A Little vPro Goes a Long Way

August Wehrmann, Vice President – Research and Development, N-able Technologies

Feb 19, 2008

Categories: Technology Alliance

Keeping abreast of the new trends is important for any industry. In the IT space in particular, there is no shortage of new ideas and features that promise to deliver lower costs, competitive advantage, the list goes on. So I guess the trick is to be able to separate the hype from the reality, to look beyond the "coolness" factor and try to understand what the practical application might be.

Strictly speaking, Intel® vPro™ is not new, it's been around for a couple of years and is currently on its third revision. For those not familiar with its benefits, you can get a good overview on the Intel web site. But why am I evangelizing it here? Well let me tell you.

At the heart of Intel® vPro™ technology is Intel® Active Management Technology (Intel® AMT). Intel AMT embeds a Manageability Engine (ME) that provides a robust and reliable protocol for remote manageability regardless of the operating system (with some exceptions such as Mac OS) or of the OS state. Put simply: You can manage vPro systems remotely, even if the OS is shut down or even corrupted.

Naturally though, any technology used to enhance the manageability of a device is useless without a management platform to exercise it to its full potential. Here are some of the features of Intel® vPro™ technology and benefits when combined with a remote monitoring and management platform.

  • Platform and Hardware Inventory Discovery – Regardless of power on/off state or OS state, the management platform is able to detect and discover any device that has a power and LAN connection. So in the case where desktops are shutdown by users at night (or on weekends/vacation) it won't leave you as a service provider wondering if the device has mysteriously disappeared when your run your periodic inventory scans. Future support by software/OS vendors will also make software inventory discovery and license management possible by publishing updates to AMT's non-volatile storage (NVRAM).
  • System Defense – If malicious/suspicious behavior is detected originating from a vPro-enabled desktop the system can be “isolated” from the local network by cutting off its network connectivity in order to minimize any damage or disruption that the malicious behavior could cause. The exception to the isolation policy would be that inbound access from a remote management platform can be left open as a "back door" which would be used by the service provider in order to take steps to fix the problem. Once the problem is resolved, network connectivity can be restored.
  • Remote Console Access – The ability to take remote control of a system is a "must have" in terms of the capabilities that a service provider uses. The problem with current solutions is that they rely on client side applications that run on top of the OS. But what about a situation where the OS is corrupted or doesn't boot at all? AMT's Serial-over-LAN (or what I like to call Serial-over-Internet when used with a remote management platform) can be leveraged to view the console and interact with it as the system boots before the OS attempts to load. In this case, you can access the BIOS, modify settings and troubleshoot the boot sequence as if you were sitting in front of the system. Furthermore, with another feature called IDE-Redirection, the system can be booted to the OS level from a known good image served from a remote system so that additional troubleshooting can occur.

As the head of a development organization that builds a remote management platform, I'm always on the lookout for new technologies that can enhance the remote management features that we provide to our users. In terms of rounding out our platform capabilities, Intel® vPro™ technology goes a long way.

Bookmark this post with:          
 
 

Links to this post

Comments

On 03 Mar 2008 02:25, Mike Scallion said:

We were actually in a pilot study with vPro and the study itself was not difficult. I must say that that integration into N-Able was much easier than first thought. Although at this time, integration into N-Able is limited to basic power functions and asset tracking, upcoming pre-releases have shown that the technology is fast becoming a core within N-Able. I can see long lasting benefits to using the technology and we have seen where the current level of support for the product will allow us to provide less downtime and annoyance to the end user community we support. It was only a matter of time before the desktop/laptop support caught up to the server level of manageability. With Dell DRAC's and HP OpenView, we have had this capability for years. It seems to be a natural progression to centralized management and enhanced features that even end users themselves will reap benefits from. Imagine for a moment that you are the end user, forgot and powered off your machine....no worries, login to the web interface, turn on your machine and there ya go, back in business ready to work another 8 hours today!

On 12 Aug 2009 06:28, Garrett said:

Is it possible for N-Able to have license discovery? Curious to this, as it would be nifty for N-Able to monitor amount of licenses that are in use on a terminal server. And if they are all in use, then it would generate an alert notifying us that all licenses are in use.

Leave a comment





CAPTCHA Image Validation