b0700sf e
b0700sf e
b0700sf e
*B0700SF* *E*
B0700SF
Rev E
February 9, 2016
Schneider Electric, Invensys, Foxboro, and I/A Series are trademarks of Schneider Electric SE, its subsidiaries
and affiliates.
All other brand names may be trademarks of their respective owners.
iii
B0700SF – Rev E Contents
3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8........ 35
Scenario 1 ............................................................................................................................... 36
Scenario 2 ............................................................................................................................... 37
Scenario 3 ............................................................................................................................... 37
Scenario 4 ............................................................................................................................... 37
Scenario 5 ............................................................................................................................... 38
Scenario 6 ............................................................................................................................... 39
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on
The MESH Control Network ............................................................................................. 41
Installing I/A Series SE Software v8.8 on Primary
Domain Controllers on The MESH Control Network ........................................................... 41
Server Preparation .............................................................................................................. 41
Notes on Installing I/A Series System Software ................................................................... 43
Changing the Station Name ............................................................................................... 44
Disabling the VirusScan Console ........................................................................................ 44
Preparing Network Interface Cards (NICs) For Installation ............................................... 45
Canceling and Resuming the Security Enhanced Installation Process ................................. 46
Installation Procedure ......................................................................................................... 47
Installing the I/A Series Software v8.8 Trailer CD-ROM .............................................. 62
Restarting Your System .................................................................................................. 63
Installing Optional Software ............................................................................................... 63
System Manager and System Management Display Handler (SMDH)
Installation Notes .......................................................................................................... 63
Primary Domain Controller Postinstallation Procedures .................................................... 65
Changing Passwords ...................................................................................................... 65
Creating Users in Active Directory ................................................................................ 68
Tombstone Lifetime Attribute in Active Directory ........................................................ 75
Backing Up Active Directory ......................................................................................... 75
Continuing Installation ...................................................................................................... 75
Installing Security Enhanced I/A Series Software v8.8
on Secondary Domain Controllers on The MESH Control Network ..................................... 76
Server Preparation .............................................................................................................. 76
Notes on Installing I/A Series System Software ................................................................... 77
Changing the Station Name ............................................................................................... 78
Disabling the VirusScan Console ........................................................................................ 79
Preparing Network Interface Cards (NICs) For Installation ............................................... 80
Canceling and Resuming the Security Enhanced Installation Process ................................. 81
Installation Procedure ......................................................................................................... 82
Installing the I/A Series Software v8.8 Trailer CD-ROM ............................................ 100
Restarting Your System ................................................................................................ 101
Installing Optional Software ............................................................................................. 101
iv
Contents B0700SF – Rev E
v
B0700SF – Rev E Contents
vi
Contents B0700SF – Rev E
vii
B0700SF – Rev E Contents
viii
Contents B0700SF – Rev E
ix
B0700SF – Rev E Contents
x
Figures
2-1. Disable Virus Scan Access Protection .......................................................................... 15
2-2. On-Access Scan Properties Dialog Box ........................................................................ 16
2-3. Confirming Cancellation of Software Installation ....................................................... 17
2-4. InstallShield Wizard Completed - Interrupted ............................................................ 18
2-5. AutoPlay Dialog Box ................................................................................................... 19
2-6. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box ..... 20
2-7. Selecting to Install a Domain Controller ..................................................................... 21
2-8. Load Committed Configuration Install Files ............................................................... 22
2-9. Installation Media Folder Browser ............................................................................... 23
2-10. Load Committed Configuration Install Files - Binding ............................................... 24
2-11. I/A Series Network Installation (For Certain NIC Cards) ........................................... 25
2-12. I/A Series Installshield Wizard - Next .......................................................................... 25
2-13. I/A Series Installshield Wizard - Install ........................................................................ 26
2-14. Installation Media Dialog Box ..................................................................................... 27
2-15. Media Folder Browser ................................................................................................. 27
2-16. Installation Media Dialog Box - For Diskettes ............................................................. 28
2-17. Complete Installation .................................................................................................. 28
2-18. Example of Installation Log ......................................................................................... 29
2-19. Installing System Manager Server ................................................................................ 32
4-1. Disable Virus Scan Access Protection .......................................................................... 44
4-2. On-Access Scan Properties Dialog Box ........................................................................ 45
4-3. Confirming Cancellation of Software Installation ....................................................... 46
4-4. Confirming Installation Interruption .......................................................................... 47
4-5. InstallShield Wizard Completed - Interrupted ............................................................ 47
4-6. AutoPlay Dialog Box ................................................................................................... 48
4-7. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box ..... 49
4-8. Selecting to Install a Domain Controller ..................................................................... 50
4-9. Load Committed Configuration Install Files ............................................................... 51
4-10. Installation Media Folder Browser ............................................................................... 52
4-11. I/A Series Network Installation (For Certain NIC Cards) ........................................... 53
4-12. Server Platform Setup Dialog Box ............................................................................... 53
4-13. Active Directory Warning ........................................................................................... 54
4-14. Active Directory Installation via DOS Window .......................................................... 54
4-15. Promoting to Primary Domain Controller via DOS Window ..................................... 55
4-16. Setting up the Platform for a Secure I/A Series Installation ......................................... 56
4-17. Active Directory Domain Settings Applied .................................................................. 57
4-18. I/A Series Secure User Accounts Dialog Box ............................................................... 57
4-19. Invensys IASeries Install: Workstation Reboot Request Dialog Box ............................ 58
4-20. You Are About To Be Logged Off Dialog Box ............................................................ 58
4-21. Installation Media Dialog Box ..................................................................................... 59
4-22. Media Folder Browser ................................................................................................. 60
4-23. Installation Media Dialog Box - For Diskettes ............................................................. 61
4-24. Example of Installation Log ......................................................................................... 62
4-25. Installing System Manager Server ................................................................................ 64
xi
B0700SF – Rev E Figures
4-26. Resetting Passwords via Active Directory Users and Computers .................................. 66
4-27. Resetting a Password ................................................................................................... 66
4-28. Setting the Restore Mode Password via ntdsutil.exe .................................................... 67
4-29. Using and Exiting ntdsutil.exe .................................................................................... 67
4-30. Creating Users via Active Directory Users and Computers .......................................... 68
4-31. New Object - User ...................................................................................................... 69
4-32. New Object - User - Password Updates ....................................................................... 70
4-33. New Object - User - Finish ......................................................................................... 70
4-34. Opening the New User Properties Dialog Box ............................................................ 71
4-35. New User Properties Dialog Box ................................................................................. 72
4-36. Select Groups .............................................................................................................. 73
4-37. Multiple Names Found Dialog Box ............................................................................ 73
4-38. Closing Select Groups Dialog Box .............................................................................. 74
4-39. Closing Properties Dialog Box .................................................................................... 74
4-40. Disable Virus Scan Access Protection .......................................................................... 79
4-41. On-Access Scan Properties Dialog Box ........................................................................ 80
4-42. Confirming Cancellation of Software Installation ....................................................... 81
4-43. Confirming Installation Interruption .......................................................................... 82
4-44. InstallShield Wizard Completed - Interrupted ............................................................ 82
4-45. AutoPlay Dialog Box ................................................................................................... 83
4-46. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box ..... 84
4-47. Selecting to Install a Domain Controller ..................................................................... 85
4-48. Load Committed Configuration Install Files ............................................................... 86
4-49. Installation Media Folder Browser ............................................................................... 87
4-50. I/A Series Network Installation (For Certain NIC Cards) ........................................... 88
4-51. Server Platform Setup Dialog Box (SDC) .................................................................... 89
4-52. Resetting UTC Date ................................................................................................... 90
4-53. Unable to Determine Local Time on the PDC ............................................................ 90
4-54. Server Platform Setup Dialog Box (Second SDC) ....................................................... 91
4-55. Invensys IASeries Install: Workstation Reboot Request Dialog Box ............................ 92
4-56. Server Platform Setup Dialog Box (PDC Account Information) ................................. 93
4-57. Server Platform Setup Dialog Box (Verify Domain Name and Site Name Fields) ....... 94
4-58. Active Directory Installation via DOS Window .......................................................... 95
4-59. Assigning Role of Secondary Domain Controller via DOS Window ........................... 95
4-60. Setting Up the Platform for a Secure I/A Series Installation ......................................... 96
4-61. InstallShield Wizard for I/A Series Software ................................................................ 97
4-62. Installation Media Dialog Box ..................................................................................... 97
4-63. Media Folder Browser ................................................................................................. 98
4-64. Installation Media Dialog Box - For Diskettes ............................................................. 99
4-65. Example of Installation Log ....................................................................................... 100
4-66. Installing System Manager Server .............................................................................. 102
4-67. Setting the Restore Mode Password via ntdsutil.exe .................................................. 103
4-68. Using and Exiting ntdsutil.exe .................................................................................. 104
5-1. Disable Virus Scan Access Protection ........................................................................ 109
5-2. On-Access Scan Properties Dialog Box ...................................................................... 110
5-3. Confirming Cancellation of Software Installation ..................................................... 111
5-4. Confirming Installation Interruption ........................................................................ 111
5-5. InstallShield Wizard Completed - Interrupted .......................................................... 112
xii
Figures B0700SF – Rev E
xiii
B0700SF – Rev E Figures
xiv
Figures B0700SF – Rev E
7-5. Installation Disc Is Not Compatible With This Windows Version Warning ............. 201
7-6. Invoking adprep32 /forestprep .................................................................................. 201
7-7. Invoking adprep32 /domainprep /gpprep .................................................................. 202
7-8. Invoking adprep32 /rodcprep .................................................................................... 202
7-9. AutoPlay Dialog Box ................................................................................................. 205
7-10. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box ... 206
7-11. Selecting to Install a Domain Controller On-MESH ................................................ 207
7-12. I/A Series Installation Warning ................................................................................. 207
7-13. Load Committed Configuration Install Files ............................................................. 208
7-14. Installation Media Folder Browser ............................................................................. 209
7-15. I/A Series Network Installation (For Certain NIC Cards) ......................................... 210
7-16. Server Platform Setup Dialog Box ............................................................................. 211
7-17. I/A Series Installation Date Warning ......................................................................... 212
7-18. Unable to Determine Local Time on the PDC .......................................................... 212
7-19. Server Platform Setup (For Second SDC) ................................................................. 213
7-20. Invensys IASeries Install: Workstation Reboot Request Dialog Box .......................... 214
7-21. Server Platform Setup (On-MESH) Continued ........................................................ 215
7-22. Server Platform Setup (On-MESH) Continued Part 2 .............................................. 216
7-23. Active Directory Warning ......................................................................................... 217
7-24. Active Directory Installation via a Command Prompt ............................................... 217
7-25. Assigning Role of Secondary Domain Controller via Command Prompt .................. 218
7-26. Verifying the Health of the Existing Active Directory System ................................... 219
7-27. I/A Series Installation Warning for DC Health Log File ............................................ 220
7-28. Verifying the Health of the Existing Active Directory System (Errors Found) ........... 221
7-29. I/A Series Installation Errors in DC Health Log File ................................................. 222
7-30. Setting Up the Platform For a Secure I/A Series Installation ...................................... 223
7-31. Installation Media Dialog Boxes ................................................................................ 224
7-32. Media Folder Browser ............................................................................................... 224
7-33. Installation Media Dialog Box - For Diskettes ........................................................... 225
7-34. Selecting FoxInt NDIS Intermediate Miniport Driver .............................................. 226
7-35. Adapter Properties Dialog Box .................................................................................. 226
7-36. Internet Protocol (TCP/IP) Properties Dialog Box .................................................... 227
7-37. Internet Protocol (TCP/IP) Properties Dialog Box .................................................... 228
8-1. Active Directory Users and Computers Console (Administrator Account) ................ 232
8-2. [User] Properties Dialog Box ..................................................................................... 233
8-3. Adding User to Groups ............................................................................................. 234
8-4. Active Directory Users and Computers Console (Administrator Account) ................ 235
8-5. Installation Disc Is Not Compatible With This Windows Version Warning ............. 236
8-6. Invoking adprep32 /forestprep .................................................................................. 236
8-7. Invoking adprep32 /domainprep /gpprep .................................................................. 237
8-8. Invoking adprep32 /rodcprep .................................................................................... 237
8-9. Internet Protocol (TCP/IP) Properties Dialog Box .................................................... 238
8-10. Advanced TCP/IP Settings Dialog Box (IP Settings) ................................................. 239
8-11. Advanced TCP/IP Settings Dialog Box (DNS) ......................................................... 240
8-12. Internet Protocol (TCP/IP) Properties Dialog Box .................................................... 241
8-13. DNS Manager Dialog Box (Server Properties) .......................................................... 242
8-14. Server Properties Dialog Box ..................................................................................... 243
8-15. DNS Manager Dialog Box (Removing Existing Stations) .......................................... 244
xv
B0700SF – Rev E Figures
8-16. DNS Manager Dialog Box (Reverse Lookup Zone) .................................................. 245
8-17. New Zone Wizard (Zone Type) ................................................................................ 246
8-18. New Zone Wizard (Active Directory Zone Replication Scope) ................................. 247
8-19. New Zone Wizard (Reverse Lookup Zone Name) ..................................................... 248
8-20. New Zone Wizard (Dynamic Update) ...................................................................... 249
8-21. DNS Manager Dialog Box (New Pointer) ................................................................. 250
8-22. New Resource Record Dialog Box ............................................................................. 251
8-23. Restart DNS Service .................................................................................................. 252
8-24. nslookup Service ....................................................................................................... 252
8-25. Local Area Connection 3 Properties .......................................................................... 254
8-26. Internet Protocol Version 4 (TCP/IPv4) Properties ................................................... 255
8-27. Set-ExecutionPolicy AllSigned .................................................................................. 256
8-28. AutoPlay Dialog Box ................................................................................................. 256
8-29. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box ... 257
8-30. Selecting to Install a Domain Controller Off-MESH ................................................ 258
8-31. I/A Series Installation Warning ................................................................................. 258
8-32. Load Committed Configuration Install Files ............................................................. 259
8-33. Installation Media Folder Browser ............................................................................. 260
8-34. Server Platform Setup (Off-MESH) .......................................................................... 261
8-35. I/A Series Installation Date Warning ......................................................................... 262
8-36. Unable to Determine Local Time on the PDC .......................................................... 262
8-37. Server Platform Setup (For Second SDC) ................................................................. 263
8-38. Invensys IASeries Install: Workstation Reboot Request Dialog Box .......................... 264
8-39. Server Platform Setup (Off-MESH) Continued ........................................................ 265
8-40. Active Directory Warning ......................................................................................... 265
8-41. Active Directory Installation via Command Prompt ................................................. 266
8-42. Assigning Role of Secondary Domain Controller via Command Prompt .................. 266
8-43. Verifying the Health of the Existing Active Directory System ................................... 267
8-44. I/A Series Installation Warning for DC Health Log File ............................................ 268
8-45. Verifying the Health of the Existing Active Directory System (Errors Found) ........... 269
8-46. I/A Series Installation Errors in DC Health Log File ................................................. 270
8-47. Setting Up the Platform For a Secure I/A Series Installation ...................................... 271
8-48. Configure DNS Setting Dialog Box .......................................................................... 272
8-49. Internet Protocol (TCP/IP) Properties - Removing On-MESH DNS Entries ........... 273
8-50. Internet Protocol (TCP/IP) Properties - Setting for Off-MESH
Network Interface Card ............................................................................................ 274
8-51. Selecting IA Computers -> New -> Computer .......................................................... 275
8-52. New Object - Computer ........................................................................................... 276
8-53. Selecting Pre-8.8 IA Computers -> New -> Computer .............................................. 276
9-1. InterForestMigration Folder ...................................................................................... 281
9-2. Disable Virus Scan Access Protection ........................................................................ 282
9-3. On-Access Scan Properties Dialog Box ...................................................................... 283
9-4. Selecting Reset Password ........................................................................................... 284
9-5. Reset Password Dialog Box ....................................................................................... 285
9-6. Set-ExecutionPolicy Unrestricted .............................................................................. 285
9-7. Internet Protocol (TCP/IP) Properties Dialog Box - Off-MESH NIC Card ............. 286
9-8. Internet Protocol (TCP/IP) Properties Dialog Box - FoxInt NDIS Intermediate
Miniport Driver ........................................................................................................ 287
xvi
Figures B0700SF – Rev E
xvii
B0700SF – Rev E Figures
xviii
Figures B0700SF – Rev E
xix
B0700SF – Rev E Figures
xx
Figures B0700SF – Rev E
xxi
B0700SF – Rev E Figures
D-78. Active Directory Installation Wizard - Restarting the Computer ............................... 492
D-79. Active Directory Users and Computers - Delete a Domain Controller Connection ... 493
D-80. Active Directory Users and Computers - Delete Confirmation .................................. 493
D-81. Active Directory Users and Computers - Delete a Domain Controller Settings ......... 494
D-82. Active Directory Users and Computers - Delete Confirmation .................................. 494
D-83. Active Directory Users and Computers - Deleting a Domain Controller ................... 495
D-84. Active Directory Users and Computers - Delete a Server ........................................... 495
D-85. Active Directory Users and Computers - Delete Confirmation .................................. 496
D-86. Active Directory Users and Computers - Creating New Computer Account ............. 496
D-87. New Object - Computer Dialog Box ......................................................................... 497
D-88. Workstation System Properties .................................................................................. 498
D-89. Computer Name Changes Dialog Box - Workgroup ................................................. 499
D-90. Computer Name Change - Remember Local Admin Password ................................. 499
D-91. Log in IADomainAdmin ........................................................................................... 500
D-92. Computer Name Change - Welcome to the [YourName] Workgroup ...................... 500
D-93. Computer Name Change - Restart Computer ........................................................... 500
D-94. Closing System Properties Dialog Box ...................................................................... 501
D-95. Computer Name Changes Dialog Box - Domain ...................................................... 502
D-96. Windows Security Dialog Box ................................................................................... 502
D-97. Computer Name Changes Dialog Box - Welcome to the [YourName] Domain ....... 503
D-98. Computer Name Changes Dialog Box - Need to Restart To Apply Changes ............ 503
D-99. Close System Properties Dialog Box .......................................................................... 504
D-100. Computer Name Changes Dialog Box - Need to Restart To Apply Changes ............ 504
D-101. Local Area Connection Properties Dialog Box ........................................................... 505
D-102. Internet Protocol Version 4 (TCP/IP4) Properties Dialog Box .................................. 506
D-103. Advanced TCP/IP Settings Dialog Box .................................................................... 507
D-104. Opening ADSI Edit Directory Services ..................................................................... 509
D-105. ADSI Edit Directory Services - Connect To .............................................................. 509
D-106. ADSI Edit Directory Services - Configuration ........................................................... 510
D-107. ADSI Edit Directory Services - Properties Selection .................................................. 511
D-108. Attribute Editor - Attribute Selection ........................................................................ 512
D-109. Attribute Value -- Tombstone Lifetime Period .......................................................... 512
F-1. MESH Configurator NIC Selection .......................................................................... 519
F-2. NIC Selection on Unknown Platform/BIOS ............................................................. 520
F-3. Network Connections ............................................................................................... 521
F-4. Network Connections Showing Device Names ......................................................... 521
F-5. Off-MESH NIC Selection ........................................................................................ 522
F-6. NICs on The MESH Control Network Selection ..................................................... 522
H-1. SNMP Service Properties Dialog Box ........................................................................ 528
I-1. Windows Features Dialog Box .................................................................................. 531
I-2. Server Manager ......................................................................................................... 532
I-3. Add Features Wizard ................................................................................................. 533
I-4. Confirm Installation Selections ................................................................................. 534
J-1. Windows Firewall Settings ........................................................................................ 536
J-2. Printer Properties Dialog Box .................................................................................... 537
K-1. Run rsop.msc ............................................................................................................ 539
K-2. Resultant Set of Policy Window ................................................................................ 540
K-3. Computer Configuration Properties Dialog Box ....................................................... 541
xxii
Tables
1-1. I/A Series Software v8.8 Platform Specific Media Kits ................................................... 6
1-2. I/A Series Software v8.8 Day 0 Media Kit (K0201GA) ................................................. 8
1-3. Additional Packages for I/A Series Software V8.8 .......................................................... 9
3-1. Domain Controller Installation/Migration Scenarios for I/A Series Software v8.8 ....... 36
C-1. McAfee VirusScan Enterprise + AntiSpyware Enterprise Exclusion List .................... 429
xxiii
B0700SF – Rev E Tables
xxiv
Preface
Purpose
The purpose of this document is to describe I/A Series software installation on Windows worksta-
tions and servers. I/A Series software v8.8 software is not supported on Solaris stations.
I/A Series software v8.8 delivers optional enhanced security features for the I/A Series system that
facilitates meeting client and government specifications, for example, North American Electric
Reliability Corporation (NERC) standards.
During a Day 0 software installation, you will have an option of choosing to install the Security
Enhanced (SE) I/A Series software v8.8, which requires Microsoft Active Directory® network ser-
vices, or standard I/A Series software v8.8 without the security enhancements. Depending on
your environment, you may not be able to take advantage of security enhanced I/A Series software
v8.8, for example, if you need to allow an older third-party application to run that has not been
rewritten to work in the secure environment.
Revision Information
For this release of this document (B0700SF, Rev. E), the following changes were made:
Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or
Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing Off-
MESH Networks”
Added a note to Step 20 of “Installation Procedure for Clients of New Off-MESH
Domain Controllers” on page 379.
Reference Documents
You should be familiar with the following I/A Series® documents:
System Management Displays (B0193JC)
System Definition: A Step-By-Step Procedure (B0193WQ)
System Definition Release Notes for Windows 7 and Windows Server 2008 (B0700SH)
Time Synchronization User’s Guide (B0700AQ)
The Foxboro Evo Control Network Architecture Guide (B0700AZ)
Address Translation Station User’s Guide (B0700BP)
Control Processor 270 (CP270) On-Line Image Update (B0700BY)
Security Enhancements User's Guide for I/A Series Workstations with Windows 7 or
Windows Server 2008 Operating Systems (B0700ET)
Symantec System Recovery 2011 Workstation Edition and Server Edition Guide for
I/A Series Workstations (B0700ES)
McAfee VirusScan® and AntiSpyware Enterprise 8.8i Installation (B0700EQ)
xxv
B0700SF – Rev E Preface
xxvi
Preface B0700SF – Rev E
Glossary
Term Definition
Active Directory A network services application created by Microsoft Corporation.
FCS Configuration Tools Foxboro® Control Software suite of configuration tools (formerly
known as the InFusion™ Engineering Environment)
H90 or P90 A rack-mounted server class computer utilized as an I/A Series sys-
tem terminal server or a high availability workstation
H91 or P91 A tower server class computer utilized as an I/A Series system termi-
nal server or a high availability workstation
H92 or P92 A desktop workstation class computer utilized as an I/A Series sys-
tem workstation
Off-Mesh A descriptor applied to stations which are not located on The Mesh
control network - and instead connected via a separate customer-
supplied network.
The procedures for configuring these stations for a system with the
security enhanced I/A Series software differ significantly from the
procedures for configuring stations on The Mesh control network.
On-Mesh A descriptor applied to stations which are located on The Mesh con-
trol network.
PDC Primary Domain Controller
SDC Secondary Domain Controller
SE Security Enhanced I/A Series software
Security Enhanced (SE) I/A Series software containing the optional security enhancements.
I/A Series software V8.8
SMDH System Management Display Handler
SP Service Pack
Standard I/A Series I/A Series software without security enhancements installed.
software v8.8
SysDef I/A Series System Definition software
xxvii
B0700SF – Rev E Preface
xxviii
1. Software Installation Overview
This chapter provides an overview for the concepts and installation processes described in this
document.
This document describes installation of the standard and security enhanced I/A Series software
v8.8 on stations running the following operating systems:
Windows 7
Windows Server 2008 R2 Standard
The following information is provided in this chapter:
How to use this installation guide
Overview of the types of software installations supported by this release
System configuration and creating the Commit installation media
Pre-installation system backup
How to acquire documentation for the I/A Series system v8.8
Media upgrade kits for supported hardware
Installation media for I/A Series software v8.8
NOTE
In this document, the term “workstation” can refer to both desktop workstations
and servers in an I/A Series system.
Installation Concepts
Starting with I/A Series software v8.8, the concept of installation has changed from a granular
model to a more comprehensive model. (Note that this section refers to installation on a new
workstation/server, rather than an upgrade to an existing Foxboro Evo or I/A Series software
installation.)
I/A Series software v8.7 and earlier had the concept of “selected package installation”, which
allowed each software package which was part of the I/A Series software to be installed separately -
for example, each package might be on a separate diskette, and only the diskettes you wanted
installed on a workstation/server could be provided during the installation.
In I/A Series software v8.8 and later, the installation process is more automated, providing more
flexibility to allow the appropriate system configuration application to determine which packages
are required for a workstation/server. Typically, the process works as follows:
1. The Foxboro system configuration application creates Commit media which specifies
which packages are to be installed on each workstation/server.
2. All packages, with the exception of the OS1FDB package, are provided on the instal-
lation DVD. The OS1FDB has several variations, and so the appropriate variation
must be selected
1
B0700SF – Rev E 1. Software Installation Overview
3. When run, the installation application installs the appropriate packages. If there are
any Device Integrator modules configured, then the OS1FDB media will be requested
individually per letterbug. A different set of OS1FDB media can be chosen for each
letterbug or this can be skipped per letterbug.
After the installation is complete, you can perform these installation tasks on the existing Foxboro
Evo or I/A Series software:
Perform a Day 1 operation, which adds packages or updates the software configura-
tion based on changes from the system configuration application.
If you skipped the installation of the OS1FDB package, you can add it with this
operation.
Perform a Repair operation, to verify that all files are present and not corrupted, and
applying updates and fixes as needed.
The method of upgrading to a new version of Foxboro Evo or I/A Series software differs signifi-
cantly depending from which version you are upgrading, and to which version you are upgrading.
For example, the upgrade from I/A Series software v8.5 to I/A Series software v8.7 is a Release
Update, which updates existing software packages but does not add any new packages.
Also, be aware of that for I/A Series software v8.8, serial alarm printers are no longer supported.
2
1. Software Installation Overview B0700SF – Rev E
Standard I/A Series software installation - The standard I/A Series software is for sys-
tems that do not require Microsoft® Active Directory Domain Controllers. The same
standard installation is applied to all I/A workstations. For I/A Series software v8.8,
there is only one procedure for installing this software on a workstation or server.
Unlike the I/A Series software v8.6 and v8.7, I/A Series software v8.8 is not an
“upgrade” on top of I/A Series software v8.5. I/A Series software v8.8 must be
installed as a new image on a station which supports Windows 7 or Windows Server
2008 R2 Standard.
Security-Enhanced (SE) I/A Series software installation - Security-Enhanced (SE)
I/A Series software are used on systems that require Microsoft® Active Directory
Domain Controllers. In these systems, all the workstation clients of these domain
controllers are members of a secure domain (domain clients). There are two separate
categories of security enhanced (SE) installations:
a. New security enhanced I/A Series software installations - There are three different
installation scenarios for these new installations.
b. Installation on existing stations with security enhanced I/A Series software v8.5,
v8.6. or v8.7 - There are three different scenarios for existing stations with security
enhanced software. These are referred to as migrations.
Refer to Chapter 3 “Installation or Migration Scenarios for Security Enhanced
I/A Series Software v8.8” for a detailed explanation of these scenarios.
3
B0700SF – Rev E 1. Software Installation Overview
For a list of the minimum hardware requirements, refer to the Hardware and Software Specific
Documentation listed in “Reference Documents” on page xxv and the following PSSes:
Model H92 and Model P92 Workstations Windows® 7 Professional Operating System
(PSS 21H-4D13 B4)
Model H91 and Model P91 Workstation Servers for the Windows Server® 2008 R2
Operating System (PSS 21H-4U6 B4)
Model H90 and Model P90 Workstation Servers for the Windows Server® 2008 R2
Operating System (PSS 21H-4U12 B4)
NOTE
The PDC and SDC domain controller pair cannot be successfully backed up, as
such a backup procedure is not supported by Microsoft.
Next, you physically install the software on each target workstation. This procedure includes
installing a new operating system image on the station and performing a Day 0 installation, which
is a fresh I/A Series software installation that wipes out any I/A Series software installed on it pre-
viously.
If you are installing Security Enhanced (SE) I/A Series software v8.8, you MUST install the Pri-
mary Domain Controller (PDC) first.After Day 0 installations, controllers require an image
update, so careful planning will be required. The On-Line Image Update (or On-Line Upgrade)
procedure is not available for Day 0 installations because the control database files (workfiles) are
lost during the Day 0 software installation. To restore the control database after a Day 0 installa-
tion, you must perform an Initialize and LoadAll. The on-line image update procedure is available
for future upgrades that do not involve a Day 0 installation on the host workstation. Refer to Con-
trol Processor 270 (CP270) On-Line Image Update (B0700BY).
4
1. Software Installation Overview B0700SF – Rev E
I/A Series Configurator Component (IACC) v2.5 or later - I/A Series System Configu-
ration Component (IACC) User's Guide (B0700FE).
Foxboro Control Software (FCS) v4.0 or later - For instructions on installing FCS,
refer to Foxboro Control Software Installation Guide (B0750RA). To create the Commit
installation media, follow the procedures in Hardware Configuration User’s Guide
(B0750BB).
After creating or editing the system configuration, you must create Commit installation media for
use during software installation.
NOTE
Be sure to label Commit installation media with the I/A Series versions on which it
can be used, for example, V8.8 or V8.2/V8.3/V8.4/V8.4.x/V8.5/V8.6/V8.7/V8.8.
NOTE
You should have only a single System Configuration (set of Commit media) for
your I/A Series software. From a single configuration database, you can produce
media for multiple versions of I/A Series software by providing a Package Distribu-
tion Disk (10091). Starting with I/A Series software v8.8, there is no package distri-
bution disk, so this request can be ignored in System Definition. For earlier
versions, this was used to produce specific information on the Commit disk that
was used by the I/A Series installation application to allow systems with I/A Series
software v8.7 or earlier to co-exist with systems with I/A Series software v8.8.
See the documentation listed below for information on how to import existing con-
figurations using System Definition v3.1, IACC v2.6, or FCS v5.0.
NOTE
If importing an older configuration from an earlier version of System Definition
(pre-v3.0), any stations intended for use in an I/A Series system v8.8 must be
migrated to either the new WSTA70 (for Windows 7) or WSVR70 (for Windows
Server 2008 R2 Standard) station type. After migrating these stations, new Commit
media must be created.
5
B0700SF – Rev E 1. Software Installation Overview
The following kits can be ordered from BuyAutomation. When ordering these Operating System
upgrade kits for use in servers, be aware of the intended use as a Primary or Secondary Domain
Controller, Terminal Server, or Highly Available Workstation. The use of a server as a Highly
Available workstation (with no domain controlling or Terminal Services (for Windows 7 stations)
or Remote Desktop Services (for Windows Server 2008 R2 Standard servers) has a different prod-
uct licensing scheme for deliverables that are part of these upgrade kit part numbers. The
K0174xx media disk part numbers that are used to load the systems are not listed in BuyAutoma-
tion.
Use Table 1-1 below to verify that you have the necessary media kit(s).
Table 1-1. I/A Series Software v8.8 Platform Specific Media Kits
Media Upgrade
Kit Part Number Kit Description
K0201FJ Windows 7 Professional SP1 Operating System Upgrade Kit for I/A Series
Workstation Dell T3500 P92 Style K Rev. A,B and Style L Rev. A, B
K0201FM Windows 7 Professional SP1 Operating System Upgrade Kit for I/A Series
Workstation Dell T3500 Gen II P92 Style M Rev. A,B
K0201FQ Windows 7 Professional SP1 Operating System Upgrade Kit for I/A Series
Workstation HP Z400 H92 Style A Rev. A, B
K0201FK Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell R710 Gen I Rack Mount P90 Style D
Rev. A, B Configured as Highly Available Workstation
K0201GL Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell T610 Tower P91 Style G Rev. A, B, C
Configured as Highly Available Workstation
K0201FL Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Server Dell R710 Gen I Rack Mount P90 Style D Rev. A, B Con-
figured as Server (Remote Desktop, Domain Controller, McAfee ePO, etc.)
K0201GM Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Server Dell T610 Tower P91 Style G Rev. A, B, C Configured as
Server (Remote Desktop, Domain Controller, McAfee ePO, etc.)
K0201FX Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell R710 Gen II Rack mount P90 Style E
Rev. A, B Configured as Highly Available Workstations
K0201GN Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell Dell T710 Gen II Tower P91 Style H
Rev. A, B Configured as Highly Available Workstations
K0201FY Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell R710 Gen II Rack mount P90 Style E
Rev. A, B Configured as Server (Remote Desktop, Domain Controller,
McAfee ePO, etc.)
K0201GP Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell T710 Gen II Tower P91 Style H Rev. A,
B Configured as Server (Remote Desktop, Domain Controller, McAfee ePO,
etc.)
6
1. Software Installation Overview B0700SF – Rev E
Table 1-1. I/A Series Software v8.8 Platform Specific Media Kits (Continued)
Media Upgrade
Kit Part Number Kit Description
K0201FN Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell R710 Gen II Rack mount P90 Style F
Rev. A, B Configured as Highly Available Workstations
K0201GQ Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell T710 Gen II Tower P91 Style J Rev. A, B
Configured as Highly Available Workstations
K0201FP Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell R710 Gen II Rack mount P90 Style F
Rev. A, B Configured as Server (Remote Desktop, Domain Controller,
McAfee ePO, etc.)
K0201GR Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server Dell T710 Gen II Tower P91 Style J Rev. A,
B Configured as Server (Remote Desktop, Domain Controller, McAfee ePO,
etc.)
K0201FT Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server HP DL380 Rack server H90 Style A Rev. A
Configured as Highly Available Workstations
K0201FU Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server HP DL380 Rack server H90 Style A Rev. A
Configured as Server (Remote Desktop, Domain Controller, McAfee ePO,
etc.)
K0201FR Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server HP ML350 Tower Server H91 Style A Rev. A
Configured as Highly Available Workstations
K0201FS Windows Server 2008 R2 Standard SP1 Operating System Upgrade Kit for
I/A Series Workstation Server HP ML350 Tower Server H91 Style A Rev. A
Configured as Server (Remote Desktop, Domain Controller, McAfee ePO,
etc.)
NOTE
For the I/A Series workstation HP Z420, H92 Style C, use the media part number
K0174KC shipped with the workstation. If you wish to purchase backups of this
CD-ROM, be aware that it is not available through BuyAutomation; request it from
Global Customer Support at https://support.ips.invensys.com.
7
B0700SF – Rev E 1. Software Installation Overview
Use the checklist below to verify that you have all the Day 0 media to install I/A Series software
v8.8:
Table 1-2. I/A Series Software v8.8 Day 0 Media Kit (K0201GA)
8
1. Software Installation Overview B0700SF – Rev E
Additional Media
Depending on your software configuration, you may also need additional software packages.
These packages are installed from their respective CDs or DVDs via standard installation proce-
dures, and are not included on the I/A Series software media.
9
B0700SF – Rev E 1. Software Installation Overview
Table 1-3. Additional Packages for I/A Series Software V8.8 (Continued)
10
1. Software Installation Overview B0700SF – Rev E
Table 1-3. Additional Packages for I/A Series Software V8.8 (Continued)
11
B0700SF – Rev E 1. Software Installation Overview
12
2. Standard I/A Series Software
v8.8 Day 0 Installation
This chapter describes procedures to perform an initial installation of I/A Series software v8.8 with-
out security enhancements. An initial installation, or an installation which removes all instances of
existing I/A Series software, is referred to as a “Day 0” operation.
Workstation/Server Preparation
This section applies to both Windows 7 and Windows Server 2008 R2 Standard stations on
which I/A Series software is being installed without security enhancements for the first time, or
overwriting existing I/A Series software. (This is referred to as a Day 0 installation, as opposed to
a Day 1 installation which is performed on a workstation/server on which the I/A Series software
have already been installed with the intention of retaining existing control databases and such.)
Perform the following steps to set up the hardware and restore the operating system onto your
workstation.
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes on Installing I/A Series System Software” on
page 14. If not, continue following the steps in this section.
1. Install hardware, restore the Windows operating system, and update drivers for your
workstation. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) for hardware require-
ments specific to the V8.8 release. For instructions on installing memory
upgrades, PCI cards, and so forth, refer to the “Installing Hardware Upgrades”
chapter of the hardware and software specific instruction document shipped with
your workstation.
b. Using the V8.8 Restore Media, restore the Windows operating system on your
workstation. Follow the instructions of Appendix A “Startup Options”.
! WARNING
Only use the media kits listed in Table 1-1 to restore the operating system of an
V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
13
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
Open the Windows Date and Time applet by clicking the Date and Time
icon in the Control Panel.
Click the Change Date and Time button.
Adjust the date and time.
Click OK.
Click the Change time zone button.
Select the correct time zone from the drop-down list and select the checkbox
(if not already selected) to automatically adjust the clock for daylight saving
time (DST) changes, if desired.
Click OK.
d. For any procedures not found in Step 1.b above, refer to the “Installing and
Updating Drivers” chapter of the hardware and software specific instruction docu-
ment shipped with the server.
2. Perform the procedures in Appendix G “IASeries_NIC_Data.msi Installation (Pre-
I/A Series Installation)” on page 525.
! CAUTION
GPS PCI time cards are installed only in primary and backup Master TimeKeeper
workstations or servers as configured for MTK. The MTK workstations or servers
with I/A Series software v8.8 and later must install the GPS PCI time card, driver,
and control utility before installing I/A Series software. Refer to the Time Synchroni-
zation User’s Guide (B0700AQ) to perform this installation.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
14
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
15
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
NOTE
The check box should be re-enabled at the end of the installation.
16
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
NOTE
Refer to the Hardware and Software Specific Instructions document included with
your station to determine the NIC cards it supports.
Proceed as follows:
1. Right-click the My Computer icon, and click Manage. Double-click Device Man-
ager. In the Device Manager window, expand the Network adapters list.
2. Right-click the desired card and click Properties. In the Properties dialog box that
appears, select the Advanced tab.
3. In the Property field, click Flow Control. In the Value field, select Disable from
the drop-down menu list.
4. In the Property field, click Speed & Duplex. In the Value field, in the drop-down
menu list:
For a station on The Mesh control network, select 100 Mb Full.
For a station on another network other than The Mesh control network (off-
Mesh), select Auto.
5. Click OK.
6. For each additional NIC, repeat Steps 2 through 5.
7. Shutdown and restart the system for the driver changes to take effect. Click the Start
button and click Shut Down; select Restart from the pull-down menu and click OK.
Click Yes to cancel, or No to resume the installation process. If you click Yes, you are returned to
the installation dialog box as shown in Figure 2-4. If you want to see the installation log, check
Show the Windows Installer log. Click Finish.
17
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
! CAUTION
Exiting during the software installation process causes an incomplete installation
and may cause the workstation to become unstable. This requires that you reload
the operating system.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
Installation Procedure
1. Ensure that the workstation is attached to The Mesh network.
2. Unplug any non-Mesh network cables.
3. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A), if it is
not already in the station.
4. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 2-5. Click
Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
18
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a pre-V8.8 image. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the workstation using the
proper V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the workstation using the proper V8.8 Restore
media. (See page 5.)
19
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
Figure 2-6. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
20
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
7. Select the radio button setting for Install I/A Series software without
security enhancements. Click Next to continue.
8. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 2-8. Click Load to load the committed configuration files.
21
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
9. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 2-9. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a floppy diskette, put
the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 2-8 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
22
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
23
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
10. Once the installation files have been loaded, click Bind as shown in Figure 2-10 to
launch I/A Series Network Installation.
:
11. The dialog box shown in Figure 2-11 is displayed if the network configuration from
System Definition does not match the available NIC hardware. Select the two net-
work cards and click Next.
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation.
If this dialog box is not displayed, the NIC cards have been automatically configured.
Proceed to the next step.
24
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
Figure 2-11. I/A Series Network Installation (For Certain NIC Cards)
12. The MSI installer opens for I/A Series Day 0 software. Click Next.
25
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
14. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 2-14 is displayed for each OS1FDB station configured to be hosted by the
workstation being installed.
NOTE
This will occur one time for each OS1FDB station configured.
26
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
27
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
16. If you selected Use Diskette in the previous step, the dialog box in Figure 2-16
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
At the end of the installation, the installation log is displayed. You can view this log
later by clicking the Start button and selecting All Programs -> Invensys ->
IASeries -> Utilities -> Log Viewer.
28
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
29
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
30
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
NOTE
The System Manager Server should be installed only if the IASVCS package is
assigned to the station.
31
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
f. Click Next and then Install to install the System Manager Server.
If the SMDH package was not configured and the System Manager client is not
installed, System Manager may be added by running the complete System Manager
installation process from the System Manager CD-ROM (K0174GG).
NOTE
The System Manager client is installed only if the IASVCS package is assigned to
the station.
32
2. Standard I/A Series Software v8.8 Day 0 Installation B0700SF – Rev E
Alternately, you can open a command prompt - click the Start button and click
Programs -> Accessories -> Command Prompt. Then, type
servermanager.msc and press <Enter>.
b. In the Features Summary section, click Add features.
c. Select the Desktop Experience check box, and then click Next.
d. Complete the wizard by clicking Install.
2. Configure the Windows Audio service to start automatically.
a. Open a command prompt, type Services.msc and press <Enter>.
b. Scroll down in the Services (Local) window, right-click Windows Audio and
select Properties.
c. In the General tab, select Automatic in the Startup Type drop-down menu.
d. Click OK.
e. Close the Services dialog box.
3. Open a command prompt.
a. Type the following: sc config beep start= auto
b. Press <Enter>. This configures the Beep Driver to start automatically.
4. Enable the SystemSoundsService task to run on user logon, as follows:
a. Open the Task Scheduler: click the Start button and click Control Panel ->
Administrative Tools and double-click Task Scheduler.
Alternately, you can open a command prompt, type Taskschd.msc and press
<Enter>.
b. Open the Task Library.
c. Navigate to the Microsoft/Windows/Multimedia section.
d. Right-click the SystemSoundsService task and click Enable.
e. Click OK.
f. Close the Task Scheduler.
The Beep Driver is enabled.
33
B0700SF – Rev E 2. Standard I/A Series Software v8.8 Day 0 Installation
2. From the System Monitor display, select the Time button to access the Set Date and
Time screen. Set the current date and time by clicking the appropriate arrows on the
screen. Click RETURN - SET.
For an active externally sourced MTK, the Set Date and Time display is unavailable. The date and
time are automatically established and synchronized by an external GPS satellite.
Refer to Time Synchronization User’s Guide (B0700AQ) for a complete description of the time
synchronization subsystem.
Completing Installation
To complete the installation, re-enable the Enable on-access scanning at system
startup feature in the McAfee VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on Access Protection and select Enable, as shown in Figure 2-1 on
page 15.
4. Right-click on On-Access Scanner and click Enable.
5. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 2-2 on page 16.
6. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
7. Click OK to close this dialog box.
34
3. Installation or Migration
Scenarios for Security Enhanced
I/A Series Software v8.8
If you are performing an installation or migration for a system with Security Enhanced
I/A Series software v8.8, this chapter assists you in determining the various tasks needed for
your specific system configuration.
For installations that require additional security over that provided by the standard I/A Series soft-
ware v8.8, a system with the security enhanced I/A Series software v8.8 is available. This security
implementation involves having servers that provide the role of Microsoft® Active Directory
Domain Controllers. A domain controller is a server on a Microsoft Windows network that is
responsible for allowing host access to Windows domain resources. It stores user account informa-
tion, authenticates users and enforces security policy for a Windows domain.
There has to be at least one domain controller present to act as the “primary” domain controller,
but the recommendation is to have a second server acting as a “secondary” domain controller to
provide redundancy. All the workstation clients of these domain controllers are members of a
secure domain (domain clients).
Determine the installation scenario for your I/A Series system as follows:
1. There are two separate types of installations for systems with security enhanced
I/A Series software v8.8. Determine which are applicable for the stations in your
I/A Series system:
New Installation - Installation of this security enhanced software on worksta-
tions/servers on which I/A Series software has never been installed. For this instal-
lation, the domain controllers and all client domain workstations are newly
installed with I/A Series software v8.8.
Workstations with standard I/A Series software can also be installed on the same
Mesh network but will not be members of the secure domain.
Migration - Installation of this software on existing workstations/servers on which
security enhanced I/A Series software v8.5, v8.6. or v8.7 has been installed previ-
ously. One or more of the existing domain client workstations must remain in
place and co-exist on the same domain as the new domain clients with I/A Series
software v8.8 while the migration is occurring, but then that domain client can be
migrated to I/A Series software v8.8, and the old Active Directory GPOs and OUs
that support the older I/A Series version could be removed from Active Directory
eventually.
2. Next, the domain controller target destination must be determined. This is based on
where the domain controllers will be located after the installation:
On-Mesh - On The Mesh control network.
Off-Mesh - On a separate network.
35
B0700SF – Rev E 3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8
3. Once you have determined the installation type (New Installation or Migration) and
the domain controller target destination (On-Mesh or Off-Mesh), use this informa-
tion to select your installation scenario from Table 3-1. Then proceed to the appropri-
ate section in this document to install the software, as directed.
Table 3-1 provides the details concerning each different installation scenario.
Table 3-1. Domain Controller Installation/Migration Scenarios for I/A Series Software v8.8
Scenario 1
In this scenario:
New domain controllers (PDC and SDC) are located on The Mesh control network
(On-Mesh). All stations (new domain controllers and new domain client worksta-
tions) are loaded with I/A Series software v8.8.
There are no stations with security enhanced I/A Series software v8.7 or earlier on the
domain.
Stations with standard (non-SE) I/A Series software v8.8 or earlier are supported on
the same Mesh network but not on the secure domain.
36
3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8 B0700SF – Rev E
Refer to Chapter 4 “Security Enhanced I/A Series Software v8.8 Installation for Domain Control-
lers on The MESH Control Network” for the installation instructions for this scenario.
Scenario 2
In this scenario:
New domain controllers (PDC and SDC) are located on a separate, customer-sup-
plied network (Off-Mesh). All stations (new domain controllers and new domain
client workstations) are loaded with I/A Series software v8.8.
There are no stations with security enhanced I/A Series software v8.7 or earlier on the
domain.
Stations with standard (non-SE) I/A Series software v8.8 or earlier are supported on
the same Mesh network but not on the secure domain.
Refer to Chapter 5 “Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH
Domain Controllers” for the installation instructions for this scenario.
Scenario 3
This scenario is designed for systems in which you already have a PDC with Windows Server
2008 R2 Standard on which you want to install the I/A Series components for Active Directory.
In this scenario:
I/A Series software v8.8 is installed to an existing PDC with Windows Server 2008 R2
Standard installed on an Off-Mesh network. The existing PDC is running Windows
Server 2008 R2 Standard with no I/A Series software. The existing PDC installed on a
separate network (Off-Mesh) is a customer-supplied station that has customer-specific
Active Directory components with no I/A Series software.
This installation is not completely automated by the I/A Series software v8.8 installa-
tion program and requires some manual steps as indicated in Chapter 6 “Security
Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
Domain Controllers”.
All domain clients are installed as new workstations with I/A Series software v8.8.
There are no stations with security enhanced I/A Series software v8.7 or earlier on the
domain.
Stations with standard (non-SE) I/A Series software v8.8 or earlier are supported on
the same Mesh network but not on the secure domain.
Refer to Chapter 6 “Security Enhanced I/A Series Software v8.8 Installation for Existing Off-
MESH Primary Domain Controllers” for the installation instructions for this scenario.
Scenario 4
In this scenario:
This is a migration of an existing PDC on The Mesh control network with Window
Server 2003 and I/A Series software v8.5, v8.6 or v8.7 to a new PDC on The Mesh
37
B0700SF – Rev E 3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8
control network with Windows Server 2008 R2 Standard and I/A Series software
v8.8.
The new PDC with Windows Server 2008 R2 Standard can either be a new server or
an existing SDC that is capable of running Windows Server 2008 R2 Standard.
The installation is not completely automated by the I/A Series software v8.8 installa-
tion program and requires some manual steps as indicated in Chapter 7 “Migrating
I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The
MESH Control Network”.
The station name for the new PDC must be the name of a new station with I/A Series
software v8.8 that is configured to have only the IAMESH package. The name of this
station must be included on the Commit installation media.
The existing PDC will switch roles and become an SDC on The Mesh control net-
work with Windows Server 2003. This station will keep its same name.
SDCs are configured as follows:
All existing SDCs with I/A Series software v8.7 or earlier must be taken off-line
(removing them from Active Directory, described in Appendix D “Secondary
Domain Controllers in an I/A Series System” - demoting is required for domain
controllers).
These off-line stations must have Windows Server 2008 R2 Standard installed on
them (if their hardware supports this operating system).
Each off-line station must have the appropriate software installed on them to
make them an SDC according to the instructions in this document.
This requires that either a new letterbug (station name) is provided which is desig-
nated as a station with I/A Series software v8.8 in the Commit installation media
or that the existing station name is converted in System Definition to be a station
with I/A Series software v8.8.
Refer to Chapter 7 “Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Con-
troller on The MESH Control Network” for the installation instructions for this scenario.
Scenario 5
In this scenario:
This is a migration of an existing PDC on The Mesh control network with Window
Server 2003 and I/A Series software v8.5, v8.6 or v8.7 to a new PDC installed on a
separate network (Off-Mesh) with Windows Server 2008 R2 Standard and I/A Series
software v8.8.
The new PDC with Windows Server 2008 R2 Standard can either be a new server or
an existing SDC that is capable of running Windows Server 2008 R2 Standard.
The installation is not completely automated by the I/A Series software v8.8 installa-
tion program and requires some manual steps as indicated in Chapter 8 “Migrating
I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller”.
The station name for the new PDC does not have to be included on the Commit
installation media. This new name is configured in the Active Directory according to
the instructions.
38
3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8 B0700SF – Rev E
The original PDC (with I/A Series software v8.5, v8.6 or v8.7) is no longer used after
the installation and can be removed.
The old SDC must be removed. This involves demoting the domain controller and
removing from Active Directory. Any other SDC station on the I/A Series system v8.7
or earlier on The Mesh control network must also be removed and reloaded as stations
with I/A Series software v8.8 (Off-Mesh) if desired:
All existing SDCs with I/A Series software v8.7 or earlier must be taken off-line
(removing them from Active Directory, described in Appendix D “Secondary
Domain Controllers in an I/A Series System” - demoting is required for domain
controllers).
These off-line stations must have Windows Server 2008 R2 Standard installed on
them (if their hardware supports this operating system).
Each off-line station must be installed as an Off-Mesh SDC according to the
instructions in this document.
Refer to Chapter 8 “Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary
Domain Controller” for the installation instructions for this scenario.
Scenario 6
In this scenario:
This is a migration of an existing PDC on The Mesh control network with Window
Server 2003 and I/A Series software v8.5, v8.6 or v8.7 to an existing PDC on a sepa-
rate network (Off-Mesh) with Windows Server 2008 R2 Standard. The existing PDC
is a customer station that has customer-specific Active Directory components with no
I/A Series software.
The installation is not completely automated by the I/A Series software v8.8 installa-
tion program and requires some manual steps as indicated in Chapter 9 “Migrating
I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
Controller”.
The station name for the new PDC does not have to be included on the Commit
installation media. This new name is configured in the Active Directory according to
the instructions.
The original PDC and all original SDC stations (with I/A Series software v8.5, v8.6
or v8.7) will no longer function as domain controllers on the I/A Series network.
It is possible to do one of the following with the original PDC and any original SDC
stations:
Reload these stations with I/A Series software v8.5/8.6/8.7 and connect them to
the new migrated domain. This involves reloading the Windows Server 2003 R2
operating system on these station and re-installing I/A Series software as described
in I/A Series 8.5 Software Installation Guide (B0700SB).
Remove Active Directory from these stations and then connect them directly to
the new domain without reloading I/A Series software (staying at v8.5/8.6/8.7).
This involves performing the procedures for demoting a domain controller, start-
ing with each SDC station and ending with the PDC station (all on the old
39
B0700SF – Rev E 3. Installation or Migration Scenarios for Security Enhanced I/A Series Software v8.8
domain). Then, the stations must be connected physically to the new Off-Mesh
domain and then joined to the new Active Directory domain.
Reload these stations with I/A Series software v8.8 (if the hardware supports the
Windows Server 2008 R2 Standard operating system). This involves backing up
anything relevant on the station, reloading the operating system, and installing
I/A Series software v8.8. In this case, these stations either need to be assigned a
new workstation name (change the Commit installation media to add a new sta-
tion with I/A Series software v8.8) or migrate the existing letterbug to become an
station with I/A Series v8.8 in System Definition, as described in System Defini-
tion: A Step-By-Step Procedure (B0193WQ).
NOTE
The procedure to add an SDC station to this domain after the migration is com-
pleted is out of the scope of this document. The domain is an existing setup and
already has its domain controllers configured.
Refer to Chapter 9 “Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Pri-
mary Domain Controller” for the installation instructions for this scenario.
40
4. Security Enhanced I/A Series
Software v8.8 Installation for
Domain Controllers on
The MESH Control Network
This chapter describes procedures to install security enhanced I/A Series software v8.8 on
primary and secondary domain controller servers on The Mesh control network.
Proceed to the appropriate section:
For Primary Domain Controllers on The Mesh control network, proceed to the next
section.
For Secondary Domain Controllers on The Mesh control network, proceed to
“Installing Security Enhanced I/A Series Software v8.8 on Secondary Domain Con-
trollers on The MESH Control Network” on page 76.
NOTE
After the IAInstaller account has been created during the PDC software installation,
use this account for all subsequent installation tasks, such as installing additional
software. However, due to the permissions assigned to IAInstaller, do not use it for
any other role, such as operation of the station.
Server Preparation
The primary domain controller (PDC) must be a server-class station installed with the Windows
Server 2008 R2 Standard operating system, and must be the first station in the I/A Series system
installed with the security enhanced I/A Series software. For this procedure, it is assumed that the
PDC is installed on The Mesh control network (which is a dedicated I/A Series maintained net-
work).
Perform the following steps to set up the hardware and restore the operating system onto your pri-
mary domain controller server:
41
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes on Installing I/A Series System Software” on
page 43. If not, continue following the steps in this section.
1. Install hardware, restore the Windows Server 2008 R2 Standard operating system, and
update drivers for your server. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) to be sure that your hard-
ware meets all hardware requirements specific to the I/A Series software V8.8
release. For instructions on installing memory upgrades, PCI cards, and so forth,
refer to the “Installing Hardware Upgrades” chapter of the Hardware and Software
Specific Instructions document shipped with your server.
b. Using the V8.8 Restore Media, restore the Windows Server 2008 R2 Standard
operating system on your server. Follow the instructions of Appendix A “Startup
Options”.
! WARNING
Only use the media kits listed in Table 1-1 to restore the operating system of an
V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
42
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
! WARNING
The server must be connected to The Mesh network before installing I/A Series
software.
! CAUTION
Disconnect non-I/A Series network connections but do not disable the adapters for
these network cards.
! CAUTION
The network interface drivers used for connection to The Mesh may require updat-
ing before installing I/A Series Version 8.8 software. Failure to do this may lead to
communication errors. See Appendix A “Startup Options”.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
NOTE
It is not possible to log onto either type of domain controller (primary or second-
ary) with any of the standard I/A Series user accounts (such as users that are mem-
bers of the IA Plant Operators, IA Plant Admins, or IA Plant Engineers groups). It
is possible to log onto a domain controller with the “IAManager”, “IAInstaller”, and
“IADomainAdmin” accounts. However, all of the I/A Series software functionality
is not available through these user accounts. The recommended configuration for
the domain controllers is IAMESH only.
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
43
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
44
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
NOTE
The check box should be re-enabled at the end of the installation.
45
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
NOTE
Refer to the Hardware and Software Specific Instructions document included with
your station to determine the NIC cards it supports.
Proceed as follows:
1. Right-click the My Computer icon, and click Manage. Double-click Device Man-
ager. In the Device Manager window, expand the Network adapters list.
2. Right-click the desired card and click Properties. In the Properties dialog box that
appears, select the Advanced tab.
3. In the Property field, click Flow Control. In the Value field, select Disable from
the drop-down menu list.
4. In the Property field, click Speed & Duplex. In the Value field, in the drop-down
menu list:
For a station on The Mesh control network, select 100 Mb Full.
For a station on another network other than The Mesh control network (off-
Mesh), select Auto.
5. Click OK.
6. For each additional NIC, repeat Steps 2 through 5.
7. Shutdown and restart the system for the driver changes to take effect. Click the Start
button and click Shut Down; select Restart from the pull-down menu and click OK.
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
46
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
You are returned to the installation dialog box as shown in Figure 4-5. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
Installation Procedure
Proceed as follows:
1. Ensure that the server is attached to The Mesh network.
47
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the server using the proper
V8.8 restore media. (See page 5.)
48
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
Figure 4-7. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
49
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
7. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install this workstation as a domain controller (secondary or pri-
mary):
8. If you are migrating from a previous version of I/A Series software (pre-v8.8), check
the “Migrate from Pre-8.8 I/A Series (PDC Only)” box. Otherwise, do not
check this box.
Security enhanced I/A Series software v8.8 should only be installed on the Windows 7
or Windows Server 2008 R2 Standard operating systems as provided by Invensys.
9. Click Next.
10. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 4-9. Click Load to load the committed configuration files.
50
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
11. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 4-10. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a floppy diskette, put
the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 4-9 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
51
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
12. Once the installation files have been loaded, click Bind as shown in Figure 4-9 on
page 51 to launch the I/A Series Network Installation.
13. The dialog box shown in Figure 4-11 is displayed if the network configuration from
System Definition does not match the available NIC hardware. If this dialog box is
displayed, select the two network cards and click Next.
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation.
If this dialog box is not displayed, the NIC cards have been automatically configured.
Proceed to the next step.
52
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
Figure 4-11. I/A Series Network Installation (For Certain NIC Cards)
14. Click Next. The Server platform setup dialog appears as shown in Figure 4-12. Leave
the “Install as a Primary Domain Controller (PDC)” choice selected.
53
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
15. If Secondary Domain Controller (SDC) stations are planned for this I/A Series sys-
tem, select the SDC stations from the “Select the Secondary Domain Controller Sta-
tions” drop-down list and click Set. If no SDC stations are planned, click Skip.
16. In the “Enter domain information for Active Directory setup and Prepare” area, enter
the name of your domain (iaseries.local is the default), the site name
(IASERIES is the default), and the password for the logged on user account (normally
the password for the Fox account). When done, click Prepare.
17. A warning dialog appears as shown in Figure 4-13. Ensure that the name you have
chosen for your Active Directory domain is correct and will not conflict with another
domain on the same network. Click OK to continue.
18. Click Install to load the Active Directory Domain Services onto this server and to
promote the server to the role of Primary Domain Controller.
A DOS window is displayed while Active Directory is being installed, as shown in
Figure 4-14.
54
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
The DOS window shows progress while the system is promoted to Primary Domain
Controller status and DNS is installed, as shown in Figure 4-15.
19. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “Administrator” account with the password
“Password1”.
20. Restart the installation by launching Setup.exe from the DVD drive, as described in
Steps 3- 4 above. The dialog box shown in Figure 4-16 is displayed. Click Apply.
55
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-16. Setting up the Platform for a Secure I/A Series Installation
A DOS window is displayed while the Active Directory domain settings are applied,
as shown in Figure 4-17.
56
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
21. The I/A Series Secure User Accounts dialog box opens as shown in Figure 4-18. Enter
in the user names and passwords for the standard I/A Series domain accounts and
click Create.
57
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
NOTE
The names of these accounts may be changed, but the default values are recom-
mended. Passwords must meet password complexity requirements. Password com-
plexity requirements include: an 8-character minimum password length; at least one
lowercase character; at least one uppercase character; and at least one numeric
character.
22. When the Invensys IASeries Install: Workstation Reboot Request dialog box appears,
as shown in Figure 4-19, click Reboot.
Figure 4-19. Invensys IASeries Install: Workstation Reboot Request Dialog Box
The following dialog box indicates that the server will be rebooted.
23. After the server reboots, log on with the “IA Installer” account with the password cho-
sen in the previous steps.
24. The installation continues automatically. Click Next and then Install to run the
installation.
25. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 4-21 is displayed.
To install this package, insert the first OS1FDB package diskette and click Load. After
the first disk has been loaded, insert the second OS1FDB package diskette and click
Load.
58
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
To bypass the installation of this package, click Skip. The installation continues, but
this dialog box is displayed again for each of the OS1FDB stations configured on this
station.
NOTE
This will occur one time for each OS1FDB station configured.
59
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
60
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
27. If you selected Use Diskette in the previous step, the dialog box in Figure 4-23
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
61
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
62
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
63
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
f. Click Next and then Install to install the System Manager Server.
If the SMDH package was not configured and the System Manager client is not
installed, System Manager may be added by running the complete System Manager
installation process from the System Manager CD-ROM (K0174GG).
NOTE
The System Manager client is installed only if the IASVCS package is assigned to
the station.
64
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
In order to run the Foxboro Control Panel applet, navigate to the folder
D:\usr\fox\system32. Right-click on Foxboro.cpl, select Run as Adminis-
trator, and click OK to close the dialog box. Click Yes to accept the User Account
Control (UAC) prompt.
NOTE
On I/A Series servers with Windows Server 2008 R2 Standard, FoxPanels requires
that the Beep Driver component be running to operate. If you have FoxPanels on
this domain controller, refer to “Installing the Beep Driver (I/A Series Servers with
FoxPanels Only)” on page 32 for installation instructions.
65
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-26. Resetting Passwords via Active Directory Users and Computers
2. Enter the new password and confirm it in the Reset Password dialog box:
3. Click OK.
The restore mode password for Active Directory on this server should be configured at this time.
Perform the following steps:
66
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
2. Click OK.
3. Type the following text in the command prompt window:
set dsrm password
reset password on server <SERVERNAME>
<password>
<password>
quit
quit
<SERVERNAME> is the actual name of your PDC server. <Password> is the newly
chosen Active Directory Restore Mode password.
NOTE
Be sure to document this password and save it in a secure place for future retrieval.
Without this password you will not be able to recover Active Directory.
67
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
In addition, set the passwords for all of the domain client workstations. Initially the local
IAManager account (the original Administrator account on all of the domain clients) has its pass-
word set to Password1. On each domain client, the password should be changed.
Figure 4-30. Creating Users via Active Directory Users and Computers
All users are created under the Accounts\Users\Standard OU, including IA Plant
Engineers, IA Plant Operators, and IA Plant Admins.
The dialog box shown in Figure 4-31 opens.
68
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
3. Enter the First name, Full name, and User logon name as the same value (for exam-
ple,. Operator1).
4. Click Next.
5. In the dialog box shown in Figure 4-32, clear the User must change password at
next logon check box. Select the Password never expires check box.
6. Enter the password and confirm the password.
7. Click Next.
69
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
70
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
9. Double-click on the new user name in the Active Directory Users and Computers dia-
log box to open the Properties dialog box, as shown in Figure 4-34.
71
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
72
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
13. Select the desired I/A Series standard user group (for example, IA Plant Engineers)
and click OK.
73
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
14. Click OK to close the Select Groups dialog box shown in Figure 4-38.
15. Click OK to close the Properties dialog box shown in Figure 4-39.
74
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
16. Repeat the above steps for as many users as desired. The different standard user groups
provide different policy settings and system access.
Continuing Installation
Re-enable the Enable on-access scanning at system startup feature in the McAfee
VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 4-2 on page 45.
4. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
5. Click OK to close this dialog box.
If you have a secondary domain controller on The Mesh control network, proceed to “Installing
Security Enhanced I/A Series Software v8.8 on Secondary Domain Controllers on The MESH
Control Network” on page 76.
If you do not have an SDC, proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8
Installation for Domain Clients or Connecting Security Enhanced I/A Series Software v8.5-8.7
Domain Clients to Existing Off-MESH Networks” for the installation procedure for the domain
clients.
75
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Server Preparation
The secondary domain controller (SDC) must be a server-class station installed with the Win-
dows Server 2008 R2 Standard operating system. For this procedure, it is assumed that the SDC
is installed on The Mesh control network (which is a dedicated I/A Series maintained network).
Perform the following steps to set up the hardware and restore the operating system onto your sec-
ondary domain controller server:
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes on Installing I/A Series System Software” on
page 77. If not, continue following the steps in this section.
1. Install hardware, install the Windows Server 2008 R2 Standard operating system, and
update drivers for your server. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) to be sure that your hard-
ware meets all hardware requirements specific to the I/A Series software V8.8
release. For instructions on installing memory upgrades, PCI cards, and so forth,
refer to the “Installing Hardware Upgrades” chapter of the Hardware and Software
Specific Instructions document shipped with your server.
b. Using the V8.8 Restore Media, restore the Windows Server 2008 R2 Standard
operating system on your server. Follow the instructions of Appendix A “Startup
Options”.
! WARNING
Only use the media kits listed in Table 1-1 to restore the operating system of an
V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
c. Set the time and date.to match the date and time on the PDC. Perform the fol-
lowing:
Open the Windows Date and Time applet by clicking the Date and Time
icon in the Control Panel.
Click the Change Date and Time button.
Adjust the date and time.
76
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
Click OK.
Click the Change time zone button.
Select the correct time zone from the drop-down list and select the checkbox
(if not already selected) to automatically adjust the clock for daylight saving
time (DST) changes, if desired.
Click OK.
NOTE
While installing an SDC, it is important to ensure that the UTC system time
matches the UTC system time on the domain (as viewed on the PDC). The date
and time must match, though the time which Windows displays may differ if the
time zones are not the same on the two stations.
Be careful when changing the time zone prior to adjusting the system time as this
can cause the AM/PM setting to change.
Also, be aware that the checkbox included for some time zones which defines
whether or not the time will be automatically adjusted for Daylight Saving Time
can cause the system time to differ by an hour.
d. For any procedures not found in Step 1.b above, refer to the “Installing and
Updating Drivers” chapter of the Hardware and Software Specific Instructions doc-
ument shipped with the server.
2. Perform the procedures in Appendix G “IASeries_NIC_Data.msi Installation (Pre-
I/A Series Installation)” on page 525.
! WARNING
The server must be connected to The Mesh network before installing I/A Series
software.
! CAUTION
Disconnect non-I/A Series network connections but do not disable the adapters for
these network cards.
77
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
! CAUTION
The network interface drivers used for connection to The Mesh may require updat-
ing before installing I/A Series Version 8.8 software. Failure to do this may lead to
communication errors. See “Installing/Updating the Network Interface Card Driv-
ers” section in your Hardware and Software Specific Instructions document.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
NOTE
It is not possible to log onto either type of domain controller (primary or second-
ary) with any of the standard I/A Series user accounts (such as users that are mem-
bers of the IA Plant Operators, IA Plant Admins, or IA Plant Engineers groups). It
is possible to log onto a domain controller with the “IAManager”, “IAInstaller”, and
“IADomainAdmin” accounts. However, all of the I/A Series software functionality
is not available through these user accounts. The recommended configuration for
the domain controllers is IAMESH only.
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
78
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
79
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
NOTE
The check box should be re-enabled at the end of the installation.
80
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
NOTE
Refer to the Hardware and Software Specific Instructions document included with
your station to determine the NIC cards it supports.
Proceed as follows:
1. Right-click the My Computer icon, and click Manage. Double-click Device Man-
ager. In the Device Manager window, expand the Network adapters list.
2. Right-click the desired card and click Properties. In the Properties dialog box that
appears, select the Advanced tab.
3. In the Property field, click Flow Control. In the Value field, select Disable from
the drop-down menu list.
4. In the Property field, click Speed & Duplex. In the Value field, in the drop-down
menu list:
For a station on The Mesh control network, select 100 Mb Full.
For a station on another network other than The Mesh control network (off-
Mesh), select Auto.
5. Click OK.
6. For each additional NIC, repeat Steps 2 through 5.
7. Shutdown and restart the system for the driver changes to take effect. Click the Start
button and click Shut Down; select Restart from the pull-down menu and click OK.
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
81
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
You are returned to the installation dialog box as shown in Figure 4-44. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
Installation Procedure
Proceed as follows:
82
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
1. Ensure that the Primary Domain Controller has been installed and is attached to The
Mesh network.
2. Ensure that the Secondary Domain Controller server is attached to The Mesh
network.
3. Unplug any non-Mesh network cables.
4. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
5. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 4-45.
Click Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the server using the proper
V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper V8.8 Restore
media. (See page 5.)
83
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-46. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
84
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
8. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install this workstation as a domain controller (secondary or pri-
mary):
9. Click Next.
10. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 4-48. Click Load to load the install files.
85
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
11. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 4-49. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a floppy diskette, put
the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 4-9 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
86
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
12. Once the Commit files have been loaded, click Bind as shown in Figure 4-9 on
page 51 to launch the I/A Series Network Installation utility.
13. The dialog box shown in Figure 4-50 is displayed if the network configuration from
System Definition does not match the available NIC hardware. Select the two net-
work cards and click Next.
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation.
If this dialog box is not displayed, the NIC cards have been automatically configured.
Proceed to the next step.
87
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-50. I/A Series Network Installation (For Certain NIC Cards)
14. Click Next. The Server platform setup dialog appears as shown in Figure 4-51. Select
the “Install as a Secondary Domain Controller (SDC)” radio button.
88
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
15. In the “Provide information for the domain administrator account and click Autho-
rize” area (see Figure 4-51), enter in the name of the primary domain controller
(PDC) station. Verify the account name with authority to add workstation to the
domain (i.e. iaseries.local\IAInstaller). Enter the password for this account and click
Authorize.
16. If the local system time does not match the PDC system time, the dialog box shown
in Figure 4-52 appears. Click OK. Fix the local system time to match the PDC time
(see “Server Preparation” on page 76) and re-click Authorize.
89
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 4-53 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
17. If there is another Secondary Domain Controller on the network, choose that SDC’s
name from the “Select the Secondary Domain Controller Stations” drop-down list
and click Set, as shown in Figure 4-54. Otherwise, click Skip.
90
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
NOTE
If after connecting the domain client to an SDC and the software installation does
not continue after the reboot, the system time may not have been set correctly. Refer
to “Setting Time Correctly After Failure to Continue Software Installation After
Reboot (SDC or Domain Client)” on page 539 to correct this.
91
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
20. When the Invensys IASeries Install: Workstation Reboot Request dialog box appears,
as shown in Figure 4-55, click Reboot.
Figure 4-55. Invensys IASeries Install: Workstation Reboot Request Dialog Box
21. After the server reboots, log onto the server with the “IA Installer” account using the
password as it was set during the PDC server’s installation.
22. The installation restarts automatically. The Server platform setup dialog box appears
as shown in Figure 4-56. Re-enter the PDC’s server name, domain “admin” account
name, and domain “admin” account password. Click Authorize.
92
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
Figure 4-56. Server Platform Setup Dialog Box (PDC Account Information)
23. Verify the Domain Name and Site Name fields, shown in Figure 4-57. If satisfied,
click Prepare.
93
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-57. Server Platform Setup Dialog Box (Verify Domain Name and Site Name Fields)
24. A warning dialog appears. Ensure that the name you have chosen for your Active
Directory domain is correct and will not conflict with another domain on the same
network.
25. Click Install to load the Active Directory Domain Services onto this server and to
assign the server to the role of Secondary Domain Controller.
A DOS window is displayed while Active Directory is being installed, as shown in
Figure 4-58.
94
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
The DOS window shows progress while the system is assigned to its Secondary
Domain Controller status and DNS is installed, as shown in Figure 4-59.
Figure 4-59. Assigning Role of Secondary Domain Controller via DOS Window
26. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “IA Installer” account with the password as set in
the Server platform setup dialog box above (Figure 4-57).
27. The installation process restarts automatically. The dialog box shown in Figure 4-60 is
displayed. Click Apply.
95
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Figure 4-60. Setting Up the Platform for a Secure I/A Series Installation
A DOS window is displayed while the Active Directory domain settings are applied.
96
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
29. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 4-62 is displayed.
To install this package, insert the first OS1FDB package diskette and click Load. After
the first disk has been loaded, insert the second OS1FDB package diskette and click
Load.
To bypass the installation of this package, click Skip. The installation continues, but
this dialog box is displayed again for each of the OS1FDB stations configured on this
SDC.
97
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
98
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
31. If you selected Use Diskette in the previous step, the dialog box in Figure 4-23
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
99
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
100
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
101
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
f. Click Next and then Install to install the System Manager Server.
If the SMDH package was not configured and the System Manager client is not
installed, the System Manager may be added by running the complete System Man-
ager installation process from the System Manager CD-ROM (K0174GG).
NOTE
The System Manager client is installed only if the IASVCS package is assigned to
the station.
102
4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control Network
In order to run the Foxboro Control Panel applet, navigate to the folder
D:\usr\fox\system32. Right-click on Foxboro.cpl, select Run as Adminis-
trator, and click OK to close the dialog box. Click Yes to accept the User Account
Control (UAC) prompt.
2. Click OK.
3. Type the following text in the command prompt window:
set dsrm password
reset password on server <SERVERNAME>
<password>
<password>
quit
quit
<SERVERNAME> is the actual name of your SDC server. <Password> is the newly
chosen Active Directory Restore Mode password.
103
B0700SF – Rev E 4. Security Enhanced I/A Series Software v8.8 Installation for Domain Controllers
NOTE
Be sure to document this password and save it in a secure place for future retrieval.
Without this password you will not be able to recover Active Directory.
Continuing Installation
Re-enable the Enable on-access scanning at system startup feature in the McAfee
VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 4-41 on page 80.
4. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
5. Click OK to close this dialog box.
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for the domain clients.
104
5. Security Enhanced I/A Series
Software v8.8 Installation for
New Off-MESH Domain
Controllers
This chapter describes procedures to install security enhanced I/A Series software v8.8 on new
primary and secondary domain controller servers on a separate network from The Mesh control
network.
Proceed to the appropriate section:
For Off-Mesh Primary Domain Controllers, proceed to the next section.
For Off-Mesh Secondary Domain Controllers, proceed to “Installing Security
Enhanced I/A Series Software v8.8 on Off-MESH Secondary Domain Controllers”
on page 139.
NOTE
Use the “IA Installer” account for all installation tasks. However, due to the
permissions assigned to “IA Installer”, do not use it for any other role, such as
operation of the station.
Server Preparation
The primary domain controller (PDC) must be a server-class station installed with the Windows
Server 2008 R2 Standard operating system, and must be the first station in the I/A Series system
installed with the security enhanced I/A Series software. For this procedure, it is assumed that the
PDC is installed on a separate network (which is called an “Off-Mesh” network), not connected
to The Mesh control network.
Perform the following steps to set up the hardware and restore the operating system onto your pri-
mary domain controller server:
105
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes on Installing I/A Series System Software” on
page 107. If not, continue following the steps in this section.
1. Install hardware, restore the Windows Server 2008 R2 Standard operating system, and
update drivers for your server. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) to be sure that your hard-
ware meets all hardware requirements specific to the I/A Series software V8.8
release. For instructions on installing memory upgrades, PCI cards, and so forth,
refer to the “Installing Hardware Upgrades” chapter of the Hardware and Software
Specific Instructions document shipped with your server.
b. Using the V8.8 Restore Media, restore the Windows Server 2008 R2 Standard
operating system on your server. Follow the instructions of Appendix A “Startup
Options”.
! WARNING
Only use the media kits listed in Table 1-1 to restore the operating system of an
V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
106
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
! WARNING
The server must be connected to the Off-Mesh network before installing I/A Series
software.
! CAUTION
Disconnect non-I/A Series network connections but do not disable the adapters for
these network cards.
! CAUTION
The network interface drivers used for connection to The Mesh may require updat-
ing before installing I/A Series software v8.8. Failure to do this may lead to commu-
nication errors. See Appendix A “Startup Options”.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
NOTE
It is not possible to log onto either type of domain controller (primary or second-
ary) with any of the standard I/A Series user accounts (such as users that are mem-
bers of the IA Plant Operators, IA Plant Admins, or IA Plant Engineers groups).
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
107
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
108
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
109
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
NOTE
The check box should be re-enabled at the end of the installation.
110
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
111
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
You are returned to the installation dialog box as shown in Figure 5-5. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
112
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
Installation Procedure
NOTE
If you unplugged any non-Mesh network cables prior to performing the Day 0
installation, plug in the non-Mesh network cables at this time.
Proceed as follows:
1. Click the Start button and then click Control Panel -> Network and Sharing
Center. In the Tasks pane, click Change adapter settings.
2. Right-click the connection that you want to change, and then click Properties. If
you are prompted for an administrator password or confirmation, type the password
or provide confirmation.
3. Click the Networking tab. Under “This connection uses the following items”, click
Internet Protocol Version 4 (TCP/IPv4), and then click Properties. The
Internet Protocol Version 4 (TCP/IPv4) Properties dialog box opens as shown in
Figure 5-6.
4. Set the server to have exactly one statically configured NIC adapter for use by Active
Directory, as shown in Figure 5-6. Click OK when done.
Note: The IP address does not need to match the IP address shown in this figure.
113
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
5. Set the PowerShell execution policy on the server by executing the following com-
mand from within Windows PowerShell:
Set-ExecutionPolicy AllSigned
6. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
7. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 5-8. Click
Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
114
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the server using the proper
V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper V8.8 Restore
media. (See page 5.)
Figure 5-9. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
115
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
10. Select the Install I/A Series software for a security enhanced system.
Then select Install the workstation as an OFF-MESH domain controller
(secondary or primary) bullets as shown in Figure 5-10.
Click Next to continue.
116
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
11. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 5-11. Click Load to load the committed configuration files.
12. The browser for the folder which contains the committed configuration install files
opens, as shown in Figure 5-12. If the installation media with your Commit files is on
the server’s hard drive or a network, browse to the location of the media and click
Select Folder. If the installation media with your Commit files is on a floppy dis-
kette, put the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 5-11 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
117
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
118
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
13. Click Next. The Server platform setup dialog box appears as shown in Figure 5-13.
Leave the Install as a Primary Domain Controller (PDC) choice selected.
119
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
14. If a Secondary Domain Controller (SDC) server is planned for this I/A Series system,
add the SDC servers from the drop-down list by selecting the Add Off-Mesh check-
box shown in Figure 5-13. The dialog box shown in Figure 5-14 opens to indicate
where the IP addresses for SDC stations can be set. Enter each of the known SDC IP
addresses and click Done.
15. In Figure 5-15, click Set to choose the SDC stations in your list or Skip to choose no
SDC station IP addresses. If this server does not have exactly one statically set NIC
adapter, the message shown in Figure 5-15 is displayed. Once the NIC settings are
corrected, you can click Set or Skip again to continue.
120
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
16. Enter the name of your domain (offmesh.local is the default), the site name
(OFFMESH is the default), and the password for the logged on user account (normally
the password for the Fox account).
121
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
18. The warning dialog box shown in Figure 5-17 appears. Make sure at this time that the
name you have chosen for your Active Directory domain is correct and will not con-
flict with another domain on the same network. Click OK to continue.
19. Click Install to load the Active Directory Domain Services onto this server and to
promote the server to the role of Primary Domain Controller.
A DOS window is displayed while Active Directory is being installed, as shown in
Figure 5-18.
The DOS window shows progress while the system is promoted to Primary Domain
Controller status and DNS is installed, as shown in Figure 5-19.
122
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
20. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “Administrator” account with the password
“Password1” or the actual password if the password was changed prior to installing
I/A Series software.
123
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
21. Restart the installation by launching Setup.exe from the DVD drive, as described in
Step 3 above. The dialog box shown in Figure 5-20 is displayed. Click Apply.
Figure 5-20. Setting up the Platform for a Secure I/A Series Installation
124
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
A DOS window is displayed while the Active Directory domain settings are applied,
as shown in Figure 5-21.
22. The I/A Series Secure User Accounts dialog box opens as shown in Figure 5-22. Enter
in the user names and passwords for the standard I/A Series domain accounts and
click Create.
125
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
NOTE
The names of these accounts may be changed, but the default values are recom-
mended. Passwords must meet password complexity requirements. Password com-
plexity requirements include: an 8-character minimum password length; at least one
lowercase character; at least one uppercase character; and at least one numeric
character.
23. Add a new Computer account for any SDC stations that will be added to the domain.
Click the Start button and select Control Panel -> Administrative Tools ->
Active Directory Users and Computers.
24. In the console tree, right-click Computers (under Active Directory Users and
Computers\domain node\Computers).
25. Point to New, and then click Computer. In the New Object dialog box that appears
(see Figure 5-23), add the new computer name in both “Computer name” fields.
126
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These logs can also
be printed.
Restart your server as described in the following section.
NOTE
On I/A Series servers with Windows Server 2008 R2 Standard, FoxPanels requires
that the Beep Driver component be running to operate. If you have FoxPanels on
this domain controller, refer to “Installing the Beep Driver (I/A Series Servers with
FoxPanels Only)” on page 32 for installation instructions.
127
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Figure 5-25. Resetting Passwords via Active Directory Users and Computers
128
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
2. Enter the new password and confirm it in the Reset Password dialog box:
3. Click OK.
The restore mode password for Active Directory on this server should be configured at this time.
Perform the following steps:
1. Select Run from the Start menu and enter ntdsutil.exe:
2. Click OK.
3. Type the following text in the command prompt window:
set dsrm password
reset password on server <SERVERNAME>
<password>
<password>
quit
quit
<SERVERNAME> is the actual name of your PDC server. <Password> is the newly
chosen Active Directory Restore Mode password.
129
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
NOTE
Be sure to document this password and save it in a secure place for future retrieval.
Without this password you will not be able to recover Active Directory.
130
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
2. Under the Accounts\Users\Standard OU, right-click Standard, and select New ->
User:
Figure 5-29. Creating Users via Active Directory Users and Computers
All users are created under the Accounts\Users\Standard OU, including IA Plant
Engineers, IA Plant Operators, and IA Plant Admins.
The dialog box shown in Figure 5-30 opens.
131
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
3. Enter the First name, Full name, and User logon name as the same value (for exam-
ple,. Operator1).
4. Click Next.
5. In the dialog box shown in Figure 5-31, clear the User must change password at
next logon check box. Select the Password never expires check box.
6. Enter the password and confirm the password.
7. Click Next.
132
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
133
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
9. Double-click on the new user name in the Active Directory Users and Computers dia-
log box to open the Properties dialog box, as shown in Figure 5-33.
134
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
135
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
13. Select the desired I/A Series standard user group (for example, IA Plant Engineers)
and click OK.
136
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
14. Click OK to close the Select Groups dialog box shown in Figure 5-37.
15. Click OK to close the Properties dialog box shown in Figure 5-38.
137
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
16. Repeat the above steps for as many users as desired. The different standard user groups
provide different policy settings and system access.
Continuing Installation
Re-enable the Enable on-access scanning at system startup feature in the McAfee
VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 5-2 on page 110.
4. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
5. Click OK to close this dialog box.
If you have a secondary domain controller on the same separate network, proceed to “Installing
Security Enhanced I/A Series Software v8.8 on Off-MESH Secondary Domain Controllers” on
page 139.
If you do not have an SDC, proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8
Installation for Domain Clients or Connecting Security Enhanced I/A Series Software v8.5-8.7
Domain Clients to Existing Off-MESH Networks” for the installation procedure for the domain
clients.
138
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
Server Preparation
The secondary domain controller (SDC) must be a server-class station installed with the Win-
dows Server 2008 R2 Standard operating system. For this procedure, it is assumed that the SDC
is installed on a separate network (which is called an “Off-Mesh” network), not connected to The
Mesh control network.
Perform the following steps to set up the hardware and restore the operating system onto your sec-
ondary domain controller server:
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes on Installing I/A Series System Software” on
page 140. If not, continue following the steps in this section.
1. Install hardware, install the Windows Server 2008 R2 Standard operating system, and
update drivers for your server. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) to be sure that your hard-
ware meets all hardware requirements specific to the I/A Series software V8.8
release. For instructions on installing memory upgrades, PCI cards, and so forth,
refer to the “Installing Hardware Upgrades” chapter of the Hardware and Software
Specific Instructions document shipped with your server.
b. Using the V8.8 Restore Media, restore the Windows Server 2008 R2 Standard
operating system on your server. Follow the instructions of Appendix A “Startup
Options”.
! WARNING
Only use the media kits listed in Table 1-1 on page 6 to restore the operating system
of an V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
c. Set the time and date.to match the date and time on the PDC. Perform the fol-
lowing:
Open the Windows Date and Time applet by clicking the Date and Time
icon in the Control Panel.
Click the Change Date and Time button.
Adjust the date and time.
139
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Click OK.
Click the Change time zone button.
Select the correct time zone from the drop-down list and select the checkbox
(if not already selected) to automatically adjust the clock for daylight saving
time (DST) changes, if desired.
Click OK.
NOTE
While installing an SDC, it is important to ensure that the UTC system time
matches the UTC system time on the domain (as viewed on the PDC). The date
and time must match, though the time which Windows displays may differ if the
time zones are not the same on the two stations.
Be careful when changing the time zone prior to adjusting the system time as this
can cause the AM/PM setting to change.
Also, be aware that the checkbox included for some time zones which defines
whether or not the time will be automatically adjusted for Daylight Saving Time
can cause the system time to differ by an hour.
d. For any procedures not found in Step 1.b above, refer to the “Installing and
Updating Drivers” chapter of the Hardware and Software Specific Instructions doc-
ument shipped with the server.
2. Perform the procedures in Appendix G “IASeries_NIC_Data.msi Installation (Pre-
I/A Series Installation)” on page 525.
! WARNING
The server must be connected to the Off-Mesh network before installing I/A Series
software.
! CAUTION
Disconnect non-I/A Series network connections but do not disable the adapters for
these network cards.
140
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
! CAUTION
The network interface drivers may require updating before installing I/A Series soft-
ware v8.8. Failure to do this may lead to communication errors. See the “Install-
ing/Updating the Network Interface Card Drivers” section in your Hardware and
Software Specific Instructions document.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
NOTE
It is not possible to log onto either type of domain controller (primary or second-
ary) with any of the standard I/A Series user accounts (such as users that are mem-
bers of the IA Plant Operators, IA Plant Admins, or IA Plant Engineers groups). It
is possible to log onto a domain controller with the “IAManager”, “IAInstaller”, and
“IADomainAdmin” accounts. However, all of the I/A Series software functionality
is not available through these user accounts. The recommended configuration for
the domain controllers is IAMESH only.
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
141
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
142
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
NOTE
The check box should be re-enabled at the end of the installation.
143
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
144
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
You are returned to the installation dialog box as shown in Figure 5-43. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
145
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Installation Procedure
NOTE
If you unplugged any non-Mesh network cables prior to performing the Day 0
installation, plug in the non-Mesh network cables at this time.
Proceed as follows:
1. Click the Start button and then click Control Panel -> Network and Sharing
Center. In the Tasks pane, click Change adapter settings.
2. Right-click the connection that you want to change, and then click Properties. If
you are prompted for an administrator password or confirmation, type the password
or provide confirmation.
3. Click the Networking tab. Under “This connection uses the following items”, click
Internet Protocol Version 4 (TCP/IPv4), and then click Properties. The
Internet Protocol Version 4 (TCP/IPv4) Properties dialog box opens as shown in
Figure 5-44.
4. Set the server to have exactly one statically configured NIC adapter for use by Active
Directory, as shown in Figure 5-44. Click OK when done.
Note: The IP address does not need to match the IP address shown in this figure.
Figure 5-44. Internet Protocol Version 4 (TCP/IPv4) Properties
146
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
5. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
6. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 5-45.
Click Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the server using the proper
V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper V8.8 Restore
media. (See page 5.)
147
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Figure 5-46. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
148
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
9. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install this workstation as an OFF-MESH domain controller (second-
ary or primary):
149
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
11. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 5-48. Click Load to load the committed configuration files.
12. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 5-49. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a floppy diskette, put
the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 5-48 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
150
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
151
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
13. Click Next. The Server platform setup dialog box appears as shown in Figure 5-50.
Select the Install as an off-mesh Secondary Domain Controller (SDC)
radio button.
14. In the Domain Controller IP Address field, enter the IP address of the Off-Mesh PDC
server and the password of the account authorized to add stations to the domain
(default value is offmesh.local\IAInstaller). Click Authorize.
15. If the local system time does not match the PDC system time, the dialog box shown
in Figure 5-51 appears. Click OK. Fix the local system time to match the PDC time
(see “Server Preparation” on page 139) and re-click Authorize.
152
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 5-52 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
153
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
16. If Secondary Domain Controller (SDC) servers are planned for this I/A Series system,
add the SDC servers from the drop-down list by selecting the Add Off-Mesh check-
box shown in Figure 5-53.
17. The dialog box shown in Figure 5-54 opens to indicate where the IP addresses for
SDC stations can be set. Enter each of the known SDC IP addresses and click Done.
154
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
18. In Figure 5-53, click Set to choose the SDC stations in your list or Skip to choose no
SDC station IP addresses. If this server does not have exactly one statically set NIC
adapter, the message shown in Figure 5-55 is displayed. Once the NIC settings are
corrected, you can click Set or Skip again to continue.
19. Verify the name of the domain and click Connect. If successful, a message is displayed
to indicate that the connection to the domain has succeeded. If unsuccessful, a reason
for the failure is displayed.
20. When the Invensys IASeries Install: Workstation Reboot Request dialog box appears,
as shown in Figure 5-56, click Reboot.
Figure 5-56. Invensys IASeries Install: Workstation Reboot Request Dialog Box
21. After the server reboots, log on with the “IAInstaller” account with the password cho-
sen during the PDC station installation.
22. The installation process restarts automatically. The Server platform setup dialog
appears as shown in Figure 5-57. Re-enter the Domain Controller IP Address, domain
admin account name (Authorized Account), and domain admin account password
(Authorized Password). Click Authorize.
155
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
156
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
23. Verify the Domain Name and Site Name fields and click the Prepare button.
24. The warning dialog box shown in Figure 5-59 appears. Make sure at this time that the
name you have chosen for your Active Directory domain is correct. Click OK to
continue.
157
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
25. Click Install to load the Active Directory Domain Services onto this server and to
assign the server to the role of Secondary Domain Controller.
A DOS window is displayed while Active Directory is being installed, as shown in
Figure 5-60.
The DOS window shows progress while the system is assigned to its Secondary
Domain Controller status and DNS is installed, as shown in Figure 5-61.
Figure 5-61. Assigning Role of Secondary Domain Controller via DOS Window
158
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
26. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “IAInstaller” account with the password as set in
the Server platform setup dialog box above.
27. The installation process restarts automatically. The dialog box shown in Figure 5-62 is
displayed. Click Apply.
Figure 5-62. Setting Up the Platform for a Secure I/A Series Installation
A DOS window is displayed while the Active Directory domain settings are applied.
The installation of the Off-Mesh SDC server is complete. DNS is installed automatically with
Active Directory.
159
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These logs can also
be printed.
160
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
161
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
f. Click Next and then Install to install the System Manager Server.
If the SMDH package was not configured and the System Manager client is not
installed, the System Manager may be added by running the complete System Man-
ager installation process from the System Manager CD-ROM (K0174GG).
NOTE
The System Manager client is installed only if the IASVCS package is assigned to
the station.
162
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
In order to run the Foxboro Control Panel applet, navigate to the folder
D:\usr\fox\system32. Right-click on Foxboro.cpl, select Run as Adminis-
trator, and click OK to close the dialog box. Click Yes to accept the User Account
Control (UAC) prompt.
2. Click OK.
3. Type the following text in the command prompt window:
set dsrm password
reset password on server <SERVERNAME>
<password>
<password>
quit
quit
<SERVERNAME> is the actual name of your SDC server. <Password> is the newly
chosen Active Directory Restore Mode password.
163
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
NOTE
Be sure to document this password and save it in a secure place for future retrieval.
Without this password you will not be able to recover Active Directory.
164
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
3. Enter the name of the new workstation in the Computer name field and click OK as
shown in Figure 5-68. The OU for “Pre-8.8 workstations” on migrated systems will
be named “Pre-8.8 IA Computers” as shown in Figure 5-69.
165
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
166
5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers B0700SF – Rev E
Continuing Installation
Re-enable the Enable on-access scanning at system startup feature in the McAfee
VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 5-40 on page 143.
4. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
5. Click OK to close this dialog box.
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for the domain clients.
167
B0700SF – Rev E 5. Security Enhanced I/A Series Software v8.8 Installation for New Off-MESH Domain Controllers
168
6. Security Enhanced I/A Series
Software v8.8 Installation
for Existing Off-MESH Primary
Domain Controllers
This chapter describes procedures to install security enhanced I/A Series software v8.8 on an
existing primary domain controller server with Windows Server 2008 R2 Standard on a
separate network (not on The Mesh control network).
Overview
If you already have a PDC with Windows Server 2008 R2 Standard on which you want to install
the I/A Series components for Active Directory, follow the instructions in this chapter to perform
this installation.
Be aware that this scenario does not include installation of an SDC. If you have an SDC, the
Active Directory should be replicated to that SDC after the I/A Series installation to the PDC.
If you do not have an SDC and want to add one now, you can purchase an Invensys-supplied
SDC and install I/A Series software v8.8 on it as described in “Installing Security Enhanced
I/A Series Software v8.8 on Off-MESH Secondary Domain Controllers” on page 139. Alter-
nately, you can use a non-Invensys server as your SDC and install only the appropriate Microsoft
Active Directory software.
NOTE
It is not possible to log onto either type of domain controller (primary or second-
ary) with any of the standard I/A Series user accounts (such as users that are mem-
bers of the IA Plant Operators, IA Plant Admins, or IA Plant Engineers groups). It
is possible to log onto a domain controller with the “IAManager”, “IAInstaller”, and
“IADomainAdmin” accounts.
169
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
NOTE
Use the IAInstaller account for all installation tasks. However, due to the
permissions assigned to IAInstaller, do not use it for any other role, such as
operation of the station.
170
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
171
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
NOTE
The check box should be re-enabled at the end of the installation.
172
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
173
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
You are returned to the installation dialog box as shown in Figure 6-5. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
174
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
Installation Procedure
NOTE
If you unplugged any non-Mesh network cables prior to performing the Day 0
installation, plug in the non-Mesh network cables at this time.
Proceed as follows:
1. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
2. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 6-6. Click
Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the server. Otherwise, restore the server using the proper
V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper V8.8 Restore
media. (See page 5.)
175
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
Figure 6-7. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
176
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
5. Select the Install I/A Series software for a security enhanced system
and Install to an existing OFF-MESH PDC station (PDC only) bullets as
shown in Figure 6-8.
Click Next to continue.
6. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 6-9. Click Load to set the installation target drive to D:\ and load
the committed configuration files.
177
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
7. The browser for the folder which contains the committed configuration install files
opens, as shown in Figure 6-10. If the installation media with your Commit files is on
the server’s hard drive or a network, browse to the location of the media and click
Select Folder. If the installation media with your Commit files is on a floppy dis-
kette, put the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 6-9 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
178
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
179
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
8. Click Next. The dialog box appears as shown in Figure 6-11. Click Apply.
180
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
9. A command prompt is displayed while the Active Directory domain settings are
applied. When asked Do you want to run software from this trusted pub-
lisher, press A (for Always run) and press <Enter>. This allows the signed scripts to
configure your system.
10. The I/A Series Secure User Accounts dialog box opens as shown in Figure 6-13. Enter
in the user name and password for the standard I/A Series domain account and click
Create.
181
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
NOTE
The names of these accounts may be changed, but the default values are recom-
mended. Passwords must meet password complexity requirements. Password com-
plexity requirements include: an 8-character minimum password length; at least one
lowercase character; at least one uppercase character; and at least one numeric
character.
At the end of the installation, the installation log is displayed. You can view the installation log at
any time by clicking the Start button and selecting All Programs -> Invensys -> IASeries ->
Utilities -> Log Viewer.
182
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These logs can also
be printed.
183
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
Figure 6-16. Creating Users via Active Directory Users and Computers
184
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
All users are created under the Accounts\Users\Standard OU, including IA Plant
Engineers, IA Plant Operators, and IA Plant Admins.
The dialog box shown in Figure 6-17 opens.
3. Enter the First name, Full name, and User logon name as the same value (for exam-
ple,. Operator1).
4. Click Next.
5. In the dialog box shown in Figure 6-18, clear the User must change password at
next logon check box. Select the Password never expires check box.
6. Enter the password and confirm the password.
7. Click Next.
185
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
186
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
9. Double-click on the new user name in the Active Directory Users and Computers dia-
log box to open the Properties dialog box, as shown in Figure 6-20.
187
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
188
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
13. Select the desired I/A Series standard user group (for example, IA Plant Engineers)
and click OK.
189
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
14. Click OK to close the Select Groups dialog box shown in Figure 6-24.
15. Click OK to close the Properties dialog box shown in Figure 6-25.
190
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
16. Repeat the above steps for as many users as desired. The different standard user groups
provide different policy settings and system access.
3. Enter the name of the new workstation in the Computer name field and click OK as
shown in Figure 6-27. The OU for “Pre-8.8 workstations” on migrated systems will
be named “Pre-8.8 IA Computers” as shown in Figure 6-28.
191
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
192
6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary Domain Controllers B0700SF
Continuing Installation
Re-enable the Enable on-access scanning at system startup feature in the McAfee
VirusScan Console as follows:
1. Right-click the McAfee shield in the toolbar and click VirusScan Console.
2. Click Yes to accept the User Account Control (UAC) prompt.
3. Right-click on On-Access Scanner and select Properties. The On-Access Scan
Properties dialog box opens as shown in Figure 6-2 on page 172.
4. Check the check-box labeled Enable on-access scanning at system startup
and click Apply.
5. Click OK to close this dialog box.
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for the domain clients.
193
B0700SF – Rev E 6. Security Enhanced I/A Series Software v8.8 Installation for Existing Off-MESH Primary
194
7. Migrating I/A Series Software
v8.5/8.6/8.7 to a New Primary
Domain Controller on The MESH
Control Network
This chapter describes how to migrate an existing On-Mesh Primary Domain Controller
(PDC) with I/A Series software v8.5/8.6/8.7 to a new PDC with Windows Server 2008 R2
Standard, located on The Mesh control network.
The source station for this migration can either be:
A new I/A Series server, shipped with an I/A Series software v8.8 (or later) image
installed.
An existing SDC with I/A Series software v8.5/8.6/8.7 installed, which will be con-
verted to a PDC with an I/A Series software v8.8 (or later) image installed.
The target station (the station onto which the new software will be installed) for this migration is
the new PDC with Windows Server 2008 R2 Standard.
After the migration, both the domain clients which existed pre-I/A Series software v8.8 and the
new I/A Series domain clients (post-I/A Series software v8.8) will be connected to the same
domain. Existing group policies will be maintained while new I/A Series software v8.8 group pol-
icies will be enacted. The steps in this section only need to be followed once for the domain
migration in order to establish the new PDC station.
Perform the procedures provided below.
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
195
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
NOTE
Do not reload an existing SDC with I/A Series software v8.5-8.7 with the Windows
Server 2008 R2 Standard operating system if this SDC will be used as the new
PDC.
For the source On-Mesh Primary Domain Controller (PDC) with I/A Series software
v8.5/8.6/8.7 for this migration, proceed as follows:
1. Log into the existing (pre-I/A Series software v8.8) On-Mesh PDC using a domain
administrator account (such as IADomainAdmin).
2. Open the Active Directory Users and Computers console - click the Start button and
select Control Panel -> Administrative Tools -> Active Directory Users
and Computers.
3. Under the Users organizational unit (OU), find the domain administrator account
which is being used for this installation, as shown in Figure 7-1.
196
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
Figure 7-1. Active Directory Users and Computers Console (Administrator Account)
197
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
4. Right-click on the user name and click Properties. The user Properties dialog box
opens as shown in Figure 7-2.
5. Verify that the domain administrator account is a member of both the Schema
Admins and Enterprise Admins groups by selecting the Member Of tab as shown in
Figure 7-2. If this user account is not, the user must be added to both these groups, as
follows:
a. From the Member Of tab, select the Add button.
b. Type in the name of the group which needs to be added (such as Schema Admins
or Enterprise Admins) and click OK, as shown in Figure 7-3. Repeat this for
each group.
198
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
199
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
Figure 7-4. Active Directory Users and Computers Console (Administrator Account)
8. If the current domain administrator account was added to either the “Schema
Admins” or “Enterprise Admins” in the steps above, log off from this account and log
back on to the station using the same account.
200
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
9. Insert the Microsoft® Windows Server® 2008 R2 Standard DVD. Acknowledge the
warning shown in Figure 7-5.
Figure 7-5. Installation Disc Is Not Compatible With This Windows Version Warning
10. Open a command prompt. Click the Start button, click Programs -> Accessories -
> Command Prompt.
11. In the command prompt, navigate to the “E:\Support\ADPrep” folder. As shown in
Figure 7-6, enter the following command: adprep32 /forestprep
201
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
202
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
16. If you are upgrading an existing Secondary Domain Controller with I/A Series soft-
ware v8.5/8.6/8.7 to become the new target PDC, you must remove the Active Direc-
tory from this SDC as described in the following substeps. If you do not have an SDC
and are installing a new station as the target PDC, proceed to “Preparation and Instal-
lation for New Target Primary Domain Controller” on page 204.
To remove the Active Directory from the SDC, perform one of the two following
procedures:
a. Use dcpromo on the existing SDC to remove Active Directory as described in
“Removing Domain Controller Functionality from a Workstation” on page 487.
b. In Active Directory Sites and Services on the source PDC, click Actions ->
Refresh. The NTDS settings that were shown under the SDC name are
removed. If they are not, the removal operation of the Active Directory from the
SDC was unsuccessful and you cannot continue. Contact Global Customer Sup-
port for assistance.
-OR-
a. Use Symantec System Recovery (SSR) to load the new I/A Series software v8.8
platform image on the existing SDC station to be upgraded. Refer to Symantec
System Recovery 2011 Workstation Edition and Server Edition Guide for I/A Series
Workstations (B0700ES) for instructions.
b. On the source PDC, click the Start button and select Control Panel -> Admin-
istrative Tools -> Active Directory Sites and Services. Navigate to
Sites -> [Domain Name] -> Servers -> [Name of SDC]. Remove the SDC
station from the list along with every entry underneath.
17. Proceed to the next section.
203
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
NOTE
Use the IAInstaller account for all installation tasks. However, due to the
permissions assigned to IAInstaller, do not use it for any other role, such as
operation of the station.
NOTE
Refer to the Hardware and Software Specific Instructions document included with
your station to determine the NIC cards it supports.
Proceed as follows:
1. Right-click the My Computer icon, and click Manage. Double-click Device Man-
ager. In the Device Manager window, expand the Network adapters list.
2. Right-click the desired card and click Properties. In the Properties dialog box that
appears, select the Advanced tab.
3. In the Property field, click Flow Control. In the Value field, select Disable from
the drop-down menu list.
4. In the Property field, click Speed & Duplex. In the Value field, in the drop-down
menu list:
For a station on The Mesh control network, select 100 Mb Full.
For a station on another network other than The Mesh control network (off-
Mesh), select Auto.
5. Click OK.
6. For each additional NIC, repeat Steps 2 through 5.
7. Shutdown and restart the system for the driver changes to take effect. Click the Start
button and click Shut Down; select Restart from the pull-down menu and click OK.
204
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
3. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 7-9. Click
Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
! CAUTION
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper v8.8 (or later)
Restore media.
205
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
Figure 7-10. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
6. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install the workstation as a domain controller (secondary or pri-
mary), as shown in Figure 7-11.
Also select the check box labeled Migrate from Pre-8.8 I/A Series (PDC
Only) under the selection you checked, as shown in Figure 7-11.
206
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
7. Click Next.
8. Acknowledge the warning shown in Figure 7-12.
207
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
9. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 7-13. Click Load to load the committed configuration files.
10. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 7-14. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a diskette, put the dis-
kette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 7-13 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
208
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
11. Once the Commit files have been loaded, click Bind as shown in Figure 7-13 on
page 208 to launch the I/A Series Network Installation utility.
12. The dialog box shown in Figure 7-15 is displayed for some servers (Dell T3500 and
R710 servers) if the network configuration from System Definition does not match
the available NIC hardware. Select the two network cards and click Next.
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation.
If this dialog box is not displayed, the NIC cards have been automatically configured.
Proceed to the next step.
209
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
Figure 7-15. I/A Series Network Installation (For Certain NIC Cards)
210
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
13. Click Next. The Server platform setup dialog appears as shown in Figure 7-16. The
Install as a Secondary Domain Controller (SDC) bullet is selected by
default. Initially, this station is installed as an SDC station and will be promoted to be
the PDC station before the installation completes.
14. Enter in the name of the existing PDC (from which you are migrating), as shown in
Figure 7-16.
In the Authorized Account field, verify that the domain joining account name dis-
played has the authority to add workstations to the domain
(i.e. iaseries.local\IAInstaller).
In the Authorized Password field, enter the password for this account.
When finished, click Authorize.
211
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
15. If the local system time does not match the system time on the existing PDC (from
which you are migrating), a message is displayed as shown in Figure 7-17. Click OK.
Fix the local system time to match the existing PDC’s time and re-click Authorize.
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 7-18 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
212
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
16. If there is another SDC station on the network, choose that SDC’s name from the
drop-down list and click Set, as shown in Figure 7-19. Otherwise, click Skip.
213
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
17. In the “Select a Host Domain for this workstation and click Connect” field, verify the
name of the domain and click Connect. The message shown is in Figure 7-20 dis-
played to indicate that the connection to the domain has succeeded.
If unsuccessful, a reason for the failure is displayed.
Figure 7-20. Invensys IASeries Install: Workstation Reboot Request Dialog Box
18. After the server reboots, log on with the “IAInstaller” account with the password as it
was set during the PDC’s installation.
19. The installation continues automatically. The Server platform setup dialog box
appears.
Re-enter in the name of the existing PDC (from which you are migrating), as shown
in Figure 7-21.
In the Authorized Account field, verify that the domain joining account name dis-
played has the authority to add workstations to the domain
(i.e. iaseries.local\IAInstaller).
In the Authorized Password field, enter the password for this account.
When finished, click Authorize.
214
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
215
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
20. Under the “Enter domain information for Active Directory setup and click Prepare”
area, verify the Domain Name and Site Name fields and click the Prepare button.
216
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
21. A warning dialog appears as shown in Figure 7-23. Ensure that the name you have
chosen for your Active Directory domain is correct and will not conflict with another
domain on the same network.m
22. Click Install to load the Active Directory Domain Services onto this server and to
assign the server to the role of Secondary Domain Controller.
A command prompt is displayed while Active Directory is being installed, as shown in
Figure 7-24.
The command prompt shows progress while the system is assigned to its Secondary
Domain Controller status and DNS is installed, as shown in Figure 7-25.
217
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
Figure 7-25. Assigning Role of Secondary Domain Controller via Command Prompt
23. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “IADomainAdmin” account with the password as
set during the PDC’s installation.
218
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
24. The installation restarts automatically and the I/A Series Software Installation dialog
box appears as shown in Figure 7-26. Click Verify to check the health of the Active
Directory domain. This takes several minutes. It may be necessary to wait as much as
an hour before proceeding past this dialog box, depending on how long it takes for
Active Directory to replicate to this new SDC.
Figure 7-26. Verifying the Health of the Existing Active Directory System
219
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
25. When complete, the warning dialog box shown in Figure 7-27 is displayed if errors
are found. One or more conditions could be detected including diagnostic failures,
event log errors, and replication failures.
Figure 7-27. I/A Series Installation Warning for DC Health Log File
220
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
26. To view the log, click View in Figure 7-28. After viewing the errors, it may be neces-
sary to correct the issues in the Active Directory domain. Click the Verify button as
many times as necessary after you take each corrective action to ensure that no further
issues exist. After clicking Verify, clicking View opens the updated diagnostic results.
Figure 7-28. Verifying the Health of the Existing Active Directory System (Errors Found)
NOTE
The following error messages are expected during a migration and can be safely
ignored:
Warning 1:
Warning: SVRINF is not advertising as a time server.
......................... SVRINF failed test Advertising
Invalid service type: RpcSs on SVRINF, current value
WIN32_OWN_PROCESS, expected value WIN32_SHARE_PROCESS
w32time Service is stopped on [SVRINF]
......................... SVRINF failed test Services
221
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
Warning 2:
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed,
error 1355
A Good Time Server could not be located.
......................... iaseries.local failed test LocatorCheck
NOTE
It can take several hours for event log messages which were generated during the
migration to clear from this log. System log failures (such as the following) should
be investigated if they persist long after the migration has completed.
......................... NESRV4 failed test SystemLog
27. If it is determined that it is safe to ignore the errors in the log, click Ignore to con-
tinue, as shown in Figure 7-29. Acknowledge the following warning.
222
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
28. Click Next. The dialog shown in Figure 7-30 is displayed. Click Apply.
Figure 7-30. Setting Up the Platform For a Secure I/A Series Installation
A command prompt is displayed while the Active Directory settings are applied.
29. Click Next and then Install to run the installation.
30. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 7-31 is displayed.
To install this package, insert the first OS1FDB package diskette and click Load. After
the first disk has been loaded, insert the second OS1FDB package diskette and click
Load.
To bypass the installation of this package, click Skip. If Skip is selected, the installa-
tion will continue, but this dialog will be displayed again for each of the OS1FDB sta-
tions configured on this I/A Series station.
NOTE
This will occur one time for each OS1FDB station configured.
223
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
224
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
32. If you selected Use Diskette in the previous step, the dialog box in Figure 7-33
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
NOTE
After migration is complete, install Windows Server 2008 R2 Standard with
I/A Series software v8.8 on all of your SDCs.
225
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
2. In the adapter’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Properties.
The Internet Protocol (TCP/IP) Properties dialog box appears as shown in
Figure 7-36.
226
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
3. The first two DNS entries are displayed in DNS server addresses section. Click
Advanced.
NOTE
The installation will attempt to set the DNS entries on the existing stations with
I/A Series software v8.7 or earlier. However, this can fail for multiple reasons. You
may see the following message in the AD Setup log (D:\usr\fox\sp\ADSetup.log):
Failed to configure the DNS setting for AW0001 station. Access is
denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED)).
The instructions for setting up DNS entries on existing stations with I/A Series
software v8.7 or earlier should be followed for all stations with I/A Series software
v8.7 or earlier even though it is possible that some entries have been set already. It is
critical to system interoperability that these settings are made.
227
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
4. Set the first DNS entry in the list to match the IP address of the new PDC with
I/A Series software v8.8. Add additional entries for any SDC stations (with Windows
Server 2003 or Server 2008 R2 Standard). Click OK to save the DNS settings.
NOTE
For all domain clients migrated from a domain with I/A Series software
v8.5/8.6/8.7 to a domain with I/A Series software v8.8, it may be necessary to move
the migrated domain client’s object in Active Directory before beginning the client’s
installation procedure. Refer to “Migrating Domain Client from Domain in
I/A Series System v8.7 Or Earlier to a Domain in I/A Series System v8.8” on
page 358.
Continuing Installation
Refer to “Installing Optional Software” on page 63 to install any additional packages on your new
PDC.
Be sure to re-enable McAfee VirusScan on all the PDCs, SDCs and domain clients on which you
disabled it. Refer to “Re-Enabling the McAfee VirusScan Console” on page 408.
228
7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller on The MESH Control Network
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for all new domain clients.
229
B0700SF – Rev E 7. Migrating I/A Series Software v8.5/8.6/8.7 to a New Primary Domain Controller
230
8. Migrating I/A Series Software
v8.5/8.6/8.7 to a New Off-MESH
Primary Domain Controller
This chapter describes how to migrate an existing On-Mesh Primary Domain Controller
(PDC) with I/A Series software v8.5/8.6/8.7 to a new PDC with Windows Server 2008 R2
Standard which is on a separate network, not located on The Mesh control network (Off-
Mesh).
The source station for this migration can either be:
A new I/A Series server, shipped with an I/A Series software v8.8 (or later) image
installed.
An existing SDC with I/A Series software v8.5/8.6/8.7 installed, which will be con-
verted to a PDC with an I/A Series software v8.8 (or later) image installed.
The target station (the station onto which the new software will be installed) for this migration
will become new PDC with Windows Server 2008 R2 Standard.
After the migration, both the domain clients which existed pre-I/A Series software v8.8 and the
new I/A Series domain clients (with I/A Series software v8.8) will be connected to the same
domain. Existing group policies will be maintained while new I/A Series software v8.8 group pol-
icies will be enacted. The steps in this section only need to be followed once for the domain
migration in order to establish the new PDC station.
Perform the procedures provided below.
For the source On-Mesh Primary Domain Controller (PDC) with I/A Series software
v8.5/8.6/8.7 for this migration, proceed as follows:
1. Log into the existing On-Mesh PDC using a domain administrator account (such as
IADomainAdmin).
231
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
2. Open the Active Directory Users and Computers console - click the Start button and
select Programs -> Administrative Tools -> Active Directory Users and
Computers.
3. Under the Users organizational unit (OU), find the domain administrator account
which is being used for this installation, as shown in Figure 8-1.
Figure 8-1. Active Directory Users and Computers Console (Administrator Account)
232
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
4. Right-click on the user name and click Properties. The user Properties dialog box
opens as shown in Figure 8-2.
5. Verify that the domain administrator account is a member of both the “Schema
Admins” and “Enterprise Admins” groups by selecting the Member Of tab as shown
in Figure 8-2. If this user account is not, the user must be added to both these groups,
as follows:
a. From the Member Of tab, select the Add button.
b. Type in the name of the group which needs to be added (Schema Admins or
Enterprise Admins) and click OK, as shown in Figure 8-3. Repeat this for each
group.
233
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
234
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
Figure 8-4. Active Directory Users and Computers Console (Administrator Account)
8. If the current domain administrator account was added to either the Schema Admins
or Enterprise Admins in the steps above, then log off from this account and log back
on to the station using the same account.
235
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
9. Insert the Microsoft® Windows Server® 2008 R2 Standard DVD that was delivered
with your server. Acknowledge the warning shown in Figure 8-5.
Figure 8-5. Installation Disc Is Not Compatible With This Windows Version Warning
10. Open a command prompt. Click the Start button, and click Programs -> Accesso-
ries -> Command Prompt.
11. In the command prompt, change the directory to the “E:\Support\ADPrep” folder. As
shown in Figure 8-6, enter the following command: adprep32 /forestprep
236
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
237
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
! CAUTION
In Network Connections, which lists the available NICs, do not change the name of
any “Local Area Connection x” network connection. This can result in software
installation issues or system instability.
b. In the Network and Connections dialog box, right-click the FoxInt NDIS Inter-
mediate Miniport Driver, and click Properties.
c. In the adapter’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Proper-
ties. The Internet Protocol (TCP/IP) Properties dialog box appears as shown in
Figure 8-9.
238
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
17. Remove all default gateway settings for this network interface by clicking Advanced.
In the Advanced TCP/IP Settings dialog box shown in Figure 8-10, click the IP
Settings tab. Under Default gateways, remove all the entries.
Remove
all entries
18. Click the DNS tab, as shown in Figure 8-11. In the DNS server addresses, in order of
use field, remove all the entries. When done, click OK to close this dialog box and
apply the changes.
239
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
Remove
all entries
19. Open the Internet Protocol (TCP/IP) Properties dialog box for the network adapter
for the new Off-Mesh I/A Series network.
a. On the desktop, right-click My Network Places, and click Properties.
b. In the Network and Sharing Center dialog box, right-click the network adapter
that the Off-Mesh domain controller will use, and click Properties.
c. In the adapter’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click
Properties. The Internet Protocol (TCP/IP) Properties dialog box appears as
shown in Figure 8-12.
d. Set the IP address and preferred DNS server IP address to the same value (shown
as “181.182.81.1” as an example in Figure 8-12) and click OK.
240
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
After clicking on Close, the status of the Local Area Connection is “connected”.
241
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
20. Open the DNS Manager. Click the Start button and select Programs -> Adminis-
trative Tools -> DNS. Right-click on the DNS server (workstation name, shown as
“SVRINF” in Figure 8-13) and click Properties.
21. In the server Properties dialog box, click the Interfaces tab as shown in
Figure 8-14. Select all IP addresses in the list, except one, and click Remove.
For the last IP address, change it to be the IP address of the Off-Mesh network card
configured in the previous step.
Click Add then select the remaining IP address and click Remove.
Click OK in Properties dialog box.
242
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
Remove
all entries
and add one
for the new
Off-MESH
network card.
243
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
22. In the DNS Manager, select the I/A Series forward lookup zone (i.e. iaseries.local).
Remove the entries for the existing I/A Series stations which are on the existing
I/A Series Mesh control network, as shown in Figure 8-15.
23. In the DNS Manager, remove the reverse lookup zone for the existing On-Mesh
I/A Series network (i.e. 151.128.152.x Subnet).
24. Add a new reverse lookup zone for the new Off-Mesh I/A Series network as follows.
244
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
245
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
b. Click Next. Select Primary Zone and click Next as shown in Figure 8-17.
246
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
c. Click the “To all DNS servers in the Active Directory domain
iaseries.local” bullet (“iaseries.local” may vary depending on the actual
name of the I/A Series domain) as shown in Figure 8-18. Click Next.
Figure 8-18. New Zone Wizard (Active Directory Zone Replication Scope)
247
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
d. In the Network ID field, enter in the first three octets of the Off-Mesh I/A Series
network card as shown in Figure 8-19. Click Next.
248
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
e. Click the Allow only secure dynamic updates bullet and click Next as
shown in Figure 8-20. Click Finish to close the New Zone Wizard.
249
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
f. Right-click on the new zone and select New Pointer as shown in Figure 8-21.
250
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
g. In the New Resource Record dialog box, set the pointer value to the last octet in
the Off-Mesh I/A Series network card’s IP address as shown in Figure 8-22.
In the Host name field, enter the full name of your server (“svrinf.iaseries.local” is
the example shown in Figure 8-22) and click OK.
251
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
j. In the Services dialog box, right-click the DNS Server, and then click Restart as
shown in Figure 8-23.
25. Click the Start button, and click Programs -> Accessories -> Command Prompt to
open a command prompt. Type nslookup and press <Enter>. If DNS is functioning
properly, it should show that it found the local DNS server with the IP address set in
the previous steps (shown as 181.182.81.1 in Figure 8-23).
! CAUTION
Until DNS is working properly, the migration procedure cannot continue.
252
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
253
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
NOTE
Use the IAInstaller account for all installation tasks. However, due to the
permissions assigned to IAInstaller, do not use it for any other role, such as
operation of the station.
254
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
3. Set the PowerShell execution policy on the target PDC by executing the following
command from within Windows PowerShell:
Set-ExecutionPolicy AllSigned
255
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
4. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
5. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 8-28.
Click Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
256
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
! CAUTION
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper I/A Series software
v8.8 (or later) Restore media.
Figure 8-29. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
8. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install the workstation as an OFF-MESH domain controller (second-
ary or primary), as shown in Figure 8-30.
Also select the check box labeled Migrate from Pre-8.8 I/A Series (PDC
Only) under the selection you checked, as shown in Figure 8-30.
257
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
9. Click Next.
10. Acknowledge the warning shown in Figure 8-31.
258
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
11. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 8-32. Click Load to set the installation target drive to D:\ and
load the committed configuration files.
12. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 8-33. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a diskette, put the dis-
kette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 8-33 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
259
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
13. Click Next. The I/A Series Software Installation dialog box appears as shown in
Figure 8-34, in which the “Install as a Secondary Domain Controller (SDC)” choice
is selected by default. Initially, this server will be installed as an SDC and will be pro-
moted to the role of the PDC before the installation completes.
260
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
14. Enter in the IP address of the existing PDC (from which you are migrating), as shown
in Figure 8-34.
In the Authorized Account field, verify that the domain joining account name dis-
played has the authority to add workstations to the domain
(i.e. iaseries.local\IAInstaller).
In the Authorized Password field, enter the password for this account.
When finished, click Authorize.
261
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
15. If the local system time does not match the system time on the existing PDC (from
which you are migrating), a message is displayed as shown in Figure 8-35. Click OK.
Fix the local system time to match the existing PDC’s time and re-click Authorize.
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 8-36 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
262
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
16. If there is another SDC station on the network, choose that SDC’s name from the
drop-down list and click Set, as shown in Figure 8-37. Otherwise, click Skip.
263
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
17. In the “Select a Host Domain for this workstation and click Connect” field, verify the
name of the domain and click Connect. The message shown is in Figure 8-38 dis-
played to indicate that the connection to the domain has succeeded.
If unsuccessful, a reason for the failure is displayed.
Figure 8-38. Invensys IASeries Install: Workstation Reboot Request Dialog Box
18. After the server reboots, log on with the “IAInstaller” account with the password as it
was set during the PDC’s installation.
19. The installation continues automatically. The Server platform setup dialog box
appears.
Re-enter in the IP address of the existing PDC (from which you are migrating), as
shown in Figure 8-39.
In the Authorized Account field, verify that the domain joining account name dis-
played has the authority to add workstations to the domain (i.e. iaseries.local\IAIn-
staller).
In the Authorized Password field, enter the password for this account.
When finished, click Authorize.
264
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
20. Under the “Enter domain information for Active Directory setup and click Prepare”
area, verify the Domain Name and Site Name fields and click the Prepare button.
21. A warning dialog appears as shown in Figure 8-40. Ensure that the name you have
chosen for your Active Directory domain is correct and will not conflict with another
domain on the same network.
265
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
22. Click Install to load the Active Directory Domain Services onto this server and to
assign the server to the role of Secondary Domain Controller.
A command prompt is displayed while Active Directory is being installed, as shown in
Figure 8-41.
The command prompt shows progress while the system is assigned to its Secondary
Domain Controller status and DNS is installed, as shown in Figure 8-42.
Figure 8-42. Assigning Role of Secondary Domain Controller via Command Prompt
266
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
23. The server reboots automatically after Active Directory has been installed.
After the server reboots, log into the “IADomainAdmin” account with the password as
set during the PDC’s installation.
24. The installation restarts automatically and the I/A Series Software Installation dialog
box appears as shown in Figure 8-43. Click Verify to check the health of the Active
Directory domain. This takes several minutes. It may be necessary to wait as much as
an hour before proceeding past this dialog box, depending on how long it takes for
Active Directory to replicate to this new station.
Figure 8-43. Verifying the Health of the Existing Active Directory System
267
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
25. When complete, the warning dialog box shown in Figure 8-43 is displayed if errors
are found. One or more conditions could be detected including diagnostic failures,
event log errors, and replication failures.
Figure 8-44. I/A Series Installation Warning for DC Health Log File
268
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
26. To view the log, click View in Figure 8-44. After viewing the errors, it may be neces-
sary to correct the issues in the Active Directory domain. Click the Verify button as
many times as necessary after you take each corrective action to ensure that no further
issues exist. After clicking Verify, clicking View opens the updated diagnostic results.
Figure 8-45. Verifying the Health of the Existing Active Directory System (Errors Found)
NOTE
The following error messages are expected during a migration and can be safely
ignored:
Warning 1:
Warning: SVRINF is not advertising as a time server.
......................... SVRINF failed test Advertising
Invalid service type: RpcSs on SVRINF, current value
WIN32_OWN_PROCESS, expected value WIN32_SHARE_PROCESS
w32time Service is stopped on [SVRINF]
......................... SVRINF failed test Services
269
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
Warning 2:
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed,
error 1355
A Good Time Server could not be located.
......................... iaseries.local failed test LocatorCheck
NOTE
It can take several hours for event log messages which were generated during the
migration to clear from this log. System log failures (such as the following) should
be investigated if they persist long after the migration has completed.
......................... NESRV4 failed test SystemLog
27. If it is determined that it is safe to ignore the errors in the log, click Ignore to con-
tinue, as shown in Figure 8-43. Acknowledge the following warning.
270
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
28. Click Next. The dialog shown in Figure 8-47 is displayed. Click Apply.
Figure 8-47. Setting Up the Platform For a Secure I/A Series Installation
A command prompt is displayed while the Active Directory settings are applied.
29. Click Finish.
271
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
30. When prompted, enter the required information for the Active Directory settings.
Enter the administrator account name on the I/A Series v8.5/8.6/8.7 domain (default
is iaseries.local\IAManager). Enter the password for the administrator account on the
I/A Series v8.5/8.6/8.7 domain. Click OK.
NOTE
The installation will attempt to set the DNS entries on the existing stations with
I/A Series software v8.7 or earlier. However, this can fail for multiple reasons. You
may see the following message in the AD Setup log (D:\usr\fox\sp\ADSetup.log):
Failed to configure the DNS setting for AW0001 station. Access is
denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED)).
The instructions for setting up DNS entries on existing stations with I/A Series
software v8.7 or earlier should be followed for all stations with I/A Series software
v8.7 or earlier even though it is possible that some entries have been set already. It is
critical to system interoperability that these settings are made.
272
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
34. Right-click the I/A Series network interface card, and click Properties.
In the adapter’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Properties.
The Internet Protocol (TCP/IP) Properties dialog box appears as shown in
Figure 8-49.
Remove the IP addresses from the Preferred DNS server and Alternate DNS server
fields.
Clear
these
fields.
Figure 8-49. Internet Protocol (TCP/IP) Properties - Removing On-MESH DNS Entries
273
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
35. Next, set the IP Address and DNS settings for the Off-Mesh network interface card
according to the IP setting of the new Off-Mesh domain, as demonstrated in
Figure 8-50. Then click OK to apply the changes.
Set
these
fields.
36. Reboot the server. Click the Start button and click Shut Down; select Restart from
the pull-down menu and click OK.
The installation procedure for the domain controller is complete.
NOTE
After migration is complete, install Windows Server 2008 R2 Standard with
I/A Series software v8.8 on all of your SDCs.
274
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
1. Click the Start button and select Control Panel -> Administrative Tools ->
Active Directory Users and Computers. You may need to scroll down to see
this menu selection.
2. From Active Directory Users and Computers, right-click on the “IA Comput-
ers” OU and select New -> Computer as shown in Figure 8-51.
3. Enter the name of the new workstation in the Computer name field and click OK as
shown in Figure 8-52. The OU for “Pre-8.8 workstations” on migrated systems will
be named “Pre-8.8 IA Computers” as shown in Figure 8-53.
275
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
276
8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller B0700SF – Rev E
Continuing Installation
NOTE
For all domain clients migrated from a domain with I/A Series software
v8.5/8.6/8.7 to a domain with I/A Series software v8.8, it may be necessary to move
the migrated domain client’s object in Active Directory before beginning the client’s
installation procedure. Refer to “Migrating Domain Client from Domain in
I/A Series System v8.7 Or Earlier to a Domain in I/A Series System v8.8” on
page 358.
Refer to “Installing Optional Software” on page 63 to install any additional packages on your new
PDC.
Be sure to re-enable McAfee VirusScan on all the PDCs, SDCs and domain clients on which you
disabled it. Refer to “Re-Enabling the McAfee VirusScan Console” on page 408.
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for the domain clients.
277
B0700SF – Rev E 8. Migrating I/A Series Software v8.5/8.6/8.7 to a New Off-MESH Primary Domain Controller
278
9. Migrating I/A Series Software
v8.5/8.6/8.7 to a Pre-Existing Off-
MESH Primary Domain Controller
This chapter describes how to migrate an existing (source) On-Mesh Primary Domain
Controller with I/A Series software v8.5/8.6/8.7 and Windows Server 2003 to a pre-existing
(target) Off-Mesh Primary Domain Controller (PDC) with I/A Series software v8.8 or later
and Windows Server 2008 R2 Standard.
This procedure involves:
Copying the inter-forest migration scripts to a portable drive, and downloading the
required third-party software
Transferring the Active Directory Settings from the source On-Mesh PDC to the tar-
get Off-Mesh PDC
Installing required third-party software to the target Off-Mesh PDC
Migrating passwords and group policy objects (GPOs) from the source On-Mesh
PDC (with the Password Export Server) to the target Off-Mesh PDC
Migrating the domain clients with I/A Series software v8.5/8.6/8.7) to the new Off-
Mesh domain.
You must transfer all user accounts, groups and computers manually to the migration organiza-
tional unit (OU) on the source On-Mesh PDC.
The inter-forest migration scripts on the I/A Series v8.8 Day 0 DVD-ROM will:
Migrate all the user accounts, groups, group memberships, passwords and security
identifiers (SIDs) from the On-Mesh PDC’s migration OU to the pre-existing Off-
Mesh PDC’s migration OU.
Install the new I/A Series Security Phase 2 Active Directory components on the target
Off-Mesh PDC automatically using other scripts.
After migrating the user accounts, groups and computers, each client workstation must be
removed from the source On-Mesh PDC and added to the target Off-Mesh PDC (the station
onto which the new software will be installed).
In these procedures, the:
Existing On-Mesh Primary Domain Controller with I/A Series software v8.5/8.6/8.7
and Windows Server 2003 is referred to as the source PDC.
Existing Off-Mesh Primary Domain Controller (PDC) with Windows Server 2008
R2 Standard and the I/A Series software v8.8 Active Directory group policies or Phase
2 Active Directory security components installed on it is referred to as the target
PDC.
279
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
280
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
NOTE
SQL Server 2008 R2 Express Edition is not supported.
NOTE
This is NOT the pwdmig.msi file found in the support files provided with the
Windows Server 2003 R2 operating system.
281
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
282
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
NOTE
The check box should be re-enabled at the end of the installation.
283
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
284
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
2. Enter the password in the two fields as shown in Figure 9-5 and click OK.
3. Log off from the source PDC and log back into the source PDC using the newly-set
password.
4. Set the PowerShell execution policy on the source PDC by executing the following
command from within Windows PowerShell:
Set-ExecutionPolicy Unrestricted
5. Open the Internet Protocol (TCP/IP) Properties dialog box for the Off-Mesh NIC
card as follows:
a. On the desktop, right-click My Network Places, and click Properties.
b. In the Network and Connections dialog box, right-click the Off-Mesh NIC card,
and click Properties.
285
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
c. In the card’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Proper-
ties. The Internet Protocol (TCP/IP) Properties dialog box appears as shown in
Figure 9-7.
d. In the Internet Protocol (TCP/IP) Properties dialog box, set the TCP/IP address
and DNS server address to match the network settings of the target PDC. The
DNS server address should be the IP address of the target PDC.
Figure 9-7. Internet Protocol (TCP/IP) Properties Dialog Box - Off-MESH NIC Card
NOTE
The installation will attempt to set the DNS entries on the existing stations with
I/A Series software v8.7 or earlier. However, this can fail for multiple reasons. You
may see the following message in the AD Setup log (D:\usr\fox\sp\ADSetup.log):
Failed to configure the DNS setting for AW0001 station. Access is
denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED)).
The instructions for setting up DNS entries on existing stations with I/A Series
software v8.7 or earlier should be followed for all stations with I/A Series software
v8.7 or earlier even though it is possible that some entries have been set already. It is
critical to system interoperability that these settings are made.
286
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
6. Open the Properties dialog box for the FoxInt NDIS Intermediate Miniport Driver
(I/A Series network card).
a. On the desktop, right-click My Network Places, and click Properties.
b. In the Network and Connections dialog box, right-click the FoxInt NDIS Inter-
mediate Miniport Driver, and click Properties.
c. Disable the TCP/IP protocol on the FoxInt NDIS Intermediate Miniport Driver
by un-checking the Internet Protocol (TCP/IP) check box in the list of supported
protocols as shown in Figure 9-8.
Uncheck
Figure 9-8. Internet Protocol (TCP/IP) Properties Dialog Box - FoxInt NDIS Intermediate
Miniport Driver
287
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
7. Click the Start button, and click Programs -> Accessories -> Command Prompt to
open a command prompt. Verify the basic TCP/IP connectivity by pinging the target
PDC from the command prompt.
288
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
8. Open Windows PowerShell and navigate to the folder containing the inter-forest
migration scripts (.\InterForestMigration\PrepSourceDomain), to which you copied
them in “Preparation for Installation” on page 280. In the Windows PowerShell com-
mand prompt, execute the command .\PrepSourceDomainForMigration.ps1 to
prepare the source PDC for migration
NOTE
If Windows PowerShell was already open before this step to set an execution policy,
the PowerShell command prompt must be closed and then reopened before per-
forming this step.
289
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
9. In the Inter-Forest Migration dialog box, shown in Figure 9-11, provide the
information requested for your source and target PDCs. In this example, the target
PDC is named existing.local with an IP address of 181.182.81.1 and an administra-
tor account name of Administrator. The source PDC IP address is 181.182.81.2 in
this example.
10. Review the Active Directory setup log (D:\usr\fox\sp\ADSetup.log) for errors.
290
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
11. From within Active Directory Users and Computers, drag the “IA Computers” and
“IA Users” Organizational Units (OUs) to the Migration OU as shown in
Figure 9-12.
291
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
12. Select the Exceed_Users group, the IA Installer group, the IA Services group, the
IA Services user (named IAServices in Figure 9-13), and the IA Installer user (named
IAInstaller in Figure 9-13) from within the Users OU. Drag these users and groups to
the Migration OU as shown in Figure 9-13.
Figure 9-13. Moving Additional Users and Groups into the Migration OU
292
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
13. After the previous steps have been performed, the Migration OU appears as shown in
Figure 9-14.
Any additional users and groups may also be dragged into the Migration OU if they
are to be migrated. However, the migration process does not support migrating
custom OUs. All objects must be located directly under the Migration OU.
NOTE
Any non-standard accounts or groups (such as those which were not created by
default during the installation of I/A Series software v8.5) will be migrated if they
are placed directly inside the Migration OU. However, any links which had been
made to group policy objects (GPOs) before the migration will be lost. After the
migration is complete, it will be necessary to recreate the OUs which had contained
these Active Directory objects and manually move the objects into their respective
OUs. It will also be necessary to re-establish any links to the GPOs in order for
these user groups and accounts to work as they had on the pre-migrated system.
293
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
294
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
Figure 9-16. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
295
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
5. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Perform an inter-forest migration, Pre-8.8 to existing OFF-MESH
(load commit files only)
6. Click Next.
296
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
7. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 9-18. Click Load to set the installation target drive to D:\ and
load the committed configuration files.
8. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 9-19. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a diskette, put the dis-
kette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 9-19 indicates
the number of the requested Commit diskette to the right of the Load button (101
for the first diskette, 102 for the second, and so forth). Insert each diskette in the set
and click Load.
297
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
9. Click Next.
10. Once the committed configuration installation files have been loaded, click Finish.
298
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
11. Verify that the TCP/IP settings for the target PDC are compatible with the settings
made on the source PDC. Open the Internet Protocol (TCP/IP) Properties dialog box
for the target PDC’s Off-Mesh NIC card as follows:
a. On the desktop of the target PDC, right-click My Network Places, and click
Properties.
b. In the Network and Connections dialog box, right-click the Off-Mesh NIC card,
and click Properties.
c. In the card’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Proper-
ties. The Internet Protocol (TCP/IP) Properties dialog box appears as shown in
Figure 9-21.
d. In the Internet Protocol (TCP/IP) Properties dialog box, ensure the IP address is
compatible with the settings made for the source domain controller. When fin-
ished, click OK twice to close these dialog boxes.
Figure 9-21. Internet Protocol (TCP/IP) Properties Dialog Box - Target PDC’s
Off-MESH NIC Card
299
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
12. Click the Start button, and click Programs -> Accessories -> Command Prompt to
open a command prompt. Verify the basic TCP/IP connectivity by pinging the target
PDC from the command prompt.
13. Install the Microsoft SQL Server 2008 SP3 Express Edition software v10.00.5500.00
downloaded in “Preparation for Installation” on page 280, using the directions
described in “Installing Microsoft SQL Server 2008 SP3 Express Edition
v10.00.5500.00” on page 306.
Note that SQL Server 2008 R2 Express Edition is not supported.
300
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
14. Open Windows PowerShell and navigate to the folder containing the inter-forest
migration scripts (.\InterForestMigration\PrepTargetDomain), to which you copied
them in “Preparation for Installation” on page 280. In the Windows PowerShell com-
mand prompt, execute the command .\PrepTargetDomainForMigration.ps1 to
prepare the target PDC for migration
301
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
15. In the Inter-Forest Migration dialog box, shown in Figure 9-24, provide the
information requested for your source PDC. In this example, the source PDC is
named iaseries.local with an IP address of 181.182.81.2 and an administrator
account name of IAManager.
302
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
19. Click the Start button, and click Programs -> Accessories -> Command Prompt to
open a command prompt. Create the password migration export file by executing the
following command from the command prompt:
C:\Windows\admt\admt.exe key /opt:create /sd:“[SOURCE_PDC]”
/kf:“[PASSWORD_EXPORT_FILE]” /KeyPassword:“[PASSWORD]”
Where:
[SOURCE_PDC] is the name of the source PDC.
[PASSWORD_EXPORT_FILE] is the location and name for the new password
export file.
[PASSWORD] is the key password.
For example (as shown in Figure 9-26), if the name of the source PDC is “iaser-
ies.local” and the name of the password export file is “D:\source.pes”, the command
would be:
C:\Windows\admt\admt.exe key /opt:create /sd:“iaseries.local”
/kf:“D:\source.pes” /KeyPassword:“Password1”
303
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
20. From Active Directory Users and Computers, right-click on the Built-in Admin-
istrators group and select Properties. In the Administrators Properties dialog
box, select the Members tab and click the Add button as shown in Figure 9-27.
304
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
21. In the Select Users, Contacts, Computers, Service Accounts or Groups dialog box,
enter the full name of the source PDC’s administrator account (in this example,
IASERIES\IAManager) and click OK.
Figure 9-28. Select Users, Contacts, Computers, Service Accounts or Groups Dialog Box
305
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
306
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
3. Click OK.
307
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
4. Click Next.
308
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
5. Check the I accept the license terms check box and click Next.
309
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
Figure 9-33. SQL Server Installation Center - Install Setup Support Files
310
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
7. Click Next.
Figure 9-34. SQL Server Installation Center - Setup Support Files Installed
311
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
8. Check the Database Engine Services check box and click Next.
312
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
313
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
314
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
11. Select the “NT AUTHORITY\SYSTEM” account for the SQL Server Database
Engine. Then, click Next.
315
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
316
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
Figure 9-40. SQL Server Installation Center - Error and Usage Reporting
317
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
318
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
319
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
320
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
321
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
322
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
3. As shown in Figure 9-46, select the I Agree radio button and click Next.
Figure 9-46. Installing Active Directory Migration Tool v3.2 - License Agreement
323
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
4. As shown in Figure 9-47, leave the default setting and click Next.
Figure 9-47. Installing Active Directory Migration Tool v3.2 - Customer Experience
Improvement
324
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
5. Enter the instance name (chosen during the SQL Server 2008 Express SP3 installa-
tion). The default is .\SQLEXPRESS as shown in Figure 9-48. Then click Next.
Figure 9-48. Installing Active Directory Migration Tool v3.2 - Database Selection
325
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
6. Click Next.
Figure 9-49. Installing Active Directory Migration Tool v3.2 - Database Import
326
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
7. When prompted as shown in Figure 9-50, click Finish to complete the Active Direc-
tory Migration Tool installation.
327
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
2. At the end of the Password Migration service installation, when asked if you want to
restart the computer (see Figure 9-52), select No.
328
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
3. Click Start -> Run. In the Run dialog box, type services.msc and click OK. The
Services dialog appears. Right-click on the Password Export Server Service
entry and select Properties.
329
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
4. In the Service Properties dialog box, select a startup type of Automatic and click OK.
330
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
7. In the GPMC console tree, locate the Default Domain Controllers GPO as shown in
Figure 9-55, right-click it and select Edit.
331
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
332
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
10. Enter the name of the Administrator account on the target domain and click OK.
333
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
334
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
3. As shown in Figure 9-60, select the I Accept the License Agreement radio but-
ton and click Next.
335
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
4. Click Browse as shown in Figure 9-61. Browse to the location in which you created
the source.pes file in “Preparing the Target Primary Domain Controllers” on
page 294. (For example, in Figure 9-61, the location is D:\.) Click OK to close the
Browse dialog box. Then click Next.
5. When the dialog box shown in Figure 9-62 appears, type the password you provided
for this file in “Preparing the Target Primary Domain Controllers” on page 294
(“Password1”) in the Password and Confirm fields. Then click Next.
336
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
7. When the dialog box shown in Figure 9-64 appears, enter the source PDC Adminis-
trator account credentials (IASERIES\IAManager) to configure the Password Export
Server and click OK.
337
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
8. Click OK.
Figure 9-65. ADMT Password Migration DLL - Account Granted Log On As a Service Right
338
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
10. Do not restart the source PDC. When prompted as shown in Figure 9-67, click No.
NOTE
1) You cannot use the 64-bit Windows PowerShell to execute these scripts.
2) The source PDC must be available and must be logged into with the account
under which the Password Export Server Service is setup to run.
339
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
5. When prompted, provide the name of the source PDC (iaseries.local in the example
shown in Figure 9-69).
340
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
3. Enter the name of the new workstation in the Computer name field and click OK as
shown in Figure 9-71. The OU for “Pre-8.8 workstations” on migrated systems will
be named “Pre-8.8 IA Computers” as shown in Figure 9-72.
341
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
342
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
343
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
Figure 9-74. Internet Protocol (TCP/IP) Properties Dialog Box - FoxInt NDIS Intermediate
Miniport Driver
2. Open the Internet Protocol (TCP/IP) Properties dialog box for the Off-Mesh NIC.
a. In the Network and Connections dialog box, right-click the Off-Mesh NIC, and
click Properties.
b. In the NIC’s Properties dialog box, in the “This connection uses the following
items” section, click Internet Protocol (TCP/IP), and then click Proper-
ties.
344
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
IP Address of
the Target
PDC
Figure 9-75. Internet Protocol (TCP/IP) Properties Dialog Box - Off-MESH NIC
345
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
4. When asked, enter the IAManager account credentials and click OK.
346
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
5. Click OK.
6. Click OK.
Figure 9-79. Computer Name Changes - Note that Domain Client Must Be Restarted
7. In the System Properties dialog box, in the Computer Name tab, click the Change
button again.
347
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
8. Select the Domain radio button and enter in the name of the Off-Mesh domain.
Click OK.
9. Enter the credentials for an account with permission to add stations to the Off-Mesh
domain and click OK.
348
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
Figure 9-84. Computer Name Changes - Note that Domain Client Must Be Restarted
12. Click OK as shown in Figure 9-85. Do not reboot the computer when prompted.
349
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
14. Click Start -> Run. In the Run dialog box, type services.msc and click OK. The
Services dialog appears. Right-click on FoxNTGUIAppServices and select
Properties.
350
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
15. Select the Log On tab as shown in Figure 9-88. In the “This account:” field, enter the
name of the IAServices account on the new Off-Mesh domain. After the migration, it
should only be necessary to change the domain name. Enter and confirm the pass-
word for this account. When finished, click OK.
16. The dialog box shown in Figure 9-89 appears if the account information was entered
correctly. Click OK.
351
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
18. Click the Start button, and click Programs -> Accessories -> Command Prompt to
open a command prompt. Type the following command and then press <Enter>:
SetIAStartupAcct
19. Reboot the domain client. Click the Start button and click Shut Down; select
Restart from the pull-down menu and click OK.
The migration process is complete.
NOTE
After migration is complete, install Windows Server 2008 R2 Standard with
I/A Series software v8.8 on all of your SDCs.
352
9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain Controller B0700SF – Rev E
Continuing Installation
NOTE
For all domain clients migrated from a domain with I/A Series software
v8.5/8.6/8.7 to a domain with I/A Series software v8.8, it may be necessary to move
the migrated domain client’s object in Active Directory before beginning the client’s
installation procedure. Refer to “Migrating Domain Client from Domain in
I/A Series System v8.7 Or Earlier to a Domain in I/A Series System v8.8” on
page 358.
Refer to “Installing Optional Software” on page 63 to install any additional packages on the PDC.
Be sure to re-enable McAfee VirusScan on all the PDCs, SDCs and domain clients on which you
disabled it. Refer to “Re-Enabling the McAfee VirusScan Console” on page 408.
Proceed to Chapter 10 “Security Enhanced I/A Series Software v8.8 Installation for Domain Cli-
ents or Connecting Security Enhanced I/A Series Software v8.5-8.7 Domain Clients to Existing
Off-MESH Networks” for the installation procedure for the domain clients.
353
B0700SF – Rev E 9. Migrating I/A Series Software v8.5/8.6/8.7 to a Pre-Existing Off-MESH Primary Domain
354
10. Security Enhanced I/A Series
Software v8.8 Installation
for Domain Clients or Connecting Security Enhanced
I/A Series Software v8.5-8.7
Domain Clients to Existing Off-MESH Networks
This chapter describes procedures to install security enhanced I/A Series software v8.8 on your
domain clients and connect them to the appropriate On-Mesh or Off-Mesh domain controller.
It also describes how to connect an existing domain client with I/A Series software v8.5-v8.7 to
an existing Off-Mesh domain controller.
Workstation/Server Preparation
This section applies to the Windows 7 and Windows Server 2008 R2 Standard stations that are
being installed as domain clients. The domain client may be connected to a domain client either
on The Mesh control network (which is a dedicated I/A Series maintained network) or on
another network (which is called an “Off-Mesh” network).
Dialog boxes on these two types of platforms may differ slightly, but will be functionally identical,
with minor exceptions as documented below.
Perform the following steps to set up the hardware and restore the operating system onto your
workstation:
NOTE
If this is a new station shipped from the Invensys factory with the V8.8 Restore
image identified by the media kits in Table 1-1 and verified in your workstation’s
H-code (or P-code), proceed to “Notes for Installing I/A Series System Software” on
page 356. If not, continue following the steps in this section.
1. Install hardware, restore the Windows operating system, and update drivers for your
workstation or server. Perform the following:
a. Refer to I/A Series System V8.8 Release Notes (B0700SG) to be sure that your hard-
ware meets all hardware requirements specific to the V8.8 release. For instructions
on installing memory upgrades, PCI cards, and so forth, refer to the “Installing
Hardware Upgrades” chapter of the hardware and software specific instruction
document shipped with your workstation or server.
b. Using the V8.8 Restore Media, restore the Windows operating system on your
workstation or server. Follow the instructions of Appendix A “Startup Options”.
355
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
! WARNING
Only use the media kits listed in Table 1-1 to restore the operating system of an
V8.8 station.
Do not follow the instructions for installing I/A Series software from your hardware
specific instruction manual. Follow the software installation procedure below.
NOTE
While installing a secure domain client, it is important to ensure that the UTC sys-
tem time matches the UTC system time on the domain (as viewed on the PDC).
The date and time must match, though the time which Windows displays may dif-
fer if the time zones are not the same on the two stations.
Be careful when changing the time zone prior to adjusting the system time as this
can cause the AM/PM setting to change.
Also, be aware that the checkbox included for some time zones which defines
whether or not the time will be automatically adjusted for Daylight Saving Time
can cause the system time to differ by an hour.
d. For any procedures not found in Step 1.b above, refer to the “Installing and
Updating Drivers” chapter of the hardware and software specific instruction docu-
ment shipped with the station.
2. Perform the procedures in Appendix G “IASeries_NIC_Data.msi Installation (Pre-
I/A Series Installation)” on page 525.
356
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
! CAUTION
In Control Panel -> Network Connections, which lists the available NICs, do not
change the name of any “Local Area Connection x” network connection. This can
result in software installation issues or system instability.
! CAUTION
GPS PCI time cards are installed only in primary and backup Master TimeKeeper
workstations or stations as configured for MTK. The MTK workstations or stations
with I/A Series software v8.8 and later must install the GPS PCI time card, driver,
and control utility before installing I/A Series software. Refer to the Time Synchroni-
zation User’s Guide (B0700AQ) to perform this installation.
NOTE
On servers with the Windows Server 2008 R2 Standard operating system, it is rec-
ommended that no roles be added to the system which are not necessary for the
operation of the server. Adding unnecessary roles (for example, adding the Remote
Desktop Services role when the server is not to be used as a remote session host) can
create security weaknesses in the overall system.
NOTE
Use the IAInstaller account for all installation tasks. However, due to the
permissions assigned to IAInstaller, do not use it for any other role, such as
operation of the station.
NOTE
Refer to the Hardware and Software Specific Instructions document included with
your station to determine the NIC cards it supports.
Proceed as follows:
1. Right-click the My Computer icon, and click Manage. Double-click Device Man-
ager. In the Device Manager window, expand the Network adapters list.
2. Right-click the desired card and click Properties. In the Properties dialog box that
appears, select the Advanced tab.
3. In the Property field, click Flow Control. In the Value field, select Disable from
the drop-down menu list.
4. In the Property field, click Speed & Duplex. In the Value field, in the drop-down
menu list:
357
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
358
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
3. Determine if the account of the domain client to be installed as an I/A Series software
v8.8 domain client is in the “Pre-8.8 IA Computers” OU as shown in Figure 10-1.
359
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
4. Drag the account of the domain client into the “IA Computers” OU as shown in
Figure 10-2.
360
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
361
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
NOTE
The check box should be re-enabled at the end of the installation.
362
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
Click Yes to cancel, or No to resume the installation process. If you click Yes, the following dialog
box appears. Click OK:
363
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
You are returned to the installation dialog box as shown in Figure 10-7. If you want to see the
installation log, check Show the Windows Installer log. Click Finish.
To restart the installation process after clicking Cancel, re-insert the DVD labeled “I/A Series
v8.8 Day 0 DVD-ROM” (K0174KE-A). A dialog box appears asking if you want to continue
with the installation.
If you click Yes, the installation will return to the dialog box that was canceled. If you click No,
installation will restart from the beginning.
Installation Procedures
The following installation procedures are provided:
“Installation Procedure (On The MESH Control Network)” on page 365 - for
domain clients with I/A Series software v8.8 on The Mesh control network
“Installation Procedure for Clients of New Off-MESH Domain Controllers” on
page 379 - for domain clients with I/A Series software v8.8 on a new Off-Mesh
network
“Installation Procedure for Pre-Existing Domain Clients (I/A Series Software v8.5-
v8.7) to Existing Off-MESH Domain Controllers” on page 397 - for pre-existing
domain clients with I/A Series software v8.5-v8.7 on an existing Off-Mesh network.
364
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the station. Otherwise, restore the station using the
proper V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the station using the proper V8.8 Restore
media. (See page 5.)
365
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
Figure 10-9. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
366
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
9. A dialog box appears that allows you to select whether you are installing I/A Series
software without security enhancements or for a security-enhanced system. Select
Install I/A Series software for a security enhanced system and
Install this workstation as a client workstation:
367
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
11. The next dialog box requests that you load the committed configuration install files,
as shown in Figure 10-11. Select the Use an On-MESH Domain Controller radio
button. Click Load to load the committed configuration files.
12. The browser for the folder containing the committed configuration install files opens,
as shown in Figure 10-12. If the installation media with your Commit files is on the
server’s hard drive or a network, browse to the location of the media and click Select
Folder. If the installation media with your Commit files is on a floppy diskette, put
the diskette in the diskette drive (A:\) and click Use Diskette.
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 10-11 indi-
cates the number of the requested Commit diskette to the right of the Load button
(101 for the first diskette, 102 for the second, and so forth). Insert each diskette in
the set and click Load.
368
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
13. Once the installation files have been loaded, click Bind as shown in Figure 10-11 to
launch the I/A Series Network Installation utility.
14. The dialog box shown in Figure 10-13 is displayed if the network configuration from
System Definition do not match the available NIC hardware.
If this dialog boxes is not displayed, the NIC cards have been automatically config-
ured. Proceed to the next step.
369
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation.
NOTE: I/A Series Network Installation dialog box shown above is for an On-MESH domain client,
and is provided to illustrate the concept of the NIC Adapter Device Number only.
Figure 10-13. I/A Series Network Installation (For Certain NIC Cards)
NOTE
For help in determining the correct network adapter(s) to select, click the Start
button and then select Control Panel -> Network and Internet -> Network
Connections. The Network Connections dialog box appears as shown in
Figure 10-14. Identify the NIC adapter device number for the NIC to be connected
to the Domain Controller’s network (it should have an entry in the Connectivity
column).
Note that the NIC Adapter Device Number indicated in Figure 10-13 aligns with
the NIC Adapter Device Number shown in Figure 10-14. This should not be
confused with the Local Area Connection number (shown in Figure 10-14).
370
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
15. The Ready to connect this workstation to the I/A Series domain dialog box appears as
shown in Figure 10-15. Enter the name (letterbug) of the domain controller server
and the password for the “IA Installer” account. Verify the user account with authori-
zation to add stations to the domain.
If “offmesh.local” is the name of your domain, enter the password and click
Authorize.
If “offmesh.local” is not your domain, change the domain name, enter the pass-
word and click Authorize.
371
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
Figure 10-15. Ready to Connect This Workstation to the I/A Series Domain
16. If the local system time does not match the PDC system time, the dialog box shown
in Figure 10-16 appears. Click OK. Fix the local system time to match the PDC time
(see “Workstation/Server Preparation” on page 355) and re-click Authorize.
372
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 10-17 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
NOTE
If after connecting the domain client to an I/A Series domain and the software
installation does not continue after the reboot, the system time may not have been
set correctly. Refer to “Setting Time Correctly After Failure to Continue Software
Installation After Reboot (SDC or Domain Client)” on page 539 to correct this.
373
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
17. If a Secondary Domain Controller (SDC) is planned for this I/A Series system, select
the SDC from the “Select the Secondary Domain Controller Stations” drop-down list
and click Set. If no SDC station is planned, click Skip.
18. Fill in the name of the host domain (iaseries.local is the default) and click
Connect.
19. If the workstation is connected to the domain, the dialog box shown in Figure 10-18
appears. Click Reboot.
Figure 10-18. Invensys IASeries Install: Workstation Reboot Request Dialog Box
The following dialog box indicates that the server will be rebooted.
20. When the station reboots, log into the domain using the “IA Installer” account.
374
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
21. The installation restarts automatically. Click Next and then Install to run the
installation process.
22. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 10-21 is displayed.
To install this package, insert the first OS1FDB package diskette and click Load. After
the first disk has been loaded, insert the second OS1FDB package diskette and click
Load.
To bypass the installation of this package, click Skip. The installation continues, but
this dialog box is displayed again for each of the OS1FDB stations configured on this
I/A Series station.
NOTE
This will occur one time for each OS1FDB station configured.
375
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
376
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
24. If you selected Use Diskette in the previous step, the dialog box in Figure 10-23
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
377
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
26. Proceed to “Completing the Domain Client Installation” on page 402.
378
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
This procedure is for adding domain clients to new Off-Mesh domain controllers. Proceed as
follows:
1. Ensure the PDC for this domain client has been installed and is attached to the sec-
ondary (non-I/A Series) network.
2. Ensure that the domain client’s object is under the correct I/A Series software v8.8
Organizational Unit (OU) in the Active Directory.
3. Ensure the domain client is attached to The Mesh control network.
4. Ensure the domain client is attached to the secondary (non-I/A Series) network.
5. Insert the DVD labeled “I/A Series v8.8 Day 0 DVD-ROM” (K0174KE-A).
6. If AutoPlay is enabled, the AutoPlay dialog box appears as shown in Figure 10-25.
Click Run setup.exe.
Otherwise, navigate to the DVD drive and double-click setup.exe.
379
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
! CAUTION
If you are prompted with a dialog box indicating that you need to restart for the
configuration changes made to the Security Enhanced Installer to take effect, you
may have restored a non-secure image intended for I/A Series software v8.5-8.7 on
Windows XP or Windows Server 2003 R2. If you are sure you used the proper V8.8
restore image, then reboot the station. Otherwise, restore the station using the
proper V8.8 restore media. (See page 5.)
If a dialog box appears indicating that .NET Framework is required, then you have
used incorrect restore media. Restore the server using the proper V8.8 Restore
media. (See page 5.)
Figure 10-26. Microsoft Visual C++ 2010 Redistributable Package (x64) Installation Dialog Box
380
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
9. Select the Install I/A Series software for a security enhanced system
bullet as shown in Figure 10-27. Ensure that Install this workstation as a
client workstation is selected. Then click Next.
381
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
10. The Load committed configuration install files dialog box appears as shown in
Figure 10-28.
Select the Use an Off-MESH Domain Controller radio button. Enter the IP
address for the Off-Mesh PDC. Enter the IP address and net mask for the local Off-
Mesh NIC card or select the Use DHCP check box. Click Select.
NOTE
I/A Series software can only be installed to the D:\ drive.
382
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
NOTE
If you have multiple Commit diskettes, the Stamp ID: field in Figure 10-29 indi-
cates the number of the requested Commit diskette to the right of the Load button
(101 for the first diskette, 102 for the second, and so forth). Insert each diskette in
the set and click Load.
383
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
12. Once the Commit files have been loaded, click Bind as shown in Figure 10-30 to
launch the I/A Series network installation.
Figure 10-30. Load Committed Configuration Install Files Dialog Box - Bind
NOTE
If after clicking the Bind button, the installation does not proceed and the Bind
button is still enabled, it is likely that the Off-Mesh NIC card was configured with
the desired IP address prior to running the I/A Series installation. If this is the case,
reset the Off-Mesh NIC settings to use DHCP and re-click the Bind button.
NOTE
If after clicking the Bind button, the install does not proceed and the Load button
is enabled, it is likely that there is a mismatch in the configuration between your
NIC hardware and your network system configuration. Verify and fix the commit-
ted configuration install files as necessary and reload these install files in order to
continue.
384
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
13. The dialog box shown in Figure 10-31 is displayed. Select the onboard NIC that
communicates with the PDC and the SDC on the secondary network (that is, the
Off-Mesh NIC). This NIC was set up on page 382. Then click Next.
! CAUTION
Be certain to pick the correct NICs as this selection cannot be changed later in the
installation. Refer to the explanation on page 371 for the difference between the
NIC adapter device number and the local area connection number for a NIC.
NOTE: I/A Series Network Installation dialog box shown above is for an On-MESH domain client,
and is provided to illustrate the concept of the NIC Adapter Device Number only.
Figure 10-31. I/A Series Network Installation (For Certain NIC Cards)
NOTE
For help in determining the correct network adapter(s) to select, click the Start
button and then select Control Panel -> Network and Internet -> Network
Connections. The Network Connections dialog box appears as shown in
Figure 10-32. Identify the NIC adapter device number for the NIC to be connected
to the Domain Controller’s network (it should have an entry in the Connectivity
column).
Note that the NIC Adapter Device Number indicated in Figure 10-31 aligns with
the NIC Adapter Device Number shown in Figure 10-32. This should not be
confused with the Local Area Connection number (shown in Figure 10-32).
385
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
14. Select the NIC(s) that communicate with The Mesh control network (that is, the On-
Mesh NICs). Then click Next.
Figure 10-33. I/A Series Network Installation (For Certain NIC Cards)
15. Click Next. The Ready to connect this workstation to the I/A Series domain dialog
box appears as shown in Figure 10-34. Fill in the Domain Controller IP Address of
the PDC server, and verify the user account with authorization to add stations to the
domain.
If “offmesh.local” is the name of your domain, enter the password and click
Authorize.
386
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
If “offmesh.local” is not your domain, change the domain name, enter the pass-
word and click Authorize.
NOTE
There are instances in which “offmesh.local” will not be your domain, such as if
your domain controllers were migrated off of The Mesh control network.
NOTE
It may be necessary to use a different account in this dialog box if migrating to an
existing Off-Mesh domain. In this case, the Administrator account may be neces-
sary depending on how the “IA Installer” group member has been configured.
Figure 10-34. Ready to Connect This Workstation to the I/A Series Domain Dialog Box
16. If the local system time does not match the PDC system time, the dialog box shown
in Figure 10-35 appears. Click OK. Fix the local system time to match the PDC time
(see “Workstation/Server Preparation” on page 355) and re-click Authorize.
387
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
In some cases, it will not be possible to determine the remote system time. In this case,
the dialog box shown in Figure 10-36 is displayed. It is important to ensure that the
local and remote system times match (including date, time, AM/PM) before continu-
ing. Note that the checkbox displayed for some time zones which allows the system to
automatically adjust for Daylight Saving Time can affect the time displayed by the
system by one hour.
17. If SDC stations are planned for this I/A Series system, expand the drop-down list
from “Select the Secondary Controller Domains” and select the Add Off-Mesh entry.
A dialog box opens in which the IP addresses for SDC stations can be set. Enter each
of the known SDC’s IP addresses and click Done.
388
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
18. Click Set to choose the SDC stations in your list or Skip to choose no SDC station
IP addresses. If this station has more than one statically set NIC adapter, a message is
displayed indicating that the domain controller must have at least one NIC card con-
figured with a static IP address in order to continue the installation. Once the NIC
settings are corrected, click Set or Skip again to continue.
19. The “Select a Host Domain for this workstation and click Connect” area is added as
shown in Figure 10-38. If “offmesh.local” is not the name of your domain, change the
domain field as needed. Click Connect.
Figure 10-38. Select a Host Domain for this workstation and click Connect Area
389
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
20. If connected to the domain, the message shown in Figure 10-39 is displayed.
Click Reboot. The following dialog box indicates that the station is about to be
rebooted.
NOTE
If the installation returns the error message stating that a restart could not be sched-
uled, start the installation manually after the reboot completes. (You should not
wait for a restart since the error message states that the restart will not occur.) Be
aware that if you start the setup.exe installer and no GUI opens, wait for several
minutes for the GUI to open, as a large amount of data in the setup needs to be
copied to the local support folder. Check the Task Manager to confirm that
setup.exe is running. If it is still running, continue to wait.
21. When the station reboots, log into the domain using the “IAInstaller” account.
390
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
22. The installation restarts automatically. You may have to wait for a few minutes before
the installation continues. Click Next.
391
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
24. If the OS1FDB package is configured on this server, the dialog box shown in
Figure 10-43 is displayed.
To install this package, insert the first OS1FDB package diskette and click Load. After
the first disk has been loaded, insert the second OS1FDB package diskette and click
Load.
To bypass the installation of this package, click Skip. The installation continues, but
this dialog box is displayed again for each of the OS1FDB stations configured on this
I/A Series station.
NOTE
This will occur one time for each OS1FDB station configured.
392
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
If your installation media for the OS1FDB package is not on a floppy diskette, browse
to the location of your stamped media and click the Select Folder button
If your installation media for the OS1FDB package is on a floppy diskette, click Use
Diskette. The diskette must be in the diskette drive (A:\). Once the Use Diskette
button is clicked, the diskette will be read.
393
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
26. If you selected Use Diskette in the previous step, the dialog box in Figure 10-45
appears. Insert the second diskette in the OS1FDB set and click Load. The diskette
must be inserted in drive A:\.
NOTE
The DNS entries for the Off-Mesh NIC fail to set during the domain client instal-
lation. After completing the I/A Series installation, but before rebooting the
domain client, open the Off-Mesh NIC card settings in the Internet Protocol Ver-
sion 4 (TCP/IPv4) Properties dialog box as follows:
Click the Start button and then click Control Panel -> Network and Sharing
Center. In the Tasks pane, click Change adapter settings. Right-click on the
adapter and click Properties.
In this same dialog box, select Internet Protocol Version 4 (TCP/IPv4) and
click Properties. In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog
box, as shown in Figure 10-46, set the first DNS entry to be the IP address of the
Off-Mesh PDC station. Set all additional DNS entries to be the IP addresses of the
Off-Mesh SDC stations.
394
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
395
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
28. Proceed to “Completing the Domain Client Installation” on page 402.
396
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
397
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
Figure 10-48. Internet Protocol (TCP/IP) Properties Dialog Box - Off-MESH NIC Card
2. If the pre-existing domain client was not a part of the original I/A Series configuration
prior to the migration of the target PDC, it may be necessary to add the domain cli-
ent to Active Directory. On the target PDC, in Active Directory Users and Comput-
ers, ensure that there is a computer account for the pre-existing domain client in the
“Pre-8.8 IA Computers” OU as shown in Figure 10-49.
398
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
Figure 10-49. Adding Pre-Existing Domain Client (I/A Series Software v8.5) to Active Directory
399
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
4. At Step 16, when the “Ready to connect this workstation to the I/A Series domain”
page appears as shown in Figure 10-50, in the Domain Controller Letterbug field,
enter the IP address for the target PDC.
Also enter:
In the Domain Admin Account field, the domain name and domain administra-
tor account name (created during the domain client’s former PDC’s installation)
In the Domain Admin Password field, the domain administrator password (set
during the PDC server installation)
5. Click Authorize.
400
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
6. Do not select any SDC stations. Select the Skip button when prompted, as shown in
Figure 10-51.
7. Click Connect.
8. A warning dialog box appears regarding the time on the domain client workstation
matching the time on the domain, as shown in Figure 10-52. Ensure the date and
time are correct to within five minutes before continuing. Perform the instructions
provided in Step 21 of “Installation Procedure” in I/A Series 8.5 Software Installation
Guide (B0700SB).
401
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
9. Continue with Step 22 of “Installation Procedure” in I/A Series 8.5 Software Installa-
tion Guide (B0700SB) and complete the installation procedure.
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
402
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
403
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
I/A Series system management is carried out by the operator primarily via the:
System Manager, discussed in System Manager (B0750AP), or
System Management Display Handler (SMDH), discussed in System Management
Displays (B0193JC).
Be aware of the following notes regarding the installation of these software packages.
On servers/workstations configured with the SMDH package (ASMDW7), the Sys-
tem Manager will be installed. Uninstalling the System Manager through the
Programs and Features dialog box (accessed via the Control Panel) results in the
server/workstation defaulting to SMDH as the system management application.
SMDH can only be invoked through FoxView. From the I/A Series initial display,
access the SMDH displays from the System button on the FoxView main window.
System Manager displays can be invoked directly, without the need for a separate
application.
Be aware that FoxView is not typically loaded on a domain controller. Invensys rec-
ommends the IAMESH only configuration on domain controllers, in which SMDH
or System Manager is not installed.
On servers/workstations where System Manager is installed by the Day 0 installation
of I/A Series software, only the System Manager client is installed.
NOTE
The System Manager Server should be installed only if the IASVCS package is
assigned to the station.
404
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
f. Click Next and then Install to install the System Manager Server.
If the SMDH package was not configured and the System Manager client is not
installed, System Manager may be added by running the complete System Manager
installation process from the System Manager CD-ROM (K0174GG).
NOTE
The System Manager client is installed only if the IASVCS package is assigned to
the station.
When logging into domain client workstations, an I/A Series user account should be
used, which is a member of one of the standard I/A Series user groups such as IA Plant
Engineers or IA Plant Operators.
! CAUTION
Logging on with the IAInstaller account will not result in the logon command run-
ning; FoxView will not start and Exceed will not be launched.
405
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
NOTE
On I/A Series servers with Windows Server 2008 R2 Standard, FoxPanels requires
that the Beep Driver component be running to operate. If you have FoxPanels on
this server, refer to “Installing the Beep Driver (I/A Series Servers with FoxPanels
Only)” on page 32 for installation instructions.
406
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
1. Click the Start button and select Control Panel -> Administrative Tools ->
Computer Management. Right-click on the IAManager account and select Set
Password.
2. Passwords changed in this manner will result in certain encrypted data becoming inac-
cessible. At this point, make sure there is no encrypted data stored under this user
account and click Proceed.
407
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
3. Enter in the new password and confirm this entry. Any password entered after the
installation of the secure I/A Series system must meet domain password complexity
requirements.
408
10. Security Enhanced I/A Series Software v8.8 Installation for Domain Clients or Connecting Security Enhanced
409
B0700SF – Rev E 10. Security Enhanced I/A Series Software v8.8 Installation
410
11. Performing a Day 1 Installation
This chapter describes the procedure to perform a Day 1 Installation.
Before performing this installation procedure, the I/A Series software must already be installed on
the workstation and be running. You must allow the software installation procedures to turn off
the I/A Series software as required.
! CAUTION
Exiting or cancelling during the software installation process causes an incomplete
installation and may cause the station to become unstable. This requires that you
reload the operating system.
NOTE
Use the IAInstaller account for all installation tasks. However, due to the
permissions assigned to IAInstaller, do not use it for any other role, such as
operation of the station.
411
B0700SF – Rev E 11. Performing a Day 1 Installation
4. Click Get Standard Stations to get all reconcile files for standard I/A Series sta-
tions.
5. When prompted, fill in the Primary Domain Controller server name (Domain Con-
troller Name), Domain Name, Secure Username and Secure Password. If the domain
is Off-Mesh, the PDC station’s IP address should be provided instead of the
workstation name.
412
11. Performing a Day 1 Installation B0700SF – Rev E
6. Click Get SE Stations to get all reconcile files for secure I/A Series stations using
the provided credentials.
7. Select the stations that need to be reconciled in the check-list box on the left-hand
side of the dialog box.
8. Select the appropriate radio button at the top of the dialog box: Create new
reconcile media or Appending to existing reconcile media.
9. Click Create to write to the media. The folder browser dialog box opens, as shown in
Figure 11-3.
413
B0700SF – Rev E 11. Performing a Day 1 Installation
Figure 11-3. Select the Location Where You Want Your Reconcile Files Saved
10. If you want to write the installation files to a diskette, be aware that the diskette must
already be in a tar format.
To write to a tar format floppy diskette in the diskette drive (A:\), click Use
Diskette.
To write the installation files to a folder location, select a folder and click Select
Folder.
11. If you selected Appending to existing reconcile media in Step 8 and
Reconcile installation media (with media number 201) is not provided in the A:\
floppy drive, the dialog box shown in Figure 11-4 is displayed.
414
11. Performing a Day 1 Installation B0700SF – Rev E
12. Use the Reconcile media generated with this utility within I/A Series System Defini-
tion to update the commit media.
13. Insert the Day 0 DVD in the workstation/server for which you want to perform a
Day 1 installation.
14. Run setup.exe. If I/A Series software is running, the dialog shown in Figure 11-5 is
displayed.
15. Click Yes and reboot the workstation manually. Click the Start button and click Shut
Down; select Restart from the pull-down menu and click OK.
Restart setup.exe after rebooting the workstation.
16. Select the Perform a Day 1 operation on the I/A Series workstation
bullet in the I/A Series Software Installation dialog box, as shown in Figure 11-6.
415
B0700SF – Rev E 11. Performing a Day 1 Installation
416
11. Performing a Day 1 Installation B0700SF – Rev E
Click on the Setup Log, Pkg Log, and Init Log buttons to view these logs. These
logs can also be printed.
19. Reboot the workstation. Click the Start button and click Shut Down; select Restart
from the pull-down menu and click OK.
20. Install the V8.8 trailer CD-ROM as described in the following section.
NOTE
A Day 1 installation should be performed on all I/A Series stations every time the
System Definition is changed.
417
B0700SF – Rev E 11. Performing a Day 1 Installation
If you have the CD-ROM labeled “I/A Series 8.8 Trailer CD-ROM” (K0174KT),
insert this CD-ROM into the station. The installation launches automatically.
If you acquired the trailer application setup.exe via another method, such as copy-
ing it from a shared network drive or downloading it from the GSC website, dou-
ble-click setup.exe to launch the installation.
2. Click Next and then click Install to start the installation process.
3. If the user currently logged in is not an administrator, a User Account Control (UAC)
prompt may appear. Click Yes to accept the UAC prompt.
NOTE
During the trailer installation, if the following message appears, “The Setup must
update files or services that cannot be updated while the system is running. If we
choose to continue, reboot will be required to continue the setup,” click OK. The
installation continues as normal. Do not reboot the station if you see this message.
This message is shown in the event that you are installing the trailer after booting
into the I/A Series software (which you should not have done if you are performing
this procedure as written in this section).
The following procedure must be performed after a Day 1 installation procedure on all Nodebus
workstations (AP, AW, and WP) to add I/A Series addressing information to the host files on
Nodebus components. To perform the Post-Commit for Pre-8.0, install the Pre-V8.1
Compatibility Diskette on each Nodebus workstation.
The following sections detail the steps for installing the disk on the two platforms.
418
11. Performing a Day 1 Installation B0700SF – Rev E
419
B0700SF – Rev E 11. Performing a Day 1 Installation
420
Appendix A. Startup Options
This appendix describes the startup options in I/A Series workstations and servers.
For the startup options in I/A Series workstations and servers, refer to:
For standard I/A Series installations - see “I/A Series Startup Account” and “I/A Series
Startup and Security Options” in I/A Series System V8.8 Release Notes (B0700SG)
For security enhanced I/A Series installations - see “I/A Series Startup and Security
Options” in Security Enhancements User's Guide for I/A Series Workstations with Win-
dows 7 or Windows Server 2008 Operating Systems (B0700ET)
421
B0700SF – Rev E Appendix A. Startup Options
422
Appendix B. Changing the Station
Name
This appendix describes how to change a station’s name.
The Windows workstation or server name must match the workstation or server letterbug name
as it was configured in SysDef and saved onto your Commit installation media before you install
the I/A Series software. For systems with multiple workstations or servers, you must change the
default workstation/server names.
The I/A Series workstation/server letterbug is an uppercase six-character alphanumeric worksta-
tion name recognized by the I/A Series software. The letterbug is defined during System Defini-
tion and is written to the Commit installation media.
To make your workstation or server letterbug name match your host name, perform the following
procedure:
1. Click the Start button and click Control Panel.
2. In the Control Panel group, double-click System. The System Properties dialog box
opens.
423
B0700SF – Rev E Appendix B. Changing the Station Name
3. Click Advanced system settings in the left pane of the System window.
424
Appendix B. Changing the Station Name B0700SF – Rev E
4. In the System Properties dialog box, select the Computer Name tab (Figure B-2).
Figure B-2. Computer Name Tab in the System Properties Dialog Box
425
B0700SF – Rev E Appendix B. Changing the Station Name
5. In the Computer Name tab, click Change. The Computer Name Changes dialog box
opens (Figure B-3).
6. In the Computer Name Changes dialog box, click Computer Name and (using all
uppercase characters) change the name to the applicable letterbug assignment on the
Commit. Click OK.
NOTE
The Computer Name field must contain six (6) uppercase characters and numbers.
7. Click Workgroup in the “Member of ” section of the Computer Name Changes dialog
box and ensure that the workgroup name is WORKGROUP. (see Figure B-3).
8. In the Computer Name Changes dialog box, click OK.
9. Click OK to close the System Properties dialog box.
426
Appendix B. Changing the Station Name B0700SF – Rev E
10. A message box opens asking if you want to restart your computer. Click OK.
11. When the system restarts, it logs you on as “Fox”. Proceed with I/A Series software
installation.
427
B0700SF – Rev E Appendix B. Changing the Station Name
428
Appendix C. Excluding Files,
Folders, and Drives
This appendix provides procedures for excluding files, folders and drives from the McAfee
VirusScan Enterprise + AntiSpyware Enterprise software.
The following files and folders must be excluded on I/A Series H91/P91 and H92/P92
workstations:
Exclude
File or Folder to Exclude Subfolders?
D:\usr\fox\exten\dcisrvr.exe No
D:\usr\fox\exten\fbmload.exe No
D:\usr\fox\exten\rls.exe No
D:\usr\fox\exten\romload_srvr.exe No
D:\usr\fox\sp\files\iom* No
D:\usr\fox\exten\om_impdb.exe No
For each file listed above, proceed as follows to exclude these files:
1. Double-click the VirusScan icon in the system tray to bring up the VirusScan Status
window.
429
B0700SF – Rev E Appendix C. Excluding Files, Folders, and Drives
430
Appendix C. Excluding Files, Folders, and Drives B0700SF – Rev E
Figure C-2. On-Access Scan Properties Dialog Box - Selecting All Processes
431
B0700SF – Rev E Appendix C. Excluding Files, Folders, and Drives
4. Click the Exclusions tab, and then click Exclusions to open the Set Exclusions
dialog box. Initially, the Set Exclusions dialog box appears blank, indicating that no
files are excluded from scanning.
432
Appendix C. Excluding Files, Folders, and Drives B0700SF – Rev E
433
B0700SF – Rev E Appendix C. Excluding Files, Folders, and Drives
7. In the When to exclude area, specify when to exclude the items from scanning.
Choose On read and On write.
8. Click OK to save your changes and return to the Set Exclusions dialog box.
434
Appendix D. Secondary Domain
Controllers in an I/A Series System
This chapter details the installation and configuration procedures for the security enhancements
provided for I/A Series v8.8 or later systems, which may also include FCS 4.0 or later software.
In the security-enhanced I/A Series system, the secondary domain controller (SDC) functions as a
backup to the primary domain controller (PDC) server for both Active Directory and DNS ser-
vices. This means that if the PDC becomes unavailable for any reason, the SDC provides such
functions as:
Servicing log on requests to the I/A Series network
Allowing for the creation, deletion, and modification of user accounts
Servicing DNS name resolution requests
Some functionality will be unavailable or may be limited during the time that a PDC is offline
and the SDC has not been promoted to PDC. This includes, but is not limited to:
Domain schema cannot be extended.
New SDC workstations cannot be added to the domain.
Ability to add users and computers to the domain may be limited.
Group polices cannot be edited.
It is recommended that the PDC remain the PDC and all SDC stations remain as SDC stations
once the security-enhanced I/A Series system has been installed. If a PDC is unavailable for a
short period of time (e.g. less than a week), it is highly recommended that an SDC is not pro-
moted to take over the role of PDC. This is because the offline PDC will not be automatically
demoted to be an SDC. During this time when the PDC is offline, do not add any new stations.
When the PDC comes back online, there would be two primary domain controllers, one of which
must then be demoted.
! CAUTION
Bringing up two PDC stations on the I/A Series system must be avoided.
435
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Infrastructure Master
Domain Naming Master
Schema Master
Note that these roles are also referred to as “operations master” roles. The steps in the next section
provide a method for transferring all five roles from the PDC to one of the SDC servers.
Proceed as follows to transfer the domain controller roles from a working PDC to an existing sec-
ondary domain controller:
1. To transfer the RID Master, PDC Emulator, and Infrastructure Master FSMO roles:
a. Click the Start button and select Control Panel -> Administrative Tools ->
Active Directory Users and Computers.
b. Open Active Directory Users and Computers in the left-hand tree view
and open the domain (iaseries.local) -> Invensys -> Accounts -> Users ->
Administrators. In the right-hand pane, right-click IADomainAdmin and select
Properties.
436
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
437
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
438
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-5. Active Directory Users and Computers - Connect to Domain Controller
i. Select the domain controller which is to become the new PDC. Click OK.
439
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
440
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-7. Active Directory Users and Computers - Set Operations Masters
441
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
442
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-11. Active Directory Domains and Trusts - Connect to Domain Controller
443
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Figure D-12. Active Directory Domains and Trusts - Selecting Domain Controller to Become
The New PDC
444
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-13. Active Directory Domains and Trusts - Set Operations Masters
445
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
g. Click OK.
NOTE
This procedure can only be completed by a schema administrator. By default, the
only user with schema administrator privileges is the system administrator (i.e., the
user account which is named IAManager at the time the workstation is first
installed).
a. Open a command prompt. From the Start menu, click Programs -> Accesso-
ries -> Command Prompt.
b. In the command prompt, type regsvr32 schmmgmt.dll and press <Enter>.
This will register the Scheme Management DLL.
446
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
d. Open the Run window, type MMC and press <Enter>. This will open the Micro-
soft Management Console.
447
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
4. From Available Snap-ins, select Active Directory Schema and click Add.
448
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
5. Click OK.
449
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
450
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
f. Right-click on Active Directory Schema in the left-hand tree view and select
Change Active Directory Domain Controller.
451
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
h. Right-click on Active Directory Schema in the left-hand tree view and select
Operations Master.
i. Click OK.
452
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
l. Click OK.
453
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Unavailable
PDC is unavailable due to
a hardware or software failure. Primary Domain Secondary Domain
Controller Controller
Unavailable
FSMO roles are seized by the
existing SDC. This server Primary Domain Primary Domain
becomes the Primary Domain Controller Controller
Controller.
NOTE
This is a last-resort measure that should only be taken if the PDC holding the roles
will not be able to be restored. Once you perform this procedure, you will not be
able to bring the PDC back online without first removing its installation of Active
Directory. (This is discussed in a later section.)
To seize the Active Directory roles because the PDC will no longer be available:
1. On the SDC server which will become the PDC, open the Run window, type ntdsu-
til and press <Enter>. This starts the Active Directory Services Maintenance Utility.
454
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
455
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
The full text of the above operation should appear similar to the following in the com-
mand prompt window. Text in bold is the text entered by the user.
C:\Windows\system32\ntdsutil.exe: roles
fsmo maintenance: connections
server connections: connect to server NESRV4.iaseries.local
Binding to NESRV4.iaseries.local ...
Connected to NESRV4.iaseries.local using credentials of locally logged on
user.
server connections: q
fsmo maintenance: seize naming master
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210397, problem
5002 (UNAVAILABLE), data 1722
456
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
457
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
458
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
459
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Unavailable
Primary Domain Controller
(PDC) NESRV5 is unavailable. Primary Domain Primary Domain
NESRV4 has seized FSMO Controller Controller
roles and is the only PDC on
the system.
Disconnected from
I/A Series Network
and Restarted
NESRV5 is physically
disconnected from the Primary Domain Primary Domain
I/A Series network prior Controller Controller
to restarting.
Connected to
I/A Series Network
Active Directory is removed
from NESRV5 and it is No Longer a Primary Domain
reconnected to the I/A Series Domain Controller Controller
network.
Figure D-33. Restoring FSMO Roles to a Primary Domain Controller That Had Its Roles Seized
Alternatively, you can remove and restore the Active Directory by reinstalling the operating system
and I/A Series software on this workstation. (This is a longer and more complicated procedure
than the one described in Figure D-33 but it is a viable alternative.) To accomplish this, com-
pletely reload this workstation from the base Invensys-provided Day 0 workstation image and fol-
low the instructions for installing a secondary domain controller provided in Chapter 4 “Security
Enhanced I/A Series Software v8.8 Installation for Domain Controllers on The MESH Control
Network” or Chapter 5 “Security Enhanced I/A Series Software v8.8 Installation for New Off-
MESH Domain Controllers”. Once this workstation is completely installed as an SDC, follow the
procedure listed below for promoting this workstation to be the PDC while the existing primary
domain controller is still available to be demoted.
460
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Proceed as follows:
1. Start the server up while physically disconnected from the I/A Series network.
2. Click the Start button and select Control Panel -> Administrative Tools ->
Services, stop the Net Logon service.
3. Open the Run window, type dcpromo /forceremoval. Press <Enter>.
4. If this server previously held all five FSMO roles, six warnings will be displayed; one
for each role previously held and one additional warning is displayed for the data held
in Active Directory for the DNS server. Acknowledge each warning as they are dis-
played to continue. See Figure D-35 through Figure D-37.
461
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
462
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
463
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
464
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
6. Click Next.
7. Click OK.
465
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
8. Enter an Administrator account password for the new local Administrator account on
this server. The name of this account will be Administrator which is different from
the account name originally created by the I/A Series installation. This account name
can be changed later through the standard Microsoft dialog boxes. Click Next.
466
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
9. Click Next.
467
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
468
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
14. This workstation must be manually added back onto the domain. Use the IADomain-
Admin account along with the password entered above to log onto the workstation.
15. Click the Start button and select Control Panel -> System. From the System win-
dow, select Advanced system settings from the left-hand pane. Click the Change
button on the System Properties dialog box.
16. Select the Domain radio button and enter the domain name.
17. A dialog box will indicate that the computer has been added to the domain. Click OK.
469
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
18. A dialog box will indicate that the computer must be restarted. Click OK.
20. If this workstation must be reloaded as a primary or secondary domain controller, the
dcpromo utility can be used to reinstall Active Directory. The remaining steps below
describe reloading Active Directory on the failed server.
Open the Run windows, and type dcpromo. Press <Enter>.
470
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
471
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
472
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
23. Select the second radio button indicating that this is an additional domain controller
for an existing domain and click Next.
473
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
474
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
25. Select the forest root domain name and click Next.
475
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
26. Select the site for the new domain controller and click Next.
Figure D-56. Active Directory Installation Wizard - Site for New Domain Controller
476
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-57. Active Directory Installation Wizard - Additional Domain Controller Options
477
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
28. Click No, I will assign static IP addresses to all physical network
adapters.
478
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-60. Active Directory Installation Wizard - Database and Log Folders
479
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Figure D-61. Active Directory Installation Wizard - Restore Mode Administrator Password
480
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
481
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
33. Wait while the wizard configures the Active Directory Domain Services.
482
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
36. Reboot the server and log in with a domain administrator user account.
37. Click the Start button and select Control Panel -> Administrative Tools ->
DNS.
38. Right-click on each forward and reverse lookup zone and select Properties. There
should be three in total.
483
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
39. Check the Allow Zone Transfers checkbox and select the second radio button
choice to allow transfers only to servers listed on the Name Server tab. Click OK.
40. The server may now be restored as a PDC or be left as an SDC station. To make this
server a PDC, refer to “Transferring the Operations Master Roles” on page 436 to
transfer domain controller roles from one domain controller to another.
When you have completed the restoration, verify that the SDC is working properly, as discussed
in the next subsection.
484
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
3. Use this new user account to log onto one of the client workstations.
To test that the SDC is servicing DNS name resolution requests while the backup is offline, pro-
ceed as follows:
1. Open a command prompt on one of the client workstations.
2. With the PDC still connected to the network, type nslookup and press <Enter>.
3. With the PDC still connected to the network, in the command prompt, type
“nslookup <CLIENT2>”, where <CLIENT2> is another client station on the domain.
The IP address of the second client will be retrieved from the primary DNS server
(NESRV5.iaseries.local in this case) to verify that the PDC is no longer available
4. Type “nslookup <CLIENT2> <SDCStationName>” to verify tat the SDC responds to
the DNS request.
485
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
9. In the event that this does not work with the PDC disconnected, it is possible that the
NIC card settings were not made for the SDC when the I/A Series software was
installed. On every workstation, the SDC IP addresses should be configured as sec-
ondary DNS locators. The NIC settings should appear as shown in Figure D-70 for a
client workstation on a system with a primary and one secondary DNS server. These
settings are only necessary for the FoxInt NDIS Intermediate Miniport Drive. In this
case, 151.128.152.205 is for the PDC and 151.128.152.209 is for the SDC.
486
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-70. Typical NIC Settings for a Client Workstation on a System with a Primary and
One Secondary DNS Server
487
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
3. Click Next.
488
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
4. Click OK to the following warning. The SDC is also a Global Catalog provider.
Figure D-73. Active Directory Installation Wizard - Global Catalog Provider Warning
5. Leave un-checked the check box indicating that this is the last domain controller in
the domain. Click Next.
489
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
6. Enter an Administrator account password for the new local Administrator account on
this server. The name of this account will be Administrator which is different from
the account name originally created by the I/A Series installation. This account name
can be changed later through the standard Microsoft dialog boxes. Click Next.
490
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
7. Click Next.
491
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
8. Wait while the wizard configures the Active Directory Domain Services.
492
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Proceed as follows:
1. Click the Start button and select Control Panel -> Administrative Tools ->
Active Directory Users and Computers.
2. Navigate to the Domain Controllers entry in the tree view under the domain
name.
3. Right-click on the domain controller connection in the right-hand pane to remove
and select Delete.
Figure D-79. Active Directory Users and Computers - Delete a Domain Controller Connection
493
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
5. Right-click on the domain controller settings to remove in the left-hand pane and
select Delete.
Figure D-81. Active Directory Users and Computers - Delete a Domain Controller Settings
494
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
Figure D-83. Active Directory Users and Computers - Deleting a Domain Controller
8. Right-click on the server to remove in the left-hand pane and select Delete.
495
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
10. If this workstation is to be added back to the system as a domain client, this worksta-
tion name must be added manually to the list of IA Computers in Active Directory.
Navigate to the IA Computers entry in the tree view under the domain name.
11. Right-click on IA Computers and select New -> Computer.
Figure D-86. Active Directory Users and Computers - Creating New Computer Account
496
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
12. Enter the name of the I/A Series workstation and click OK.
NOTE
These steps are not necessary if there was an SDC present on the I/A Series
network.
497
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
Proceed as follows:
1. Right-click on My Computer in Windows Explorer and select Properties. Click
the Change button on the System Properties dialog box.
498
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
499
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
5. Log in as IADomainAdmin.
6. A dialog box indicates that the computer has been added to the workgroup entered.
Click OK.
7. A dialog box indicates that you will need to restart the station to apply the
changes.Click OK.
500
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
9. Upon closing the System Properties dialog box, click Yes to have the workstation
restarted.
10. After the workstation restarts, log on with the local administrator account credentials.
11. Right-click on My Computer in Windows Explorer and select Properties. Click the
Change button on the System Properties dialog box.
12. Select the Domain radio button and enter the domain name.
501
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
13. When prompted, add the username and password of the account with permission to
join this domain. Click OK when done.
502
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
14. A dialog box indicates that the computer has been added to the domain. Click OK.
Figure D-97. Computer Name Changes Dialog Box - Welcome to the [YourName] Domain
15. A dialog box indicates that the computer must be restarted. Click OK.
Figure D-98. Computer Name Changes Dialog Box - Need to Restart To Apply Changes
503
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
17. Upon closing the System Properties dialog box, click Restart Now to have the
workstation restart.
Figure D-100. Computer Name Changes Dialog Box - Need to Restart To Apply Changes
504
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
505
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
506
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
6. In the Advanced TCP/IP Settings dialog box, select the DNS tab.
This is what the NIC settings should look like for a client workstation on a system
with a primary and one secondary DNS server. These settings are only necessary for
the FoxInt NDIS Intermediate Miniport Driver. In this case, the IP address ending in
84 is for the PDC and the IP address ending in 112 is for the SDC. Add the SDC IP
Address on each station if it is not already present.
507
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
NOTE
It is highly recommended that the following procedures are performed for changing
the tombstone lifetime value. This will help ensure that backups remain current and
usable. A value of a least 180 days is recommended. This should be done before
BESR or Active Directory backups are taken. Also, make sure that the value
changed is replicated to all domain controllers before creating backups.
NOTE
Refer to Appendix E “Guidelines for Using BESR for Backing Up and Restoring
Domain Controllers” for additional information on backups.
! WARNING
Certain Windows Support Tools, if used improperly, might cause your computer to
stop functioning. It is recommended that only experienced users install and use
Windows Support Tools.
In order to perform the following steps, you can use the IADomainAdmin account or you will
need to be a member of the “Enterprise Admins” group.
To view or change attribute values by using ADSI Edit:
1. Click Start, click Run, type ADSIEdit.msc and then click OK.
508
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
509
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
3. From the drop-down menu under “Select a well known naming context”, select
Configuration. Click OK.
510
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
511
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
8. In the CN=Directory Service Properties dialog, scroll down, click the tomb-
stoneLifetime attribute, and click Edit.
9. Configure the tombstone lifetime period (in days), then click OK.
512
Appendix D. Secondary Domain Controllers in an I/A Series System B0700SF – Rev E
In order to verify the value has been set, the following command can be executed in a command
prompt window:
dsquery * "cn=Directory Service,cn=Windows NT,cn=Services,
cn=Configuration,dc=iaseries,dc=local" -scope base -attr tombstonelifetime
If your domain name is not “iaseries.local,” then replace the distinguished name of the domain in
the above command from “dc=iaseries,dc=local” to the actual distinguished name of your domain.
513
B0700SF – Rev E Appendix D. Secondary Domain Controllers in an I/A Series System
514
Appendix E. Guidelines for Using
BESR for Backing Up and Restoring
Domain Controllers
This appendix provides guidelines for using Symantec Backup Exec System Recovery (BESR) to
backup and restore images on domain controllers.
The Symantec Backup Exec System Recovery (BESR) product is used to backup and restore
I/A Series workstations and servers. However, when used with domain controllers (PDC or SDC),
restoring an old image that has Active Directory installed on it is a last resort approach when you
have more than one domain controller. If you have a working domain controller and you need to
restore another domain controller, it is best to reinstall the second domain controller and allow
replication to occur with the good domain controller instead of restoring the second domain con-
troller from a backup image.
The Symantec Backup Exec System Recovery (BESR) product and all procedures for using this
product are described in Symantec System Recovery 2011 Workstation Edition and Server Edition
Guide for I/A Series Workstations (B0700ES).
For normal backups of Active Directory, the best practice is to perform a System State backup and
a group policy backup:
Refer to http://technet.microsoft.com/en-us/magazine/2008.05.adbackup.aspx?pr=blog for
information on performing Active Directory backups.
Use the Group Policy Management Console (GPMC) to perform group policy back-
ups. Click the Start button and select Control Panel -> Administrative Tools -
> Group Policy Management.
In the case of servers that have Active Directory installed on them, i.e., domain controllers, the
following guidelines should be followed if you are forced to restore them from BESR backups.
NOTE
These procedures refer to tools that are part of the Windows Support Tools. If you
have not installed these tools, refer to “Changing the Tombstone Lifetime Attribute
in Active Directory” on page 508.
515
B0700SF – Rev E Appendix E. Guidelines for Using BESR for Backing Up and Restoring Domain Controllers
516
Appendix E. Guidelines for Using BESR for Backing Up and Restoring Domain Controllers B0700SF – Rev E
5. Set the PDC as “authoritative” for SYSVOL. Refer to the “Authoritative FRS restore”
procedure described in the following Microsoft article:
http://support.microsoft.com/kb/290762
6. Boot up the next domain controller (SDC). If this SDC is On-Mesh, restore its BESR
backup image as described in Symantec System Recovery 2011 Workstation Edition and
Server Edition Guide for I/A Series Workstations (B0700ES). If this SDC is Off-Mesh, it
is recommended that the box be reinstalled.
7. After the domain controller is rebooted, if it has been reinstalled, join it to the
domain. In any case, verify it is working properly. See the next section’s instructions
on checking the health of Active Directory.
8. Repeat steps 6 and 7 for each additional domain controller.
517
B0700SF – Rev E Appendix E. Guidelines for Using BESR for Backing Up and Restoring Domain Controllers
518
Appendix F. I/A Series MESH
Configurator
This appendix describes how to use the I/A Series Mesh Configurator for workstations with
Windows 7 and servers with Windows Server 2008 R2 Standard on The Mesh control
network.
The I/A Series Mesh Configurator application installs the COMEX protocol and Redundant
Ethernet Data Link (REDL) virtual adapter, and configures Internet Protocol (IP) addresses for
stations on The Mesh control network. A station can have one or two connections to The Mesh
(if it has one or two switch connections in System Definition).
The Mesh Configurator provides a user interface to select the Network Interface Cards (NICs) for
these connections.
Silent Installation
The Day 0 installer will attempt to configure The Mesh connections automatically. You are not
prompted with a graphical interface if the workstation has:
Two switch connections, and there are exactly two NICs in PCI Slots, or
One switch connection, and there is exactly one NIC in a PCI Slot.
In these cases, The Mesh Configurator selects the NIC(s) in the PCI Slot(s) for The Mesh con-
nections.
519
B0700SF – Rev E Appendix F. I/A Series MESH Configurator
When NIC locations are “Unknown”, you need to manually select the NICs for The Mesh con-
nections. The following procedure is recommended:
1. Disconnect all Ethernet cables except those from The Mesh (and from the Off-Mesh
Domain Controller, if one is in use).
NOTE
Do not assign static IP addresses to the workstation NICs before running The Mesh
Configurator. If the configurator reports an IP conflict, find the adapter with the
duplicate IP address, change it to use DHCP, then run the configurator again.
2. Display the Network Connections from the Start menu -> Network and Sharing
Center -> Change adapter settings (or type “view network connections”
from the Start menu search bar), and set the view to Details.
520
Appendix F. I/A Series MESH Configurator B0700SF – Rev E
3. By default, the columns are not wide enough to display all the necessary information.
Resize the Device Name column so it is wide enough to show the full text:
4. Identify and record the Device Names that do not have a red X next to their icons.
These are the Device Names that should be selected in The Mesh Configurator.
NOTE
Take care not to confuse Names with Device Names. In the above example, the
Allied Telesis adapter 2 is not the same NIC as Local Area Connection 2.
5. If installing with an Off-Mesh Domain Controller, you are prompted to select the
NIC connected to the Domain Controller’s network.
521
B0700SF – Rev E Appendix F. I/A Series MESH Configurator
6. After selecting the NIC for the Off-Mesh Domain Controller (or if installing without
one), you are prompted to select the NIC(s) connected to The Mesh control network.
NOTE
A NIC selected for the Off-Mesh Domain Controller will be removed from the list
of available NICs when selecting The Mesh connection(s).
Unless there is an error or further user interaction is required, The Mesh Configurator exits
silently. If no error message is returned, this indicates a successful installation.
522
Appendix F. I/A Series MESH Configurator B0700SF – Rev E
NOTE
You must run The Mesh Configurator after restoring a workstation image from a
backup created on different hardware (for example, when replacing defective hard-
ware).
Open the configurator from the Start menu -> All Programs -> Invensys -> IASeries ->
Utilities -> Mesh Configurator (or type “mesh configurator” from the Start menu
search bar).
The Mesh Configurator cannot run while The Mesh networking is enabled. If neces-
sary, it will turn off I/A Series and restart the workstation before running.
The Mesh Configurator can only be run by users with administrator credentials.
The configurator remembers the selections made on previous installations. Previously selected
NIC(s) will be checked; you can leave them checked or select new NIC(s). If you originally
installed The Mesh Configurator with an Off-Mesh Domain Controller, it prompts you to select
the NIC connected to the Domain Controller’s network.
NOTE
The Mesh Configurator does not support Post Day 0 Operations on single-NIC
configurations.
523
B0700SF – Rev E Appendix F. I/A Series MESH Configurator
524
Appendix G. IASeries_NIC_Data.m
si Installation (Pre-I/A Series
Installation)
This appendix describes how to acquire and install the IASeries_NIC_Data.msi file, which
replaces the PCIBusSlotAddress.xml file in the Day 0 image.
525
B0700SF – Rev E Appendix G. IASeries_NIC_Data.msi Installation (Pre-I/A Series Installation)
526
Appendix H. SNMP Community
String Configuration
This appendix describes how to configure the SNMP community string for workstations with
Windows 7 and servers with Windows Server 2008 R2 Standard.
SNMP (Simple Network Management Protocol) is an internet protocol used in network manage-
ment systems to monitor network-attached devices such as workstations, servers, routers,
switches, and so forth.
The SNMP community string is a text string that acts as a password to authenticate messages that
are sent between the management software and the device (the SNMP agent). This string must be
configured in two places: the SNMP service (included with the Windows operating system) and
the I/A Series Server Manager configuration file. It should be configured only after the I/A Series
software has been installed on the workstation or server.
NOTE
The community string is case-sensitive and must be identical in both places.
527
B0700SF – Rev E Appendix H. SNMP Community String Configuration
NOTE
Be aware that your community string is case-sensitive.
9. Click Add.
To limit the acceptance of SNMP packets, click the Accept SNMP packets from
these hosts bullet. Click the Add… button, and then type the appropriate host
name, IP address or IPX address in the Host name, IP or IPX address box. You can
restrict the access to the local host (127.0.0.1) or only specific servers by using this set-
ting.
10. Click OK when done.
528
Appendix H. SNMP Community String Configuration B0700SF – Rev E
11. For the settings to take effect, right-click the SNMP service from the Services window.
Stop and then restart the SNMP service.
To configure the I/A Series Server Manager configuration file, proceed as follows:
1. Using Windows Explorer, navigate to the \usr\fox\sysmgm\smat\ folder on the drive
on which the I/A Series software is installed (typically D:\).
2. Open (or create) the text file named: servm.cfg
3. Type the community string using the following format:
default_string: yourcommunitystring
(Type in the same string you used above.)
4. Save the file and then reboot.
For security purposes, it is highly recommended that you do not use a well-known default com-
munity string such as “public.” You should use a string that is compliant with your site’s password
complexity policy.
529
B0700SF – Rev E Appendix H. SNMP Community String Configuration
530
Appendix I. Telnet Installation
This appendix describes how to install the optional application telnet on systems with
Windows 7 or Windows Server 2008 R2 Standard operating systems, if desired.
By default, telnet is not installed on systems with Windows 7 or Windows Server 2008 R2 Stan-
dard operating systems. Telnet is an optional feature and if it is needed, it can be installed manu-
ally as described below.
5. Click OK to close the Windows Features dialog box. The telnet application will be
installed.
To use the telnet application, open a command prompt window and type telnet to start a ses-
sion.
531
B0700SF – Rev E Appendix I. Telnet Installation
532
Appendix I. Telnet Installation B0700SF – Rev E
6. In the Add Features Wizard, scroll down to the Telnet Client checkbox and check the
box next to it, as shown in Figure I-3.
7. When Confirm Installation Selections opens, click Install as shown in Figure I-4.
533
B0700SF – Rev E Appendix I. Telnet Installation
8. A dialog will appear showing the installation progress. When the installation is com-
pleted, click Close.
To use the telnet application, open a command prompt window and type telnet to start a ses-
sion.
534
Appendix J. Printer Sharing
This appendix describes how to enable sharing to printers on stations with Windows 7 or
Windows Server 2008 R2 Standard operating systems, if desired.
As with previous Microsoft operating systems, Windows 7 and Windows Server 2008 R2 Stan-
dard allow a printer to be shared by multiple stations.
However, to do this, Microsoft requires that the Windows Firewall service be enabled.
NOTE
Enabling this service does not require the Microsoft Windows Firewall to be used.
For I/A Series workstations and servers, Invensys provides the McAfee
configurable firewall as the preferred firewall and recommends that the Microsoft
Windows Firewall not be used.
535
B0700SF – Rev E Appendix J. Printer Sharing
Sharing a Printer
To share a printer hosted by a workstation with Windows 7 or Windows Server 2008 R2 Stan-
dard, proceed as follows:
1. Click the Start button, and click Devices and Printers.
2. Right-click the icon of the printer that is to be shared and select Printer
properties.
3. In the Properties dialog box, click the Sharing tab.
4. Click the Change Sharing Options button if it is displayed as shown in Figure J-2.
536
Appendix J. Printer Sharing B0700SF – Rev E
5. Check the “Share this printer” checkbox and type in a Share name.
6. If this printer will be shared with a station that has a 32-bit OS (such as an x86 version
of Windows XP), install additional drivers (before setting up the station with
Windows XP) by clicking the Additional Drivers… button and then by checking
the x86 checkbox.
Otherwise, click OK. If you see the following error, the Windows Firewall service has
not been turned on as described in the previous section: “Operation could not be
completed (Error 0x000006D9)”
537
B0700SF – Rev E Appendix J. Printer Sharing
538
Appendix K. Troubleshooting
This appendix provides troubleshooting procedures.
539
B0700SF – Rev E Appendix K. Troubleshooting
540
Appendix K. Troubleshooting B0700SF – Rev E
3. In the Computer Configuration Properties dialog box, select the Error Informa-
tion tab to view the errors for this policy set. The error shown in Figure K-3 indicates
that the time does not match the time on the domain controller: “The clocks on the
client and server machine are skewed.”
4. If the error shown in Figure K-3 is found on your system, fix the time on the SDC or
domain client as described in the “Server Preparation” of the appropriate chapter for
your station in this document and reboot. After rebooting, the software installation
may be restarted by running Setup.exe on the installation DVD.
Accept the UAC request in order to start the installation.
541
Invensys Systems, Inc.
38 Neponset Avenue
Foxborough, MA 02035-2037
United States of America
www.schneider-electric.com