SOFTWARE HOUSE From Tyco Security Products

EFTA01226472 Dataset 9 174 pages Download original PDF Download as text
SOFTWARE HOUSE From Tyco Security Products C•CURE 9000 Version 2.50 Installation and Upgrade Guide REVISION R0 UM-131-RO EFTA01226472 C•CURE and Software House are registered trademarks of Tyco Security Products. The trademarks, logos, and service marks displayed on this document are registered in the United States [or other countries]. Any misuse of the trademarks is strictly prohibited and Tyco will aggressively enforce its intellectual property rights to the fullest extent of the law, including pursuit of criminal prosecution wherever necessary. All trademarks not owned by Tyco are the property of their respective owners, and are used with permission or allowed under applicable laws. Product offerings and specifications are subject to change without notice. Actual products may vary from photos. Not all products include all features. Availability varies by region; contact your sales representative. C•CURE 9000 Version: 2.50 Document Number: UM-131 Revision: R0 Release Date: December 2015 This manual is proprietary information of Software House. Unauthorized reproduction of any portion of this manual is prohibited. The material in this manual is for information purposes only. It is subject to change without notice. Software House assumes no responsibility for incorrect information this manual may contain. O 2015 Tyco Security Products All rights reserved. EFTA01226473 Table of Contents Preface How to Use this Manual Finding More Information xii Conventions xiii Chapter 1 C•CURE 9000 Overview Understanding Clients and Servers 1-2 The Server for C•CURE 9000 1-2 Supported Hardware 1-2 Readers 1-2 The C•CURE 9000 Client 1-3 Administration Application 1-3 Monitoring Station 1-3 Networking Protocol 14 Hardware - Controllers/ Panels 1-5 STAR Controllers 1-5 apC/8X Panels 1-5 Hardware/Software Capacities for the Server 1.6 Hardware/Software Requirements for Clients 1-7 Optional Hardware and Software 1-8 Chapter 2 Setting Up Software and Hardware Installing Windows 2-2 C•CURE 9000 Installation Location 2-2 Connecting the Computer to the Network 2-3 Server/Client Setup Requirements 2-3 Network Protocol 2-3 Setting Fonts and Screen Resolution 2-3 Verifying TCP/IP 2-3 Synchronizing Time for Networked Computers 2-4 Configuring a Separate Time Server 2-5 Configuring Each Computer To Get Time from Internet Independently 2-5 Setting a Domain Controller as Time Server and Synchronizing It with External Time Source 2-5 Synchronizing Non-domain Time Server Computers with External Time Source 24 Configuring a Non-domain Computer as Time Server 24 Manually Configuring Computers to Synchronize with Time Server—When Not in a domain 2-7 Manually Configuring Computers to Synchronize with Domain Time Server 2-8 C•CURE 9000 Installation and Upgrade Guido Ill EFTA01226474 Table of Contents Setting System Clock 2-8 Configuring Network Communications 2-10 C•CURE 9000 Clients 240 STAR Controllers 240 Connecting apCs 240 NetVue Controllers 240 Opening Ports in Windows Firewall 241 Risks of Opening Ports 241 How Ports Work 241 Limiting Amount of RAM Memory Allocated to SQL Server 2-15 Setting Up Security for SQL Server 2008 82/2012/2014 246 Security Mode 246 Windows Principal Provisioning 246 Specify SQL Server Administrator(s) 246 Setting Up Protocols for SQL Standard/Enterprise Editions 2-17 Remote SQL Server Setup 2-18 Overview 248 Enable Remote Connections for Existing SQL Server 248 Enable SQL Server Browser Service 249 Create Exceptions in Windows Firewall 249 Create Exception for SQL Server in Windows Firewall 2-20 Create Exception for SQL Server Browser Service in Windows Firewall 2-20 Configuring ILS on Windows Server Operating Systems 2-21 ITS Web Services ASP.NET Setting 2-21 Pre-installation Checklist 2-22 Do you have these items/ 2-22 Have you performed these steps on each computer/ 2-22 Chapter 3 Installing C•CURE 9000 Software Installation Overview 3-2 Steps to Install C•CURE 9000 Software 3-3 Installation Preparation 3-4 Checking Network Status 3-4 Checking System Privileges 3-4 Database Installation 3-4 SQL Server Database Permissions 3-4 Beginning the C•CURE 9000 Installation 3-6 Installing victor Application Server and C• CURE 9000 Client 3-8 Installing the Server 3-8 Installing the Client (with the Server) 3-15 Customizing the Software House Services 3-18 Installing a C•CURE 9000 Client Only 3-19 Services/Server Components for C•CURE 9000 3-21 Iv C•CURE 9000 Installation and Upgrade Guide EFTA01226475 Table of Contents Starting C•CURE 9000 Services/Server Components 3-22 Repairing C•CURE 9000 Server or Client 3-24 Chapter 4 Installing C•CURE 9000 Integrations and Services C•CURE 9000 Integrations and Services Overview 4-2 Installing C•CURE 9000 Web Client 4-2 Installing C•CURE Co Web Service 4-2 Installing victor Web Service 4-2 Installing C•CURE 9000 Client Auto-Update and C•CURE 9000 Language Pack 4-3 Beginning the Installation of the Integrations and Services 4-4 Client Auto-Update Utility 4-6 Installing/Configuring Client Auto-Update 46 Using Client Auto-Update 4-8 Installing C•CURE 9000 Language Pack 4-10 Chapter 5 Upgrading C•CURE 9 000 Software Overview of the Upgrade Process 5-2 Upgrading Your SQL Server Version 5-2 Steps to Upgrade the C•CURE 9000 Software 5-3 Upgrading C•CURE 9000 5-5 Upgrading the Client (with the Server) 5-8 Upgrading a C•CURE 9000 Client Only 5-10 Chapter 6 Installing a Master Application Server Installation Guidelines for a Master Application Server 6-2 MAS Installation Prerequisites 6-3 SQL Server Database Permissions for MAS Installation 6-4 Configuring the MAS Installer on the MAS SQL Server Database 6-4 Installation Preparation 6-5 Checking Network Status 6-5 Installing from a Shared Network DVD Drive 6-5 Checking System Privileges 6-5 Database Installation 6-5 C•CURE 9000 MAS Installation Summary 6-6 Installing a New MAS 6-7 Installing the Client (with the Server) 6-12 C•CURE 9000 Services/Server Components 6-13 Upgrading a MAS 6-14 Multi-version Support 6-14 C•CURE 9000 Installation and Upgrade Guido EFTA01226476 Table of Contents Chapter 7 Installing a Satellite Application Server Installation Guidelines for a Satellite Application Server 7-2 SAS Installation Prerequisites 7-3 SQL Server Database Permissions for SAS Installation 7-4 Configuring SQL Server Database Permissions for Services Account 7-5 Configuring the SAS Installer on the SAS SQL Server Database 7-5 Installation Preparation 7-7 Checking Network Status 7-7 Installing from a Shared Network DVD Drive 7-7 Checking System Privileges 7-7 Steps to Install C•CURE 9000 Software 7-8 Installing a New SAS 7-9 Installing the Client (with the Server) 7-13 Upgrading a SAS 7-14 Multi-version Support 7-14 Chapter 8 Licensing C•CURE 9000 Overview 8-2 About C•CURE 9000 Licensing 8-2 Considerations for Licensing C•CURE 9000 8-2 License Scope 8-2 Accessing the License Manager Application 8-4 C•CURE 9000 Licensing Tasks 8-9 Licensing a New C•CURE 9000 - Temporary to Permanent License 8-10 Requesting Your Permanent License 8-11 Validating Your Permanent License 8-12 Enabling and Disabling Your Current License Options 8.14 Licensing a C•CURE 9000 Upgrading to Version 230 8.15 Monitoring Your Current License 8.16 Viewing License Status in the About C•CURE 9000 Dialog Box 8-16 Viewing License Status in the License Manager Application 8-18 Modifying Your Current License to Add Capacity/Options 8.19 Modifying Your Current License to Evaluate an Option 8.20 Repairing Licensing in a System Crash 8.21 8-21 Chapter 9 Uninstalling the C•CURE 9000 Software Uninstalling Overview 9-2 Before Uninstalling C•CURE 9000 9-2 Uninstalling C•CURE 9000 9-3 Uninstalling C•CURE 9000 Language Pack 9-5 vl C•CURE 9000 Installation and Upgrade Guide EFTA01226477 Table of Contents Chapter 10 Troubleshooting C•CURE 9000 Install Logs 10-2 Installation 10-3 Licensing 10-4 Communications 10-6 Windows 10-7 Inputs and Outputs 10-8 Card Readers 10-9 Monitor Display and Operation 10-10 Start Up 10-11 Monitoring Station 10-12 Reports and Maps 10-13 Miscellaneous Problems 10-14 MAS and SAS 10-15 Chapter 11 Software House Customer Support Contacting the Software House Customer Support Center 11-2 Telephone Technical Support 11-2 Before Calling 11-2 Index C•CURE 9000 Instal!anon and Upgrade Guido vii EFTA01226478 Table of Contents All C•CURE 9000 Installation and Upgrade Guide EFTA01226479 Preface The C• CURE 9000 Installation and Upgrade Guide is for new and experienced security system users responsible for installing either the Standalone C•CURE 9000 or a C•CURE 9000 Master or Satellite Application Server (MAS and SAS) and for troubleshooting any system problems. NOTE For specifics on installing a MAS and/or SAS, see Chapter 6: Installing a Master Application Server and Chapter 7: Installing a Satellite Application Server. In this preface ♦ How to Use this Manual x ♦ Finding More Information xii ♦ Conventions xiii C•CURE 9000 Installatron and Upgrade Outdo Ix EFTA01226480 Preface How to Use this Manual This manual includes the following sections. Turn to the appropriate section for the information you need. Chapter 1, "C•CURE 9000 Overview" Provides basic information about the C•CURE 9000 network. It includes information on Clients and Servers, some system requirements, and optional hardware. Read both this chapter and Chapter 2 before you start the installation process. (See the current C•CURE 9000 data sheet for full system requirements.) Chapter 2, "Setting Up Software and Hardware" Provides guidelines for setting up your software and hardware in preparation for installing C• CURE 9000. Read both Chapter 1 and this chapter before you start the installation process. Chapter 3, "Installing C•CURE 9000 Software" Provides an overview of the installation process and step-by-step instructions for installing both the Servers and Clients for C•CURE 9000. This chapter also includes information about C• CURE 9000 services and server components and about repairing the C• CURE 9000 system. Chapter 4, "Installing C•CURE 9000 Integrations and Services" Provides an overview of the installation process for C• CURE 9000 Integrations and Services and where appropriate, step-by-step instructions for installing some of these. This chapter also includes information about installing the C• CURE 9000 language pack and about the Client Auto-Update Utility with step-by-step instructions for configuring and using it. Chapter 5, "Upgrading C•CURE 9000 Software" Provides step-by-step instructions for upgrading both C•CURE 9000 system Servers and Clients. Chapter 6, "Installing a Master Application Server" Provides an overview of the installation process and step-by-step instructions for installing a C•CURE 9000 Master Application Server (MAS) as well as information about upgrading a C•CURE 9000 MAS. Chapter 7, "Installing a Satellite Application Server" Provides an overview of the installation process and step-by-step instructions for installing a C• CURE 9000 Satellite Application Server (SAS). This chapter also includes information about upgrading a C• CURE 9000 SAS. x C•CURE 9000 Installation and Upgrade Guide EFTA01226481 Preface Chapter 8, "Licensing C•CURE 9000" Provides license information and instructions for registering your C•CURE 9000 system. Chapter 9, "Uninstalling the C•CURE 9000 Software" Provides instruction for uninstalling the C•CURE 9000 system and the C•CURE 9000 language pack Chapter 10, "Troubleshooting C•CURE 9000" Provides guidelines for troubleshooting both hardware and software problems. Chapter 11, "Software House Customer Support" Provides information on the Software House Customer Support Center, including guidelines for obtaining support. C•CURE 9000 Insta(Milan and Upgrade Guido xi EFTA01226482 Preface Finding More Information You can access manuals and online Help for more information about C•CURE 9000. Software House Manuals and Documents The Software House manuals and documents listed in the following three sections are available in Adobe PDF format on the C•CURE 9000 DVD and online at the Software House Member Center website You can access these manuals/documents if you copy the appropriate PDF files from the C•CURE 9000 Installation DVD English \ Manuals folder. The available manuals appear as hyperlinks in the online.pdf file in the aforementioned C•CURE 9000 DVD English \ Manuals folder. (Translated manuals for some of the supported languages are also available in Adobe PDF format in the LanguagePack folder on the C•CURE 9000 DVD.) Software Manuals • C•CURE 9000 Area and Zones Guide ■ C•CURE 9000 C•CURE ID User Guide ■ C•CURE 9000 Card Formats and Smart Card Keys User Guide ■ C•CURE 9000 Data Views Guide ■ C•CURE 9000 Enterprise Architecture Guide ■ C•CURE 9000 Guard Tour Guide ■ C•CURE 9000 Getting Started Guide ■ C•CURE 9000 Hardware Configuration Guide ■ C•CURE 9000 Installation Quick Reference ■ C•CURE 9000 Monitoring Station Guide ■ C•CURE 9000 Personnel Configuration Guide ■ C•CURE 9000 Server Configuration Application Guide ■ C•CURE 9000 Software Configuration Guide ■ C•CURE 9000 System Maintenance Guide ■ C•CURE 9000 Video Guide Additional Helpful Documents • Beeps and LED Definitions (Timing patterns for standard/alternate LED and beep cycles) • Capacity Planning for iSTAR Controllers (STAR Capacity estimating in multiple card system) Online Help You can access C•CURE 9000 Help by pressing F1 or clicking Help from the menu bar in the Administration/Monitoring Station applications. xll C•CURE 9000 Installation and Upgrade Guide EFTA01226483 Preface Conventions This manual uses the following text formats and symbols. I Convention I Meaning Bold This font indicates screen elements, and also indicates when you should take a direct action in a procedure. Bold font describes one of the following items: • A command or character to type, or • A button or option on the screen to press, or • A key on your keyboard to press • A screen element or name blue color text indicates a hyperlink to a URL, or a cross-reference to a figure, table, or section In this guide. Regular !talk font indicates a new term, or a book title. <te)d> indicates a variable. The following items are used to indicate important information. NOTE Indicates a note. Notes call attention to any item of information that may be of special importance. TIP Indicates an alternate method of performing a task. O STOP Indicates a caution. A caution contains information essential to avoid damage to the system. A caution can pertain to hardware or software. Indicates a warning. A warning contains information that advises users that failure to avoid a specific action could result in physical harm to the user or to the hardware. Indicates a danger. A danger contains information that users must know to avoid death or serious injury. C•CURE 9000 Installaaon and Upgrade Outdo xiil EFTA01226484 Preface xlv C•CURE 9000 Installation and Upgrade Guide EFTA01226485 C•CURE 9000 Overview C• CURE 9000 has automated installation programs that install the software and the database. It has a separate licensing application to register the software. However, you must complete some manual network setup procedures before installing the C•CURE 9000 software. This chapter provides information about clients and servers, as well as some system requirements. NOTE For specifics on installing a MAS and/or SAS, see Chapter 6: Installing a Master Application Server and Chapter 7: Installing a Satellite Application Server. For additional information, refer to the release notes file on the C•CURE 9000 Installation DVD, and for full system requirements, see the current C•CURE 9000 data sheet. In this chapter ♦ Understanding Clients and Servers 1-2 ♦ Hardware/Software Capacities for the Server 1-6 ♦ Hardware/Software Requirements for Clients 1-7 ♦ Optional Hardware and Software 1-8 C•CURE 9000 InstaOben and Upgrade Outdo 1-1 EFTA01226486 Understanding Clients and Servers Understanding Clients and Servers With C•CURE 9000, a computer can act both as a Server and a Client ■ A Server performs basic security functions and can be accessed by multiple users. A Server also functions as a Host for iSTAR controllers and apC panels, and other peripherals. ■ A Client performs administrative and monitoring functions for a single user. The Server for C•CURE 9000 You must have a Server computer on the C•CURE 9000 security system network for the system to operate. This Server is now the victor Application Server. It stores the C•CURE 9000 driver software and associated data files, including: ■ C•CURE 9000 configuration database that contains data tables with information about system configuration and personnel records. ■ iSTAR, apC, and Video support. (Video Support not evaluated by UL) ■ Historical information in database files called the historical journal. ■ Journal Maintenance and Backup/Restore Tools. ■ Client software. • Administration application. • Monitoring Station. ■ Bi-directional interface for CCTV. (Not evaluated by UL) Supported Hardware The Server supports the following hardware: ■ C•CURE iSTAR Classic/Pro Controllers. ■ C•CURE iSTAR eX Controllers. ■ C•CURE iSTAR Edge Controllers. ■ C•CURE iSTAR Ultra Controllers. ■ apC Panels. Readers Card readers support a variety of card technologies, including magnetic stripe, Wiegand, Wiegand-compatible (such as proximity), biometric encrypted magnetic card types, Smart cards, and Government cards. The following readers have been evaluated by UL: ■ RM1-MP, RM2-MP, RM2L-MP, RM3-MP ■ RM1-PH, RM2-PH, RM2L-PH, RM3-PH, RM1-PI, RM2-PI, RM2L-PI ■ Model RM1-W ■ RM1-4000, RM2-4000, RM2L-4000, RM1-IC, RM2-IC, RM2L-1C 1-2 C-CURE 9000 Installation and Upgrade Guide EFTA01226487 Understanding Clients and Servers The C•CURE 9000 Client A C•CLI:l. 91(10 Client contains the following features and options: Administration Application Allows you to: • Configure system security objects such as: • Controllers • Panels • Doors and readers • Holidays • Schedules • System events and triggers • C•CURE and third-party Video hardware, and CCTV switchers (not evaluated by UL). • Configure partitions, iSTAR areas, intrusion zones, keypad commands, and guard tours. • Configure elevators, floors, and video tours. • Configure personnel records, operators, and operator privileges. • Display, import, and export personnel records and other system data. • Configure events to respond to: • Inputs • Video alarms • Communications failures • Configure events to activate actions such as: • Activating outputs and CCTV control • Activate other events • Configure Application (Monitoring) Layouts. • Use Dynamic Views to view configuration data and system status. • Display, import, and export images. • Design and print badges with C•CURE ID. • Report on historical and configuration information and video clips. Monitoring Station Allows you to: • View general activity and events. • View the status of objects. • Acknowledge events. • Perform manual actions. C•CURE 9000 Installation and Upgrade Guido 1-3 EFTA01226488 Understanding Clients and Servers ■ View personnel data including images, live video display of an IP camera, and system maps. ■ View live and/or recorded digital video. ■ View alarm messages. ■ Monitor cardholder admits and rejects. ■ Configure each station to automatically display the image associated with a card access/ reject. Networking Protocol The Server and its Clients are usually separate computers connected via the TCP/1P networking protocol. You can also run the Client and Server functions on the same computer. NOTE The C•CURE 9000 Operator is tied to the Windows login. When users start any client application, they are queried as to which Windows User/ Principal they are. This value is used to ascertain which privileges they possess. Figure 1-1 on page 1-4 illustrates how the Clients and Server function in C•CURE 9000 and how iSTAR and apC Controllers connect to them. RAH* 1-1: C•CURE 9000: Clients and Servers Each Server contains: • The C•CURE 9000 Configuration, Journal, and Audit Databases • ISTAR Cluster Support • Server / Client Software • Video and other optional drivers victor Application Server STAR and apC Reader Controllers BOR MOM Ethernet C•CuPEl000cuet C•CuRE9O1Cison C•CcOf 5C00Ciert EaCh Client may contain: • Administration Application • Monitoring Station Applications • System Maps • [Cadging Hardware and Software 1-4 C•CURE 9000 Installation and Upgrade Guide EFTA01226489 Understanding Clients and Servers Hardware - Controllers/Panels NOTE The C•CURE 9000 documentation uses the term controller to refer to the different types of iSTARs and panel to describe apC/8X panels. Communications between a server and multiple iSTAR controllers or apC/8X panels are via TCP/IP over an Ethernet network. iSTAR Controllers STAR Classic/Pro, STAR eX, STAR Edge, and STAR Ultra are Ethernet-ready controllers. C • CURE 9000 acts as a database and journal host, and networks to the iSTAR controllers for initial set-up—managing peripheral hardware and generating activity reports. The host downloads personnel information, configuration information, and event-directed actions to the STAR controllers. The controllers enable local management of events without host intervention. apC/8X Panels The advanced processing Controller (apC) panel is an intelligent field device that performs basic access control tasks. The apC/8X access control field panels coordinate communication between the victor Application Server and the system security hardware, such as card readers. C•CURE 9000 Installation and Upgrade Guido 1-5 EFTA01226490 Hardware/Software Capacities for the Server Hardware/Software Capacities for the Server O Be sure to verify all hardware for compatibili with Windows. See the Microsoft web site for more information . See the current C•CURE 9000 data sheet for up-to-date information about the hardware and software default capacities for the Server for the different model series. The data sheet also includes system requirements for the following items: Processor Network Adaptor Card Hard Disk Drives SQL Server Database RAM Windows Operating System Backup device DVD Drive Video Card Required Services Monitor The installation program checks the free disk space on the system drive. If there is insufficient space, an error message displays and the install closes. 1-6 C•CURE 9000 Installation and Upgrade Guide EFTA01226491 Hardware/Sofvare Requirements for Clients Hardware/Software Requirements for Clients Be sure to verify all hardware for compatibility with Windows. See the Microsoft web site for more information You can configure one or more Clients in your C•CURE 9000 system. You must have at least 2 GB of free space on the installation drive prior to installation. See the current data sheet for up-to-date hardware and software requirements information for a C•CURE 9000 Client for the following: Processor DVD Drive RAM MonitorMdeo Adaptor Board Disk Drive Network Adaptor Card Mouse Windows Operating System Keyboard C•CURE 9000 Instal!anon and Upgrade Outdo 1-7 EFTA01226492 Optional Hardware and Software Optional Hardware and Software You can use the following items with the C•CURE 9000, but they are not required: ■ Printer. ■ Sound Card, for audible notifications of alarms and events. ■ 24-bit or 32-bit color video adapter board for high resolution maps, including photographs. ■ Additional backup software for network and scheduled backups. ■ C•CURE Video Servers: • American Dynamics - VideoEdge NVR - Intellex - HDVR - TVR • ExacqVision ■ CCTV switchers: • American Dynamics ■ General Purpose Interface See the C•CURE 9000 C•CURE ID User Guide for items related to the Badging option. 1-8 C•CURE 9000 Installation and Upgrade Guide EFTA01226493 2 Setting Up Software and Hardware This chapter provides information on setting up the computer hardware and software before installing the C•CURE 9000 software. NOTE For specifics on installing a MAS and/or SAS, see Chapter 6: Installing a Master Application Server and Chapter 7: Installing a Satellite Application Server. For additional information on requirements and known limitations, refer to the Release Notes file on the C•CURE 9000 Installation DVD. In this chapter ♦ Installing Windows 2-2 ♦ C•CURE 9000 Installation Location 2-2 ♦ Connecting the Computer to the Network 2-3 ♦ Synchronizing Time for Networked Computers 24 ♦ Configuring Network Communications 2-10 ♦ Limiting Amount of RAM Memory Allocated to SQL Server 2-15 ♦ Setting Up Security for SQL Server 2008 R2/2012/2014 2-16 ♦ Setting Up Protocols for SQL Standard/Enterprise Editions 2-17 ♦ Remote SQL Server Setup 2-18 ♦ Configuring IIS on Windows Server Operating Systems 2-21 ♦ Pre-installation Checklist 2-22 C•CURE 9000 Installation and Upgrade Outdo 2-1 EFTA01226494 Installing Windows Installing Windows Install the appropriate Windows operating system and service packs for both the victor Application Server and C•CURE 9000 Client, as described in the current C•CURE 9000 data sheet, following the installation instructions provided b Microsoft. For information on Windows servers, see the Microsoft web site The Windows operating system of the Server system must be configured to boot from the C:/ drive. Otherwise, your C•CURE 9000 license may not validate correctly and allow you to run C•CURE 9000. (C•CURE 9000 itself does not need to be installed on the C:/ drive.) C•CURE 9000 Installation Location You must install the C•CURE 9000 software on every computer that you will use in the security system. The installation program prompts you to install either the Server with the Client or the Client alone. Table 2.1: C•CURE 9000 Installation Table If your security system will use... Then install... Single computer Server and Client software on that computer. Two or more computers • Server and Client software on the computer that will be the ServerMost. - and - • Client software on each computer to be used as a Client. 2-2 C•CURE 9000 Installation and Upgrade Guide EFTA01226495 Connecting the Computer to the Network Connecting the Computer to the Network If you are installing C• CURE 9000 on a pre-existing corporate network, you need to first perform some manual setup tasks to enable the C• CURE 9000 system to run on your network. Server/Client Setup Requirements Unless otherwise noted, you must perform all the tasks described on the following pages on the victor Application Server and on all C•CURE 9000 Clients that will run C•CURE 9000. Network Protocol The victor Application Server communicates using the TCP/1P network protocol. Setting Fonts and Screen Resolution C•CURE 9000 does not support large fonts. Select the Display icon in the Windows Control Panel to set the font size to small on the server and clients, and set the screen resolution to 1024 x 768 or higher. Verifying TCP/IP To Verify that TCP/IP Is Working before Installing C•CURE 9000 1. Select Start>Run>cmd to display the command prompt. 2. At the command prompt, enter the following command: PING [your IP address or computer name] Successful pings return a message beginning "Reply from," while unsuccessful pings return the message "Request timed out" or "host unreachable." NOTE Use TCP/1P addresses or names for the verification. You will repeat this procedure after installing the software. For more information on installing TCP/IP, see the Microsoft web site: C•CURE 9000 Instal!aeon and Upgrade Outdo 2-3 EFTA01226496 Synchronizing Time for Networked Computers Synchronizing Time for Networked Computers Computers in a C•CURE 9000 network need to have their clocks synchronized to a user- selected time standard. Otherwise, C•CURE 9000 activity time stamps may not be correct. For the computers in the C• CURE 9000 network there are basically three different situations, summarized in the following list. NOTE The list describes the three most common situations, but there can be other more rarefied cases. Be aware that everything is configurable and defaults can be overridden manually or using group policy. Always confirm that your network is synchronizing the time as expected. In addition, for each case in the list there are additional options available. For further information, see • - Or - • Search for "Windows Time Service" on the internet. WS.1.0).aspx 1. All computers (the victor Application Server and all C•CURE 9000 Clients) are in the same Active Directory Forest. In this case, all the computers have their time synchronized automatically by Active Directory by default. You do not have to do anything, but you should confirm that the time is being synchronized. However, Software House recommends that you synchronize the domain controllers (DCs) with an external clock. See "Setting a Domain Controller as Time Server and Synchronizing It with External Time Source" on page 2-5. In addition, to verify that a domain computer is synchronized with the domain time server, see "Manually Configuring Computers to Synchronize with Domain Time Server" on page 2-8. 2. All computers (the victor Application Server and all C•CURE 9000 Clients) are in different Active Directory Forests. In this case, you must synchronize the DCs in the different forests. Once their time is synchronized, the change propagates to all the other computers by default. See "Setting a Domain Controller as Time Server and Synchronizing It with External Time Source" on page 2-5. 3. The computers are not using Active Directory at all — you are using workgroups. The computers have time server built in. You can use either of the following two methods: • "Configuring a Separate Time Server" - The more robust method. See page 2-5. • "Configuring Each Computer To Get Time from Internet Independently"- the easier method. See page 2-5. 2-4 C•CURE 9000 Installation and Upgrade Guide EFTA01226497 Synchronizing Time for Networked Computers Configuring a Separate Time Server To Configure a Separate Time Server I. Configure one computer as the time server. For directions, see "Configuring a Non- domain Computer as Time Server" on page 2-6. Ideally the time server computer should then have its time set using an atomic clock standard. See "Setting a Domain Controller as Time Server and Synchronizing It with External Time Source" on page 2-5. 2. Configure the other computers to synchronize their time with the time server—set their time from the primary computer. For directions, see "Manually Configuring Computers to Synchronize with Time Server —When Not in a domain" on page 2-7. Configuring Each Computer To Get Time from Internet Independently This method is set up by default, so you merely need to verify its occurrence. NOTE This method has the problem that it requires the ntp port (usually port 123, a UDP port) to be open on your firewall. To Verify a Computer Gets its Time from the Internet 1. From the Windows desktop, go to Start>Control Panel>Date and Time. The Date and Time Properties window appears. 2. Open the Internet Time tab and click the Change settings button. 3. On the Internet Time Settings dialog box, select the Synchronize with an Internet time- server check box. 4. In the Server field, leave or select another appropriate time source from the drop-down list. 5. Click the Update Nov button to verify that the computer can successfully obtain the time. 6. Click OK. Setting a Domain Controller as Time Server and Synchronizing It with External Time Source 'Ibis is part of domain administration. For information, see: v=WS.10).aspx C•CURE 9000 Installation and Upgrade Guido 2-5 EFTA01226498 Synchronizing Time for Networked Computers Synchronizing Non-domain Time Server Computers with External Time Source To Synchronize a Time Server Computer with a Standard Time Source ■ Go to download their "Atomic clock sync" application, and install it on your computer. • Have this application synchronize once a day. (This method uses Http, so no additional ports are required to be open.) -or- ■ Connect to a time server running Network Time Protocol (ntp) or Simple Network Time Protocol (sntp). (Uses UDP Port 123.) You can configure this to happen automatically: a. From the Windows desktop, go to Start>Control Panel>Date and Time. The Date and Time Properties window appears. b. Open the Internet Time tab and click the Change settings button. c. On the Internet Time Settings dialog box, select the Synchronize with an Internet time-server check box. d. In the Server field, leave or select another appropriate time source from the drop-down list e. Click the Update Now button to verify that the computer can successfully obtain the time. f. Click OK. NOTE This second method has the following problems: ■ It requires the ntp port (usually port 123, a UDP port) to be open on your firewall. ■ It synchronizes only once a week. If you desire greater accuracy, you can change the frequency of synchronization by editing the registry. For information, see the Microsoft documentation. Configuring a Non-domain Computer as Time Server To Set Up a Windows Computer as a Time Server 1. Make sure that the "Windows Time" service is installed and set to start automatically on this computer. (Check in the Windows Control Panel Services window that Startup is set to Automatic). Ideally, this computer should synchronize with an external time source. For the procedure, see the preceding section. 2-6 C•CURE 9000 Installation and Upgrade Guide EFTA01226499 Synchronizing Time for Networked Computers 2. Edit the following registry entry: HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ W32Time Coatis \ a. In the right pane, right-click AnnounceFlags, and then click Modify. b. In the Edit DWORD Value dialog box, under Value data, type 5, and then click OK. 3. Edit the following registry subkey: HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ W32Time\TimeProviders\NtpServer\ a. In the right pane, right-click Enabled, and then click Modify. b. In the Edit DWORD Value dialog box, type 1 under Value data, and then click OK. 4. Restart the Windows Time service for the change to take effect by entering the following at the command line: net stop w32time net start w32time Manually Configuring Computers to Synchronize with Time Server—When Not in a domain To Synchronize the Computers with the Time Server Computer 1. Make sure that the "Windows Time" service is installed and set to start automatically on these computers. (Check in the Windows Control Panel Services window that Startup is set to Automatic). 2. Issue the following at the command line: w32tm/config/manualpeerlist:time_server_machine/syncfromflags:manual /update (Where time_server_machine is the computer name of the primary time server.) 3. Restart the Windows Time service for the change to take effect by entering the following at the command line: net stop w32time net start w32time NOTE This time synchronization will happen by default every few days. Computers are typically synchronized to within a few seconds of each other. C•CURE 9000 Instal!anon and Upgrade Guido 2-7 EFTA01226500 Synchronizing Time for Networked Computers Manually Configuring Computers to Synchronize with Domain Time Server (This is the default setting, but it can be turned off depending upon the installation.) To Ensure a Domain Computer is Set to Automatically Synchronize with Domain Time Server 1. Make sure that the "Windows Time" service is installed and set to start automatically on these computers. (Check in the Windows Control Panel Services window that Startup is set to Automatic). 2. Issue the following at the command line: w32tm /config /syncfromflags:domhier /update 3. Restart the Windows Time service for the change to take effect by entering the following at the command line: net stop w32time net start w32time NOTE This time synchronization will happen by default a few times per day. Computers are typically synchronized to within a few seconds of each other. Setting System Clock Since C•CURE 9000 uses the system clock for tracking activity, it is important that it be correct. NOTE The time zone for the Windows clock is set by default to Greenwich Mean Time (GMT), which is not correct for most users. Verify that the time zone is correct for the system's location. If your location uses Daylight savings time, also verify that the "Automatically Adjust Clock for Daylight Saving Time" check box is selected. (Both the time zone and the time are set from Start>Control Panel>Date and Time.) ■ If you are not automatically synchronizing the clocks (Software House recommends that you automatically synchronize them), you must set the system clock on every system running the C• CURE 9000 Server or Client. ■ If you are synchronizing the clocks automatically, the clock should be set manually only on the time server computer, and the Windows Time service will set the clocks on all other computers. ■ In either case, if the C•CURE 9000 system server time will change by more than a few seconds, or if you change the time zone, you must perform the following procedure on the victor Application server. 2-8 C•CURE 9000 Installation and Upgrade Guide EFTA01226501 Synchronizing Time for Networked Computers a To Change the Time Zone, Date, or Time 1. Do a full shutdown of the C•CURE 9000 Service using the Server Configuration application. 2. Make the necessary changes (or wait for the Windows Time Service to make the changes). • If you are using automatic time synchronization and you want this computer to synchronize to the time server immediately, issue the following command at the command prompt: w32tm/resync 3. Do a full startup of the C•CURE 9000 Service using the Server Configuration application. C•CURE 9000 InstaIlanon and Upgrade Guido 2-9 EFTA01226502 Configuring Network Communications Configuring Network Communications C • CURE 9000 supports network communications for the following security objects: C•CURE 9000 Clients C•CURE 9000 clients communicate with the host computer using TCP/IP protocol within a local area network (LAN) or across a wide area network (WAN). iSTAR Controllers iSTAR controllers communicate with the C•CURE 9000 host using TCP/1P protocol. The onboard ports are Ethernet; therefore, you must physically connect iSTAR controllers to an Ethernet LAN. The host computer and the iSTAR controllers can be in a WAN only if the gateways/routers are specified in the STAR controllers. You can specify the IP addresses for member slave controllers in the software by using the Hardware pane in the C•CURE 9000 Administration application. You can specify IP addresses for controllers in the following ways: ■ Use the supplied ICU.exe module to configure the IP addresses for the master controllers. ■ You can specify gateways/routers by using the supplied ICU.exe module to configure the gateways/routers in the controllers. Connecting apCs NOTE When you are specifying IP addresses for controllers, Software House recommends that you obtain the IP address from a DHCP server— utilizing the method that retains the static IP address (based on the MAC address). Advanced Processor Controllers (apCs) are wired to RS-232 or RS-485 serial connections, or connected to terminal servers. For detailed information, refer to the apC Technical Manual and the apC/8X Technical Manual. NetVue Controllers NetVue controllers communicate with the C•CURE 9000 host using the TCP/IP protocol within a Local Area Network (LAN) or across a Wide Area Network (WAN). Refer to the individual controller installation guides for information about which ports to use with the controllers. (NetVue Controllers are not evaluated by UL) 2-10 C•CURE 9000 installation and Upgrade Guide EFTA01226503 Configuring Network Communications Opening Ports in Windows Firewall 'Co help protect the security of your computer, you should keep Windows Firewall on, so that unsolicited requests to connect to your Server computer are blocked. However, C • CURE 9000 requires access to certain ports within the system. To allow this type of connection, you must allow an exception or open a port for a specific program or service. Risks of Opening Ports A port is an opening into your computer through which information can flow. Each time that you allow an exception or open a port for a program to communicate through Windows Firewall, your computer is made more vulnerable. Opening a port increases the risk that unknown intruders can find unprotected connections. If you have many open ports, your computer can become a victim of these intruders. To help decrease your security risk if you open ports: ■ Only open a port when you need it. ■ Never open a port for a program that you do not recognize. ■ Close a port when you no longer need it. How Ports Work Each port has a number, which is like an address. Many programs and services have a "permanent address"— they have predefined port numbers. You can find the correct port number for a program or service in Table 2-2 on page 2-12 which lists exceptions that may be added to the Windows Firewall to allow the C•CURE 9000 application to operate in a Shared Server List Format (SSLF) environment. The SSLF format has been developed to list servers in a standard, organized framework that can be used with many software tools and edited with every common text editor. Exceptions can be made for particular ports and for programs that use dynamically -assigned ports. Some programs do not have predefined port numbers. These programs open ports automatically as needed—such as ICU.exe (shown in Table 2-2 on page 2-12). For a program like this to connect to your computer, Windows Firewall must allow the program to open the correct port. For these programs to work correctly, they must be listed on the Exceptions tab in the Windows Firewall application. NOTE To enable Windows Firewall and add ports for the Windows 7, Windows 8.1, Windows 2008 RZ or Windows Server 2012 R2 operating systems, see Microsoft's directions. Be aware that you must be logged on as an administrator to perform the necessary procedures. C•CURE 9000 Installaaen and Upgrade Guido 2-11 EFTA01226504 Configuring Network Communications Table 2-2 on page 2-12 lists port assignments and other C•CURE 9000 exceptions. The table uses the following abbreviations: ■ victor Application Server = vAS ■ Database Server = DB Server NOTE Other considerations for using Microsoft SQL Server may apply to your use of a firewall. For more information, see the following Microsoft technical articles: ■ How to: Configure a Windows Firewall for Database Engine Access ms175043(v=sq1.105).aspx ■ Configuring the Windows Firewall to Allow SQL Server Access v=sq1105).aspx Table 2.2: Port Assignments for C•CURE 9000 Port Name Exception Type Location Traffic Direction from vAS Connection initiate from 80 IIS TCP vAS inbound Client 80 VideoEdge NVR Admin./Alarm Pod TCP vAS 123 For Time synchronization UDP 389 Default LDAP Port TCP vAS outbound vAS to LDAP Server 443 HTTPS Port for SSL connections with C•CURE Go TCP Server 554 VideoEdge NVR Live Pon TCP Server 1433 SQL Server TCP DB Server outbound vAS to SQL Server 1433 SQL Server UDP DB Server outbound vAS to SQL Server 1434 SQL Server UDP DB Server outbound vAS to SQL Server 1521 Oracle Listener TCP DB Server outbound vAS to Oracle Server 1999 ISTAR, Master Port for Incoming slave connections TCP Master ISTAR NIA From Slaves 2001 ICU.exe, UDP Broadcast Port Program Laptop Inbound to Laptop 'STAR Panels 2800 apC Driver TCP vAS inbound apC Panels 2800 ISTAR Host Port for 'STAR Driver TCP vAS inbound 'STAR Panels 2801 ISTAR Fast Personnel Download Host Port TCP vAS inbound 'STAR Panels 2802 ISTAR Fast Image Download Host Port TCP vAS inbound 'STAR Panels 2803 ISTAR Encryption Port TCP vAS inbound 'STAR Panels 3001 apC Comm Port Default TCP Server 2-12 C•CURE 9000 Installation and Upgrade Guide EFTA01226505 Configuring Network Communications Table 2.2: Port Assignments for C•CURE 9000. continued Traffic Connection Port Name Exception Type Location Direction Initiate from vAS from 5000 IntellexAPI Base Address' TCP Intellex outbound vAS to Intellex Server Server 5001 IntellexAPI Live Port' TCP Intellex outbound vAS to Intellex Server Server 5003 IntellexAPI Alarm Port' TCP Intellex outbound vAS to Intellex Server Server 5000- Lantronix Terminal Server' TCP Lantronix outbound vAS to Device 5003 Device 7144- EMC Replistor TCP Server/Client inbound/outbound One of the EMC vAS's 7145 to other Servers In the EMC Cluster 8005 System Trace URI TCP Server 8006 Remote Hardware Interface Ust URI TCP Server 8042- EMC AutoStart TCP Server/Client inbound/outbound One of the EMC vAS's 8045 8085 Auto Update TCP vAS Inbound 9000 Client 8985 Base Address of Driver Service TCP Server 8995 Server Component Framework Driver TCP vAS Inbound vAS Port (and Trace Viewer URI) 8996 CrossFire Service of Web Client TCP vAS Inbound 9000 Client Session 8997 Admin/Monitor Client Stream TCP vAS inbound 9000 Client 8998 CrossFire Service of HTTP Client TCP vAS inbound 9000 Client Session 8999 CrossFire Service of TCP Client TCP vAS Inbound 9000 Client Session 10001- DSC through Lantronix device (or serial TCP Server 10002 port) 10001- Simplex 4100U through Lantronix TCP Server 10002 device (or serial port) 22609 VideoEdge HDVR Admin/Une/Alarm TCP Server Port 27000 TycoESS License Service TCP vAS Inbound vAS/9000 Client 28001 'STAR Edge/Ultra/oX. Fast Download TCP vAS Inbound Encrypted ISTAR Connection Panels 28002 ISTAR Edge/Ultra/0X. Fast Image TCP vAS Inbound Encrypted ISTAR Download Panels 28003 ISTAR Edge/Ultra/eX. Used by host to accept Edge/Ultra/eX requests for certificate signing TCP vAS Inbound Encrypted 'STAR Panels C•CURE 9000 Installabon and Upgrade Guido 2-13 EFTA01226506 Configuring Network Communications Table 2.2: Port Assignments for C•CURE 9000. continued Port Name Exception type Location Traffic Direction from vAS Connection Initiate from 28004 ISTAR Edge/Ultra/eX. Used by Edge/ Ultra/eX to accept a signed certificate TCP Encrypted ISTAR Panels outbound vAS 28005 ISTAR Ultra/eX. for connection made to host 2nd IP/Name (Dual IP - Ultra/eX only) TCP Notsupported on Host yet WA N/A 28007 ISTAR Edge/Ultra/eX. For masters 2nd network connection TCP Master N/A 'STAR Panels 28009 ISTAR Edge/UltraleX. Master port for Incoming slave connections TCP Master ISTAR N/A 'STAR Panels 28010 Host port for incoming slave connections TCP vAS inbound 'STAR Panels 32200- 38200 VideoEdge NVR Streaming Port UDP Server 47808 mix UDP Server SoftwareHouse.Crossfire.Server.exe Program Server ICU.exeNextGen Program Server SQL Server" Program DB Server SothvareHouse.NextGen.ClientAdmIn Workstation.exe Program Client SofhvareHouse.Client.Monitoring Statlon.exe Program Client •Ports 5000-5003 may be used for Intellex and Lantronix. When there is a conflict, alternate ports such as 6000-6003 can be used. • •See "Create Exception for SQL Server in Windows Firewall" on page 2-20. 2-14 C•CURE 9000 Installation and Upgrade Guide EFTA01226507 Limiting Amount of RAM Memory Allocated to SQL Server Limiting Amount of RAM Memory Allocated to SQL Server If your SQL Server/SQL Server Express is running on the same computer as the victor Application Server, you should limit the amount of memory SQL Server can use to around 50% of the total RAM on the server computer. The amount of memory SQL Server needs depends on how large a database your system has—50% is only a rule of thumb. You must do this after you have installed SQL Server, but before you install the C• CURE 9000 software on the server. For instance, if the server has 4 GB of RAM, allocate 2000 MB to SQL Server. Follow the steps below to configure this allocation. -mg To Limit RAM Memory for SQL Server 1. Run SQL Server Management Studio and connect to SQL server. 2. Select your server name in the Object Explorer pane. 3. Right-click to select Properties. 4. Under Select a page on the upper left, click the Memory. 5. In the Server Memory options box, set the memory as follows: a. Minimum server memory (in MB) field set to 100 MB b. Maximum server memory (in MB) field (The default is 214748367.) Set to the maximum amount of memory allowed to SQL Server based on the formula in the introductory paragraph above. Example: Set to 2 GB so enter 2048. 6. Click OK. C•CURE 9000 Meta(lawn and Upgrade Outdo 2-15 EFTA01226508 Setting Up Security for SQL Server 2008 R2/2012/2014 Setting Up Security for SQL Server 2008 R2/2012/2014 SQL Server 2008 R2/2012/2014 decrease the surface and attack areas for the server and its databases by doing the following: ■ Instituting a policy of least privileges. ■ Increasing the separation of Windows administration and SQL Server administration. Internal accounts are protected and separated into operating system functions and SQL Server functions. Consequently, new SQL Server 2008 R2/2012/2014 installations: ■ No longer add the lo

📷 Images in this document (174 detected; 6 largest described)

AI-generated factual descriptions of embedded images (llava:13b). These are searchable across the corpus.

[Image 1] The image shows a screenshot of a webpage with a blue and white color scheme. The webpage appears to be related to CURE 2000, which is described as a "Visual Web Service." The screenshot includes a login form with fields for username and password. Below the login form, there is a section titled "Installing CURE 2000," followed by instructions for installing the software. The text is too small to r [Image 2] The image shows a document with text and a photograph. The document appears to be an instruction manual or guide, possibly for software installation or an upgrade. The text includes the name "Software House" and mentions "Tyco Security Products." There is a reference number "REV: 00" and a version number "V 2.0." The photograph on the document shows a modern building with reflective glass facades, [Image 3] The image shows a page from a document, which appears to be a guide or manual titled "Installation Guidelines for a Satellite Application Server." The document is structured with numbered sections and subsections, and there are bullet points with instructions or information. The text is in English, and there are no visible images or graphics other than the text itself. The document seems to be a t [Image 4] The image shows a page from a document, which appears to be a technical or informational paper. The title of the document is "Upgrading & SAS," suggesting that it is related to the SAS (Statistical Analysis System) software. The document contains text and bullet points, which are likely to provide information about the upgrade process for SAS systems. There are no visible names, dates, places, or [Image 5] The image is a scanned document, specifically a page from a manual or guide. The document is titled "Installing CURE 2000 Language Pack" and appears to be related to software installation or configuration. There are several paragraphs of text, which are too small to read in detail, but they seem to provide instructions or information about the language pack installation process. At the bottom of [Image 6] The image shows a page from a document, which appears to be a manual or guide related to "Client Auto Update Utility." The page contains text and bullet points, which are likely instructions or information about the utility. There are two highlighted sections with blue text boxes, one on the left and one on the right, which seem to be important notes or instructions. The text is too small to read