Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Text Part Number: OL-6242-01
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and
iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco
Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Empowering the Internet Generation,
Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ
Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Pac ke t, PIX, Post-Routing, Pre-Routing,
ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, StrataView Plus, TeleRouter, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered
trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship
between Cisco and any other company. (0502R)
THIS PRODUCT INCLUDES THE FOLLOWING THIRD PARTY LICENSED SOFTWARE:
Reporting Security Problems in Cisco Productsvii
Obtaining Technical Assistancevii
Cisco Technical Support Websiteviii
Submitting a Service Requestviii
Definitions of Service Request Severityviii
Obtaining Additional Publications and Informationix
CONTENTS
CHAPTER
CHAPTER
1Overview1-1
About Network Registrar1-1
System Requirements1-2
Installation Modes1-3
License Keys1-3
Backup Software and Virus Scanning Guidelines1-4
Server Event Logging1-4
Running Performance Monitoring Software on Windows1-5
Running Other Protocol Servers1-5
Upgrading1-5
Starting and Stopping Servers on Windows2-8
Starting and Stopping Servers on Solaris or Linux2-9
Troubleshooting the Installation2-9
APPENDIX
APPENDIX
I
NDEX
APerforming a Silent InstallationA-1
BLab Evaluation InstallationsB-1
Installing Network Registrar in a LabB-1
Testing the Lab InstallationB-1
Uninstalling in a Lab EnvironmentB-2
iv
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Preface
This guide describes how to install Cisco CNS Network Registrar 6.2 Beta on the supported operating
systems: Windows, Solaris, and Linux. It is written for the system administrators who will be installing
the software, and assumes that you understand your site configuration and the basic steps for installing
software. (For information on configuring and managing Network Registrar, refer to the Cisco CNS Network Registrar User’s Guide.)
The guide is organized into these chapters and appendixes.
Chapter 1OverviewIntroduces Network Registrar and provides critical system
information that must be read before installing the software.
Chapter 2Installing and
Upgrading Network
Registrar
Appendix APerforming a Silent
Installation
Appendix BLab Evaluation
Installations
Obtaining Documentation
Cisco documentation and additional literature are available on Cisco.com. Cisco also provides several
ways to obtain technical assistance and other technical resources. These sections explain how to obtain
technical information from Cisco Systems.
Cisco.com
You can access the most current Cisco documentation at this URL:
http://www.cisco.com/univercd/home/home.htm
You can access the Cisco website at this URL:
http://www.cisco.com
Describes how to install or upgrade Network Registrar; and how
to uninstall it, stop and start servers, and troubleshoot the
installation.
Explains how to perform a silent installation, upgrade, or
uninstallation of the Network Registrar product.
Explains how to install, upgrade, or uninstall Network Registrar
if it is being used in a lab environment.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
v
Documentation Feedback
You can access international Cisco websites at this URL:
Cisco documentation and additional literature are available in a Documentation DVD package, which
may have shipped with your product. The Documentation DVD is updated regularly and may be more
current than printed documentation. The Documentation DVD package is available as a single unit.
Registered Cisco.com users (Cisco direct customers) can order a Cisco Documentation DVD (product
number DOC-DOCDVD=) from the Ordering tool or Cisco Marketplace.
Cisco Ordering tool:
http://www.cisco.com/en/US/partner/ordering/
Cisco Marketplace:
http://www.cisco.com/go/marketplace/
Ordering Documentation
You can find instructions for ordering documentation at this URL:
• Registered Cisco.com users (Cisco direct customers) can order Cisco product documentation from
the Ordering tool:
http://www.cisco.com/en/US/partner/ordering/
• Nonregistered Cisco.com users can order documentation through a local account representative by
calling Cisco Systems Corporate Headquarters (California, USA) at 408 526-7208 or, elsewhere in
North America, by calling 1 800 553-NETS (6387).
Documentation Feedback
You can send comments about technical documentation to bug-doc@cisco.com.
You can submit comments by using the response card (if present) behind the front cover of your
document or by writing to the following address:
Cisco Systems
Attn: Customer Document Ordering
170 West Tasman Drive
San Jose, CA 95134-9883
We appreciate your comments.
vi
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Cisco Product Security Overview
Cisco provides a free online Security Vulnerability Policy portal at this URL:
• Report security vulnerabilities in Cisco products.
• Obtain assistance with security incidents that involve Cisco products.
• Register to receive security information from Cisco.
A current list of security advisories and notices for Cisco products is available at this URL:
http://www.cisco.com/go/psirt
If you prefer to see advisories and notices as they are updated in real time, you can access a Product
Security Incident Response Team Really Simple Syndication (PSIRT RSS) feed from this URL:
Cisco is committed to delivering secure products. We test our products internally before we release them,
and we strive to correct all vulnerabilities quickly. If you think that you might have identified a
vulnerability in a Cisco product, contact PSIRT:
• Emergencies— security-alert@cisco.com
• Nonemergencies— psirt@cisco.com
TipWe encourage you to use Pretty Good Privacy (PGP) or a compatible product to encrypt any sensitive
information that you send to Cisco. PSIRT can work from encrypted information that is compatible with
PGP versions 2.x through 8.x.
Never use a revoked or an expired encryption key. The correct public key to use in your correspondence
with PSIRT is the one that has the most recent creation date in this public key server list:
In an emergency, you can also reach PSIRT by telephone:
• 1 877 228-7302
• 1 408 525-6532
Obtaining Technical Assistance
OL-6242-01
For all customers, partners, resellers, and distributors who hold valid Cisco service contracts, Cisco
Technical Support provides 24-hour-a-day, award-winning technical assistance. The Cisco Technical
Support Website on Cisco.com features extensive online support resources. In addition, Cisco Technical
Assistance Center (TAC) engineers provide telephone support. If you do not hold a valid Cisco service
contract, contact your reseller.
Cisco CNS Network Registrar Installation Guide
vii
Obtaining Technical Assistance
Cisco Technical Support Website
The Cisco Technical Support Website provides online documents and tools for troubleshooting and
resolving technical issues with Cisco products and technologies. The website is available 24 hours a day,
365 days a year, at this URL:
http://www.cisco.com/techsupport
Access to all tools on the Cisco Technical Support Website requires a Cisco.com user ID and password.
If you have a valid service contract but do not have a user ID or password, you can register at this URL:
http://tools.cisco.com/RPF/register/register.do
NoteUse the Cisco Product Identification (CPI) tool to locate your product serial number before submitting
a web or phone request for service. You can access the CPI tool from the Cisco Technical Support
Website by clicking the Tools & Resources link under Documentation & Tools.Choose Cisco Product
Identification Tool from the Alphabetical Index drop-down list, or click the Cisco Product
Identification Tool link under Alerts & RMAs. The CPI tool offers three search options: by product ID
or model name; by tree view; or for certain products, by copying and pasting show command output.
Search results show an illustration of your product with the serial number label location highlighted.
Locate the serial number label on your product and record the information before placing a service call.
Submitting a Service Request
Using the online TAC Service Request Tool is the fastest way to open S3 and S4 service requests. (S3
and S4 service requests are those in which your network is minimally impaired or for which you require
product information.) After you describe your situation, the TAC Service Request Tool provides
recommended solutions. If your issue is not resolved using the recommended resources, your service
request is assigned to a Cisco TAC engineer. The TAC Service Request Tool is located at this URL:
http://www.cisco.com/techsupport/servicerequest
For S1 or S2 service requests or if you do not have Internet access, contact the Cisco TAC by telephone.
(S1 or S2 service requests are those in which your production network is down or severely degraded.)
Cisco TAC engineers are assigned immediately to S1 and S2 service requests to help keep your business
operations running smoothly.
To open a service request by telephone, use one of the following numbers:
Asia-Pacific: +61 2 8446 7411 (Australia: 1 800 805 227)
EMEA: +32 2 704 55 55
USA: 1 800 553-2447
For a complete list of Cisco TAC contacts, go to this URL:
http://www.cisco.com/techsupport/contacts
Definitions of Service Request Severity
viii
To ensure that all service requests are reported in a standard format, Cisco has established severity
definitions.
Severity 1 (S1)—Your network is “down,” or there is a critical impact to your business operations. You
and Cisco will commit all necessary resources around the clock to resolve the situation.
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Obtaining Additional Publications and Information
Severity 2 (S2)—Operation of an existing network is severely degraded, or significant aspects of your
business operation are negatively affected by inadequate performance of Cisco products. You and Cisco
will commit full-time resources during normal business hours to resolve the situation.
Severity 3 (S3)—Operational performance of your network is impaired, but most business operations
remain functional. You and Cisco will commit resources during normal business hours to restore service
to satisfactory levels.
Severity 4 (S4)—You require information or assistance with Cisco product capabilities, installation, or
configuration. There is little or no effect on your business operations.
Obtaining Additional Publications and Information
Information about Cisco products, technologies, and network solutions is available from various online
and printed sources.
• Cisco Marketplace provides a variety of Cisco books, reference guides, and logo merchandise. Visit
Cisco Marketplace, the company store, at this URL:
http://www.cisco.com/go/marketplace/
• Cisco Press publishes a wide range of general networking, training and certification titles. Both new
and experienced users will benefit from these publications. For current Cisco Press titles and other
information, go to Cisco Press at this URL:
http://www.ciscopress.com
• Packet magazine is the Cisco Systems technical user magazine for maximizing Internet and
networking investments. Each quarter, Packet delivers coverage of the latest industry trends,
technology breakthroughs, and Cisco products and solutions, as well as network deployment and
troubleshooting tips, configuration examples, customer case studies, certification and training
information, and links to scores of in-depth online resources. You can access Packet magazine at
this URL:
http://www.cisco.com/packet
• iQ Magazine is the quarterly publication from Cisco Systems designed to help growing companies
learn how they can use technology to increase revenue, streamline their business, and expand
services. The publication identifies the challenges facing these companies and the technologies to
help solve them, using real-world case studies and business strategies to help readers make sound
technology investment decisions. You can access iQ Magazine at this URL:
http://www.cisco.com/go/iqmagazine
• Internet Protocol Journal is a quarterly journal published by Cisco Systems for engineering
professionals involved in designing, developing, and operating public and private internets and
intranets. You can access the Internet Protocol Journal at this URL:
http://www.cisco.com/ipj
• World-class networking training is available from Cisco. You can view current offerings at
this URL:
http://www.cisco.com/en/US/learning/index.html
OL-6242-01
Cisco CNS Network Registrar Installation Guide
ix
Obtaining Additional Publications and Information
Cisco CNS Network Registrar Installation Guide
x
OL-6242-01
Overview
This guide describes how to install Cisco CNS Network Registrar 6.2 Beta on Windows, Solaris, and
Linux operating systems. You can also refer to these documents for important information about
configuring and managing Network Registrar:
• For configuration and management procedures for Network Registrar, see the Cisco CNS Network
Registrar User’s Guide.
• For details about commands available through the command line reference (CLI), see the Cisco CNS
Network Registrar CLI Reference.
About Network Registrar
Network Registrar is a network server suite that automates managing enterprise IP addresses. It provides
a stable infrastructure that increases address assignment reliability and efficiency. It includes these
servers (see Figure 1-1 on page 1-2):
CHAPTER
1
• Dynamic Host Configuration Protocol (DHCP)
• Domain Name System (DNS)
• Router Interface Configuration (RIC)
• Simple Network Management Protocol (SNMP)
• Trivial File Transfer Protocol (TFTP)
You can control these servers by using the Network Registrar web-based user interface (Web UI) or the
command line interface (CLI). These user interfaces can also control server clusters that run on different
platforms.
You can install Network Registrar in the local or regional mode:
• Local mode is used for managing local cluster protocol servers.
• Regional mode is used for managing multiple local clusters through a central management model.
A regional cluster centrally manages local cluster servers and their address spaces. The regional
administrator can perform these operations:
• Push and pull configuration data to and from the local DNS and DHCP servers.
• Obtain subnet utilization and IP lease history data from the local clusters.
• Manage the router interface configuration (RIC) server that integrates with cable modem
termination systems (CMTSs) directly from the regional cluster.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
1-1
System Requirements
Figure 1-1Network Registrar User Interfaces and the Server Cluster
Regional cluster
Central
management
Central
IP history
Telnet/SSH
HTTP/SCP
Subnet
utilization
Smart
allocation
RIC
server
Database
server
Chapter 1 Overview
Routers
HTTP/SCP
System Requirements
Review these system requirements before installing the Network Registrar 6.2:
• Java—You must have the Java Runtime Environment (JRE) 1.4.2 or later (or the equivalent Java
Development Kit [JDK]) installed on your system. (The JRE is available from Sun Microsystems on
its website.)
• Operating system—Your Network Registrar machine must meet these minimum requirements on the
Windows, Solaris, or Linux operating systems. (See Table 1-1 on page 1-3.)
• User Interface—Network Registrar currently includes two user interfaces: a Web UI and a CLI:
Local cluster
Local
web UI
DHCP
DNS
TFTP
DHCP failover pairs
Database
server
SCP
SCP
Local cluster
Local
web UI
DHCP
DNS
TFTP
Database
server
DNS secondary servers
111444
1-2
–
The Web UI runs on a minimum of Microsoft Internet Explorer 6.0 (Service Pack 2), Mozilla
Firefox 1.0, or Netscape 7.0 and requires Java JRE 1.4.2 or later.
–
The CLI runs in a Windows, Solaris, or Linux command window.
TipInclude a network time service in your configuration to avoid time differences between the local and
regional clusters. This method ensures that aggregated data at the regional server appears consistently.
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Chapter 1 Overview
Table 1-1Network Registrar Server Minimum Requirements
ComponentWindowsSolarisLinux
CPU architecture Intel Pentium III or
OS versionWindows XP or
RAM512 MB for all operating systems
Disk space18 GB recommended, minimum 310 MB required for installation
Swap space100 MB free swap space
Installation Modes
The modes of installation that exist for the local and regional clusters are new installations and upgrades
from a previous version with or without data migration. These installations or upgrades are performed
by using operating-system-specific software installation mechanisms:
its equivalent
Windows 2003
Installation Modes
Sun Netra AC200 Intel Pentium III or its equivalent
Solaris 8 or
Solaris 9
Red Hat Enterprise Server (ES) 3.0
• Windows—InstallShield setup program
• Solaris—pkgadd command
• Linux—install_cnr script that uses RPM Package Manager (RPM)
License Keys
Each Network Registrar software license key addresses a separate functional area. You enter these
license keys in the Web UI or CLI, which accepts the local cluster key only, or during an upgrade
installation. During an upgrade, you are prompted for a license key only if no valid license keys are
found in the existing license file. If a valid license key is found, no prompting occurs during the upgrade.
You can enter the license key during software installation or later in the Web UI or CLI. However, you
are prompted for a license key during installation only if there is no valid key in a license file, if such a
file exists from a previous installation.
The license that you have determines the options:
• If you have a permanent license, you must enter it once for each cluster. Once it is entered, you are
• If you have an invalid or expired license key, you cannot configure or manage the Network Registrar
not prompted for a license key again until you install the cluster on another machine or the license
key expires.
servers through the user interfaces until you obtain a valid license key, although the servers will
continue to function normally.
OL-6242-01
The license keys that you may need are:
• Local cluster key—Manages the local cluster servers in the Web UI or CLI. If you have Network
Registrar 6.1 installed, you can upgrade by using the key from that release.
• Regional central configuration key—Manages multiple local clusters at the regional cluster in the
Web UI only.
• Regional address space key—Manages the address space (address blocks and subnets) in the
multiple local clusters at the regional cluster.
Cisco CNS Network Registrar Installation Guide
1-3
Backup Software and Virus Scanning Guidelines
• IPv6 addressing key—Manages IPv6 addresses in the cluster.
• Router management key—Manages the RIC server at the regional cluster.
• Node count key—Records the number of managed IP addresses at the regional or local cluster.
Follow the guidelines to determine whether you need a new license key:
• Installing a new Network Registrar—Use the license key that ships with Network Registrar.
• Upgrading from 6.1—Use the license key from 6.1.
• Upgrading from a release before 6.1—Add a new license key. License keys that were valid before
6.1 will not work.
Backup Software and Virus Scanning Guidelines
If you have automatic backup or virus scanning software enabled on your system, exclude these Network
Registrar directories and their subdirectories from being scanned. If they are not excluded, file locking
issues can corrupt the databases or make them unavailable to the Network Registrar processes. If you are
installing to the default locations, exclude the following directories and their subdirectories:
Chapter 1 Overview
• Windows—
install-path\data (for example, C:\Program Files\Network Registrar\Local\data and C:\Program
Files\Network Registrar\Regional\data)
install-path\logs (for example, C:\Program Files\Network Registrar\Local\logs and C:\Program
Files\Network Registrar\Regional\logs)
• Solaris and Linux—
install-path/data (for example, /var/nwreg2/local/data and /var/nwreg2/regional/data)
install-path/logs (for example, /var/nwreg2/local/logs and /var/nwreg2/regional/logs)
Server Event Logging
System activity begins logging when you start Network Registrar. The server maintains all the logs by
default in these directories:
• Solaris and Linux—Local cluster: /var/nwreg2/local/logs;
Regional cluster: /var/nwreg2/regional/logs
To monitor the logs, use the tail -f command.
CautionIn Windows, to avoid losing the most recent system Application Event Log entries if the Event Log fills
up, use the Event Viewer system application to click the Overwrite Events as Needed check box in
Event Log Settings for the Application Log. If the installation process detects that this option is not set
properly, it displays a warning message advising corrective action.
1-4
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Chapter 1 Overview
Running Performance Monitoring Software on Windows
Running Performance Monitoring Software on Windows
On Windows systems only, if you uninstall Network Registrar and try to remove the associated data
directories while having software installed that integrates with the Windows Performance Monitor, the
software might take possession of certain shared libraries. This action prevents you from removing these
files from the Network Registrar folder; hence, the directory itself. To keep this event from happening:
1. Stop the service that is associated with the performance monitoring software.
2. Delete the Network Registrar folder.
3. Restart the service.
Running Other Protocol Servers
You cannot run the Network Registrar DNS, DHCP, or TFTP servers concurrently with any other DNS,
DHCP, and TFTP servers. In many Windows 2000 server systems, these services are enabled and running
by default. If the Network Registrar installation process detects that a conflict exists, it displays a
warning message.
Use one of these methods to change the Windows configuration from the Service Control Manager
(Control Panel > Administrative Tools > Services in Windows 2000):
Upgrading
• Change the Microsoft servers from a Startup Type of Automatic to Manual or Disabled.
• Stop the Network Registrar protocol server that conflicts with the Microsoft one by using the Stop
function in one of the user interfaces.
If you want to disable a protocol server and prevent the Network Registrar server from starting
automatically after a system reboot, use the server {dns | dhcp | tftp} disable start-on-reboot
command in the CLI.
The upgrade process differs slightly depending on the release from which you are upgrading. To preserve
your existing configurations during the upgrade:
• From Network Registrar 5.5 or earlier, you must first upgrade to 6.0 or 6.1. You must then do a
further upgrade to 6.2.
• You can upgrade to 6.2 while preserving the earlier configuration, or you can replace the
configuration.
Improvements in the Network Registrar software database from release to release can result in important
changes that affect the way that you use Network Registrar:
• The DHCP server’s configuration changed substantially in 6.2. Attributes formerly set on a scope or
DHCP server to configure DHCP failover, DNS updates and traps are now set separately and stored
in new data objects. You cannot upgrade custom or vendor-specific DHCP options; you must reenter
them using the new 6.2 functions.
• Beginning with Network Registrar 6.1.1, administrators and related data can be centrally managed,
which allows administrators, groups, and roles to be defined centrally at one time and then populated
throughout the system. To simplify central management, groups are used exclusively to associate
administrators with roles. These groups now manage the role assignments.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
1-5
Upgrading
Chapter 1 Overview
If you configured administrators with direct role assignments, the upgrade converts these role
assignments to group assignments. Group names are created from role names by appending the
suffix -group, with numbers appended as needed to avoid conflicting names. These groups are only
created for the upgrade, but only for roles that have administrators associated with them.
• If you are upgrading from 6.0, a number of name changes to processes, utilities, and files occurred
in 6.1 that can affect automated scripts that you have from previous releases.Ta ble 1-2 summarizes
these changes.
Table 1-2Name Changes from Release 6.0
Previous NameNew NameChange Action
AIC Server Agent 2.0 nwreglocal
nwregregion
Windows Network Registrar server name renamed to
local and regional server names
Displays as Network
Registrar Local (or
Regional) Server Agent
/etc/init.d/aicservagt/etc/init.d/nwreglocal
Solaris and Linux start/stop script renamed
/etc/init.d/nwregregion
aicservagt.execnrservagt.exeWindows Network Registrar server agent executable
file renamed
aicservagtcnrservagtSolaris and Linux Network Registrar server agent
executable file renamed
mcdsvr.execcmsrv.exe Windows MCD server executable renamed to the
CCM server
mcdsvrccmsrvSolaris and Linux MCD server executable renamed
to the CCM server
config_mcd_1_logconfig_ccm_1_logServer log file renamed
aicstatuscnr_statusSolaris and Linux server status utility renamed
1-6
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Checklist
CHAPTER
2
Installing and Upgrading Network Registrar
This chapter describes how to install Network Registrar 6.2 on Windows, Solaris, or Linux systems. The
chapter includes these sections:
• Checklist
• Installation and Upgrade Procedure
• Entering License Keys
• Uninstalling Network Registrar
• Starting and Stopping Servers
• Troubleshooting the Installation
Before you perform the installation or upgrade, ensure that you are prepared by reviewing this checklist:
• Does my system meet the minimum system requirements? (See the “Backup Software and Virus
Scanning Guidelines” section on page 1-4.)
• On Windows, are other applications closed, including any virus-scanning or automatic-backup
software programs?
• Do I have the proper software license keys? (See the “License Keys” section on page 1-3.
• Am I authorized for the administrative privileges needed to install the software?
• Does the target installation servers have enough disk space?
• Is this a new installation or an upgrade?
• Is the cluster mode of operation regional or local?
• Is this a full or client-only installation?
• Is the Java Runtime Environment (JRE) or Java Development Kit (JDK) installed, and where?
• Should the Web UIs use an HTTP or HTTPS connection, or both?
• Am I upgrading from an earlier version of Network Registrar? If so:
–
Are there any active user interface sessions?
–
Is my database backed up?
–
Is my Network Registrar task list empty?
OL-6242-01
Cisco CNS Network Registrar Installation Guide
2-1
Installation and Upgrade Procedure
Installation and Upgrade Procedure
Follow this procedure to install or upgrade Network Registrar. The procedure is essentially the same for
a new installation or upgrade; except that the upgrade requires a few additional steps.
Step 1Log in to the target machine using an account that has administrative privileges:
• Windows—Account in the Administrators group
• Solaris and Linux—su (superuser) or root account
Windows—Close all open applications, including any antivirus software. Also ensure that the Dr.
Watson visual notification setting is unchecked. This option prevents the servers from restarting
automatically if a failure occurs until you respond to a pop-up dialog box. The Visual Notification check
box in Dr. Watson is usually marked by default. Execute drwtsn32.exe (in C:\WINDOWS\system32),
uncheck the check box, then click OK. (Note that you can perform this step after the installation.)
Step 2Download and install the Java Runtime Environment (JRE) 1.4.2 or later, or the equivalent Java
Development Kit (JDK). These are available from Sun Microsystems at its website.
Step 3If you are not configuring secure login to the Web UI, skip to Step 4. If you are configuring secure login,
create a keystore file by using the Java keytool utility, which is located in the bin subdirectory of the
Java installation (see Step 2). Use the utility to either (1) define a self-signed certificate or (2) point to
a file for a certificate that you obtained from an external signing authority:
Chapter 2 Installing and Upgrading Network Registrar
a. To create a keystore file containing a self-signed certificate that is valid for 1 year, run this command
The keystore-file is the fully qualified path to the keystore file that you are creating. You must enter
the keystore path and password in Step 11.
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Chapter 2 Installing and Upgrading Network Registrar
CautionThe keystore password is stored in the server.xml file in the install-path\tomcat\conf
directory, which is protected to have superuser access only. Because the password is visible
as plain text in this file, do not change the file and directory permissions to make this file
generally accessible.
NoteIf you are planning multiple installations or upgrades at your site, you may want to prepare a
silent installation or upgrade response file at this point. With this response file, you can perform
subsequent installations or upgrades that occur without user input. For details, see Appendix A,
“Performing a Silent Installation.”
Step 4Load the installation CD, or browse to the network resource where the Network Registrar software is
located. If you download a distribution file from the Cisco website, run it from a different directory than
where you will install Network Registrar.
a. Windows—The cnr_6_2-nt.exe file is a self-extracting executable file that places the setup file and
other files in the directory where you run it. (If you are not configured for Autostart, run the
setup.exe file in that directory.) The Welcome to Cisco Network Registrar window appears.
Click Next. The second welcome window introduces the setup program and reminds you to exit all
current programs, including virus scanning software. If any programs are running, click Cancel,
close these programs, and return to the start of Step 4. If you already exited all programs, click Next.
b. Solaris and Linux—Be sure that the gzip and gtar utilities are available to uncompress and unpack
the Network Registrar installation files. See the GNU organization website for information on these
utilities. Follow these steps:
Installation and Upgrade Procedure
• Download the distribution file.
• Navigate to the directory in which you will uncompress and extract the installation files.
• Uncompress and unpack the .gtar.gz file. Use gtar with the –z option:
gtar -zxpf cnr_6_2-linux.gtar.gz
To unpack the .gtar file that gunzip already uncompressed, omit the –z option:
gtar -xpf cnr_6_2-linux.gtar
• Run this command or program:
Solaris—Run the pkgadd command with the –d option that specifies the directory from which
you are installing, with the –a option in case you want to upgrade from a previous release. The
name of the Network Registrar package is nwreg2:
pkgadd -a install-path/solaris/nwreg2/install/cnradmin -d install-path/solaris
nwreg2
Linux—Run the install_cnr script from the directory containing the installation files:
install-path # ./install_cnr
The install-path is the CD-ROM directory that contains the installation files or the directory that
contains the extracted Network Registrar installation files, if they were downloaded
electronically.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
2-3
Installation and Upgrade Procedure
Step 5Specify whether you want to install Network Registrar in the local or regional cluster mode (see the
“Overview” section on page 1-1):
• Windows—Keep the default Network Registrar Local or choose Network Registrar Regional.
Click Next. The Select Program Folder appears, where you determine the program folder in which
to store the program shortcuts in the Start menu. Accept the default, enter another name, or choose
a name from the Existing Folders list. Click Next.
• Solaris and Linux—Enter 1 for a local, or 2 for regional. The default mode is 1.
Step 6If you are upgrading, the upgrade process autodetects the installation directory from the previous release.
Note these Network Registrar installation directories and make any appropriate changes to meet your
needs:
• Windows default locations:
–
–
• Solaris and Linux default locations:
–
Chapter 2 Installing and Upgrading Network Registrar
Local cluster—C:\Program Files\Network Registrar\Local
Regional cluster—C:\Program Files\Network Registrar\Regional
Local cluster:
Program files—/opt/nwreg2/local
Data files—/var/nwreg2/local/data
Log files—/var/nwreg2/local/logs
Temporary files—/var/nwreg2/local/temp
–
Regional cluster:
Program files—/opt/nwreg2/regional
Data files—/var/nwreg2/regional/data
Log files—/var/nwreg2/regional/logs
Temporary files—/var/nwreg2/regional/temp
Step 7If you are upgrading from a previous release, see the “Upgrading” section on page 1-5 and continue with
the following steps. If you are performing a new installation, skip to Step 8.
a. Choose whether to keep the previous configuration or choose a new configuration:
• Windows—Keep the default Upgrade configuration database or choose Create new
configuration database. Click Next.
• Solaris and Linux—Enter y to upgrade the previous configuration database, or n to create a new
one.
b. Choose whether to archive the existing binaries and database in case this installation does not
succeed. The default and recommended choice is Yes or y:
• If you choose to archive the files, specify the archive directory. The default directories are:
Solaris and Linux—Local cluster (/opt/nwreg2/local.sav); Regional cluster
(/opt/nwreg2/regional.sav)
2-4
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Chapter 2 Installing and Upgrading Network Registrar
Step 8Choose the appropriate installation type: server and client (the default), or client-only:
• Windows—Choose Both server and client (default) or Client only. Click Next. The Select Port
window appears.
• Solaris and Linux—Entering 1 installs the server and client (the default), or 2 installs the client only.
Step 9Choose the CCM management SCP port number. (You can change this port number on your target
system.) These are the default port numbers:
• Local cluster—1234
• Regional cluster—1244
On Windows, click Next.
Step 10Enter the location of the Java installation (JRE or JDK 1.4.2 installed in Step 2). (The installation or
upgrade process tries to detect the location.)
• Windows—A dialog box reminds you of the Java requirements. Click OK and then choose the
default Java directory or another one. Click OK. The Select Connection Type window appears.
• Solaris and Linux—Enter the Java installation location.
Installation and Upgrade Procedure
NoteDo not include the bin subdirectory in the path. If you install a new Java version or change its
location, rerun the Network Registrar installer, then specify the new location in this step.
Step 11Choose whether to enable the Web UI to use a nonsecure (HTTP) or secure (HTTPS) connection for
Web U I lo gi ns:
• Windows—Choose Non-secure/HTTP (default), Secure/HTTPS (requires JSSE), or Both HTTP
and HTTPS.
• Solaris and Linux—Enter an HTTP port, a secure HTTPS port, or both HTTP and HTTPS ports.
Enabling the secure HTTPS port configures security for connecting to the Apache Tomcat 4.0 web server
by using a preconfigured JSSE installation (see Step 2 and Step 3 for configuration). (To change the
connection type, rerun the installer, and then make a different choice at this step.)
• If you choose HTTPS, or HTTP and HTTPS, click Next and continue with Step 12.
• If you choose the default HTTP connection, click Next, and skip to Step 13.
Step 12If you enabled HTTPS Web UI connectivity, you are prompted for the location of the necessary .jar files:
• If you want to use a different JSSE installation than the default set in Step 2 for the .jar files, enter it.
• For the keystore location, specify the fully qualified path to the keystore file that contains the
certificate(s) to be used for the secure connection to the Apache Tomcat web server. This is the
keystore-file that you specified in Step 3.
• For the keystore password, specify the password given when creating the keystore file. The default
password is changeit. On Windows, click Next.
OL-6242-01
Step 13Enter a port number for the Web UI connection. The defaults are:
• HTTP local cluster—8080
• HTTP regional cluster—8090
• HTTPS local cluster—8443
• HTTPS regional cluster—8453
On Windows, click Next.
Cisco CNS Network Registrar Installation Guide
2-5
Entering License Keys
The Network Registrar installation process begins. (Solaris prompts you to verify that you want to
continue with the installation.) Status messages report that the installer is transferring files and running
scripts. This process may take a few minutes:
• Windows—The Setup Complete window appears. Choose Yes, I want to restart my computer now
or No, I will restart my computer later and then click Finish.
• Solaris and Linux—Successful completion messages appear.
Step 14Verify the status of the Network Registrar servers:
• Windows—In the Services control panel, verify that the Network Registrar Local Server Agent or
Network Registrar Regional Server Agent is running after rebooting the system when the installation
has completed successfully.
• Solaris and Linux—Use the install-path/usrbin/cnr_status command to verify status. See the
“Starting and Stopping Servers” section on page 2-8.
Entering License Keys
Chapter 2 Installing and Upgrading Network Registrar
To administer the local and regional clusters that you installed, you must enter at least one license key.
Running features at the cluster may require multiple keys.
Ensure that you have read the “License Keys” section on page 1-3 for critical information about license
keys, including a description of each license type and which keys you need.
Follow this procedure to enter license keys:
Step 1Start the Network Registrar Web UI or CLI:
• To access the Web UI, open the Web browser and use the HTTP (nonsecure login) or HTTPS (secure
The hostname is the actual name of the target host.
–
The default-port-at-install is the default HTTP or HTTPS port that is specified during
installation (see the installation procedure, Step 13 on page 2-5).
On Windows, you can access the Web UI from the Start menu from the local host:
–
Local cluster—Start > Programs > Network Registrar 6.2 > Network Registrar 6.2 local
Web UI (or Network Registrar 6.2 local Web UI (secure) if you enabled secure login).
–
Regional cluster—Start > Programs > Network Registrar 6.2 > Network Registrar 6.2
regional Web UI (or Network Registrar 6.2 regional Web UI (secure) with secure login).
2-6
• To start the CLI:
–
Windows—Navigate to the install-path\bin directory and enter this command:
nrcmd -C cluster-ipaddress -N admin -P changeme
–
Solaris and Linux—Navigate to the install-path\usrbin directory and enter this command:
Chapter 2 Installing and Upgrading Network Registrar
Step 2Enter the username admin and the password changeme.
TipCisco recommends that you change this password as soon as possible to maintain system
security.
Step 3Enter the license key:
• Web UI—Enter the license key on the Add License page. Click Add. The License Type column
indicates what kind of license has been entered.
• CLI—You can enter the local cluster license only. Enter this command to define the key:
nrcmd> license set key=keystring
Uninstalling Network Registrar
Follow the appropriate procedure to uninstall Network Registrar. The procedure differs based on which
operating system you are using. (You must have administrator or superuser privileges to uninstall
Network Registrar, just as you must to install it.)
Uninstalling Network Registrar
To back up your database before uninstalling Network Registrar, see the Cisco CNS Network Registrar
User’s Guide for the procedure. (You cannot convert the 6.2 databases back to a format that the previous
releases can use.)
NoteUninstallation stops the Network Registrar server agents first. If you find that the server processes are
not shutting down, see the “Starting and Stopping Servers” section on page 2-8.
Uninstalling on Windows
Follow this procedure to uninstall Network Registrar on Windows:
Step 1Choose the Add/Remove Program function from the Windows control panel, or the Uninstall Network
Registrar choice from the Windows Start menu Network Registrar shortcut folder. The uninstallation
program removes the server and user interface components but does not delete user data files.
Step 2Optionally, delete all Network Registrar data by deleting the Network Registrar folder.
NoteTemporarily stop any service that is related to software that integrates with Performance
Monitoring that might interfere with removing shared libraries in the Network Registrar folder.
Step 3Reboot after the uninstallation completes to finish the uninstall process.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
2-7
Starting and Stopping Servers
Uninstalling on Solaris
Follow this procedure to uninstall Network Registrar on Solaris:
Step 1From the root account, use the pkgrm program to remove the nwreg2 package:
pkgrm nwreg2
The uninstallation procedure removes the server and user interface components; but does not delete user
data, such as the log and data files.
Step 2Optionally, delete the database and log files that are associated with Network Registrar, as mentioned in
the instructions at the end of the pkgrm process.
Uninstalling on Linux
Follow this procedure to uninstall Network Registrar on Linux:
Chapter 2 Installing and Upgrading Network Registrar
Step 1Run the uninstall_cnr program from the install-path/usrbin directory:
./uninstall_cnr
Stopping Server Agent...
Deleting startup files...
Removing Network Registrar...
cannot remove /opt/nwreg2/usrbin - directory not empty
cannot remove /opt/nwreg2/conf - directory not empty
package optnwreg2 not found in file index
Note that any files that have been changed (including your database) have _not_ been
uninstalled. You should delete these files by hand when you are done with them, before you
reinstall the package.
The cannot remove warnings mean that, although the uninstall program removes the server and user
interface components, it cannot delete directories that are not empty. Certain configuration and data files
that are created during installation remain deliberately after uninstallation.
Step 2Optionally, delete the database and log files that are associated with Network Registrar, as mentioned in
the instructions at the end of the uninstall_cnr script execution.
Starting and Stopping Servers
In Windows, you can stop and start the Network Registrar server agent from the Services feature of the
Windows Control Panel. If the installation completed successfully and you enabled the servers, the
Network Registrar DNS and DHCP servers start automatically each time you reboot the machine.
2-8
For the TFTP server, you must use this Network Registrar CLI command to enable it to restart on bootup:
nrcmd> tftp enable start-on-reboot
All servers in the cluster are controlled by the Network Registrar regional or local server agent. You can
stop or start the servers by stopping or starting the server agent.
For details on stopping and starting servers, see the Cisco Network Registrar User’s Guide.
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Chapter 2 Installing and Upgrading Network Registrar
Starting and Stopping Servers on Windows
Follow this procedure to start and stop servers on Windows:
Step 1Choose Start > Settings > Control Panel > Administrative Tools > Services.
Step 2From the Service list, choose Network Registrar Local Server Agent or Network Registrar Regional
Server Agent.
Step 3Click Restart or Stop, as required, and then click Close.
Starting and Stopping Servers on Solaris or Linux
In Solaris or Linux, the Network Registrar servers automatically start up after a successful installation
or upgrade. You do not need to reboot the system. Follow this procedure to start and stop servers on
Solaris or Linux:
Troubleshooting the Installation
Step 1Log in as superuser.
Step 2Start the server agent by running the nwreglocal or nwregregion script with the start argument:
# /etc/init.d/nwreglocal start ;for the local cluster
# /etc/init.d/nwregregion start ;for the regional cluster
Step 3Enter the cnr_status command to check that the servers are running:
# install-path/usrbin/cnr_status
Step 4Stop the server agent by running the nwreglocal or nwregregion script with the stop argument:
# /etc/init.d/nwreglocal stop ;for the local cluster
# /etc/init.d/nwregregion stop ;for the regional cluster
Troubleshooting the Installation
The Network Registrar installation process creates a log file, install_cnr_log, in the Network Registrar
log file directory. For upgrades, two additional log files are created: mcdupgrade_log and
lease_upgrade_log. The log directory is set to these locations by default:
• Windows:
–
Local cluster: C:\Program Files\Network Registrar\Local\logs
If the installation or upgrade does not complete successfully, first check the contents of these log files
to help determine what might have failed. Some examples of possible causes of failure are:
• An incorrect version of Java is installed.
• Insufficient disk space is available.
• Inconsistent data exists for an upgrade.
If the log messages do not clearly indicate the failure, you can gather additional debug information by
using the debug_install utility script. This script appears only if the installation failed and is located by
default in the Network Registrar program files directory:
• Windows:
• Solaris and Linux:
If the
has sufficient permissions to allow a nonprivileged installation user ID to write to it.
Chapter 2 Installing and Upgrading Network Registrar
–
Local cluster: C:\Program Files\Network Registrar\Local\debug_install.cmd
## Executing checkinstall script part of the Solaris pkgadd fails, ensure that the /tmp directory
If you still need help determining the cause or resolution of the failure, forward the output of this script
to Cisco Systems for further analysis. To contact Cisco for assistance, see the “Obtaining Technical
Assistance” section on page vii.
2-10
Cisco CNS Network Registrar Installation Guide
OL-6242-01
APPENDIX
A
Performing a Silent Installation
This appendix describes how to perform a silent installation, upgrade, or uninstallation of the Network
Registrar product. A silent installation or upgrade allows for unattended product installations based on
the configuration values that are provided at the time that a silent installation response file was created.
CautionYou must use a “clean install” mode silent-response file for fresh installations, and an “upgrade” mode
silent-response file for product upgrades. The configuration values specified in the silent-response files
are specific to a particular installation or upgrade environment, and cannot be mixed and matched.
Unpredictable results occur if you attempt to use a silent-response file that does not exactly match the
installation or upgrade system configuration.
Follow these procedures to generate a silent installation response file:
Step 1For each silent installation or upgrade, use these commands to create a separate response file:
• Windows:
setup.exe –r
Complete the installation or upgrade steps as you normally would. This command installs or
upgrades Network Registrar according to the parameters that you specified. It also generates the
setup.iss response file based on these parameters. Look for this file in the Windows installation
directory, such as C:\WINDOWS. Each time you use the command, the file is overwritten.
Cisco recommends that you rename or relocate this file before running the silent-process in Step 2.
Rename the file to something distinguishable, such as local-nr-https-install, and relocate it to a
temporary folder.
• Solaris:
pkgask –d install-path –r response-file nwreg2
Complete the installation or upgrade steps as you normally would. This action does not actually
install or upgrade Network Registrar, but simply generates a response file by the specified name that
includes the installation or upgrade parameters that you want to replicate for additional installations
or upgrades. Cisco recommends that you name the file something distinguishable, such as
local-nr-upgrade or regional-nr-https-install.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
A-1
Appendix A Performing a Silent Installation
• Linux:
Create a text response file with these variable declarations (modify the values to suit the desired
configuration for your system):
Use these commands to invoke the silent installation or upgrade for each instance:
• Windows:
setup.exe –s –f1path+response-file
Note that the silent installation fails if you do not specify the –f1 argument with a fully qualified
path to the response file, unless the response file is located in the i386 directory and setup.exe is run
from that directory.
Linux (this command is noninteractive except during an error):
•
uninstall_cnr
A-2
Cisco CNS Network Registrar Installation Guide
OL-6242-01
Lab Evaluation Installations
This appendix describes how to install, upgrade, and uninstall Network Registrar regional and local
clusters on a single machine to support smaller test configurations for evaluation purposes.
CautionInstalling the regional and local clusters on a single machine is intended only for lab evaluations, and
should not be chosen for production environments. The aggregated regional cluster databases are
expected to be too large to be reasonably located with a local server that is also running DNS or DHCP
services. Running out of free disk space causes these servers to fail.
Installing Network Registrar in a Lab
Follow this procedure to install Network Registrar on a single machine for evaluation purposes:
APPENDIX
B
Step 1Before you run the installation program, check that the machine has enough disk space to accommodate
two separate installations of Network Registrar.
Step 2Install or upgrade the local cluster on the machine, according to the procedures in Chapter 2, “Installing
and Upgrading Network Registrar.” Specify the Local cluster installation. In Windows, do not reboot.
Step 3Install or upgrade the regional cluster on the same machine, according to the same procedures. Specify
the Regional cluster installation. In Windows, this time reboot.
Testing the Lab Installation
Follow this procedure to test the installation:
Step 1Start and log in to the Web UI for the local cluster, using the URL appropriate to the port number. By
default, the local port numbers are 8080 for HTTP connections and 8443 for HTTPS (secure)
connections. In Windows, from the Start menu, choose the Network Registrar 6.2 local Web UI.
Step 2Add DNS zones and DHCP scopes, templates, client-classes, or virtual private networks (VPNs) as a test
to pull data to the regional cluster.
OL-6242-01
Cisco CNS Network Registrar Installation Guide
B-1
Uninstalling in a Lab Environment
Step 3Start and log in to the Web UI for the regional cluster, using the URL appropriate to the port number. By
default, the regional port numbers are 8090 for HTTP connections and 8453 for HTTPS (secure)
connections. In Windows, from the Start menu, choose the Network Registrar 6.2 regional Web UI.
Step 4Test the regional cluster for single sign-on connectivity to the local cluster. Try to pull DNS zone
distributions, DHCP scopes, templates, client-classes, or VPNs from the local cluster to the regional
replica database.
Uninstalling in a Lab Environment
If you need to uninstall Network Registrar, follow the procedure in the “Uninstalling Network Registrar”
section on page 2-7.
No option exists to uninstall only the regional or local cluster in a dual-mode installation environment.
Appendix B Lab Evaluation Installations
B-2
Cisco CNS Network Registrar Installation Guide
OL-6242-01
INDEX
A
Add License page, Web UI2-7
antivirus software2-2
archive directories2-4
archiving2-4