Installation Guide for Cisco Security Manager 3.0
Index

Table Of Contents

A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W -

Index

A

antivirus utilities, requirement to disable 3-5, 5-6

audience for this document viii

Auto Update Server (AUS)

documentation xi

licensing 1-7

overview 1-4

B

bootstrapping devices 7-4

browsers

requirements

cache 7-2

client 2-7

server 2-5

See also Internet Explorer

See also Mozilla

C

C/C++ library files, where stored 1-9

Catalyst 6500/7600 Device Manager (DM6500/7600), overview 1-3

cautions, significance of ix

CD-ONE

CommonServices incompatibility 1-2, 3-2, 4-3

unsupported use 3-4

certificates. See digital certificates

checklists

client, browser best practices 7-2

server

enhancing performance 3-2

installation readiness 3-5

post-installation tasks 6-2

security best practices 6-6

Cisco Marketplace xx

Cisco Press xx

Cisco Product Quick Reference Guide, obtaining xx

Cisco product security

PSIRT xvi

SAFE blueprint viii

vulnerability policy portal xvi

Cisco Security Agent

documentation C-1

installation, conditions for 1-5

overview 1-5

policies

exported, on DVD 1-5, 3-3

imported, requirement to reconcile 3-3

standalone agent 1-5, C-1

security levels

changing C-3

default C-3

understanding C-3

troubleshooting B-9, C-1

uninstalling, recommendation against 3-3, B-10

Cisco Security Manager

basic concepts 7-4

getting started 7-4

late-breaking information about viii

learning more about 7-4

logging in 7-3

overview 1-3

using 7-4

Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS)

date and time synchronization 3-5

interoperation with 3-5

overview vii

CiscoView Device Manager

features in SecurityManager 1-3

unsupported use 3-4

See also Catalyst 6500/7600 Device Manager (DM 6500/7600)

CiscoWorks

CommonServices, overview 1-2

Monitoring Center for Performance. See Performance Monitor

Monitoring Center for Security. See Security Monitor

TCP ports

Daemon Manager 2-3

HTTP 2-3

VPN/Security Management Solution (VMS), migrating data to SecurityManager x

client software

installing 5-5

InstallShield database corruption 5-5

logging in to a server 7-3

using 7-3

client systems

deleting Temp files 5-6

file locations on 1-9, 5-8

recommendation to delete Temp files 5-9

video (graphics) card drivers

confirming installed versions 2-6

upgrading 2-6

CMFLOCK.TXT file, deleting 4-11

Common Services

documentation 2-1

installation DVD to use 1-2, 3-2, 4-3

installing 2-1

licensing 1-7

patch for SecurityManager 1-2, 3-2, 4-3

required version 1-2, 3-2, 4-3

requirement to use 2-1

CSTM TCP port 2-3

D

database TCP port 2-3

date and time settings

caution against changing 3-5

recommendation to synchronize 2-1, 3-5

use of NTP servers 2-1

device bootstrapping 7-4

device credentials repository (DCR)

server process 3-5

TCP port 2-3

troubleshooting 3-5

digital certificates

requirement to create 6-2

troubleshooting 3-5

directory encryption, restriction against 2-6, 3-6

documentation

audience for this viii

on Cisco.com xiv, xviii

on DVD-ROM xv

ordering xv

reviewing updated ix

typographical conventions in viii

documentation, obtaining

Auto Update Server xi

Cisco SecurityAgent xiv, C-1

Cisco SecurityManager x

CommonServices xii

IPSManager xii

PerformanceMonitor xiv

Resource Manager Essentials (RME) xiii

documentation feedback, sending to Cisco viii, xvi

domain controllers (primary or backup), unsupported use 2-6

E

encrypted directories, restriction against 2-6, 3-6

environment variables, viewing 4-2

evaluation license

device count limitations 4-5

duration 4-5

upgrading to permanent license 1-7

Event Services software TCP port requirements

HTTP 2-3

listening 2-3

routing 2-3

services 2-3

F

FAQs, in the troubleshooting guide x

files, where stored

Cisco Security Agent

logs C-2

policies 1-5, 3-3

on client systems 1-9

on servers 1-9

file system recommendations 2-4

G

gatekeeper HIPO TCP port 2-3

getting started with Cisco SecurityManager 7-4

H

HTTP TCP port 2-2

I

installation

client software 5-5

InstallShield database corruption 5-5

planning and preparation viii

servers

dependencies 2-1

general requirements 2-1

GUI reference A-1

post-installation tasks 6-2

preparatory tasks 3-1

starting an installation 4-4

troubleshooting 4-4

verifying 6-6

Internet Explorer

cache size requirement 5-6, 5-9

confirming the installed Java version 2-7

security settings 5-9

versions supported 2-5, 2-7

See also browsers

See also Mozilla

Internet Information Server (IIS)

conflict with SecurityManager 3-4, 3-6

requirement to uninstall 3-4, 3-6

Internet Inter-ORB Protocol (IIOP) TCP port 2-2

IP addresses

disabling dynamic addresses 3-6

static address requirement 2-5

using a static address 3-6

IPS database engine TCP port 2-3

IPS Manager

documentation xii

importing IPSMC2.2 data 4-6

migrating from IPSMC 4-2, 4-6

overview 1-4

prerequisites to import IPSMC data 4-6

time required to import IPSMC data 4-7

using IpsMcDbUpgrade.pl 4-7

See also IPS MC

IPS MC

backing up server data 4-3

exporting data 4-2

migrating to IPSManager 4-2, 4-6

securing the backed-up data 4-3

See also IPS Manager

IpsMcDbUpgrade.pl 4-7

J

Java

confirming the installed version 2-7

embedded version on client systems 2-7

enabling 7-2

obtaining 2-7

version to use with IPSManager 2-7

JavaScript, enabling 7-2

L

language versions supported (Windows)

client 2-7

server 2-5

LAN Management Solution (LMS), unsupported use 3-2

licenses

file locations for

PerformanceMonitor 1-6

RME 1-5

installing 1-8

Product Authorization Key (PAK) 1-7

SecurityManager kit part numbers 1-7

settings 1-7

Software License Claim Certificate 1-7

understanding 1-7

upgrading 1-7

uploading new 1-7

working with 1-7

license server TCP port 2-3

M

Management Center for Cisco Security Agents (CSAMC), documentation xiv

Management Center for IPS Sensors (IPSMC). See IPS Manager

McAfee Antivirus

incompatibility 3-5, 5-6

reenabling 5-8

requirement to disable 5-6

requirement to uninstall 3-5

memory (RAM)

client requirements 2-6

server requirements 2-4

Monitoring Center for Performance. See Performance Monitor

Mozilla

confirming the installed Java version 2-7

security settings 5-9

versions supported 2-5, 2-7

N

NETBIOS, recommendation to disable 3-4

Networking Professionals Connection xxi

network protocols, recommendation to disable 3-4

network shares, recommendation to avoid 3-4

Network Time Protocol (NTP) server, recommendation to use 2-1, 3-5

Norton Internet Security 2005

incompatibility 5-6, 5-8

requirement to disable 5-6

requirement to uninstall 5-8

NTFS file system, requirement to use 2-4

O

ODBC driver manager

confirming the installed version 2-5

requirements 2-5

working with Sybase files 2-5

OGS TCP port 2-3

online help, tips for viewing 5-1

operating systems

on client systems

Windows2000 2-7

Windows2003 2-7

WindowsXP Professional 2-7

on servers

Windows2000 2-5

Windows 2003 Server 2-5

Osagent UDP port 2-3

overview 1-1

P

passwords

admin account 4-5

requirement to use identical passwords 4-5

security basics D-4

strong passwords

characteristics D-3

definition 3-3

how to require 3-3

recommendations D-3

System Identity Account 4-5

peer support, Networking Professionals Connection xxi

Performance Monitor

availability xiv

documentation xiv

entitlement to install 1-6

license file location 1-6

licensing 1-7

overview 1-6

PERL5LIB variable

deleting before installation 4-2

restoring after installation 4-2

permanent license, upgrading from evaluation license 1-7

point patches

applying to a client 5-9

applying to a server 4-9

caution against accepting from a third-party 4-8

default location on client systems 5-10

deleting Temp files on client systems 5-6

obtaining 4-8

recommendation to delete Temp files on client systems 5-9

version mismatch 5-9

popup blockers

configuring 5-1, 7-2

conflicting with other installed software 3-3

disabling 5-1, 7-2

requirements 7-2

troubleshooting 5-1, 7-2

ports

required for TCP 2-2

required for UDP 2-2

product registration. See licenses

PSIRT

email addresses

emergencies xvii

nonemergencies xvii

telephone numbers xvii

publications, obtaining additional xx

R

related documentation, obtaining xii

Remote Copy Protocol TCP port 2-2

removable media drives, security implications if compromised 6-6

requirements

client system 2-6

servers

installation, general 2-1

system 2-4

Resource Manager Essentials (RME)

documentation xiii

entitlement to install 1-5

installing 1-5

license file location 1-5

licensing 1-7

overview 1-5

S

SAFE blueprint viii

Secure Shell (SSH) TCP port 2-2

security

advisories xvi

emergencies, definition xvii

incidents, obtaining assistance xvi

news from Cisco

registering to receive xvi

RSS feed URL xvi

nonemergencies, definition xvii

notices xvi

PSIRT xvi

vulnerabilities, reporting xvi

SecurityManager database TCP port 2-3

SecurityMonitor 4-2

server

configuration

boot settings 3-4

date and time settings 3-5

file locations

database files 1-9

log files 1-9

miscellaneous files 1-9

installations

best practices 3-1

dependencies 2-1

procedures 4-1

performance

best practices for enhancing 3-1

operating environment 2-4, 4-3

preparation checklists 3-1

processes, verifying status 6-7

traffic

required inbound ports 2-2

required outbound ports 2-2

service agreement contracts 1-7

service packs

applying to a client 5-9

applying to a server 4-9

caution against accepting from a third-party 4-8

default location on client systems 5-10

deleting Temp files on client systems 5-6

obtaining 4-8

recommendation to delete Temp files on client systems 5-9

version mismatch 5-9

service requests

severity level definitions xix

submitting xix

services

minimum required for Windows 3-4

required for TCP 2-2

required for UDP 2-2

SNMP polling UDP port 2-2

SNMP trap UDP port 2-2

software updates. See point patches

SSL certificate invalidation 3-5

SSL mode (for HTTP server) TCP port 2-2

support

Networking Professionals Connection xxi

obtaining from Cisco xviii

service agreement contracts 1-7

Software Application Support contracts 1-7

Sybase, requirement to disable 3-6, 4-4

Sybase database files, requirement to use correct ODBC version 2-5

Syslog UDP port 2-2

T

TCP

list of required ports 2-2

list of required services 2-2

technical support (TAC)

obtaining xviii

URL for service requests xix

Telnet TCP port 2-2

Terminal Services

requirements 2-6, 3-6

unsupported configuration 2-6

Tomcat

Ajp13 connector TCP port 2-3

global library files, where stored 1-9

shutdown TCP port 2-3

training, obtaining xxi

Trivial File Transfer Protocol (TFTP) UDP port 2-2

troubleshooting

antivirus scanners 3-3

Cisco Security Agent

blocking a valid operation B-11

blocking network access B-9

diagnostic utility B-11

icon appearance changed in system tray B-10

obtaining a revised agent from TAC B-10

recognizing when the agent is disabled B-10

security level is High B-9

setting the security level to Medium B-10

untrusted rootkit detected B-9

using the log file B-9

collecting server troubleshooting information B-12

DCRServer process does not start 3-5

environment variables 4-2

error messages

client installation B-7

server installation B-2

server uninstallation B-6

file contents cannot be unpacked 4-4

file corruption

executable file 4-4

host-based intrusion software 3-3

incorrect GUI 2-6, 6-7, B-4

installation

does not run B-9

hangs B-3, B-8

problems due to PERL5LIB 4-2

reviewing log files B-14

interoperation with CS-MARS 3-5

invalid SSL certificate 3-5

java.security.cert errors 3-5

mapped drives B-5

missing

GUI B-4

product features B-4

PERL5LIB 4-2

popup blockers 3-3, 5-1, 7-2

security software conflicts 3-3

server processes

changing B-12

restarting B-13

viewing B-12

server self-test B-11

uninstallation

does not run B-9

hangs B-6

using MDCSupport.exe B-12

troubleshooting guide, obtaining x

typographical conventions in this document viii

U

UDP

list of required ports 2-2

list of required services 2-2

uninstallation

cautions against

uninstalling from infected servers 4-10

client software 5-11

InstallShield database corruption 5-11

recommendation to restart client systems 5-12

recommendation to restart servers 4-11

servers

deleting CMFLOCK.TXT 4-11

failure to delete CSCOpx/bin folder 4-11

server software 4-10

updates. See point patches

user accounts

admin D-2

casuser D-2

System Identity D-2

understanding D-1

user permissions, understanding D-3

using SecurityManager 7-4

V

variables, viewing environment variables 4-2

verifying an installation 6-6

W

web context files, where stored 1-9

Windows services, required 3-4