User Guide for CiscoWorks Common Services 3.1.1
Index

Table Of Contents

A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - R - S - T - U - V - W -

Index

A

AAA clients, configuring 4-49

access

connection security, understanding A-5

control, security and A-4

ACS

applications, registering 4-43

applications, registering through CLI 4-44

authentication failure 4-45

Common Services tasks 4-54

custom roles 4-53

predefined roles 4-52

roles on NDG basis, assigning 4-56

roles to user groups, assigning 4-54

roles to users, assigning 4-55

ACS Administrators, configuring 4-48

ACS Connection Status 3-6

adding devices to the device list 5-42

for AUS management 5-44

for cluster management 5-47

for standard management 5-42

using dcrcli 5-101

administering

Common Services 4-64

Daemon Manager, using 4-65

processes, back-end processes 4-69

processes, managing 4-66

processes, managing through CLI 4-71

processes, starting 4-68, 4-73

processes, stopping 4-68

processes, viewing 4-67

processes, viewing specific state processes 4-68

DCR 5-91

Master-Slave configuration, prerequisites 5-92

mode, changing 5-92

user-defined fields, adding 5-94

user-defined fields, deleting 5-95

user-defined fields, renaming 5-95

application registration, ACS 4-43

application registration through CLI, ACS 4-44

applications

Application panels in CiscoWorks Home Page 2-7

licensing

licensing information, viewing 4-85

licensing procedure 4-85

obtaining a license 4-85

updating licenses 4-86

registering with CiscoWorks Home Page 4-103

troubleshooting

applications not appearing 10-21

audience for this document xi

audit logs, viewing 4-62

AUS (Auto Update Server)

managing 5-70

adding 5-70

deleting 5-71

editing 5-71

setting up 5-44

Authentication failure in ACS 4-45

B

backing up data 4-73

back-up data

directory structure of 10-25

sample CMF backup directory 10-25

using CLI 4-75

Base64-encoded X.509 certificate format, definition A-7

browser issues 2-10

address bar, disabling 2-11

modal dialog box, enabling 2-11

popup dialog boxes, displaying 2-10

reports download, enabling 2-12

status bar, disabling 2-11

tabbed browsing, disabling 2-11

browsers, supported 2-10

browser-server security. See SSL

C

cautions

significance of xi

cautions regarding

admin password, guest password 4-7

backups, and the CiscoWorks Daemon Manager 4-93

data restoration from a backup 4-76

restarting Daemon Manager on Solaris 4-65

restarting Daemon Manager on Windows 4-65

certificates

terms and definitions in A-6

Base64-encoded X-509 certificate format A-7

CA (certificate authority) A-7

CiscoWorks TrustStore or KeyStore A-7

PKCS#8 A-6

public key, private key A-6

SSH A-6

SSL A-6

understanding A-5

Cisco.com connection, managing 4-57

CiscoWorks - ACS Integration 4-46

ACS server, setting up 4-47

AAA clients, configuring 4-49

ACS Administrators, configuring 4-48

CiscoWorks Admin Users, configuring in ACS 4-51

Multiple ACS servers, configuring 4-51

NDG, creating 4-48

login module, changing 4-52

prerequisites 4-47

roles in ACS 4-52

Common Services Tasks 4-54

Custom roles 4-53

predefined roles 4-52

roles to Users and User groups, assigning 4-54

Network Access restrictions 4-57

CiscoWorks Administrative Users, configuring in ACS 4-51

CiscoWorks Home Page 2-1

Common Services panel 2-7

configuring 4-102

registering applications 4-103

registering links 4-105

setting up 4-106

invoking 2-2

normal mode (HTTP) 2-2

SSL Enabled mode (HTTPS) 2-3

layout 2-6

logging in to Common Services 2-6

online help, using 2-12

using

Application panels 2-7

CiscoWorks Product Updates panel 2-8

Common Services panel 2-7

Device Diagnostic Tools panel 2-8

navigation tools 2-9

Resources panel 2-8

too lbar buttons 2-8

web server port numbers, changing 2-13

CiscoWorks LMS Portal

invoking 2-2

CiscoWorks Server, troubleshooting 10-1

collecting information on 10-1

FAQs 10-4

locked out of 10-6

MDC support 10-2

process status, checking 10-1

self-test, performing 10-1

CiscoWorks Server back-end process 4-69

CiscoWorks Server Processes 4-69, 4-71

CiscoWorks Trust Store or KeyStore, definition A-7

cmf as part of database path, explanation of 10-6

Common Services Home 3-1

Layout 3-2

Panes 3-4

Backup Status 3-7

Device Credentials and Admin Settings 3-9

Device Management Tasks 3-12

Management Tasks 3-14

Online Users 3-7

Recently Completed Jobs 3-8

Reports 3-13

Security Settings 3-4

System Tasks 3-11

Common Services Server, overview of 1-6

connection security, understanding A-5

security certificates A-5

terms and definitions A-6

Base64-encoded X.509 certificate format A-7

CA (certificate authority) A-7

CiscoWorks TrustStore or KeyStore A-7

PKCS#8 A-6

public key, private key A-6

SSH A-6

SSL A-6

connectivity

Connectivity Tools Tasks (table) 10-3

tasks 10-1

checking process status 10-1

collecting server information 10-1

MDC support 10-2

performing a self-test 10-1

testing 10-3

Custom roles in ACS 4-53

D

Daemon Manager, using 4-65

restarting on Solaris 4-65

restarting on Windows 4-65

database

inaccessible, troubleshooting 10-26

path includes "cmf," explanation 10-6

DCR

administering 5-91

Master-Slave configuration, prerequisites 5-92

mode, changing 5-92

user-defined fields, adding 5-94

user-defined fields, deleting 5-95

user-defined fields, renaming 5-95

architecture 5-8

Master DCR 5-8

Slave DCR 5-8

Standalone DCR 5-9

AUS management

adding devices 5-70

deleting AUS 5-71

editing devices 5-71

CSV file samples 5-60

CSV 2.0 5-60

CSV 3.0 5-61

devices, managing 5-41

adding 5-42

deleting 5-50

excluding 5-68

exporting 5-65

importing 5-53

viewing the device list 5-69

Device Selector, using (See Device Selector) 5-78

reports, generating 5-71

using features, Master-Slave Setup 5-112

dcr

implications on ACS 5-110

DCR (Device and Credential Repository) CLI interface, using 5-100

adding devices 5-101

CDR mode, changing 5-105

deleting devices 5-102

editing devices 5-103

exporting using 5-109

importing using 5-106

listing attributes 5-103, 5-104

viewing current DCR mode 5-104

viewing device details 5-105

deleting

AUS (Auto Update Server) 5-71

device groups 6-21

devices

from DCR 5-50

from the device list, using dcrcli 5-102

user-defined fields from DCR 5-95

users 4-10

Device and Credential Admin 5-1

Device Center 8-1

debugging tools, enabling 8-4

management station to device 8-4

packet capture 8-13

Ping, using 8-7

SNMP Set 8-10

SNMP Walk, using 8-8

Traceroute, using 8-8

invoking 8-2

launching 8-2

management functions

management tasks 8-16

reports, displaying 8-16

using 8-3

Device Selector 8-3

reports 8-16

Device Diagnostic Tools panel of CiscoWorks Home Page 2-8

devices, discovery 5-10

scheduling 5-32

adding 5-33

deleting 5-34

editing 5-33

viewing status 5-34

viewing details 5-34

devices added to DCR 5-39

devices updated to DCR 5-39

reachable devices 5-37

summary 5-35

total devices discovered 5-36

unreachable devices 5-38

devices, discovery settings

configuring 5-11

configuring filter settings 5-22

configuring global settings 5-25

configuring module settings 5-12

configuring seed devices 5-14

configuring SNMP settings 5-18

viewing 5-30

viewing summary 5-29

devices, discovery starting 5-32

devices, managing 5-41

adding 5-42

for AUS management 5-44

for cluster management 5-47

for standard management 5-42

credentials

editing 5-52

exporting 5-65

importing 5-53

deleting 5-50

device list, viewing 5-69

excluding 5-68

exporting 5-65

using CLI 5-109

using Device and Credential Admin user interface 5-67

importing 5-53

using CLI 5-106

using Device and Credential Admin user interface 5-54

See also Groups, administering

See also Software Center

Device Selector 5-78

Device Selector settings 5-84

searching devices 5-81

Advanced Search 5-81

Simple Search 5-81

selecting devices 5-80

using Device Selector 5-78

diagnosing problems. See troubleshooting

discovering devices 5-10

discovery, scheduling 5-32

discovery CLI interface, using 5-99

start 5-99

stop 5-100

view discovery 5-100

discovery features in

ACS mode 5-113

Master-Slave setup 5-113

discovery filter settings, configuring 5-22

discovery global settings, configuring 5-25

discovery module settings, configuring 5-12

discovery settings

viewing summary 5-29

discovery settings, viewing 5-30

discovery SNMP settings 5-18

discovery start 5-32

disk space, threshold configuring 4-100

documentation xii

additional online xii

audience for this xi

related to this product xii

typographical conventions in xi

E

editing

AUS (Auto Update Server) 5-71

device credentials in DCR 5-52

device group details 6-19

devices in the device list, using dcrcli 5-103

local user profile 4-8

user profiles 4-9

ESS (Event Service Software)

changing the port for

in Solaris 10-23

in Windows 10-23

excluding devices from the device list 5-68

expired server certificate, how to handle 10-12

exporting devices and credentials 5-65

using CLI 5-109

using Device and Credential Admin user interface 5-67

F

file ownership, and permissions A-2

G

Groups, administering 6-1

concepts 6-2

common 6-4

container groups 6-3

dynamic groups 6-3

group hierarchy 6-3

secured views 6-5

shared 6-4

static groups 6-3

system-defined, user-defined 6-3

creating 6-9

deleting

groups 6-21

details

modifying 6-19

viewing 6-19

editing 6-19

Group Administration 6-9

group membership, assigning 6-18

multi-server setup 6-6

properties, specifying 6-10

refreshing 6-20

rules, defining 6-11

composite rule 6-13

range operator 6-14

simple rule 6-12

single server scenario 6-6

single server setup 6-6

syntax checking 6-13, 6-14

system- and user-defined attributes 6-17

system defined attributes 6-17

H

help

CiscoWorks Product Updates panel of CiscoWorks Home Page 2-8

online documentation xii

Hostname change script, using 4-107

I

IBM SecureWay Directory, changing login module to 4-31

importing devices and credentials 5-53

using CLI 5-106

using Device andf Credential Admin user interface 5-54

IP Address range operator, See range operator

J

Java Plug-in, version to use 10-5

jobs

managing 4-89

jrm, checking 10-8

K

KerberosLogin, changing login module to 4-32

L

licensing CiscoWorks applications

license information, viewing 4-85

licensing procedure 4-85

obtaining a license 4-85

updating licenses 4-86

links, registering with CiscoWorks Home Page 4-105

LMS Setup Center 7-1

categories 7-2

Data Collection Schedule 7-8

Data Collection Settings 7-5

Data Purge Schedule 7-9

Security Settings 7-4

System Settings 7-3

launching LMS Setup Center 7-2

local user policy setup 4-5

locked out of CiscoWorks Server, troubleshooting 10-6

log files, maintaining 4-92

Log File Status report, generating 4-58

on UNIX 4-95

on Windows 4-96

logrot utility, configuring 4-96

logrot utility, running 4-97

logrot utility, using 4-96

login module

setting to ACS 4-40

application, unregistering through CLI 4-45

application registration 4-43

application registration through CLI 4-44

setting to non-ACS 4-29

CiscoWorks Local, changing to 4-30

IBM SecureWay Directory, changing to 4-31

KerberosLogin, changing to 4-32

local NT system, changing to 4-33

Local UNIX system, changing to 4-32

MS Active Directory, changing to 4-34

Netscape Directory, changing to 4-37

Radius, changing to 4-38

TACACS+, changing to 4-38

logrot utility

configuring 4-96

running 4-97

using 4-96

M

managing

Common Services jobs 4-89

Common Services resources 4-91

messaging online users 4-89

MS Active Directory, changing login module to 4-34

Multiple ACS servers, configuring 4-51

multi-server mode, and security 4-18

N

NAR. See Network Access Restrictions.

navigation tools on CiscoWorks Home Page, using 2-9

NDG, creating 4-48

Netscape Directory, changing login module to 4-37

Network Access Restrictions 4-57

Network Device Groups, creating. See NDG, creating

O

online help, using 2-12

online users, messaging 4-89

osagent, changing the port for

Solaris 10-7

Windows 10-7

overview

authentication using login modules 4-26

overview of

CiscoWorks Common Services 1-1

Common Services Server information 1-6

time zone settings, understanding 1-6

what's new in this release 1-2

Common Services Server 1-6

P

packet capture, using 8-13

peer server certificates

setting up 4-20

Permissions report, generating 4-59

PKCS#8, definition A-6

port numbers for web servers, changing 2-13

Predefined roles in ACS 4-52

preferences for system, modifying 4-98

private key, definition A-6

processes, managing 4-71

Process Status report, generating 4-60

PSUCLI 9-12

device packages, installing 9-13

device packages, listing dependents 9-15

device packages, listing device packages 9-16

device packages, uninstalling 9-14

device updates, downloading 9-15

software updates, downloading 9-14

software updates, querying 9-13

public key, definition A-6

R

Radius, changing login module to 4-38

range operator 6-14

remote connectivity, security and A-4

reports

Common Services reports 4-57

audit logs, viewing 4-62

Log File Status report 4-58

Permissions report 4-59

Process Status report 4-60

Users Logged In report 4-60

DCR Admin reports, generating 5-71

Device Center reports 8-16

resources, managing in Common Services 4-91

Resources panel of CiscoWorks Home Page 2-8

runtime security, understanding A-3

S

Secure Shell (SSH), definition A-6

security

access control, and A-4

certificates, understanding A-5

understanding A-1

general A-1

server A-2

security, setting up 4-2

AAA mode, setting up 4-25

Cisco.com login, setting up 4-57

Cisco Secure ACS support 4-28

configuring, ACS Integration 4-46

login module

setting to ACS 4-40

setting to non-ACS 4-29

multi-server mode 4-18

peer server certificates

setting up 4-20

proxy server, setting up 4-57

security levels, understanding 4-7

SSL 4-2

enabling from the CiscoWorks Server 4-3

enabling from the CLI 4-3

SSO (Single Sign-On) mode

changing 4-24

enabling 4-21

user management

local user profile, modifying 4-8

peer server, setting up 4-18

user profiles, editing 4-9

users, adding 4-8

users, deleting 4-10

users, setting up through CLI 4-10

seed devices, configuring 5-14

Self Signed certificates 4-12

self-test information, collecting 4-88

server, configuring 4-1

AAA mode, setting up 4-25

authentication using login modules 4-26

ACS Integration 4-46

applications, licensing

licensing information, viewing 4-85

licensing procedure 4-85

obtaining a license 4-85

updating licenses 4-86

certificate setup 4-12

Cisco.com login, setting up 4-57

CiscoSecureACS support 4-28

Common Services, administering 4-64

backing up data 4-73

Daemon Manager, using 4-65

jobs, managing 4-89

processes, managing 4-66

processes, managing through CLI 4-71

resources, managing 4-91

server information, collecting 4-86

disk space, threshold configuring 4-100

log files, maintaining 4-92

List of log files 4-93

on UNIX 4-95

on Windows 4-96

logging, configuring 4-99

login module

ACS 4-40

ACS, setting up 4-40

setting to ACS 4-40

setting to ACS, application registration 4-43

setting to ACS, application registration through CLI 4-44

setting to non-ACS 4-29

peer server certificates

setting up 4-20

proxy server, setting up 4-57

reports, generating 4-57

audit logs, viewing 4-62

Log File Status report 4-58

Permissions report 4-59

Process Status 4-60

Users Logged In 4-60

security. See security, setting up

Self-signed certificates 4-12

SSO (Single Sign-On) mode

changing 4-24

enabling 4-21

system preferences, modifying 4-98

user management

adding 4-8

adding through CLI

deleting 4-10

local user policy setup 4-5

local user profile, modifying 4-8

peer server, adding 4-18

setting up through CLI 4-10

user profile, editing 4-9

users, local, setting up 4-8

server certificate for CiscoWorks, expiration, how to handle 10-12

server information, collecting (Common Services) 4-86

server security, understanding A-2

administrator-imposed A-5

connection A-5

security certificates A-5

terms and definitions A-6

server-imposed A-2

access control A-4

files, file ownership, permissions A-2

other systems A-4

remote connectivity A-4

runtime A-3

setting up, local user policy 4-5

SNMP Set, using 8-10

SNMP settings, configuring 5-18

SNMP Walk, using 8-8

Software Center 9-1

activity logs, viewing 9-10

event log 9-11

scheduled job 9-10

device downloads, scheduling 9-9

device updates, checking 9-6

device updates, performing 9-5

packages, deleting 9-8

software updates, downloading 9-4

software updates, performing 9-2

list of applications installed, viewing 9-3

software updates, selecting 9-3

Software Center CLI utility 9-12

Solaris, changing ports in

for ESS 10-23

for osagent 10-7

SSL, enabling on the server 4-2

from the CiscoWorks Server 4-3

from the CLI 4-3

SSL, definition A-6

SSO (Single Sign-On) mode

changing 4-24

enabling 4-21

starting CiscoWorks applications, troubleshooting 10-5

supported browsers 2-10

T

TACACS+, changing login module to 4-38

technical support

CiscoWorks Product Updates panel of CiscoWorks Home Page 2-8

terms and definitions in security certificates A-6

Base64-encoded X.509 certificate format A-7

CA (certificate authority) A-7

CiscoWorks TrustStore or KeyStore A-7

PKCS#8 A-6

public key, private key A-6

SSH A-6

SSL A-6

time zone settings, understanding 1-6

toolbar buttons on CiscoWorks Home Page, using 2-8

Tool Bar items on CiscoWorks Home Page, using 2-8

troubleshooting

applications not appearing 10-21

back-up data, directory structure of 10-25

CiscoWorks applications, starting 10-5

CiscoWorks Server 10-1, 10-4

device connectivity, testing 10-3

FAQs 10-4

locked out of, diagnosing 10-6

server status, verifying 10-1

database

inaccessability 10-26

path includes "cmf" 10-6

devices, with the Device Diagnostic Tools panel of CiscoWorks Home Page 2-8

ESS port change

Solaris 10-23

Windows 10-23

FAQs list 10-4

Apache and Tomcat 10-28

Backup-restore 10-25

CiscoWorks Home Page 10-21

Common Services General 10-5

Database 10-26

Device Center 10-20

Device Management 10-18

EDS and ESS 10-23

Security 10-11

Software Center 10-17

Java Plug-in, which version to use 10-5

jrm 10-8

osagent port change

Solaris 10-7

Windows 10-7

See also debugging tools under Device Center

suggestions 10-35

typographical conventions in this document xi

U

UNIX systems

changing login module to local UNIX system 4-32

log files, maintaining on 4-95

user accounts

setting up

Cisco.com 4-57

local 4-8

Users Logged In report, generating 4-60

V

verifying CiscoWorks Server status 10-1

viewing

application license information 4-85

audit logs 4-62

device list 5-69

group details 6-19

Software Center activity logs 9-10

W

web server port numbers, changing 2-13

Whats New In This Release 1-2

Windows 2003 or Windows NT systems

log files, maintaining on 4-96

Windows systems

changing the port

for ESS 10-23

for osagent 10-7

jrm, running 10-8