B-1
Installation Guide for Cisco Secure ACS Solution Engine 4.1
OL-9969-03
A P P E N D I X
B
Windows Service Advisement
The operating system for the Cisco Secure ACS Solution Engine (ACS SE) is a customized and
minimized version of the Windows 2000 operating system. The ACS SE removes all extraneous services,
blocks all unused ports, and otherwise prevents all other access to the ACS server system, thereby
dramatically increasing the security posture of ACS.
The following sections present details regarding the minimization of the operating system’s services:
•
Services That are Run, page B-1
•
Services That Are Not Run, page B-2
Services That are Run
Table B-1
lists the services that are run on the ACS SE.
Table B-1
Operating System Services Automatically Run by ACS SE
Service Name
Description
COM+ Event System
Provides automatic distribution of events to subscribing COM
components.
DHCP Client
Manages network configuration by registering and updating IP
addresses and DNS names.
DNS Client
Resolves and caches Domain Name System (DNS) names.
Event Log
Logs event messages issued by programs and Windows. Event Log
reports contain information that can be useful in diagnosing
problems. Reports are viewed in Event Viewer.
IPSEC Policy Agent
Manages IP security policy and starts the ISAKMP/Oakley (IKE)
and the IP security driver.
License Logging Service
Tracks Client Access License usage for a server product.
Logical Disk Manager
Performs the Logical Disk Manager Watchdog Service.
Network Connections
Manages objects in the Network and Dial-Up Connections folder, in
which you can view local area network and remote connections.
Plug and Play
Manages device installation and configuration and notifies
programs of device changes.