 Figure 23 Intel AMT TLS with PSK One Touch Configuration 24 Figure 24 FCFH Header Locations 25 Figure 25 Fast Call for Help Alert Screen 26 Figure 26 VNC Viewer Console Remote Login 27 Figure 27 Intel AMT Client Screen Showing KVM Remote Control Access Code 27 Figure 28 VNC Viewer Management Console Access Code Screen 28 Figure 29 VNC Viewer Management Console View 28 Figure 30 Symantec ...

Page 5: ...vPro technology features of the Intel Desktop Boards DQ67SW DQ67EP and DQ67OW plus BIOS Setup details for Intel vPro technology and Intel Active Management Technology Intel AMT Ch 2 References Typographical Conventions This section contains information about the conventions used in this specification Not all of these symbols and abbreviations appear in all specifications of this type Common Notati...

Page 6: ... IPT Table 1 Feature Summary Note Intel Active Management Technology requires one of the following Intel Core i5 vPro and Intel Core i7 vPro processors Intel Core i5 2390T Intel Core i5 2400 Intel Core i5 2400S Intel Core i5 2500 Intel Core i5 2500S Intel Core i5 2500T Intel Core i7 2600 or Intel Core i7 2600S processor In addition the following Intel Xeon E3 processors support Intel AMT functiona...

Page 7: ...the different features of Intel vPro technology Intel vPro Technology Feature BIOS Setup Menu Trusted Platform Module TPM Configuration On Board Devices Intel Virtualization Technology Intel VT Security Intel Trusted Execution Technology Intel TXT Security Intel VT for Directed I O Intel VT d Security Intel Active Management Technology Intel AMT Intel ME Table 2 Location of Intel vPro Technology F...

Page 8: ... Intel vPro Technology Setup and Configuration Guide 8 Figure 2 BIOS Setup Main Menu 1 1 3 BIOS Setup Configuration Menu The Configuration Menu shown in Figure 3 contains settings for On Board Devices as well as access to the system Event Log ...

Page 9: ... DQ67OW Intel vPro Technology Setup and Configuration Guide 9 Figure 3 BIOS Setup Configuration Menu TPM is enabled or disabled by means of the Configuration On Board Devices menu as shown in Figure 4 Figure 4 BIOS Setup Configuration ...

Page 10: ... is disabled first Note Setting the Master Key Hard Disk Drive Password will not enable Hard Disk Drive password security Only by setting the Hard Disk Drive Password will the system pause during boot to ask for a password At that time either the Hard Disk Drive Password or the Master Key Password if set will allow the system to proceed Note The Supervisor Password controls access to the BIOS Setu...

Page 11: ...t accessing the Intel ME menu the user will be asked to change the default password of admin The new password must be at least eight characters long and be composed of upper and lower case letters numbers and symbols excluding colon comma and double quotes Figure 6 illustrates the initial Intel ME menu Figure 6 BIOS Setup Intel ME Menu ...

Page 12: ...p Board DQ67SW DQ67EP DQ67OW Intel vPro Technology Setup and Configuration Guide 12 Once the administrator password is set the user is presented the Intel ME main menu shown in Figure 7 Figure 7 Intel ME Main Menu ...

Page 13: ...l ME Configuration Note If Intel AMT is enabled on board LAN found under BIOS Setup Configuration On Board Devices cannot be disabled See Figure 4 Choosing Power Policy 1 On in S0 effectively disables Intel AMT Out of Band OOB operation Power Policy 2 On in S0 ME Wake in S3 S4 S5 allows Intel ME and Intel AMT to operate when the system is turned off or in a standby state After the Idle Timeout tim...

Page 14: ... Intel ME Intel AMT Configuration Figure 9 displays the main Intel AMT Configuration screen From here the user can select the Setup and Configuration Provisioning Mode as well as reset Intel AMT back to factory defaults except the Intel ME administrator password Figure 9 Intel ME Intel AMT Configuration ...

Page 15: ...r Remote Configuration or TLS with PSK Pre shared Key which can be used with a USB flash drive for One Touch Configuration Other options available from the Remote Setup and Configuration screen allow the user to assign an IP address to the Provisioning Server either IPV4 or IPV6 change from the default Server Port of 9971 or provide a Fully Qualified Domain Name FQDN for the Provisioning Server to...

Page 16: ... Configuration TLS with PKI Figure 11 shows the options for TLS with PKI configuration Figure 12 follows with a view of the Permanent Certificate Manager the User Certificate Manager operates in a similar manner Figure 11 Intel AMT TLS with PKI Provisioning Options Figure 12 Intel AMT Permanent Certificate Manager ...

Page 17: ...mote Configuration TLS with PSK For TLS with PSK the options are shown in Figure 13 The Provisioning Identifier PID is an eight character string formatted as two quartets separated by a dash Figure 13 Intel AMT TLS with PSK Provisioning Identifier PID Figure 14 Intel AMT TLS with PSK Provisioning Passphrase PPS ...

Page 18: ... and Domain Name in the Local Setup and Configuration screen previously known as SMB Small Medium Business Mode The user can also choose to share the Management Engine s FQDN with the operating system IPV6 does not allow FQDN sharing if DDNS is enabled allow dynamic updates to the DNS Domain Name System and configure the IPV4 or IPV6 TCP IP protocols Default is set to IPV4 with DHCP enabled Figure...

Page 19: ...Board DQ67SW DQ67EP DQ67OW Intel vPro Technology Setup and Configuration Guide 19 Figure 16 Intel AMT Local Configuration IPV4 Configuration Options Figure 17 Intel AMT Local Configuration IPV6 Configuration Options ...

Page 20: ... 18 KVM Remote Control Keyboard Video Mouse Configuration in Figure 19 and PRTC Protected Real Time Clock Figure 18 Intel AMT SOL IDE R Configuration The Redirection Mode setting under SOL IDE R as highlighted in Figure 18 is to allow the use of remote consoles designed for legacy platforms Intel AMT 5 0 and earlier These require specific port initialization commands whenever performing redirectio...

Page 21: ... include enabling and disabling the KVM Remote Control feature but also include the ability to set the level of user controlled security The user can choose to allow KVM Remote Control usage with or without user intervention and to allow a remote user such as IT personnel to set this policy These features provide greater flexibility to allow platform maintenance to be performed after hours when no...

Page 22: ...Mode the user needs to Enter Intel ME in BIOS Setup Under Intel AMT Configuration set the Setup and Configuration Mode to Local Under Local Setup and Configuration enter a Computer Name as shown in Figure 20 As the platform is already set for IPV4 and DHCP as defaults no other settings are necessary F10 Save and Exit will finish the Local Setup and Configuration process Once the platform reaches t...

Page 23: ...etup and Configuration Guide 23 Figure 21 and Figure 22 show the results of the MEINFO utility before and after Local Configuration Figure 21 MEINFO Output Intel AMT Defaults Figure 22 MEINFO Output Local Configuration The platform is now ready for remote management ...

Page 24: ...ning is known as One Touch Configuration Note The SCS is also the source of the PSK PID and PSK PPS keys shown in Section 1 1 5 2 1 2 Details of how to use this and other Remote Configuration methods can be found in the documentation of your SCS or management application and are beyond the scope of this document The results of Intel Desktop Boards DQ67SW DQ67EP or DQ67OW encountering a USB flash d...

Page 25: ...lication that is capable of initiating Host Based Configuration Once configured the client is considered to be in Client Control Mode which restricts certain Intel AMT features such as disabling the System Defense filters and forcing User Consent for redirection activities like KVM Remote Control and IDE r 1 6 Fast Call for Help FCFH Fast Call for Help or FCFH requires no configuration out of the ...

Page 26: ...Intel Desktop Board DQ67SW DQ67EP DQ67OW Intel vPro Technology Setup and Configuration Guide 26 Figure 25 Fast Call for Help Alert Screen ...

Page 27: ...r the purposes of this guide the Intel AMT client system is provisioned in Local SMB mode If using VNC Viewer as the remote management console the user enters the IP address of the client as shown in Figure 26 For Authentication use the Intel AMT administrator password On the client system a six digit access code will appear Figure 27 This is used in the VNC Viewer console to gain access Figure 28...

Page 28: ...Intel Desktop Board DQ67SW DQ67EP DQ67OW Intel vPro Technology Setup and Configuration Guide 28 Figure 28 VNC Viewer Management Console Access Code Screen Figure 29 VNC Viewer Management Console View ...

Page 29: ...security agent such as VASCO DIGIPASS for Web or Symantec VIP Access running on the client system For Intel Desktop Board DQ67SW DQ67EP and DQ67OW BIOS versions 0052 and later contain the proper ME firmware The Intel IPT software stack and the latest system BIOS can be obtained from the Intel Download Center The security agent can be found at the respective 3rd party websites See Section 2 for lin...

Page 30: ...g the Intel ME administrator password is to enter BIOS Maintenance Mode This is done by moving the BIOS_CFG jumper from the Normal to the Config position and powering on the board see Figure 35 for location From the BIOS Maintenance screen select Reset Intel AMT to default factory settings as displayed in Figure 32 and press Y Figure 32 BIOS Maintenance Intel AMT Reset to Defaults ...

Page 31: ...is shown Once finished the user will receive the notification shown in Figure 34 The user must then save and exit BIOS Setup power off the system and restore the BIOS_CFG jumper back to the Normal position These steps are necessary for proper reset of Intel AMT Figure 33 Intel AMT Reset in Progress Figure 34 Intel AMT Reset Complete ...

Page 32: ...ting pins 1 and 2 of the MEBX_RST header It is imperative that the jumper is removed before power is reapplied to the board Failure to do so may cause damage to the board and or its firmware Caution Do not apply board power with a jumper in place on pins 1 and 2 on the MEBX_RST header Doing so may cause damage to the board and or its firmware The BIOS_CFG and MEBX_RST headers are shown in Figure 3...

Page 33: ...m en us articles intel virtualization technology for directed io vt d enhancing intel platforms for efficient virtualization of io devices for more on Intel VT d http www intel com technology xdbit index htm iid tech_vpro_body_edb for more information on the Execute Disable Bit http software intel com en us articles fast call for help overview wapkw fast call for help for more information on Fast ...

Reviews: