Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W -
Index
A
antivirus utilities, requirement to disable 3-5, 5-6
audience for this document viii
Auto Update Server (AUS)
documentation xi
licensing 1-7
overview 1-4
B
backing up
and restoring data 4-10
Security Manager database 4-9
bootstrapping devices 7-4
browsers
requirements
cache 7-2
client 2-8
server 2-6
See also Internet Explorer
See also Mozilla
C
C/C++ library files, where stored 1-9
Catalyst 6500/7600 Device Manager (DM6500/7600), overview 1-3
cautions, significance of ix
CD-ONE
unsupported use 3-4
certificates. See digital certificates
checklists
client, browser best practices 7-2
server
enhancing performance 3-2
installation readiness 3-5
post-installation tasks 6-1
security best practices 6-6
Cisco Marketplace xiv
Cisco Press xiv
Cisco Product Quick Reference Guide, obtaining xiv
Cisco product security
PSIRT xiv
SAFE blueprint viii
vulnerability policy portal xiv
Cisco Security Agent
documentation C-1
installation, conditions for 1-6
installing Security Manager and
customized version 4-10
fully configurable version 4-10
overview 1-6
policies
exported, on DVD 1-6, 3-3
imported, requirement to reconcile 3-3
standalone agent 1-6, C-1
security levels
changing C-3
default C-3
understanding C-3
troubleshooting B-11, C-1
uninstalling
manually 4-10
uninstalling, recommendation against 3-3, B-12
Cisco Security Manager
basic concepts 7-4
getting started 7-4
late-breaking information about viii
learning more about 7-4
logging in 7-2
overview 1-3
using 7-4
Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS)
date and time synchronization 3-5
interoperation with 3-5
overview vii
CiscoView Device Manager
features in SecurityManager 1-3
unsupported use 3-4
See also Catalyst 6500/7600 Device Manager (DM 6500/7600)
CiscoWorks
CommonServices, overview 1-2
Monitoring Center for Performance. See Performance Monitor
Monitoring Center for Security. See Security Monitor
TCP ports
Daemon Manager 2-3
HTTP 2-3
VPN/Security Management Solution (VMS)
free upgrade from 4-8
migrating data to SecurityManager x
client software
installing 5-5
InstallShield database corruption 5-5
logging in to a server 7-2
using 7-2
client systems
deleting Temp files 5-6
file locations on 1-9, 5-8
recommendation to delete Temp files 5-9
video (graphics) card drivers
confirming installed versions 2-7
upgrading 2-7
CMFLOCK.TXT file, deleting 4-17
Common Services
documentation 2-1
installing 2-1
licensing 1-7
required version 1-2
requirement to use 2-1
CSTM TCP port 2-4
D
database
backup 4-9
restore 4-10
database TCP port 2-4
date and time settings
caution against changing 3-5
recommendation to synchronize 2-2, 3-5
use of NTP servers 2-2
device bootstrapping 7-4
device credentials repository (DCR)
server process 3-5
TCP port 2-4
troubleshooting 3-5
digital certificates
requirement to create 6-2
troubleshooting 3-5
directory encryption, restriction against 2-6, 3-6
documentation
audience for this viii
on Cisco.com xiv
ordering xiv
reviewing updated ix
typographical conventions in viii
documentation, obtaining
Auto Update Server xi
Cisco SecurityAgent xiii, C-1
Cisco SecurityManager x
CommonServices xii
IPSManager xi
PerformanceMonitor xiii
Resource Manager Essentials (RME) xii
documentation feedback, sending to Cisco viii, xiv
domain controllers (primary or backup), unsupported use 2-6
E
encrypted directories, restriction against 2-6, 3-6
evaluation license
device count limitations 4-6
duration 4-6
upgrading to permanent license 1-7
Event Services software TCP port requirements
HTTP 2-4
listening 2-4
routing 2-4
services 2-4
F
FAQs, in the troubleshooting guide x
files, where stored
Cisco Security Agent
logs C-2
policies 1-6, 3-3
on client systems 1-9
on servers 1-9
file system recommendations 2-5
G
gatekeeper HIPO TCP port 2-3
getting started with Cisco SecurityManager 7-4
H
HTTP TCP port 2-3
I
inline upgrade
procedure 4-9
in-place upgrade
procedure 4-9
installation
client software 5-5
InstallShield database corruption 5-5
planning and preparation viii
servers
dependencies 2-1
general requirements 2-1
GUI reference A-1
post-installation tasks 6-1
preparatory tasks 3-1
starting an installation 4-5
troubleshooting 4-5
verifying 6-6
installing
Cisco Security Agent
customized version 4-10
fully configurable version 4-10
Internet Explorer
cache size requirement 5-6, 5-9
confirming the installed Java version 2-8
security settings 5-9
versions supported 2-6, 2-8
See also browsers
See also Mozilla
Internet Information Server (IIS)
conflict with SecurityManager 3-4, 3-6
requirement to uninstall 3-4, 3-6
Internet Inter-ORB Protocol (IIOP) TCP port 2-3
IP addresses
disabling dynamic addresses 3-5
static address requirement 2-6
using a static address 3-5
IPS database engine TCP port 2-4
IPS Manager
documentation xi
importing IPSMC2.2 data 4-12
migrating from IPSMC 4-2, 4-12
overview 1-4
prerequisites to import IPSMC data 4-12
time required to import IPSMC data 4-13
using IpsMcDbUpgrade.pl 4-13
See also IPS MC
IPS MC
backing up server data 4-3
exporting data 4-2
migrating to IPSManager 4-2, 4-12
securing the backed-up data 4-3
See also IPS Manager
IpsMcDbUpgrade.pl 4-13
J
Java
confirming the installed version 2-8
embedded version on client systems 2-8
enabling 7-2
obtaining 2-8
version to use with IPSManager 2-8
JavaScript, enabling 7-2
L
language versions supported (Windows)
client 2-8
server 2-5
LAN Management Solution (LMS), unsupported use 3-2
licenses
file locations for
PerformanceMonitor 1-6
RME 1-5
installing 1-8
Product Authorization Key (PAK) 1-7
SecurityManager kit part numbers 1-7
settings 1-7
Software License Claim Certificate 1-7
understanding 1-7
upgrading 1-7
uploading new 1-7
working with 1-7
license server TCP port 2-3
M
Management Center for Cisco Security Agents (CSAMC), documentation xiii
Management Center for IPS Sensors (IPSMC). See IPS Manager
McAfee Antivirus
incompatibility 5-6
reenabling 5-8
requirement to disable 5-6
memory (RAM)
client requirements 2-7
server requirements 2-5
Monitoring Center for Performance. See Performance Monitor
Mozilla
confirming the installed Java version 2-8
security settings 5-9
versions supported 2-6, 2-8
N
NETBIOS, recommendation to disable 3-4
Networking Professionals Connection xiv
network protocols, recommendation to disable 3-4
network shares, recommendation to avoid 3-4
Network Time Protocol (NTP) server, recommendation to use 2-2, 3-5
non-Workflow mode
pending data
discarding before backup 4-8
submitting before backup 4-8
taking over session data 4-8
uncommitted changes
upgrading 4-8
Norton Internet Security 2005
incompatibility 5-6, 5-8
requirement to disable 5-6
requirement to uninstall 5-8
NTFS file system, requirement to use 2-5
O
ODBC driver manager
confirming the installed version 2-5
requirements 2-5
working with Sybase files 2-5
OGS TCP port 2-4
online help, tips for viewing 5-1
operating systems
on client systems
Windows2000 2-8
Windows2003 2-8
WindowsXP Professional 2-8
on servers
Windows2000 2-5
Windows 2003 Server 2-5
Osagent UDP port 2-4
overview 1-1
P
passwords
admin account 4-6
requirement to use identical passwords 4-6
security basics D-4
strong passwords
characteristics D-3
definition 3-3
how to require 3-3
recommendations D-3
System Identity Account 4-6
peer support, Networking Professionals Connection xiv
pending activities
and upgrade
in non-Workflow mode 4-8
in Workflow mode 4-8
Performance Monitor
availability xiii
documentation xiii
entitlement to install 1-6
license file location 1-6
licensing 1-8
overview 1-6
permanent license, upgrading from evaluation license 1-7
point patches
applying to a client 5-9
applying to a server 4-14
caution against accepting from a third-party 4-13
default location on client systems 5-10
deleting Temp files on client systems 5-6
obtaining 4-13
recommendation to delete Temp files on client systems 5-9
version mismatch 5-9
popup blockers
configuring 5-1, 7-2
conflicting with other installed software 3-3
disabling 5-1, 7-2
requirements 7-2
troubleshooting 5-1, 7-2
ports
required for TCP 2-2
required for UDP 2-2
product registration. See licenses
PSIRT xiv
publications, obtaining additional xiv
R
related documentation, obtaining xii
Remote Copy Protocol TCP port 2-3
removable media drives, security implications if compromised 6-6
requirements
client system 2-7
servers
installation, general 2-1
system 2-4
Resource Manager Essentials (RME)
documentation xii
entitlement to install 1-5
installing 1-5
license file location 1-5
licensing 1-8
overview 1-5
restoring
and backing up data 4-9
Security Manager database 4-10
S
SAFE blueprint viii
Secure Shell (SSH) TCP port 2-2
security
advisories xiv
incidents, obtaining assistance xiv
news from Cisco
registering to receive xiv
RSS feed URL xiv
notices xiv
PSIRT xiv
vulnerabilities, reporting xiv
SecurityManager database TCP port 2-3
SecurityMonitor 4-3
server
configuration
boot settings 3-4
date and time settings 3-5
file locations
database files 1-9
log files 1-9
miscellaneous files 1-9
installations
best practices 3-1
dependencies 2-1
procedures 4-1
performance
best practices for enhancing 3-1
operating environment 2-4, 4-4
preparation checklists 3-1
processes, verifying status 6-7
traffic
required inbound ports 2-2
required outbound ports 2-2
service agreement contracts 1-7
service packs
applying to a client 5-9
applying to a server 4-14
caution against accepting from a third-party 4-13
default location on client systems 5-10
deleting Temp files on client systems 5-6
obtaining 4-13
recommendation to delete Temp files on client systems 5-9
version mismatch 5-9
service requests
submitting xiv
services
minimum required for Windows 3-4
required for TCP 2-2
required for UDP 2-2
SNMP polling UDP port 2-3
SNMP trap UDP port 2-3
software updates. See point patches
SSL certificate invalidation 3-5
SSL mode (for HTTP server) TCP port 2-3
support
Networking Professionals Connection xiv
obtaining from Cisco xiv
service agreement contracts 1-7
Software Application Support contracts 1-7
Sybase, requirement to disable 3-6, 4-5
Sybase database files, requirement to use correct ODBC version 2-5
Syslog UDP port 2-3
T
TACACS+ TCP port 2-3
taking over user sessions
upgrading to Security Manager 3.0.2 and 4-8
TCP
list of required ports 2-2
list of required services 2-2
technical support (TAC)
obtaining xiv
URL for service requests xiv
Telnet TCP port 2-3
Terminal Services
requirements 2-6, 3-6
unsupported configuration 2-6
Tomcat
Ajp13 connector TCP port 2-3
global library files, where stored 1-9
shutdown TCP port 2-3
training, obtaining xiv
Trivial File Transfer Protocol (TFTP) UDP port 2-3
troubleshooting
antivirus scanners 3-3
Cisco Security Agent
blocking a valid operation B-12
blocking network access B-11
diagnostic utility B-12
icon appearance changed in system tray B-12
obtaining a revised agent from TAC B-12
recognizing when the agent is disabled B-12
security level is High B-11
setting the security level to Medium B-11
untrusted rootkit detected B-11
using the log file B-11
collecting server troubleshooting information B-13
DCRServer process does not start 3-5
error messages
client installation B-7
server installation B-2
server uninstallation B-6
file contents cannot be unpacked 4-5
file corruption
executable file 4-5
host-based intrusion software 3-3
incorrect GUI 2-7, 6-7, B-4
installation
does not run B-9
hangs B-3, B-8
reviewing log files B-16
interoperation with CS-MARS 3-5
invalid SSL certificate 3-5
java.security.cert errors 3-5
mapped drives B-5
missing
GUI B-4
product features B-4
popup blockers 3-3, 5-1, 7-2
security software conflicts 3-3
server processes
changing B-14
restarting B-15
viewing B-14
server self-test B-13
uninstallation
does not run B-9
hangs B-6
using MDCSupport.exe B-13
troubleshooting guide, obtaining x
typographical conventions in this document viii
U
UDP
list of required ports 2-2
list of required services 2-2
uninstallation
cautions against
uninstalling from infected servers 4-16
client software 5-11
InstallShield database corruption 5-11
recommendation to restart client systems 5-12
recommendation to restart servers 4-18
servers
deleting CMFLOCK.TXT 4-17
failure to delete CSCOpx/bin folder 4-17
server software 4-17
updates. See point patches
upgrading
database backup 4-9
database restore 4-10
from VMS
to Security Manager 4-8
in-place 4-9
pending activities
discarding 4-8
submitting 4-8
prerequisites 4-8
Security Manager
from 3.0 4-8
from 3.0.1 4-8
taking over session data 4-8
uncommitted data
in non-Workflow mode 4-8
in Workflow mode 4-8
using backup and restore 4-9
user accounts
admin D-2
casuser D-2
System Identity D-2
understanding D-1
user permissions, understanding D-3
using SecurityManager 7-4
V
verifying an installation 6-6
VMS, free upgrade from 4-8
W
web context files, where stored 1-9
Windows services, required 3-4
Workflow mode
approving activities 4-8
pending data
discarding before backup 4-8
submitting before backup 4-8
uncommitted changes
upgrading 4-8