Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2834 Discussions

AMT vs Windows 802.1x wired - reauth every 30/60/120 seconds.

George7
Novice
2,222 Views

Hi,

If PC is off, AMT send EAPOL and process auth 802.1x ends is success. Reauth is every 8 hours. Everything is OK.

If PC is turn on, start Windows, Windows run service dot3svc, Windows send EAPOL and process auth 802.1x ends in success.
After 30 or 60 or 120 seconds AMT (LMS) send EAPOL and this force Windows service dot3svc to reauth 802.1x and it ends successfully again. And it all repeats itself every 30/60 seconds. The problem is that this causes the network to be unavailable for about 2 seconds (repeatedly).

HW is HP 800 G5 all-in-one.
BIOS ver. 02.05.01 (SP103729.exe)
AMT FW 12.0.64.1551
Windows 10 Enterprise 1909
LMS 1946.12.0.1328 (SP103606.exe)
NIC Intel I219-LM Driver 12.18.9.20 Rev.P (SP103814.exe)

The same problem is in HP 600 G5.

Previous generations of HP G1,G2,G3 did not have this problem.

Please help. Thanks.

George

0 Kudos
1 Solution
JoseH_Intel
Moderator
1,710 Views

Hello George7,


Do you have any further details, updates, questions, or comments in regards to this issue?

This thread will be marked as resolved automatically in the next 3 business days if no activity is received. 


Regards


Jose A.

Intel Customer Support Technician


View solution in original post

0 Kudos
5 Replies
JoseH_Intel
Moderator
2,160 Views

Hello George7,


Thank you for joining the Intel community


Since this issue you describe is seeing in G5 systems then it seems to be related to AMT v12. Could you tell what security protocol do you have enabled in your AMT profile (TLS, kerberos, etc). Have you check for the latest BIOS and Management Engine (ME) firmware updates on the HP website already (if any)? BIOS seems to be up to date. But there is a Intel Management Engine driver v2009.14.0.1496 Rev.A that I don't see on your list. You could check it from here: https://ftp.hp.com/pub/softpaq/sp103501-104000/sp103606.exe


I will look forward for your updates


Jose A.

Intel Customer Support


0 Kudos
George7
Novice
2,129 Views

Hello Jose,

protocol is EAP-TLS. 

Yes, I have SP103606 installed. In description SP103606.exe is VERSION: 2009.14.0.1496, but after install is in uninstall registry (HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{GUID}) version 1946.12.0.1328. 

George7

0 Kudos
JoseH_Intel
Moderator
2,076 Views

Hello George7,


Thanks for your quick update.


Let me research a bit on this and I will let you know as soon as I have news.


Regards


Jose A.

Intel Customer Support


0 Kudos
JoseH_Intel
Moderator
1,991 Views

Hello George7:


We found this is a newly discovered bug. The issue is that AMT gets into a loop. AMT initiates the EAPOL reauthentication attempt and the OS completes it, without AMT knowing which is why AMT continues to initiate the reauthentication. Unfortunately there is currently no fix and no workaround at this time but will be addressed in next update. The fix will be released in no less than 10 weeks from now.


Regards


Jose A.

Intel Customer Support


0 Kudos
JoseH_Intel
Moderator
1,711 Views

Hello George7,


Do you have any further details, updates, questions, or comments in regards to this issue?

This thread will be marked as resolved automatically in the next 3 business days if no activity is received. 


Regards


Jose A.

Intel Customer Support Technician


0 Kudos
Reply