McAfee FIREWALL 2.1-GETTING STARTED Podręcznik Użytkownika Strona 1

Przeglądaj online lub pobierz Podręcznik Użytkownika dla Zapory sprzętowe McAfee FIREWALL 2.1-GETTING STARTED. McAfee FIREWALL 2.1-GETTING STARTED Product guide Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - McAfee ePO Deep Command 2.1.0

Product GuideMcAfee ePO Deep Command 2.1.0For use with ePolicy Orchestrator 4.6.x, 5.x.x Software

Strona 2 - License Agreement

• Intel® AMT-enabled chipset• Network hardware and software• Corporate network connection (with an AC power source)Setting up the environment requires

Strona 3 - Contents

• From the Intel® AMT systems, click McAfee Agent Status Monitor, then click Collect and Send Properties,Check New Policies, and Enforce Policies.• Cl

Strona 4

7In the System Tree, assign the policy to the required systems or group.• To assign the policy to selected systems, select the systems, click Actions

Strona 5 - A Additional information 145

4In Run the following Command afterward (optional), select the product, task type, and client tasks.Client tasks that require a system restart must be

Strona 6 - Index 165

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Policy Comparison, select ePO Deep Command 2.1.0 or ePO

Strona 7

cType the Intel® MEBX password, then retype it to confirm.Select Show Password to see the password as you type. Password confirmation is not required

Strona 8 - Product features

• For Kerberos account,1Select New Kerberos User or New Kerberos Group, as needed, select the required user or group,then click OK.2Select the user or

Strona 9 - Intel AMT overview

Tasks• Turn on your systems on page 106The Power On feature allows your Intel® AMT systems to deploy the updated securityprograms ahead of a potential

Strona 10 - Product components

Obtain User ConsentObtain User Consent to perform Intel® AMT actions using a passcode generated on the Intel® AMTsystem screen to connect.TaskFor opti

Strona 11 - Management Framework module

4(Optional) In Additional Action, select Launch Serial-over-LAN Terminal (SOL) to access the target system fromthe server side.You can use the arrow k

Strona 12 - McAfee KVM Viewer module

Connect to a system using the Serial-over-LANSerial-over-LAN (SOL) is a mechanism that enables the input and output of the serial COM port of amanaged

Strona 13 - Getting started

Management Framework moduleThe ePO Deep Command Management Framework module delivers "beyond-the-operating system"security management. This

Strona 14 - High-level architecture

• The recovery operating system image file must be an .iso file shared on a UNC mount.It must be shared and accessible by the Agent Handler. Also, mak

Strona 15 - Introduction

See also Connect to a system using the Serial-over-LAN on page 109McAfee KVM Viewer options on page 127Stop image redirection You can stop an in-progr

Strona 16

Automate Intel AMT policy enforcementCreate and use the server tasks to enforce Intel® AMT policies and turn on the remote Intel® AMTsystems at a sche

Strona 17 - Installation

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, from Server Tasks, click New Task.2In Description, type a name for th

Strona 18 - Requirements

• Renew Active Directory Password — Resets the password of the Active Directory object representing theIntel® AMT system.• Renew Administrative Passwo

Strona 19 - Software requirements

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Client Task Comparison, select ePO Deep Command 2.1.0 as

Strona 20 - AMT versions

Name ID Generates when...ConfigurationeventsDeep Command - ConfigureFailure34362 A configuration attempt has failed.Deep Command - UnconfigureFailure3

Strona 21 - Required ports

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Configuration | Server Settings, select Event Filtering,

Strona 22 - RCS server

File name Location DescriptionAMTRCSMgmtService_out.log..\Program Files\McAfee\ePO Deep Command RCSManager\AMTRCSMgmtService_out.logProvides a log of

Strona 23

9Connecting to Intel AMT systems usingKVMWith the McAfee KVM Viewer, you can remotely access Intel® AMT systems using theKeyboard-Video-Mouse (KVM) fe

Strona 24 - Install the software

McAfee KVM Viewer moduleAdministrators can use the McAfee KVM Viewer module to remotely access Intel® AMT systems that areKVM-enabled and -supported.

Strona 25 - Assign the AMT tag to systems

KVM Viewer overviewUse the McAfee KVM Viewer to remotely access your Intel® AMT systems and perform actions such asPower on, shutdown, start or restar

Strona 26

KVM requirementsMake sure that your system meets these requirements to connect to a system from McAfee KVMViewer.System RequirementsKVM host system (f

Strona 27

Add McAfee root CA certificateImport the McAfee ePO Deep Command root CA certificate to the KVM host system to authenticate aKVM connection. This task

Strona 28 - Configure user permissions

Use Microsoft Management ConsoleAdd the McAfee ePO Deep Command Root CA certificates, when used, to the certificate store of thesystem where you'

Strona 29

Task1From the KVM host system, browse to the folder where McAfee KVM Viewer is stored, thendouble-click the MKVMView file.2On the McAfee KVM Viewer Co

Strona 30 - Manage certificates

• Authentication settings — Provide credentials used in the configuration profile policy or under Intel®AMT credentials in Server Settings. Or select

Strona 31 - Uninstall the software

Connect to a local systemConnect to a local Intel® AMT system to send power control commands to the client.Task1From the KVM host system, browse to th

Strona 32

TaskFor option definitions, click ? in the interface.1From the McAfee KVM Viewer screen, click Connection | Stop.The current active session is stopped

Strona 33

Option Suboption DescriptionWireless LinkPreferenceAllows selecting the link preference for a session connected over awireless connection. For a syste

Strona 34

10TroubleshootingError messages are displayed by programs when an unexpected condition occurs that can't be fixed bythe program itself. Use this

Strona 35

Getting startedBefore using ePO Deep Command, make sure that you have specific software, hardware, and networkconfigurations in place.Setting up your

Strona 36

Issue Description Corrective actionExit code 32 A certificate request has beensent to the CertificationAuthority but the createdcertificate has put it

Strona 37 - User consent requirement

Issue Description Corrective actionConfiguration/unconfiguration taskfails with this error inServer Task Log:Intel® AMTunconfiguration failed.Initial

Strona 38 - Remote configuration

Issue Description Corrective actionHTTP 401 inAMTservice.logThis issue occurs when theserver is not able toauthenticate and connect tothe Intel® AMT s

Strona 39

Issue Description Corrective actionSocket Error — Redirectionport is not enabled on the Intel®AMT System. This error alsooccurs when a certificate ora

Strona 40 - User authentication

IDE-RedirectionIssue Description Corrective actionIDE-Redirectionsession does notinitiatesThis issue might occur due tovarious reasons.Perform these c

Strona 41 - Certificates for TLS

Remote Access using the Gateway serverIssue Description Corrective actionRemote Accessconnection fails with"Unknown CA" error inthe Stunnel

Strona 42 - Configuration states

WirelessIssue Description Corrective actionIDE-Redirection over a wirelessconnection fails with this error:Boot disk missing, please insert boot disk

Strona 43 - Configuring Intel AMT systems

Issue Description Corrective actionIntel® AMT policy enforcementfails with errors similar tothese errors in AMTservice.log:•Failed to convert time of

Strona 44 - Schedule LDAP synchronization

Issue Description Corrective actionRemote Access request usingGet Technical Help in the Intel®Management and SecurityStatus tool fails with an errorst

Strona 45

Issue Description Corrective actionAlarm Clock policy doesn'tenforceThis issue might occur dueto various reasons.Perform these checks, then perfo

Strona 46

Architecture and how components communicateePO Deep Command is comprised of multiple modules, which help you identify, manage, configure,and troublesh

Strona 47

Issue Description Corrective actionSome AMT commands notwork when selected fromAutomatic Response | New Response| Actions | Run System CommandSome of

Strona 48 - Set Intel AMT credentials

11Frequently asked questions Here are answers to frequently asked questions.Power on and Normal boot or restartWhat happens if a normal boot or restar

Strona 49

• Client Tasks are enabled.• Appropriate managed products are installed on the Intel® AMT system.• Intel® AMT system is able to communicate with the A

Strona 50 - Perform remote configuration

• Intel® Management and Security Status (IMSS)• ACUconfig status or SystemDiscoveryPropertiesWhen does the Last Power On Time parameter get updated on

Strona 51 - SCS 8.2 documentation

3Locate and select the Unconfigure Network Access option.A warning message states that the configuration is reset to the default values appears.4Press

Strona 52 - If the Intel

AAdditional informationSee these topics for more information that you may require to set up or manage ePO Deep Command.Contents Create a configurat

Strona 53

4If using Digest authentication, skip to the next step. Otherwise, in the Active Directory Integration page,click ... next to Active Directory OU and

Strona 54 - If a configured Intel

6On the Transport Layer Security (TLS) page, select Request certificate via CA plugin to configure the profile thatrecognizes McAfee ePO Deep Command

Strona 55 - Identify unconfigured systems

7On the Network Configuration page, perform these steps to set up wireless connections, then click Next.aSelect Allow WiFi connection with the followi

Strona 56 - Clear the AMT tag

•IDE redirection•KVM redirectionbIn Power Management Settings, select Always on (S0-S5).cIn Network Settings, type the password for locally accessing

Strona 57

Step Details1 Discovery and Reporting plug-in is installed on McAfee ePO, then deployed to client systems.This plug-in detects the Intel® AMT systems

Strona 58

Set up the environment for Microsoft CA authenticationTo use certificates generated by Microsoft CA, perform these tasks in addition to the other mand

Strona 59

Import certificates to serverIn an environment where McAfee ePO is deployed across different domains, import Microsoft CAcertificates to the system wh

Strona 60 - Configure Stunnel

Task1On the Certificate Authority server, click Start | Programs | Administrative Tools | Certification Authority.2From the Console Root tree, right-c

Strona 61 - Validate certificate

3Right-click the Certificate Templates and select Manage.4In the right-pane, right-click the Computer template and select Duplicate Template to open t

Strona 62

Enable the certificate template Enable the certificate template that you created for Intel® AMT configuration.Task1In the Certificate Authority server

Strona 63 - Enabling Intel AMT wireless

Task1From the Intel® SCS Console, click the icon to create a profile and to open the Configuration Profilewizard.2In Profile Description, enter a uniq

Strona 64 - Wireless profiles

cIn Network Settings, type Intel® ME BIOS Extension (MEBX) password for locally accessing theMEBX settings (default is admin on a new system).If you w

Strona 65

6Select Include all certificates in the certification path.7Type a password, then save the file as with .pfx extension.For example, test.pfx.8Run thes

Strona 66

TaskFor option definitions, click ? in the interface.1Click Start | Administrative Tools, then click Server Manager.2Expand Configuration, right-click

Strona 67 - Validate wireless settings

Modify DCOM permissions to add domain computers The configuration process requires appropriate DCOM permissions for domain computers in the serverwher

Strona 68

1IntroductionGetting started16McAfee ePO Deep Command 2.1.0 Product Guide

Strona 69 - Queries and reports

cAdd Domain Computers if it's not listed, then allow these permissions for the Domain Computers group.•Full Control•Read•Special Permission8Close

Strona 70 - Integrated Graphics

Intel® AMT action logsHere is the information about the feature-wise list of log entries created as a result of Intel® AMTactions.Table A-1 Server Ta

Strona 71 - View default queries

Table A-2 Audit Log entries (continued)Feature Audit Log entry DescriptionNormal Boot/Restart Initiated Normal Boot/Reboot Displays when Normal Boot/

Strona 72 - Custom query filters

IP address" print "Provide help as the first parameter to get more information"else: if input == "help" or input == &qu

Strona 73

try: print "Error in doing OOB Policy Enforcement on as the command failed to invoke properly due to the following err

Strona 74

IndexAactionsAMT policies, enforcing 111boot/reboot to BIOS 107configuration policy, enforcing 111IDE-redirection 109image redirection, stopping 111no

Strona 75 - Dashboards and monitors

Ffrequently asked questions 141Hhost-based configurationauthentication 38client control mode 36move to admin control 95overview 36policy 49, 94user co

Strona 76

Sserver tasksAMT policies, enforcing 112AMT tag, assigning 25power on 112Tthird-party CAauthentication, setting up 150certificate chain, creating 151c

Strona 78 - Integrated Graphics

2InstallationPerform a series of tasks to set up your ePO Deep Command software.1Make sure that your system meets the requirements.2Install the ePO De

Strona 79

RequirementsVerify that your system meets these requirements before you start the installation process.System requirements Systems RequirementsMcAfee

Strona 80 - Management Summary dashboard

Software requirements Make sure that you have the required software installed for the ePO Deep Command module thatyou're installing.Software Requ

Strona 81 - Readiness Summary dashboard

COPYRIGHTCopyright © 2014 McAfee, Inc. Do not copy without permission.TRADEMARK ATTRIBUTIONSMcAfee, the McAfee logo, McAfee Active Protection, McAfee

Strona 82 - Benefits Summary dashboard

Upgrade requirements You can upgrade to ePO Deep Command 2.1.0 from the software version 2.0.0.Supported Intel® AMT versionsSome features aren't

Strona 83

Required portsMake sure that your network security software doesn't block ports and services that are needed forIntel® AMT communications.Add the

Strona 84

Services installed on managed Intel® AMT systemsService/process Feature Ports DescriptionAMTMgmtService.exe Remoteconfiguration135 This process config

Strona 85

ePO Deep Command components in Software ManagerHere are the components that you see in Software Manager, when you select ePO Deep Command fromthe prod

Strona 86

Install the softwareInstall the extensions and deploy them to manage your Intel® AMT systems.Tasks• Install or upgrade the ePO Deep Command extensions

Strona 87

Deploy the Discovery and Reporting plug-inDeploy the Discovery and Reporting plug-in to Intel® AMT systems.Before you beginMake sure that the plug-in

Strona 88

Deploy the Management Framework clientDeploy the Management Framework client to your Intel® AMT systems to manage them using Intel®AMT actions, polici

Strona 89

3In Trusted Root Certificates, a pre-activated McAfee ePO Deep Command Root CA (CN=McAfee ePO DeepCommand Root <Date and time>) is listed. If yo

Strona 90

5In Credentials for Intel® AMT actions, select Change credentials, then select Use above credentials, or type the username and password. Use domain\us

Strona 91

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | User Management | Permission Sets.2Select the permission

Strona 92

Contents1 Introduction 7Product features ... 7Intel AMT overview ... 9Product components

Strona 93

Manage certificatesUse certificate management options to export a ePO Deep Command root CA certificate for reuse,import it, or regenerate it with the

Strona 94

3For Trusted Root Certificate, click Generate New Certificate.A new entry is added for McAfee ePO Deep Command Root in Trusted Root Certificates.4Sele

Strona 95

Uninstall the ePO Deep Command clientCreate a client task to remove the client from Intel® AMT systems, then assign it to the systems.TaskFor option d

Strona 96 - Create an Alarm Clock policy

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Software | Software Manager.2On the Software Manager pag

Strona 97 - Create a Local Access policy

2InstallationUninstall the software34McAfee ePO Deep Command 2.1.0 Product Guide

Strona 98

3Basics of Intel AMT configurationYou must configure your Intel® AMT systems before you can manage them using ePO Deep Command.You can configure your

Strona 99

Host-based configurationIn this method Intel® AMT systems are configured locally using an XML profile containing the requiredconfiguration settings.Th

Strona 100 - Create a KVM policy

Client Control mode network architectureThis illustration is an overview of a network configuration where your Intel® AMT systems supportClient Contro

Strona 101

Host-based configuration authenticationFor host-based configuration, provide credentials for Intel® AMT configuration and use McAfee ePODeep Command R

Strona 102 - Log files and services

Admin Control mode network architectureThis illustration is an overview of a network configuration where your Intel® AMT systems supportAdmin Control

Strona 103

4 Configuring Intel AMT systems 43Synchronize with Windows Active Directory ... 43Register Windows Active Directory server ...

Strona 104

How RCS Manager plug-in worksThe RCS Manager plug-in helps you manage the configuration of your Intel® AMT firmware, throughMcAfee ePO.This diagram il

Strona 105 - Use the Intel AMT actions

Certificates for TLSYou can use the Transport Layer Security (TLS) protocol to secure and authenticate communicationsacross your network.Intel® AMT us

Strona 106 - Turn on your systems

Configuration statesePO Deep Command adds a system property to determine the configuration status of Intel® AMTsystems.• Pre-configuration — By defaul

Strona 107 - Boot or restart to BIOS

4Configuring Intel AMT systemsYou can configure an Intel® AMT system using host-based configuration or remote configuration.• Host-based configuration

Strona 108

3On the Details page, complete these options.aSelect Active Directory from LDAP server type, then type the DNS-style domain name or IP address ofthe s

Strona 109

Tasks• Import a configuration profile template on page 45Import a configuration profile that you created in the Intel® RCS console or by usingACUWizar

Strona 110

TaskCreate policies based on the default policies such as McAfee Default or My Default. The default policiesprovide templates where you can add the da

Strona 111 - Enforce Intel AMT policies

fIn AMT User accounts and rights, perform one of these steps:• For Digest account, click New Digest User, type user name, type password, retype passwo

Strona 112 - Schedule out-of-band power on

• IP address — Select the source for the IP address settings:• DHCP — from the DHCP server.• Static — the same IP address as the host.• FQDN — Select

Strona 113 - Maintenance tasks

4In Credentials for Intel® AMT actions, do one of these:• Use the default ePO_Admin account — Select Use above credentials, then select Show password

Strona 114 - Compare maintenance tasks

Create the Intel AMT configuration policies ... 94Create the Intel AMT policies ...96Creating the Client Task

Strona 115 - Managing events and logs

Perform remote configurationInstall and configure the RCS Manager plug-in to manage the Intel® AMT firmware configuration fromMcAfee ePO.Before you be

Strona 116 - Filter events

• Intel® AMT systems must not be in a virtual private network (VPN) environment. Home domains ofMcAfee ePO and Intel® AMT systems differ in VPN enviro

Strona 117

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Software | Software Manager.2On the Software Manager pag

Strona 118

Configure Intel AMT systems using remote configuration policyCreate and enforce a remote configuration policy and select the Intel® RCS server and con

Strona 119

See also Create a policy to configure Intel AMT systems on page 94Enforce Intel AMT configuration policy on page 111Test your connection to an Intel A

Strona 120 - KVM Viewer overview

Unconfigure Intel® AMT systems using policyYou can unconfigure your Intel® AMT systems using the Intel® AMT configuration policy.TaskFor option defini

Strona 121 - Set up the client for KVM

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Reporting | Queries & Reports, then select ePO Deep

Strona 122

5Setting up your environment for RemoteAccessThe McAfee ePO Deep Command Gateway server acts as a proxy responsible for mediatingcommunication between

Strona 123

Remote Access depends on these components:• McAfee ePO• Intel® AMT systems configured for remote connectivity. (In some environments, these systems ar

Strona 124

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Software | Software Manager.2On the Software Manager pag

Strona 125 - McAfee KVM Viewer settings

Create a configuration profile that uses Microsoft CA certificates ... 154Generate certificates for Stunnel using Microsoft CA ...

Strona 126 - Connect to a remote system

5Copy the files to the Stunnel installation directory. For example, C:\Program Files(x86)\stunnel.You can also rename these files:• CN_McAfee_ePO_Deep

Strona 127 - McAfee KVM Viewer options

2In cert, key, and CAfile, replace the file names and location for cira.pem, cira.key, and ca.cerrespectively with the actual values.3In ciraamt, use

Strona 128

5Setting up your environment for Remote AccessValidate certificate62McAfee ePO Deep Command 2.1.0 Product Guide

Strona 129 - Troubleshooting

6Enabling Intel AMT wirelessmanageabilityWith Intel® AMT over a wireless connection, you can perform Intel® AMT actions on systems within theenterpris

Strona 130

Prerequisites for using wireless with ePO Deep CommandConsider these guidelines while performing Intel® AMT actions on the wireless clients.• Intel® A

Strona 131 - AMT actions

An Intel® AMT wireless profile might not be updated when:• A profile with similar "SSID" is present on the system.• The system is configured

Strona 132 - Serial-over-LAN

4On the Optional Settings page, select Network Configuration, select WiFi Connection, then click Next.5On the Network Configuration page, perform thes

Strona 133

bComplete these settings, then click OK.• Setup Name — Type a name for the Wi-Fi setup (up to 32 characters, and must not contain (/ \< >: ; * |

Strona 134 - IDE-Redirection

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, navigate to System Tree and open the system details of the wirelesscl

Strona 135 - McAfee KVM Viewer

7Reporting on your Intel AMT systems With the ePO Deep Command Discovery and Reporting software, you can quickly determine the statusof the Intel® AMT

Strona 136 - General issues

1IntroductionMcAfee ePO Deep Command provides centralized control to your Intel® Active Management Technology(AMT) systems regardless of whether they

Strona 137

Query DescriptionIntel® AMT ConfigurationStateDisplays a pie-chart of different Intel® AMT configuration states for alldetected systems supporting Int

Strona 138

Predefined RCS management queriesWhen the Profile Manager software is installed on McAfee ePO, these predefined queries are added tothe ePO Deep Comma

Strona 139

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, click Menu | Reporting | Queries & Reports.2From the Groups pane,

Strona 140

Group Filter Filters the results based on...BIOS Release DateThe release date of the BIOS running on Intel® AMTsystems.BIOS VersionThe version number

Strona 141 - Frequently asked questions

Group Filter Filters the results based on...KVMWhether the KVM (Keyboard, Video and Mouse switch)feature is supported on Intel® AMT systems.Last Error

Strona 142 - AMT console

Group Filter Filters the results based on...Wired Link StatusWhether Intel® AMT systems' physical networkconnection is functioning.Wired MAC Addr

Strona 143 - Configure or unconfigure

• CILA Supported — Determines the number of managed systems that support Local Access connectionsout of the total number of managed systems. The admin

Strona 144

• Intel® AMT Configuration Mode — Determines the different configuration modes that are present in thetotal number of managed systems. Because ePO Dee

Strona 145 - Additional information

• Intel® AMT Version — Displays the different versions of Intel® AMT hardware present on the managedsystems. Because ePO Deep Command supports specifi

Strona 146

• SOL Supported and Enabled — Displays the number of managed systems that support SOL connectionsout of the total number of managed systems. This moni

Strona 147

Feature DescriptionIntel® AMT firmwareconfigurationUse ePO Deep Command to perform host-based configuration or remoteconfiguration on your Intel® AMT

Strona 148 - AMT systems. However, the

Management Summary dashboardThe Management Summary dashboard displays a collection of monitors based on the results of the defaultePO Deep Command Fra

Strona 149

• Intel® AMT Configuration Events by Event type — Displays a pie chart representing the number ofconfiguration events for all detected Intel® AMT syst

Strona 150

• Ready for Host Based Configuration — Displays a pie-chart representing the number of Intel® AMT systemsthat meet and that do not meet the host-based

Strona 151 - Create a certificate chain

• Troubleshoot Remote Devices (KVM) — Displays a pie-chart representing the number of Intel® AMT systemsthat can be accessed using McAfee KVM to troub

Strona 152

• Quick reset of pre-boot password on McAfee encrypted devices — Displays a pie-chart representing the numberof Intel® AMT systems that can reset thei

Strona 153

• Wake-up devices for security scans and updates — Displays a pie-chart representing the number of Intel® AMTsystems that can automatically update the

Strona 154

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemCILAReports whether the Client-Initiated Local Acce

Strona 155

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemConfigurationStateReports the configuration state f

Strona 156

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemIntel® MEIVersionReports the version number of the

Strona 157 - Validate permissions

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemLast IDE-RSession StatusReports whether the status

Strona 158

Feature DescriptionMaintenance tasks Configure these maintenance tasks:• Synchronize Intel® AMT time • Renew Active Directorypassword• Synchronize net

Strona 159

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemReported LocalAlarm ClockTimeDisplays the alarm clo

Strona 160

Property Description WithIntel®MEIdriverinstalledWithoutIntel®MEIdriverinstalledNon-Intel®AMTSystemWireless IPv4AddressReports the IPv4 address receiv

Strona 161 - AMT action logs

Option DefinitionHost-Based ConfigurationWhether host-based configuration is supported on the client: Supported orNot Supported.Is Embedded HBC Enable

Strona 162 - Download the python client

8Managing your Intel AMT systems Manage the Intel® AMT systems in your network by using Intel® AMT policies, client task executionpolicies, Intel® AMT

Strona 163

Create the Intel AMT configuration policies Use the AMT Configuration Policies category to create policies to configure or unconfigure your Intel® AMT

Strona 164

3Select Allow ePO to enforce these settings, then perform one of these steps based on configuration modeof systems.• Admin Control mode — Select Remot

Strona 165

Create the Intel AMT policiesUse the AMT Policies category to create a policy to turn on your Intel® AMT systems, configure LocalAccess or Remote Acce

Strona 166

5Select Repeat Every to specify the days, hours, and minutes to turn on your systems at regularintervals, then save the policy.6In the System Tree, as

Strona 167

6Click Save.7In the System Tree, assign the policy to the required systems or group.• Systems — Select the systems, click Actions | Agent | Set Polici

Strona 168

TaskFor option definitions, click ? in the interface.1In the McAfee ePO console, from Policy Catalog, select ePO Deep Command 2.1.0 as the product and

Komentarze do niniejszej Instrukcji

Brak uwag