Client Management Suite

 View Only

How Do I Enable Intel AMT Dynamic DNS? 

Sep 22, 2011 03:08 PM

Intel AMT 6.x and higher platforms support dynamic DNS.   This allows the firmware to send a DNS record update, thus keeping the FQDN\IP resolution live within the environment.    Prior to Intel AMT 6.x, if a DHCP IP address were issued to the client, Intel AMT would maintain the address yet the FQDN\IP resolution within the DNS server would expire... unless dynamic DNS updates were enabled between the DHCP server to DNS server

Note: This may be the default setup of a Microsoft DHCP\DNS environment, yet is less common if Unix\Linux servers are used.   Plus - updating of DNS records based on DHCP leases could lead to undesirable situations with rogue PCs.   Many infrastructure security teams require the client to update the DNS server once the client has successfully acquired a DHCP address

However, you may have noticed that the current Intel SCS 5.4 software embedded within Symantec Management Platform 7.1 does not enable the Dynamic DNS firmware setting.    The sample image below shows the Intel AMT WebUI of a system configured via the stated setup:

It is possible to change this setting after the initial configuration event.    Use of Intel SCS 7.1 is one approach.   To gain a base familiarity with Intel SCS 7.1, take a look at the video series starting at http://www.symantec.com/connect/videos/part-1-configure-intel-amt-integrating-altiris

A post or "Delta Configuration" can be used to enable dynamic DNS or adjust settings which may not be exposed in the Symantec Management Platform interface.

To enable dynamic DNS in Intel AMT 6.x and higher systems:

  • Download and install Intel SCS 7.1  (see part 2 of the series)
  • Generate a "Delta Configuration" profile.  

  • Select only the Management Interfaces option

  • Ensure the IP and FQDN setting to update DNS is selected (Note: This is the default setting of profiles in SCS 7.1)

  • Save and export the file (see SCS 7.1 video series)
  • Distribute a package to the clients with the SCS 7.1 ACU_configurator files and the generate XML file
  • Run the following command on the client (Note: Must be executed with local system admin privileges)

acuconfig.exe configamt profile.xml

After completing the above steps, check the Intel AMT WebUI for the target client.   The Dynamic DNS option will now be enabled.

 

The opinions expressed on this site are mine alone and do not necessarily reflect the opinions or strategies of Intel Corporation or its worldwide subsidiaries 

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.