Installation Guide for Cisco Security Manager 3.0.2
Index

Table Of Contents

A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W -

Index

A

antivirus utilities, requirement to disable 3-5, 5-6

audience for this document viii

Auto Update Server (AUS)

documentation xi

licensing 1-7

overview 1-4

B

backing up

and restoring data 4-10

Security Manager database 4-9

bootstrapping devices 7-4

browsers

requirements

cache 7-2

client 2-8

server 2-6

See also Internet Explorer

See also Mozilla

C

C/C++ library files, where stored 1-9

Catalyst 6500/7600 Device Manager (DM6500/7600), overview 1-3

cautions, significance of ix

CD-ONE

unsupported use 3-4

certificates. See digital certificates

checklists

client, browser best practices 7-2

server

enhancing performance 3-2

installation readiness 3-5

post-installation tasks 6-1

security best practices 6-6

Cisco Marketplace xiv

Cisco Press xiv

Cisco Product Quick Reference Guide, obtaining xiv

Cisco product security

PSIRT xiv

SAFE blueprint viii

vulnerability policy portal xiv

Cisco Security Agent

documentation C-1

installation, conditions for 1-6

installing Security Manager and

customized version 4-10

fully configurable version 4-10

overview 1-6

policies

exported, on DVD 1-6, 3-3

imported, requirement to reconcile 3-3

standalone agent 1-6, C-1

security levels

changing C-3

default C-3

understanding C-3

troubleshooting B-11, C-1

uninstalling

manually 4-10

uninstalling, recommendation against 3-3, B-12

Cisco Security Manager

basic concepts 7-4

getting started 7-4

late-breaking information about viii

learning more about 7-4

logging in 7-2

overview 1-3

using 7-4

Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS)

date and time synchronization 3-5

interoperation with 3-5

overview vii

CiscoView Device Manager

features in SecurityManager 1-3

unsupported use 3-4

See also Catalyst 6500/7600 Device Manager (DM 6500/7600)

CiscoWorks

CommonServices, overview 1-2

Monitoring Center for Performance. See Performance Monitor

Monitoring Center for Security. See Security Monitor

TCP ports

Daemon Manager 2-3

HTTP 2-3

VPN/Security Management Solution (VMS)

free upgrade from 4-8

migrating data to SecurityManager x

client software

installing 5-5

InstallShield database corruption 5-5

logging in to a server 7-2

using 7-2

client systems

deleting Temp files 5-6

file locations on 1-9, 5-8

recommendation to delete Temp files 5-9

video (graphics) card drivers

confirming installed versions 2-7

upgrading 2-7

CMFLOCK.TXT file, deleting 4-17

Common Services

documentation 2-1

installing 2-1

licensing 1-7

required version 1-2

requirement to use 2-1

CSTM TCP port 2-4

D

database

backup 4-9

restore 4-10

database TCP port 2-4

date and time settings

caution against changing 3-5

recommendation to synchronize 2-2, 3-5

use of NTP servers 2-2

device bootstrapping 7-4

device credentials repository (DCR)

server process 3-5

TCP port 2-4

troubleshooting 3-5

digital certificates

requirement to create 6-2

troubleshooting 3-5

directory encryption, restriction against 2-6, 3-6

documentation

audience for this viii

on Cisco.com xiv

ordering xiv

reviewing updated ix

typographical conventions in viii

documentation, obtaining

Auto Update Server xi

Cisco SecurityAgent xiii, C-1

Cisco SecurityManager x

CommonServices xii

IPSManager xi

PerformanceMonitor xiii

Resource Manager Essentials (RME) xii

documentation feedback, sending to Cisco viii, xiv

domain controllers (primary or backup), unsupported use 2-6

E

encrypted directories, restriction against 2-6, 3-6

evaluation license

device count limitations 4-6

duration 4-6

upgrading to permanent license 1-7

Event Services software TCP port requirements

HTTP 2-4

listening 2-4

routing 2-4

services 2-4

F

FAQs, in the troubleshooting guide x

files, where stored

Cisco Security Agent

logs C-2

policies 1-6, 3-3

on client systems 1-9

on servers 1-9

file system recommendations 2-5

G

gatekeeper HIPO TCP port 2-3

getting started with Cisco SecurityManager 7-4

H

HTTP TCP port 2-3

I

inline upgrade

procedure 4-9

in-place upgrade

procedure 4-9

installation

client software 5-5

InstallShield database corruption 5-5

planning and preparation viii

servers

dependencies 2-1

general requirements 2-1

GUI reference A-1

post-installation tasks 6-1

preparatory tasks 3-1

starting an installation 4-5

troubleshooting 4-5

verifying 6-6

installing

Cisco Security Agent

customized version 4-10

fully configurable version 4-10

Internet Explorer

cache size requirement 5-6, 5-9

confirming the installed Java version 2-8

security settings 5-9

versions supported 2-6, 2-8

See also browsers

See also Mozilla

Internet Information Server (IIS)

conflict with SecurityManager 3-4, 3-6

requirement to uninstall 3-4, 3-6

Internet Inter-ORB Protocol (IIOP) TCP port 2-3

IP addresses

disabling dynamic addresses 3-5

static address requirement 2-6

using a static address 3-5

IPS database engine TCP port 2-4

IPS Manager

documentation xi

importing IPSMC2.2 data 4-12

migrating from IPSMC 4-2, 4-12

overview 1-4

prerequisites to import IPSMC data 4-12

time required to import IPSMC data 4-13

using IpsMcDbUpgrade.pl 4-13

See also IPS MC

IPS MC

backing up server data 4-3

exporting data 4-2

migrating to IPSManager 4-2, 4-12

securing the backed-up data 4-3

See also IPS Manager

IpsMcDbUpgrade.pl 4-13

J

Java

confirming the installed version 2-8

embedded version on client systems 2-8

enabling 7-2

obtaining 2-8

version to use with IPSManager 2-8

JavaScript, enabling 7-2

L

language versions supported (Windows)

client 2-8

server 2-5

LAN Management Solution (LMS), unsupported use 3-2

licenses

file locations for

PerformanceMonitor 1-6

RME 1-5

installing 1-8

Product Authorization Key (PAK) 1-7

SecurityManager kit part numbers 1-7

settings 1-7

Software License Claim Certificate 1-7

understanding 1-7

upgrading 1-7

uploading new 1-7

working with 1-7

license server TCP port 2-3

M

Management Center for Cisco Security Agents (CSAMC), documentation xiii

Management Center for IPS Sensors (IPSMC). See IPS Manager

McAfee Antivirus

incompatibility 5-6

reenabling 5-8

requirement to disable 5-6

memory (RAM)

client requirements 2-7

server requirements 2-5

Monitoring Center for Performance. See Performance Monitor

Mozilla

confirming the installed Java version 2-8

security settings 5-9

versions supported 2-6, 2-8

N

NETBIOS, recommendation to disable 3-4

Networking Professionals Connection xiv

network protocols, recommendation to disable 3-4

network shares, recommendation to avoid 3-4

Network Time Protocol (NTP) server, recommendation to use 2-2, 3-5

non-Workflow mode

pending data

discarding before backup 4-8

submitting before backup 4-8

taking over session data 4-8

uncommitted changes

upgrading 4-8

Norton Internet Security 2005

incompatibility 5-6, 5-8

requirement to disable 5-6

requirement to uninstall 5-8

NTFS file system, requirement to use 2-5

O

ODBC driver manager

confirming the installed version 2-5

requirements 2-5

working with Sybase files 2-5

OGS TCP port 2-4

online help, tips for viewing 5-1

operating systems

on client systems

Windows2000 2-8

Windows2003 2-8

WindowsXP Professional 2-8

on servers

Windows2000 2-5

Windows 2003 Server 2-5

Osagent UDP port 2-4

overview 1-1

P

passwords

admin account 4-6

requirement to use identical passwords 4-6

security basics D-4

strong passwords

characteristics D-3

definition 3-3

how to require 3-3

recommendations D-3

System Identity Account 4-6

peer support, Networking Professionals Connection xiv

pending activities

and upgrade

in non-Workflow mode 4-8

in Workflow mode 4-8

Performance Monitor

availability xiii

documentation xiii

entitlement to install 1-6

license file location 1-6

licensing 1-8

overview 1-6

permanent license, upgrading from evaluation license 1-7

point patches

applying to a client 5-9

applying to a server 4-14

caution against accepting from a third-party 4-13

default location on client systems 5-10

deleting Temp files on client systems 5-6

obtaining 4-13

recommendation to delete Temp files on client systems 5-9

version mismatch 5-9

popup blockers

configuring 5-1, 7-2

conflicting with other installed software 3-3

disabling 5-1, 7-2

requirements 7-2

troubleshooting 5-1, 7-2

ports

required for TCP 2-2

required for UDP 2-2

product registration. See licenses

PSIRT xiv

publications, obtaining additional xiv

R

related documentation, obtaining xii

Remote Copy Protocol TCP port 2-3

removable media drives, security implications if compromised 6-6

requirements

client system 2-7

servers

installation, general 2-1

system 2-4

Resource Manager Essentials (RME)

documentation xii

entitlement to install 1-5

installing 1-5

license file location 1-5

licensing 1-8

overview 1-5

restoring

and backing up data 4-9

Security Manager database 4-10

S

SAFE blueprint viii

Secure Shell (SSH) TCP port 2-2

security

advisories xiv

incidents, obtaining assistance xiv

news from Cisco

registering to receive xiv

RSS feed URL xiv

notices xiv

PSIRT xiv

vulnerabilities, reporting xiv

SecurityManager database TCP port 2-3

SecurityMonitor 4-3

server

configuration

boot settings 3-4

date and time settings 3-5

file locations

database files 1-9

log files 1-9

miscellaneous files 1-9

installations

best practices 3-1

dependencies 2-1

procedures 4-1

performance

best practices for enhancing 3-1

operating environment 2-4, 4-4

preparation checklists 3-1

processes, verifying status 6-7

traffic

required inbound ports 2-2

required outbound ports 2-2

service agreement contracts 1-7

service packs

applying to a client 5-9

applying to a server 4-14

caution against accepting from a third-party 4-13

default location on client systems 5-10

deleting Temp files on client systems 5-6

obtaining 4-13

recommendation to delete Temp files on client systems 5-9

version mismatch 5-9

service requests

submitting xiv

services

minimum required for Windows 3-4

required for TCP 2-2

required for UDP 2-2

SNMP polling UDP port 2-3

SNMP trap UDP port 2-3

software updates. See point patches

SSL certificate invalidation 3-5

SSL mode (for HTTP server) TCP port 2-3

support

Networking Professionals Connection xiv

obtaining from Cisco xiv

service agreement contracts 1-7

Software Application Support contracts 1-7

Sybase, requirement to disable 3-6, 4-5

Sybase database files, requirement to use correct ODBC version 2-5

Syslog UDP port 2-3

T

TACACS+ TCP port 2-3

taking over user sessions

upgrading to Security Manager 3.0.2 and 4-8

TCP

list of required ports 2-2

list of required services 2-2

technical support (TAC)

obtaining xiv

URL for service requests xiv

Telnet TCP port 2-3

Terminal Services

requirements 2-6, 3-6

unsupported configuration 2-6

Tomcat

Ajp13 connector TCP port 2-3

global library files, where stored 1-9

shutdown TCP port 2-3

training, obtaining xiv

Trivial File Transfer Protocol (TFTP) UDP port 2-3

troubleshooting

antivirus scanners 3-3

Cisco Security Agent

blocking a valid operation B-12

blocking network access B-11

diagnostic utility B-12

icon appearance changed in system tray B-12

obtaining a revised agent from TAC B-12

recognizing when the agent is disabled B-12

security level is High B-11

setting the security level to Medium B-11

untrusted rootkit detected B-11

using the log file B-11

collecting server troubleshooting information B-13

DCRServer process does not start 3-5

error messages

client installation B-7

server installation B-2

server uninstallation B-6

file contents cannot be unpacked 4-5

file corruption

executable file 4-5

host-based intrusion software 3-3

incorrect GUI 2-7, 6-7, B-4

installation

does not run B-9

hangs B-3, B-8

reviewing log files B-16

interoperation with CS-MARS 3-5

invalid SSL certificate 3-5

java.security.cert errors 3-5

mapped drives B-5

missing

GUI B-4

product features B-4

popup blockers 3-3, 5-1, 7-2

security software conflicts 3-3

server processes

changing B-14

restarting B-15

viewing B-14

server self-test B-13

uninstallation

does not run B-9

hangs B-6

using MDCSupport.exe B-13

troubleshooting guide, obtaining x

typographical conventions in this document viii

U

UDP

list of required ports 2-2

list of required services 2-2

uninstallation

cautions against

uninstalling from infected servers 4-16

client software 5-11

InstallShield database corruption 5-11

recommendation to restart client systems 5-12

recommendation to restart servers 4-18

servers

deleting CMFLOCK.TXT 4-17

failure to delete CSCOpx/bin folder 4-17

server software 4-17

updates. See point patches

upgrading

database backup 4-9

database restore 4-10

from VMS

to Security Manager 4-8

in-place 4-9

pending activities

discarding 4-8

submitting 4-8

prerequisites 4-8

Security Manager

from 3.0 4-8

from 3.0.1 4-8

taking over session data 4-8

uncommitted data

in non-Workflow mode 4-8

in Workflow mode 4-8

using backup and restore 4-9

user accounts

admin D-2

casuser D-2

System Identity D-2

understanding D-1

user permissions, understanding D-3

using SecurityManager 7-4

V

verifying an installation 6-6

VMS, free upgrade from 4-8

W

web context files, where stored 1-9

Windows services, required 3-4

Workflow mode

approving activities 4-8

pending data

discarding before backup 4-8

submitting before backup 4-8

uncommitted changes

upgrading 4-8