ThinkCentreM91p
IntelActiveManagementTechnology
CongurationGuide
ThinkCentreM91p
IntelActiveManagementTechnology
CongurationGuide
Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixC
“Notices”onpage27.
FirstEdition(March2011)
©CopyrightLenovo2011.
LENOVOproducts,data,computersoftware,andserviceshavebeendevelopedexclusivelyatprivateexpenseandare
soldtogovernmentalentitiesascommercialitemsasdenedby48C.F.R.2.101withlimitedandrestrictedrightsto
use,reproductionanddisclosure.
LIMITEDANDRESTRICTEDRIGHTSNOTICE:Ifproducts,data,computersoftware,orservicesaredeliveredpursuant
aGeneralServicesAdministration“GSA”contract,use,reproduction,ordisclosureissubjecttorestrictionssetforth
inContractNo.GS-35F-05925.
Contents
Aboutthisdocument.........v
Chapter1.IntroductiontoIntelvPro
andIntelAMT.............1
Acronyms................1
Chapter2.Featuresandbenetsof
IntelAMT...............3
Featuresandbenets............3
Chapter3.Mainfeaturesof
computersbuiltwithIntelAMT....5
CIRA..................5
KVMredirection..............6
HostBasedProvisioning...........6
Chapter4.IntelAMTsetupand
congurationonLenovoThinkCentre
M91pdesktopcomputers......7
IntelAMTcongurationsettingsinSetupUtility..7
IntelMEBxsetupandconguration......8
EnteringtheMEBxcongurationuser
interface...............8
Intel(R)MEGeneralSettings.......8
Intel(R)AMTConguration........11
Driverdescription.............19
MEI.................19
LMS.................20
SOL.................20
Chapter5.Webuserinterface....21
AccessingtheWebuserinterface.......21
ConguringtheIntelAMTcomputer....21
Loggingontotheclient.........22
FunctionsintheWebuserinterface......22
AppendixA.Examplesofconguring
IntelAMTinmanualandautomatic
setupandcongurationmodes...23
ConguringIntelAMTinmanualsetupand
congurationmode.............23
ConguringIntelAMTinautomaticsetupand
congurationmode.............23
ZTCprovisioning............23
USBprovisioning............24
AppendixB.Factorydefaultsettings
fortheIntelMEBx...........25
AppendixC.Notices.........27
Trademarks................28
©CopyrightLenovo2011
iii
ivThinkCentreM91pIntelActiveManagementT echnologyCongurationGuide
Aboutthisdocument
ThisdocumentprovidesinformationaboutIntel
®
ActiveManagementT echnology(IntelAMT)forLenovo
ThinkCentre®M91pdesktopcomputers.Thisdocumentprovidesstep-by-stepinstructionsonhowtouse
IntelAMT .
ThisdocumentisintendedfortrainedITprofessionalsorthoseresponsibleforconguringcomputers
throughouttheirorganizations.Thereadersshouldhavebasicknowledgeofnetworkandcomputer
technology,andbefamiliarwiththetermsTCP/IP,DHCP ,IDE,DNS,SubnetMask,DefaultGateway,Domain
Name,andsoon.
Thisdocumentprovidesinformationaboutthefollowingtopics:
Chapter1“IntroductiontoIntelvProandIntelAMT”onpage1:Thischapterprovidesageneralintroduction
toIntelvPro
™
andIntelAMT.
Chapter2“FeaturesandbenetsofIntelAMT”onpage3:Thischapterintroducesthefeaturesand
benetsofIntelAMT.
Chapter3“MainfeaturesofcomputersbuiltwithIntelAMT”onpage5:Thischapterintroducesthemain
featuresofIntelAMTbuilt-incomputers.
Chapter4“IntelAMTsetupandcongurationonLenovoThinkCentreM91pdesktopcomputers”on
page7:ThischapterprovidesdetailedinstructionsonhowtocongureIntelAMTsettingsonLenovo
ThinkCentreM91pdesktopcomputers.
Chapter5“Webuserinterface”onpage21:Thischapterprovidesinstructionsonhowtoaccessthe
IntelAMTWebuserinterface.
®
©CopyrightLenovo2011
v
viThinkCentreM91pIntelActiveManagementT echnologyCongurationGuide
Chapter1.IntroductiontoIntelvProandIntelAMT
IntelvProisabusinesscomputerplatformthatprovidesbusinesscomputerswithenhancedremote
managementcapabilities.ForcomputersbuiltwithIntelvPro,ITadministratorscanuseathirdpartysoftware
toremotelycollectinventoryinformation,diagnoseproblems,andprovidevariousservicesregardlessof
thecomputerpowerstateortheoperatingsystemstate.ITadministratorscanalsoisolateandprotect
individualcomputersandthenetworkfromthreats.
AsafeatureofIntelvPro,IntelAMTisdesignedtoprovideremotemanagementofcomputersregardless
ofthecomputerpowerstateortheoperatingsystemstateaslongasthecomputersareconnectedtoan
electricaloutletandanetwork.
IntelAMTisdesignedasabuildingblockandnotacompletesolution.ThisenablesOriginalEquipment
Manufacturers(OEMs)toincorporateIntelAMTintotheirclientandserverhardwareplatforms.Competent
andauthorizedthirdpartyapplicationsprovidemanagementandsecurityservicesthattakeadvantageof
theIntelAMTfeatures,suchasout-of-bandaccesstoassetinformation,eventlogs,hardwareandsoftware
tables,andembeddedcapabilities.
Acronyms
Thefollowingtablelistsandexplainssomeacronymsusedinthisdocument.
AcronymDescription
ACLAccessControlList
AMTActiveManagementTechnology
ASFAlertStandardFormat
BIOSBasicInputOutputSystem
CIRAClientInitiatedRemoteAccess
DHCPDynamicHostCongurationProtocol
DNSDomainNameServer
FQDNFullyQualiedDomainName
FWFirmware
HBPHostBasedProvisioning
HECIHostEmbeddedControllerInterface
IDE-RIntegratedDeviceElectronics-Redirection
IPInternetProtocol
ISVIndependentSoftwareVendor
KVMKeyboard-Video-Mouse
LMSLocalManageabilityService
MEManagementEngine
MEBx
MEI
NVMNonvolatilememory
OEMOriginalEquipmentManufacturer
ManagementEngineBIOSExtension
ManagementEngineInterface
©CopyrightLenovo2011
1
AcronymDescription
OOBOut-of-band
PID/PPS
PKI
PRTCProtectedRealTimeClock
PSK
PXEPrebootExecutionEnvironment
RCFGRemoteConguration
SHASecureHashAlgorithm
SMBSmallandMediumBusinesses
SOLSerial-over-LAN
TCPTransmissionControlProtocol
TLSTransportLayerSecurity
WOL
ZTCZeroTouchConguration
ProvisioningIDandProvisioningPre-sharedKey
PublicKeyInfrastructure
Pre-sharedKey
WakeonLan
2ThinkCentreM91pIntelActiveManagementT echnologyCongurationGuide
Chapter2.FeaturesandbenetsofIntelAMT
ThischapterintroducesthefeaturesandbenetsofIntelAMT.
ThefollowingtableliststheLenovobusinesscomputerswithIntelAMTinstalled.
LenovocomputerIntelAMTversion
ThinkCentreM91p
ThinkCentreM90p
ThinkCentreM58p
ThinkCentreM57p
ThinkCentreM55p
Featuresandbenets
ThinkCentreM91pcomputersbuiltwithIntelAMTenableITadministratorstobetterdiscover,heal,and
protectthenetworkedcomputingassets.
•Discover:IntelAMTstoreshardwareandsoftwareinformationinnonvolatilememory(NVM).Withbuilt-in
manageability,IntelAMTenablesITadministratorstodiscoverassetsremotely,evenwhencomputersare
turnedoff.
•Heal:Thebuilt-inmanageabilityofIntelAMTprovidesout-of-band(OOB)managementcapabilities,which
enableITadministratorstoremotelydiagnosecomputerproblemsandrecovercomputersevenifthe
operatingsystemsareinoperable.ProactivealertingandeventlogginghelpITadministratorsdetect
problemsquicklytoreducecomputerdowntime.
•Protect:TheIntelAMTsystemdefensefeatureenablesbetterprotectionforcomputersbyproactively
blockingincomingthreats,controllinginfectedcomputersbeforethecomputerscauseproblemsinthe
network,andalertingITadministratorswhencriticalsoftwareagentsareremovedfromthecomputers.
IntelAMT7.X
IntelAMT6.X
IntelAMT5.X
IntelAMT3.X
IntelAMT2.X
ThefollowingtableshowsthefeaturesandbenetsofIntelAMT.
Table1.FeaturesandbenetsofIntelAMT
FeaturesBenets
OOBsystemaccess
Remotetroubleshootingandrecovery
ProactivealertingDecreasescomputerdowntimeandminimizesITservice
RemotehardwareassettrackingIncreasesspeedandaccuracywithreducedaccounting
©CopyrightLenovo2011
Enablesremotemanagementofclientsregardlessof
clientpowerstateandoperatingsystemstate
SignicantlyreducesIThelpdeskvisitsandincreasesIT
serviceefciency
time
costs,comparedwithmanualinventorytracking
3
4ThinkCentreM91pIntelActiveManagementT echnologyCongurationGuide