User Guide for Auto Update Server 3.1
Index

Table Of Contents

A - B - C - D - E - F - G - H - I - L - M - N - O - P - R - S - T - U - V - W -

Index

A

AAA authentication

AUS and 3-7

ACS roles, overview 1-4

Adaptive Security Device Manager

See ASDM

adding

ASDM, PDM, or security appliance image files, troubleshooting B-6

devices

directly to AUS 3-5

of auto update type to DCR A-12

that exist in DCR to Security Manager A-12

to Common Services, DCR A-12

to Security Manager A-4

software images 4-2

administrative tasks 7-1

NAT settings, specifying 7-1

user roles and AUS permissions, understanding 1-6

Cisco Secure ACS roles C-4

CiscoWorks Server roles C-2

Apache webserver A-11

API Reader role and AUS privileges C-5

API Writer role and AUS privileges C-5

Approver role and AUS privileges C-3

ASA configuration files

assigning

to a single device 5-4

deleting 4-4

viewing 4-4

ASA devices

configuration files

viewing 4-4

image files

adding 4-2

deleting 4-4

initial configuration of (bootstrapping) D-1

number supported 1-3

ASA image files, troubleshooting

cannot add through the AUS GUI B-6

errors when trying to add B-6

ASA software images

assigning

to a single device 5-4

to multiple devices 5-7

deleting 4-4

ASDM 1-4

browser launch, overview 1-4

image files

adding, troubleshooting B-6

deleting 4-4

updating 2-17

launching

from AUS 3-14

from Security Manager 3-14

non-default HTTPS port number on the device 3-14

ASDM configuration files

assigning

to a single device 5-4

to multiple devices 5-7

ASDM image files, troubleshooting

errors when trying to add B-6

ASDM images

deleting 4-4

assigning devices to images, overview 1-3

assigning images to a device

multiple images 5-4

one image 5-7

overview 1-3

Select Device Assignments for Image page elements (table) 5-8

AUS (Auto Update Server)

managing from DCR

adding A-15

deleting A-16

editing A-15

AUS database 1-5

back up of 1-5

AUS Remote Interface role and privileges C-5

authentication errors, troubleshooting B-4

auto update

configuring a schedule 3-8

scheduling 3-8

Auto Update Feature

overview 1-3

using 3-12

Auto Update Immediate feature

auto update credentials, and 3-7

HTTPS port number

changing from default 3-12

restriction 3-12

overview 1-5

TACACS user name, and 3-7

auto update type

canceling a schedule 3-10

auto update types

any time 3-8

daily 3-8

never 3-8

one time 3-8

weekly 3-8

B

backup

of AUS database 1-5

bootstrapping devices to work with AUS D-1

CNS devices D-6

security appliances D-1

browser access to AUS, troubleshooting B-8

browser-server security

enabling on the server

from the CiscoWorks Server GUI 2-9

from the CLI 2-10

buttons grayed-out, troubleshooting B-9

C

canceling

a scheduled auto update 3-10

cautions

regarding

ASDM and PDM image files, updating 2-17

ASDM launching 3-14

configuration files, deleting 4-4

deleting an image file assigned to multiple devices 4-4

device manager launching 3-14

PDM launching 3-14

security appliance image files, updating 2-17

simultaneous requests to a large number of devices to contact AUS 3-12

changing

CNS bootstrap password in AUS D-8

transport protocol

to AUS A-5

changing in AUS D-8

Cisco Secure ACS roles and AUS privileges

API Reader C-5

API Writer C-5

AUS Remote Interface C-5

GUI Reader C-5

GUI Writer C-5

Help Desk C-5

Network Administrator C-4

Network Operator C-4

table comparing C-5

Cisco Security Management Suite home page

opening

normal mode (HTTP) 2-2

SSL-enabled mode (HTTPS) 2-2

Cisco Security Management Suite server

logging into and exiting 2-3

Cisco Security Management Suite Server, logging in to 2-3

Cisco Security Manager

See Security Manager

CiscoWorks Common Services

logging into and exiting 2-3

CiscoWorks desktop, logging in to 2-3

CiscoWorks home page

opening

normal mode (HTTP) 2-2

SSL-enabled mode (HTTPS) 2-2

CiscoWorks Server roles, and AUS privileges C-2

Approver C-3

Help Desk C-3

Network Administrator C-3

Network Operator C-3

System Administrator C-3

table comparing C-3

CNS bootstrap password D-8

CNS devices

bootstrapping D-6

CNS Devices report, viewing 6-12

CNS Event Gateway feature

overview 1-3

Security Manager, and D-6

CNS services

configuring

on CNS devices D-6

Common Services

and AUS interoperability

overview of A-11

components for AUS A-11

Common Services, administering

daemon manager, using 2-9

Common Services Backup dialog box 1-5

Configuration Engine A-3

configuration files

assigning

overview 1-4

procedure 5-4, 5-7

deleting

overview 1-4

procedure 4-4

updating 2-14

viewing 4-4

viewing, overview 1-4

configuring

AUS settings

after adding devices to Security Manager A-7

before adding devices to AUS or Security Manager D-1

on CNS devices D-6

auto update schedule 3-8

CNS devices D-6

security appliances D-1

security appliances to use AUS A-2

Security Manager and AUS

to communicate with PIX and ASA devices A-2

Security Manager to use AUS A-3

credentials

specifying

for device to authenticate AUS 3-7

for device to contact AUS 3-7

D

daemon manager

restarting on Windows 2-9

DCR A-12

adding, devices to A-12

and AUS credentials A-14

cannot add a display name that exists in A-6

cannot add DNS hostname/domain name that exists in A-7

overview of A-12

DCR Administration

AUS management

adding devices A-15

deleting AUS A-16

editing devices A-15

deleting

ASDM image files 4-4

AUS (Auto Update Server) A-16

configuration files 4-4

devices

from AUS 3-12

from DCR 3-11

from Security Manager 3-11

PDM image files 4-4

security appliance image files 4-4

deploying

AUS behind NAT

in enterprise DMZ 1-6

in enterprise networks 1-6

configurations

using non-Workflow mode A-3

using Workflow mode A-3

deployment job

configuring

Security Manager to use AUS A-3

Deployment Manager window A-9

and status of deployment A-9

deployment mechanism

overview of

for AUS-managed devices A-9

deployment method

and transport protocols A-10, A-11

for IOS routers

added using Add Device from Network option A-11

for PIX and ASA devices

added using the Add New Device option A-10

Detail Device Event report, viewing 6-12

Device Administration policy

configuring AUS settings, using A-7

Device and Credential Repository

See DCR

device import

understanding A-4

device manager, launching

from Security Manager 3-14

HTTPS port number

changing from default value 3-14

devices

adding

directly to AUS 3-5

from Security Manager A-4

AUS, viewing devices that have contacted 6-3

bootstrapping to work with AUS D-1

CNS devices D-6

security appliances D-1

deleting 3-11

device summaries

device not appearing in, troubleshooting B-2

summary element descriptions (table) 3-2

viewing 3-1

device support

adding directly to AUS, overview 1-3

deleting from AUS, overview 1-4

HTTPS port number

device manager, launching 3-14

image assignments

caution regarding assignment to multiple devices 4-4

Device Assignment Summary (table) 5-3

summaries of, viewing in AUS 5-3

initial configuration (bootstrapping) D-1

CNS devices D-6

security appliances D-1

IOS devices with dynamically assigned addresses, managing 1-3

rebooting after assignment B-8

summary information on, viewing 3-1

troubleshooting

downloading the same file repeatedly B-8

not appearing in device summaries B-2

not contacting AUS B-2

two images of the same type assigned B-7

DHCP support feature 1-3

discovery

of a device A-5

discovery mechanism

overview of

for AUS-managed devices A-8

discovery method

and transport protocols A-10, A-11

for IOS routers

added using Add Device from Network option A-11

for PIX and ASA devices

added using the Add New Device option A-10

DMZ

AUS deployment and 1-6

E

editing

AUS (Auto Update Server) A-15

polling interval 3-9

enable password

specifying

for device to authenticate AUS 3-7

error messages, understanding B-12

Event Failure Summary report, viewing 6-8

Event report, viewing 6-3

element descriptions (table) 6-4

Event Type Descriptions (table) 6-6

exiting

Cisco Security Management Suite Server 2-3

CiscoWorks Common Services 2-3

F

Firewall Services Module 1-5

FWSM

See Firewall Services Module

G

getting started 2-1

navigating in AUS 2-1

CiscoWorks Login Window (figure) 2-6

CiscoWorks server desktop (figure) 2-8

logging in to the CiscoWorks desktop 2-3

starting AUS 2-6

GUI Reader role and AUS privileges C-5

GUI Writer role and AUS privileges C-5

H

Help Desk role and AUS privileges

Cisco Secure ACS C-5

CiscoWorks Server C-3

HTTPS port number

changing from default

device manager, launching 3-14

requesting auto update 3-12

I

image (file) management 1-3

image assignments

summary information for, viewing 5-6

to devices

Assign an Image to Devices (table) 5-8

Device Assignment Summary (table) 5-3

multiple images 5-4

one image 5-7

summary information, viewing 5-3

troubleshooting

cannot apply two images of the same type B-7

devices not current after assignment B-7

IOS devices

and CNS Event Gateway 1-2

L

logging into

Cisco Security Management Suite 2-3

M

managed devices

bootstrapping D-1

list of 1-3

modifying

polling interval

for AUS-device contact 3-9

N

NAT

and AUS deployment 1-6

settings, specifying 7-1

support feature 1-3

navigating in AUS 2-1

Network Administrator role and AUS privileges

Cisco Secure ACS C-4

CiscoWorks Server C-3

Network Operator role and AUS privileges

Cisco Secure ACS C-4

CiscoWorks Server C-3

No Contact Since report, viewing 6-11

non-Workflow mode

overview of A-3

O

overview of AUS 1-1

administrative tasks

NAT settings, specifying 7-1

user roles and permissions, understanding 1-6

deploying AUS in your network 1-6

features in this release 1-3

ACS roles consistent with CiscoWorks format 1-4

ASDM browser launch 1-4

ASDM file management 1-3

Auto Update Feature 1-3

backup of AUS database 1-5

canceling an auto update 1-5

configuration files, deleting 1-4

device assignment to configuration files 1-4

device assignment to images 1-3

devices, adding directly in AUS 1-3

devices, deleting 1-4

DHCP support 1-3

disabling auto updates 1-5

image (file) management 1-3

integration with Security Manager 1-5

IOS devices, managing 1-3

managed devices list 1-3

NAT support 1-3

PDM browser launch 1-4

PDM file management 1-3

reports 1-4

restore of AUS database 1-5

scheduling an auto update 1-5

security appliance configuration file assignment 1-3

security appliances, number supported 1-3

Solaris support 1-5

support for ASA 1-5

support for PIX software version 7.0 1-5

P

password

changing for CNS services D-8

specifying

for device to contact AUS 3-7

PDM 1-4

browser launch, overview 1-4

image files

adding, troubleshooting B-6

deleting 4-4

updating 2-17

launching

from AUS 3-14

from Security Manager 3-14

non-default HTTP port number on the device 3-14

PDM configuration files

assigning

to a single device 5-4

to multiple devices 5-7

PDM image files, troubleshooting

cannot add through the AUS GUI B-6

errors when trying to add B-6

PDM images

deleting 4-4

PIX configuration files

assigning

to a single device 5-4

deleting 4-4

viewing 4-4

PIX Device Manager

See PDM

PIX image files, troubleshooting

cannot add through the AUS GUI B-6

errors when trying to add B-6

PIX security appliances

number supported 1-3

See security appliances

PIX software images

assigning

to a single device 5-4

to multiple devices 5-7

deleting 4-4

policies

assigning to device A-4

deploying A-3

discovery of A-8

policies, factory-default A-7

polling interval

default value 3-8

for devices to contact AUS

modifying 3-9

modifying

from Security Manager 3-9

from the Device view 3-10

from the Policy view 3-10

on the device D-3

setting

on the device D-3

R

rebooting, cannot start AUS after, troubleshooting B-9

reports

report types in this release 1-4

viewing

CNS Devices report 6-12

Detail Device Event report 6-12

Event Failure Summary report 6-8

Event report 6-3

Event Success Summary report 6-10

No Contact Since report 6-11

System Info report 6-1

troubleshooting reports B-8

restoring 1-5

AUS database 1-5

S

security, setting up

SSL

enabling from the CiscoWorks Server 2-9

enabling from the CLI 2-10

security appliances 4-4

configuration files

viewing 4-4

image files

adding 4-2

deleting 4-4

updating 2-17

initial configuration of (bootstrapping) D-1

number supported 1-3

Security Manager A-2

and CNS Event Gateway feature D-6

configuration

for using AUS A-2

device manager, launching 3-14

interoperation with AUS 1-5

overview of A-1

Security Manager menu options

not supported for AUS-managed devices

Add Device from Config File A-5

Add Device from Network A-5

supported for AUS-managed devices

Add Device from DCR A-5

Add New Device A-5

software files, managing 4-1

adding 4-2

deleting 4-4

image assignment

device assignment summary, viewing 5-3

image assignment summary, viewing 5-6

viewing 4-1

SQL database A-11

SSL, enabling on the server

from the CiscoWorks Server 2-9

from the CLI 2-10

starting

ASDM 3-14

AUS 2-6

auto updates in AUS 3-12

PDM 3-14

System Administrator role and AUS privileges

Cisco Secure ACS C-4

CiscoWorks Server C-3

System Info report, viewing 6-1

T

TACACS credentials

AUS and 3-7

TMS A-3

Token Management Server

See TMS

Tomcat servlet engine A-11

transport protocol

AUS A-5

changing to AUS A-5

CNS A-5

TMS A-5

transport protocols

for discovery and deployment

using Add Device from Network option A-11

using Add new Device option A-10

troubleshooting

FAQs

adding a file that is not a PIX image, ASA image, ASDM file, or PDM file B-6

ASDM or ASA image files, errors when trying to add B-6

authentication errors B-4

browser access to B-8

buttons grayed-out B-9

configuration errors, handling B-10

configuration file, stopping a device from downloading B-9

connection between AUS and a security appliance, checking B-10

device has not contacted AUS B-2

device not appearing in the device summary B-2

device not current after auto update request B-5

device rebooting after assignment of a new image B-8

device repeatedly downloading the same file B-8

error messages, understanding B-12

failure to start after reboot B-9

image assigned to a device not appearing B-7

image files, assigning two of the same type B-7

PDM or PIX image files, errors when trying to add B-6

reports older than seven days not displayed B-8

Security Manager, uninstalling with devices still in AUS B-9

image file, missing references between devices and 4-4

performance issues when requesting multiple devices contact AUS 3-12

U

user interface, understanding 2-10

GUI 2-10

table elements 2-12

username

specifying

for device to contact AUS 3-7

user roles and AUS privileges

Cisco Secure ACS roles, and C-4

API Reader C-5

API Writer C-5

AUS Remote Interface C-5

GUI Reader C-5

GUI Writer C-5

Help Desk C-5

Network Administrator C-4

Network Operator C-4

System Administrator C-4

table comparing C-5

CiscoWorks Server roles, and C-2

Approver C-3

Help Desk C-3

Network Administrator C-3

Network Operator C-3

System Administrator C-3

table comparing C-3

defining, overview of 1-6

using AUS to manage file assignments 5-1

V

viewing

configuration files 4-4

reports

CNS Devices report 6-12

Detail Device Event report 6-12

Event Failure Summary report 6-8

Event Report 6-3

Event Success Summary report 6-10

Event Success Summary report, viewing 6-10

No Contact Since report 6-11

System Info report 6-1

troubleshooting B-8

software files 4-1

VPN Acceleration Services Module 1-5

See VPNSM

VPNSM 1-5

W

Workflow mode

overview of A-3