Server 2008 Setup for CCIE Security

Server 2008 Setup for CCIE Security

Here is where we will setup our Server 2008 Installation for use with ISE and to complete a whole ton of Cisco ISE labs!

I think I stress this all the time throughout these studies.... But MAKE SURE YOUR TIMES ARE CORRECT ON YOUR EQUIPMENT! ISE hates incorrect times. Be punctual when dealing with ISE!

No alt text provided for this image

Next we are going to take a look at our Networking. I set some basic settings as I use this server for NTP, DNS, and Other services. Your network settings will be per your own environment.

No alt text provided for this image

As we progress we are going to want to change the computer name. By default it is going to be a random string, which is a Pain in the butt to remember when labbing. I am going to simply set this as AD01 for this lab purpose.

No alt text provided for this image

Now that we have a user friendly computer name we can move forward with adding some roles. Let's make this server our Domain Controller.

No alt text provided for this image

Once you install the domain controller, the computer is most likely going to want to reboot. For the most part (as you see below) you can click through most of the default settings.

No alt text provided for this image

To avoid having to even navigate through the windows you can just type dcpromo.exe into your command prompt/start window.

No alt text provided for this image

Server 2008 will prompt you to set DNS Server at this point as well:

No alt text provided for this image

Set your forest name:

No alt text provided for this image

Set Your Netbios Name

No alt text provided for this image

Once you go through this you are going to want to reboot:

No alt text provided for this image

Once the reboot comes up you should be logging into your new domain:

No alt text provided for this image

Now it is time to set up some certificate fun! Certificates are vital to the deployment of ISE.

A crucial step is to set a user into the IIS_IUSRS group. I will do this with my administrator account. I will navigate to server manager and Active Directory Users and Computers. I am going to make my administrators member of the IIS_IUSRS group.

No alt text provided for this image

Now that we have this administrative task completed we need to navigate back to add roles within the server manager. We will then select to add the Active Directory Certificate Services.

No alt text provided for this image

I am going to install this using the Enterprise settings, and as a Root CA. I will also choose to Create a New Private Key. For the purpose of this lab I will go with default settings. If you want to educate yourselves on some best practices, I'd suggest the following for some good ol fashioned research: https://blogs.technet.microsoft.com/pki/2012/04/27/best-practice-for-configuring-certificate-template-cryptography/

No alt text provided for this image

For the remainder of the settings I will click Next Next Next and finally Hit install.

Lets do web enrollment Services:

No alt text provided for this image

This next step is where you choose that user we added to the IIS group earlier! I am just using my administrator account.

No alt text provided for this image

Pick your cert for SSL:

No alt text provided for this image

Once you install: Close the Window:

I know none of this was exciting: But it is necessary for us to lay the ground work for our really exciting ISE labbing. The good stuff comes later! PXGRID, TRUSTSEC, PROFILING!

And finally: The legal jargon:

Though I work on-site at Cisco Systems, The Opinions Expressed In This Post Are My Own And Not Necessarily Those Of My Employer.

The postings on this site are my own and do not necessarily represent the postings, strategies or opinions of Cisco Systems.

And if you find any errors please comment, so that I can make edits. Ultimately these guides are here for people to follow along. Many network engineers studying for a CCIE exam may be VERY familiar with NGFW and VPN, but may need assistance with ISE or other technologies. I take great pride in sharing these examples, and would like for them to be as accurate as I can.

?






要查看或添加评论,请登录

Nic C.的更多文章

  • The ART of MENTORSHIP.

    The ART of MENTORSHIP.

    If you've known me for more than 7 minutes it would be impossible that you have not heard me state "Attitude Reflects…

    5 条评论
  • How work from home impacted my Engineering Confidence.

    How work from home impacted my Engineering Confidence.

    Wow, almost a month into Cisco's work from home mandate. Phew, we either sigh with relief, or groan and wonder how much…

    2 条评论
  • Almost to a Year. . . The Cisco Journey

    Almost to a Year. . . The Cisco Journey

    I arrived at Cisco almost a year ago. With the current state of affairs have so many things up in the air, I wanted to…

  • Cisco AnyConnect Performance Can you Achieve Maximum Performance?

    Cisco AnyConnect Performance Can you Achieve Maximum Performance?

    Tips: For best performance a user should be using DTLS v1.2 or IKEv2: This will result in the best performance…

    1 条评论
  • Topic of the DAY the MAC attack!

    Topic of the DAY the MAC attack!

    Media Access Control (MAC) attack: This attack revolves around CAM table overflow. Content Addressable Memory, (CAM)…

  • Initial Boot Strap for ISE ISE Babay!

    Initial Boot Strap for ISE ISE Babay!

    As my study guide here is geared towards the CCIE and my studies..

  • MY Path to CCIE Security

    MY Path to CCIE Security

    Today is the day and age of Social Media and Free Knowledge: I can learn to change my truck brakes on YouTube, make…

    3 条评论
  • A lot can happen in 10 years. . .

    A lot can happen in 10 years. . .

    10 years ago I was early into my second combat deployment based out of Taqaddum Air Base, Iraq. On this day September…

    11 条评论
  • Why you should hire a Gordie Howe

    Why you should hire a Gordie Howe

    Sad News. Gordie Howe has passed away.

    4 条评论
  • Memorial Day 2016-Personal Thoughts

    Memorial Day 2016-Personal Thoughts

    Every year Memorial day seems to get easier. Maybe it's the skills I learn in which to handle the wave and flood of…

    1 条评论

社区洞察

其他会员也浏览了