Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2931 Discussions

Intel AMT reconfigure fails

SysArch
New Contributor I
3,852 Views

​The Configuration of an uncofigured device works fine. But if I execute the same command to reconfigure the device, the command Fails:

 

"Exit with code 75. Details: Failed to complete remote configuration of this Intel(R) AMT device. Final status of Intel(R) AMT is unknown because a failure occurred when configuring the system. Intel(R) AMT operation failed. Error while configuring TLS settings. A TCP error occurred. Make sure that the destination settings are correct and that a network connection exists to the target. ".

 

I used the following command:

ACUConfig.exe /output console ConfigViaRCSonly amt1.example.com DefaultProfile

 

After the device is set to unconfigured, the configuration (with the above command) works fine again.

ACUConfig.exe /output console unconfigure

I added the verbose log of a successfully configuration and a failed reconfiguration as attachment.

 

Does anybody know why the reconfiguration fails?

 

Best regards, fabian

 

 

0 Kudos
1 Solution
SysArch
New Contributor I
3,559 Views

I was able to implement a workaround by allow the TCP port 16992 from RCS-Server to Client although TLS is used. I think this is a Bug, because the implementation guide advise, that port 16992 is not used if TLS is enabled ("Starting with Release 6.0, the port is optionally open when TLS is enabled") https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fmanageabilityports.htm

 

To clarify:

To configure a unconfigured device over RCS the following ports are sufficiently:

RPC (135,49152-65335)

AMT HTTPS (16993)

 

To reconfigure a already configured device over RCS the following ports are required:

RPC (135,49152-65335)

AMT HTTPS (16993)

AMT HTTP (16992)

 

Can you confirm the incorrect behavior of Intel RCS v12.1.0 with Intel AMT 11.8.65?

 

Best regards

View solution in original post

0 Kudos
6 Replies
JoseH_Intel
Moderator
3,559 Views

Hello SysArch,

 

Thank you for joining the community

 

May I ask if this device you unconfigured and tried to reconfigure was already provisioned and functional before the unconfiguration?

The reason for failure looks like a TLS compatibility and/or configuration issue. Did you enabled TLS on the xml profile for the reconfiguration?

 

Regards

 

Jose A.

Intel Customer Support Technician

A Contingent Worker at Intel

0 Kudos
SysArch
New Contributor I
3,559 Views

Hi Jose

 

Yes, the same device was already provisioned with the same Profile on RCS.

 

What I did exactly:

  1. Configure Client1 by ACUConfig.exe via RCS-Server Amt1 with DefaultProfile --> Successful
  2. Configure Client1 by ACUConfig.exe via RCS-Server Amt1 with DefaultProfile --> Failed
  3. Unconfigure Client1 by ACUConfig.exe --> Successful
  4. Configure Client1 by ACUConfig.exe via RCS-Server Amt1 with DefaultProfile --> Successful
  5. Configure Client1 by ACUConfig.exe via RCS-Server Amt1 with DefaultProfile --> Failed

 

I used the same rcs, client and profile in all steps. From the RCS-Server I can connect the AMT webinterface on Client1 over HTTPS without any certificate warnings.

 

As additional information I added the RCS Log for a successful configuration and a failed reconfiguration as attachment. Maybe it helps for your troubleshooting.

0 Kudos
SysArch
New Contributor I
3,559 Views

Was not possible to add two files in the same post, so here is the second one

0 Kudos
SysArch
New Contributor I
3,560 Views

I was able to implement a workaround by allow the TCP port 16992 from RCS-Server to Client although TLS is used. I think this is a Bug, because the implementation guide advise, that port 16992 is not used if TLS is enabled ("Starting with Release 6.0, the port is optionally open when TLS is enabled") https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fmanageabilityports.htm

 

To clarify:

To configure a unconfigured device over RCS the following ports are sufficiently:

RPC (135,49152-65335)

AMT HTTPS (16993)

 

To reconfigure a already configured device over RCS the following ports are required:

RPC (135,49152-65335)

AMT HTTPS (16993)

AMT HTTP (16992)

 

Can you confirm the incorrect behavior of Intel RCS v12.1.0 with Intel AMT 11.8.65?

 

Best regards

0 Kudos
JoseH_Intel
Moderator
3,559 Views

Hello SysArch,

 

Its good to hear you figured out this workaround and got it fixed.

 

It is possible the ports issue might be a bug, but it is known that both ports 16992 and 16993 are used depending a TLS or non TLS connection. What changes between AMT v11 to v12 is the deprecation of TLS 1.0 for security purposes mainly.

 

Jose A.

Intel Customer Support Technician

A Contingent Worker at Intel

 

0 Kudos
SysArch
New Contributor I
3,559 Views

"it is known that both ports 16992 and 16993 are used depending a TLS or non TLS"

Right 16992 for non TLS and 16993 for TLS. It is explicit documented (https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fmanageabilityports.htm), that port 16992 is not required if TLS is used. But based on my experience 16992 is also required during reconfiguration although using TLS.

 

Best regards

0 Kudos
Reply