Installing ACS on a Windows Server
Installing ACS on Windows is simple and straightforward. Like most Windows applications, ACS uses the Microsoft InstallShield installer. Therefore, you should be familiar with the process. To install ACS, complete these steps:
NOTE Installing ACS over Terminal Services (or Remote Desktop) is not supported. However, you can use VNC (Virtual Network Computing's remote desktop utility) to install ACS remotely.
Step 1 Log in to the server using a local Administrator account.
Step 2 Insert the ACS CD into the CD-ROM drive. If autorun is enabled, the installation starts automatically. Otherwise, run setup.exe from the root directory on the CD. (If you downloaded the software from cisco.com, extract the archive file and then run setup.exe).
NOTE If any of the minimum system requirements are not met, a dialog box appears indicating the missing components. It is recommended that you bring the system up to the minimum requirements before proceeding with the installation.
Step 3 The software license agreement appears. Read the software license agreement and, if you agree to it, select Accept.
Step 4 The welcome screen appears. Read the information on it, and then select Next.
Step 5 You are now presented with the Before You Begin dialog box. This step was originally designed to prevent common mistakes but is now out of date. Check off each of the items so that you can continue with the installation; then click Next.
Step 6 Choose a location where you want ACS installed; then click Next. The default directory is C:\Program Files\CiscoSecure ACS v4.x\.
Step 7 The Authentication Database Configuration box appears. If you plan to authenticate users against an external Windows database (SAM or AD), you can select the box here. Optionally, selecting Grant Dial-In Permission to User requires the Windows user to have dial-in rights before ACS can authenticate them. Note that all databases (including Windows databases) can be configured after the installation completes. Again, this is another legacy screen in the installation. Continue the installation by selecting Next to start copying the files.
Step 8 With the files copied, the Advanced Options dialog box appears.
Selecting any of these options causes them to appear in the web interface. However, you can always enable them after the installation completes from the Interface Configuration > Advanced Options screen in ACS. Note that none of these options is required for NAC. If you do not know what to select, I recommend selecting all of them except the Default Time of Day/Time of Week Specification. Then click Next.
Step 9 The Active Service Monitoring dialog now appears. By default, ACS monitors its services and restarts them if it detects a failure. You can disable or modify this action by choosing a different script from the dropdown list. However, I recommend keeping the default Restart All. Optionally, select Enable Mail Notifications and fill in the SMTP server and e-mail address to be notified in case of an ACS service failure (highly recommended). Select Next to continue.
Step 10 Enter a password that will be used to encrypt the local ACS database. The password must be at least eight characters in length and should include both letters and numbers. The password you enter is kept encrypted in the Windows Registry. Record the password you used and keep in a secure place. If there is ever a critical problem with the database, the password might be needed to access the database manually. After you enter the password, click Next to continue.
Step 11 The installation is almost complete. A dialog box appears with three options checked: Install ACS as a Windows Service, Launch ACS after the Installation, and Present the Readme File to the User. Click Next to perform these actions and complete the installation.
Step 12 The Setup Complete dialog box appears. Select Finish to close ACS setup.
The ACS Admin icon should appear on your desktop. Double-click it to launch a web browser to the ACS GUI. By default, Internet Explorer is launched.
As with any application that runs on Windows, the question invariably arises, "Can I install the latest Windows hotfixes?" The short answer is, "Yes." Cisco documents the hotfixes they have tested with ACS in the Release Notes, but do not consider this list as a limit to the patches you can apply. Follow the security best practices and keep the operating system patched to protect against the latest security threats. In the rare case that a hotfix causes a problem with ACS, contact the Cisco TAC. The TAC will investigate and resolve the issue as quickly as possible.
Continue reading here: Creating Network Access Profiles Using NAC Templates
Was this article helpful?