System 800xA Installation, Update and Upgrade Getting Started System Version 6.0 Power and productivity for a better world™ System 800xA Installation, Update and Upgrade Getting Started System Version 6.0 NOTICE This document contains information about one or more ABB products and may include a description of or a reference to one or more standards that may be generally relevant to the ABB products. The presence of any such description of a standard or reference to a standard is not a representation that all of the ABB products referenced in this document support all of the features of the described or referenced standard. In order to determine the specific features supported by a particular ABB product, the reader should consult the product specifications for the particular ABB product. ABB may have one or more patents or pending patent applications protecting the intellectual property in the ABB products described in this document. The information in this document is subject to change without notice and should not be construed as a commitment by ABB. ABB assumes no responsibility for any errors that may appear in this document. Products described or referenced in this document are designed to be connected, and to communicate information and data via a secure network. It is the sole responsibility of the system/product owner to provide and continuously ensure a secure connection between the product and the system network and/or any other networks that may be connected. The system/product owners must establish and maintain appropriate measures, including, but not limited to, the installation of firewalls, application of authentication measures, encryption of data, installation of antivirus programs, and so on, to protect the system, its products and networks, against security breaches, unauthorized access, interference, intrusion, leakage, and/or theft of data or information. ABB verifies the function of released products and updates. However system/product owners are ultimately responsible to ensure that any system update (including but not limited to code changes, configuration file changes, third-party software updates or patches, hardware change out, and so on) is compatible with the security measures implemented. The system/product owners must verify that the system and associated products function as expected in the environment they are deployed. In no event shall ABB be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, nor shall ABB be liable for incidental or consequential damages arising from use of any software or hardware described in this document. This document and parts thereof must not be reproduced or copied without written permission from ABB, and the contents thereof must not be imparted to a third party nor used for any unauthorized purpose. The software or hardware described in this document is furnished under a license and may be used, copied, or disclosed only in accordance with the terms of such license. This product meets the requirements specified in EMC Directive 2004/108/EC and in Low Voltage Directive 2006/95/EC. TRADEMARKS Copyright © 2003-2016 by ABB. All rights reserved. Release: Document number: January 2016 2PAA111708-600 F Table of Contents About this User Manual User Manual Conventions .................................................................................................9 Warning, Caution, Information, and Tip Icons ......................................................9 Terminology .........................................................................................................11 Section 1 - Introduction System Security ...............................................................................................................13 System 800xA media for Software Distribution .............................................................14 Accessing the System 800xA software on a virtual machine ..............................14 Mapping the System 800xA media using a network share ..................................15 System 800xA Installation Workflow .............................................................................16 Prepare .............................................................................................................16 Setup .............................................................................................................17 Configure .............................................................................................................18 System 800xA Update Workflow ....................................................................................18 System 800xA Upgrade Workflow..................................................................................19 Section 2 - System 800xA Installation Overview..........................................................................................................................21 System Functions and Node Types ......................................................................21 Node Preparation Tool .........................................................................................22 System Configuration Console.............................................................................22 Installation Process...............................................................................................23 Preparing the node ...........................................................................................................25 Creating a system ............................................................................................................27 Selecting System Functions.............................................................................................27 2PAA111708-600 F 5 Table of Contents Adding Nodes to the System........................................................................................... 28 Allocating Functions to Nodes........................................................................................ 29 Making Nodes Redundant............................................................................................... 30 Deploying the System ..................................................................................................... 31 Installing the .NET hotfix .................................................................................... 31 Maintenance .................................................................................................................... 31 Expanding the System ......................................................................................... 31 Repairing the Local Media Repository (LMR).................................................... 33 Excluding a node ................................................................................................. 33 Replacing a node.................................................................................................. 34 Removing Nodes from the System ...................................................................... 35 Renaming a node ................................................................................................. 35 Section 3 - System 800xA Update Section 4 - System 800xA Upgrade Appendix A - Prerequisites Windows Operating System ............................................................................................ 41 Selecting the Windows Operating System........................................................... 41 Considerations for Disks and File System ........................................................... 42 Windows Installation Guidelines ......................................................................... 44 Windows Operating System Updates................................................................... 45 Configuring Network Adapters ................................................................................... 45 Configuring Domain Controller and DNS Server........................................................... 48 Adding Nodes to a Domain ................................................................................. 54 Configuring Users and Groups........................................................................................ 55 New Organizational Unit ..................................................................................... 59 Groups ............................................................................................................ 59 Users, Groups, and Rights Assignments.............................................................. 60 800xA Service User .................................................................................... 64 User Account for Installation ........................................................................... 66 Other Users .......................................................................................................... 66 6 2PAA111708-600 F Table of Contents Adding 800xA Domain Users to the Local Administrator Group .......................67 Operating System Setup Use with 800xA System ......................................................68 Regional and Language Options ..........................................................................69 Enable Write Caching on Hard Disks ..................................................................70 Internet Explorer Enhanced Security ...................................................................71 Internet Security Settings for Digital Signature Validation..................................71 Disable Web Browser Popup Blocker ..................................................................72 Disable Show Window Contents While Dragging ...............................................72 Energy Saver and Screen Saver Configuration ....................................................72 Virus Scanning Configuration During Installation and Post Installation .........73 Windows Update Configuration...........................................................................73 Enable the Change Sharing Options for Different Network Profiles ...................73 Disable Server Manager Startup ..........................................................................74 Hot fix for redundancy with IPSec enabled .........................................................74 Set Date and Time for Batch Servers ...................................................................74 Disable ISATAP Setting .......................................................................................75 Group Policy Management...................................................................................75 Adding Privileges to the 800xA Service User......................................................79 Remote (Thin) Client for the Server Operating System.......................................79 Other Third Party Software .............................................................................................80 Microsoft Office Professional ..........................................................................80 Microsoft Word ................................................................................................81 Microsoft Excel ...........................................................................................82 Crystal Reports.....................................................................................................83 Autocad Integration..............................................................................................84 McAfee Integration ..............................................................................................84 Symantec .............................................................................................................85 Bulk SPL Template ..............................................................................................85 Process Engineering Tool Integration Specific Requirements .............................86 Backup Software ..................................................................................................86 Appendix B - Installation and Configuration Parameters Acquiring Installation and Configuration Parameters .....................................................87 2PAA111708-600 F 7 Table of Contents Appendix C - Related Documentation Revision History Index 8 2PAA111708-600 F About this User Manual User Manual Conventions About this User Manual Any security measures described in this user manual, for example, for user access, password security, network security, firewalls, virus protection, and so on, represent possible steps that a user of an 800xA System may want to consider based on a risk assessment for a particular application and installation. This risk assessment, as well as the proper implementation, configuration, installation, operation, administration, and maintenance of all relevant security related equipment, software, and procedures, are the responsibility of the user of the 800xA System. This user manual is intended to guide a user to install, update or upgrade System 800xA.The main purpose of this manual is to guide the user with the workflow for the different phases in installation, update and upgrade of System 800xA. Unless otherwise noted, the versions of all 800xA Base System and Functional Area software described in this user manual are the latest release of 800xA 6.0. Refer Appendix C, Related Documentation for information on site planning, engineering planning, software configuration, network design, security measures, tools, maintenance, and so on that can be found in other 800xA User Manuals. User Manual Conventions Microsoft Windows conventions as defined in the Microsoft Manual of Style are normally used for the standard presentation of material when entering text, key sequences, prompts, messages, menu items, screen elements, and so on. Warning, Caution, Information, and Tip Icons This user manual includes Warning, Caution, and Information where appropriate to point out safety related or other important information. It also includes Tip to 2PAA111708-600 F 9 Warning, Caution, Information, and Tip Icons About this User Manual point out useful hints to the reader. The corresponding symbols should be interpreted as follows: Electrical warning icon indicates the presence of a hazard which could result in electrical shock. Warning icon indicates the presence of a hazard which could result in personal injury. Caution icon indicates important information or warning related to the concept discussed in the text. It might indicate the presence of a hazard which could result in corruption of software or damage to equipment/property. Information icon alerts the reader to pertinent facts and conditions. Tip icon indicates advice on, for example, how to design your project or how to use a certain function. Although Warning hazards are related to personal injury, and Caution hazards are associated with equipment or property damage, it should be understood that operation of damaged equipment could, under certain operational conditions, result in degraded process performance leading to personal injury or death. Therefore, fully comply with all Warning and Caution notices. 10 2PAA111708-600 F About this User Manual Terminology Terminology A complete and comprehensive list of terms is included in System 800xA System Guide Functional Description (3BSE038018*). The listing includes terms and definitions that apply to the 800xA System where the usage is different from commonly accepted industry standard definitions and definitions given in standard dictionaries such as Webster’s Dictionary of Computer Terms. Term/Acronym Description Media The source containing the complete set of 800xA installation files. Node Preparation Tool (NPT) A tool used to prepare a computer before it can be configured to be a node in an 800xA system. It checks system requirements and places the installation media files on a local disk. It also installs and starts the System Installer Agent on the computer. System System is defined as a collection of one or more system functions. System Functions System functions define the capability of the system. Node Functions Node functions determine the functions that will installed on the nodes in the System. System Installer Agent (Agent) A local service on a computer that installs and configures software from the installation file copied to the local drive by given commands. Installation Installation of core packages copied to the local drive. A package is still not active, after installation; it requires configuration before use. Configuration Configuration of installed core products and of “on demand” products from the installation files copied to the local drive. A product is activated and is ready for use after configuration. Deploy A function to deploy the system or node functions to the nodes using the agent in each node. 2PAA111708-600 F 11 Terminology 12 About this User Manual 2PAA111708-600 F Section 1 Introduction System Security Section 1 Introduction The latest version of this manual is available in ABBSolutions Bank. This document reflects 800xA System and Functional Area software at the time of release. All 800xA System and Functional Area Release Notes must be read and understood before performing any installation, update and upgrade procedures. The Release Notes contain any last minute changes that have to be performed when installing or upgrading the 800xA System. All Release Notes can be found on the System 800xA Media System Version 6.0 Released Documents. The System 800xA Installation, Update and Upgrade Getting Started manual provides information and instructions about: Use • Phases and workflows associated with the installation, update and upgrade processes for System 800xA • Prerequisites for an installation Use the System 800xA 6.0 System Planning (3BSE041389*) document to help plan the requirements, both hardware and software, for the 800xA System. For information on planning for Node and System Function refer the System 800xA 6.0 System Guide Technical Data and Configuration (3BSE041434*) and System 800xA System Guide Functional Description (3BSE038018*). System Security It is very important to have a corporate security policy that is revised on a regular basis. This is the responsibility of the user of the 800xA System. Refer the System 800xA Administration and Security (3BSE037410*), System 800xA Network Configuration (3BSE034463*), and System 800xA System Planning 2PAA111708-600 F 13 System 800xA media for Software Distribution Section 1 Introduction (3BSE041389*) documents for more information on system security, users, user groups, roles and permissions. System 800xA media for Software Distribution The 800xA media is distributed either on physical media, or via software download, depending on the use case. The physical media is a secure and tamper proof Solid State Drive (SSD). The SSD is a read-only device ensuring that the content is secure and tamper proof. A software download means receiving one or more zip-files which have to be un-packaged and stored locally as described in Readme file included in the media. Table 1. System 800xA media for software distribution What does it consist of... SSD Full software package When can it be used... Installation Upgrade Where can I find it... Physical, can be ordered. Update Software download Update software package Update ABB SolutionsBank Accessing the System 800xA software on a virtual machine System 800xA software can be mapped into multiple Virtual Machines on a single server. Perform the following settings to access the System 800xA software on a virtual machine: 14 1. Connect the Solid State Drive to the virtual machine host. 2. Open Settings on the virtual machine. 3. Add... the SCSI device. 4. Select CD/DVD SMI or CD/DVD Generic in the Connection tab of the SCSI device. 5. Click Next and then Finish to complete the mapping. 2PAA111708-600 F Section 1 Introduction Mapping the System 800xA media using a network share Mapping the System 800xA media using a network share When a new installation is carried out using the Update media, the user is prompted with the location of the media used for System 800xA 6.0.The user should not browse to the mapped drives on the local node. Instead, the user should browse to the remote node where the media share is available and copy the complete path of the shared folder. To map the media on the network share: 1. Share the location of the media on the remote node. 2. Copy and paste the complete path of the shared folder, for example \\machinename\sharedfolder, in the Node Preparation Tool (NPT). Update media is available in ABB SolutionsBank. 2PAA111708-600 F 15 System 800xA Installation Workflow Section 1 Introduction System 800xA Installation Workflow The System 800xA installation is carried out in three phases as shown in Figure 1 : Figure 1. System 800xA Installation Workflow Prepare The main purpose of this phase is to configure a node to be a 800xA node. Use the System 800xA 6.0 System Guide Technical Data and Configuration (3BSE041434*), and System 800xA 6.0 System Planning (3BSE041389*) documents to plan the hardware and software requirements for an 800xA Node. A node must comply with the hardware and Operating System requirements to be configured as an 800xA node. The following tasks are carried out in the prepare phase: 16 1. Selecting, and installing the Windows Operating System 2. Configuring Network Adapters 3. Configuring Domain Controller and DNS Server 4. Configuring Users and Groups 5. Operating System Setup Use with 800xA System 6. Setting up the Other Third Party Software 2PAA111708-600 F Section 1 Introduction 7. Setup Preparing the node using the Node Preparation Tool (NPT) These procedures remain the same for any node selected to be configured as a 800xA node. Please see the Industrial IT Certification home page for a complete and up to date list of certified computers: http://www.abb.com/product/us/9AAC171278.aspx Note that the certification itself is performed towards one or more specific versions of System 800xA. Setup This phase ensures that the nodes prepared to be 800xA nodes are configured with the correct Node Functions in System 800xA. Select from the list of System Functions applicable to the system and the Node Functions intended to run on the individual nodes to setup the system. Deploying the System installs the required 800xA software on all the nodes in a centralized approach where the overall progress is indicated on Aspect Server. The system configuration information including system functions, nodes and associated node functions, node function properties and so on are stored in the Aspect Directory. This enables and ensures smooth updates and upgrades of the installed system. Do not install System 800xA software product manually. This will cause inconsistencies in the information stored in the aspect directory which will lead to unforeseen consequences in future maintenance of the system. The following tasks are carried out in the setup phase: • Creating a system • Selecting System Functions • Adding Nodes to the System • Allocating Functions to Nodes • Making Nodes Redundant 2PAA111708-600 F 17 Configure Section 1 Introduction Configure Most of the post installation configuration of the system and node functions is done before the system is deployed. However, there are post installation configuration steps that are not automated. Refer the System 800xA 6.0 Post Installation (2PAA111693*) manual along with the product specific configuration manuals to carry out the configurations. Refer the Product Specific configuration manual for specific configurations related to specific functions and features.This phase deals with configuring the 800xA Base System and Functional Areas. The system is now ready for application engineering. System 800xA Update Workflow System 800xA updates are released either with new features or problem corrections or both. The Update function in the System configuration console shall be used to update an already installed system. The three phase for a System 800xA Update are as shown in Figure 2 Figure 2. System 800xA Update Workflow To update the System 800xA: 18 1. Prepare the nodes on the system to install the updates by running the Node Preparation Tool (NPT). 2. Distribute the update media using either the: a. Centralized distribution method b. Manual distribution method 2PAA111708-600 F Section 1 Introduction 3. System 800xA Upgrade Workflow Load and deploy the update using the System Configuration Console (SCC). System 800xA Upgrade Workflow An upgrade to System 800xA 6.0 can be executed by using the System Installer function in System 800xA 6.0. Figure 3 shows the Overview of the Upgrade. Figure 3. Upgrading System 800xA - Overview To upgrade to System 800xA 6.0: 1. 2. 2PAA111708-600 F Plan the system upgrade taking into consideration the: – PC Hardware Compatibility – Third party software requirements – Decide if the upgrade is to be done Online or Offline – Ensure time synchronization for all the nodes on the system – Plan to migrate the Visual Basic Process Graphics (VBPG) to Process Graphics (PG2) Prepare the system being upgraded to include: – Migrate all VBPG to PG2 – Carry out product wise pre-upgrade procedures – Identify the Node and System Functions – Complete the 800xA Maintenance backup 19 System 800xA Upgrade Workflow – Section 1 Introduction Move the files to a safe location 3. Prepare and deploy the software based on the upgrade strategy (Online/Offline) selected. 4. Configure the system and node functions based on product- wise post-upgrade procedures Please refer the Considerations and Upgrade Flow included in the System 800xA 5.1 to 6.0. Upgrade (2PAA111694*) and System 800xA 5.0 SP2 to 6.0 Upgrade (2PAA111695*) manuals for more information. 20 2PAA111708-600 F Section 2 System 800xA Installation Overview Section 2 System 800xA Installation Before proceeding with this chapter, make sure that all prerequisites required to configure an 800xA System are completed, refer Appendix A, Prerequisites. Overview System 800xA installation includes the following: • • • System planning Centralized and automated software installation and configuration System deployment The System 800xA 6.0 is installed with minimal user interaction. It automates the installation and configuration (adding of Nodes, adding of System Functions and allocating functions to nodes) of an existing 800xA System. The configuration of all nodes in the system can be done from one place, except for the preparation of nodes which is done at each node. System Functions and Node Types System Functions define the capability of the System. Functions allocated to the nodes describe the intended functional behavior and use of a node. The selection of the System Functions determines the functions available for allocation and deploy of the nodes. The Node Types determine the main use of an 800xA system node as a: • Server • Client • Combined client and server node System 800xA supports optional redundant server configurations to increase the uptime and eliminate loss of data. The switchover functionality is one of the key 2PAA111708-600 F 21 Node Preparation Tool Section 2 System 800xA Installation features of redundancy and parallel servers. If the service with which a client application is communicating fails, or if the whole server node where the service is running fails, the client node will connect to a redundant service on the redundant server node. For more on node redundancy refer System 800xA 6.0 System Guide Technical Data and Configuration (3BSE041434*). Node Preparation Tool The Node Preparation Tool (NPT) copies the installation files to the local drive on the computer and installs the 800xA Base Software. Thus preparing the node for deployment of an 800xA System. System Configuration Console The System Configuration Console (SCC) helps the user create and deploy a System or expand an existing System 800xA 6.0 by using the following tasks: 22 • Create a System task: creates a System on the Primary Aspect Server node and making the node ready for a System deploy. • Configure System task: helps with the configuration and installation of the system functions and the functions allocated to the nodes by: – Allocating the functions to the System and the nodes and clicking Apply to save the configuration – Deploying individual or all nodes in a system via the Deploy or the Deploy System button respectively – Expanding an existing System – Excluding a node – Replacing a node – Adding and/or removing a node – Importing and exporting of configurations. This saves information about nodes, configured functions and so on to a text file that can be used for configuring other systems – Updating the system 2PAA111708-600 F Section 2 System 800xA Installation – Installation Process Viewing the task logs and collecting diagnostics data from all system nodes using the View task log and Diagnostics buttons respectively The Configure System task creates and configures aspects and objects in the system. Modifying these aspects and objects manually is not allowed and might cause inconsistencies in the system. Launch the SCC as the 800xA Installing User from the: ABB Start Menu >ABB IndustrialIT > System. Installation Process The process to be followed for installation of System 800xA is: 1. Preparing the node on page 25 2. Creating a system on page 27 3. Selecting System Functions on page 27 4. Adding Nodes to the System on page 28 2PAA111708-600 F 23 Installation Process 24 Section 2 System 800xA Installation 5. Allocating Functions to Nodes on page 29 6. Making Nodes Redundant on page 30 7. Deploying the System on page 31 2PAA111708-600 F Section 2 System 800xA Installation Preparing the node Preparing the node Prerequisites to launch the NPT tool The node is prepared and configured as per the information provided in Appendix A, Prerequisites. To prepare the node with NPT: Launch the preparation tool by starting the 'Setup.exe' from the root level of the installation media. Click on the Install Adobe Reader in NPT to install the Adobe PDF reader. 2PAA111708-600 F 25 Preparing the node Section 2 System 800xA Installation Figure 4. Node Preparation Tool (NPT) Follow the instructions provided in the tool to complete the node preparation process. The system reboots when the 800xA Base System installation is complete. Wait until all the core products are installed before proceeding with any additional installations. 26 2PAA111708-600 F Section 2 System 800xA Installation Creating a system Creating a system The purpose of creating a system is to create a framework where functions can be allocated to the System and the nodes. It allows to plan, deploy and configure a system. A system is created using the System Configuration Console (SCC) on the Primary Aspect Server. Refer the System 800xA System Guide Functional Description (3BSE038018*) to understand the node and/or system functions to be combined in a system. To know more about the licensing information associated with the System refer the System 800xA 6.0 Licensing Information (2PAA111691*). Selecting System Functions Select the System functions that will be a part of the System using the Configure System task in the SCC as shown in Figure 5. These System Functions will determine the functionality in the system, the functions allocated to the nodes and available for the configuration. System Functions cannot be removed once they are deployed. 2PAA111708-600 F 27 Adding Nodes to the System Section 2 System 800xA Installation Figure 5. Selecting the System Functions Adding Nodes to the System Adding a node to the system makes it possible to allocate functions to the node and deploy. Use System nodes tab of the Configure System task in the SCC to add a 28 2PAA111708-600 F Section 2 System 800xA Installation Allocating Functions to Nodes node and allocate the functions to the node. To deploy a node ensure that the status of the node is shown as Connected in the System nodes tab. Allocating Functions to Nodes Before deploying nodes to a System they should be allocated with the required functions that define the role they play in a System. Figure 6. Allocating functions to the node To allocate functions to nodes: Select the node in the System nodes tab and click Allocate functions to select and allocate the node functions. Provide any additional node level information needed 2PAA111708-600 F 29 Making Nodes Redundant Section 2 System 800xA Installation for the specific function and click Apply to save the system configuration as shown in Figure 6. A function allocated to a node cannot be removed once the node is deployed. Refer the System 800xA 6.0 System Guide Technical Data and Configuration (3BSE041434*) to know and plan the number of nodes and the functions that can be deployed. Making Nodes Redundant To make a node redundant, first select the node to be made redundant. Then use the Make Redundant function and select the functions that should be made redundant. If new functions are allocated to any of the nodes that have been made redundant. Ensure that the new functions are made redundant as well, to achieve complete node redundancy. Figure 7. Making a node redundant 30 2PAA111708-600 F Section 2 System 800xA Installation Deploying the System Deploying the System Deploying a System involves deploying of allocated System functions and functions to nodes which makes the System ready for Engineering and Configuration. Refer System 800xA 6.0 Post Installation (2PAA111693*) to carry out any further configuration of the system. During deploy to minimize the licensing related warnings the Central Licensing System function should be deployed first, followed by loading of the available 800xA license files. The node where the SCC is run might be rebooted during deployment. Ensure to login again with the same user credentials and accept the UAC prompt to continue the deployment. If the UAC prompt is not acknowledged on time the pop up will disappear and SCC will not be launched. In such cases, launch the SCC from the ABB Start menu to continue the deploy. The Configure System task supports exclusion of nodes at the time of deploy. Installing the .NET hotfix The workplace process will leak one handle each time a Graphic Display is closed in the Operator Workplace. This handle leak is caused due a Microsoft process and can be resolved by installing the Microsoft .NET 4.5.2 hotfix. To install the .NET4.5.2 hotfix: 1. Go to 3rd_Party_SW\Microsoft\Hotfix for .Net Framework 4.5.2 in the 800xA Media. 2. Double click 482239_intl_x64_zip.exe file and extract to a shared location. 3. Run the NDP452-KB3026376-x86-x64-AllOSENU.exe on all nodes to install the hotfix. Maintenance Expanding the System Expansion of a System is supported both at the node level and the System Function Level. This means an expansion based on System Size and/or functions. 2PAA111708-600 F 31 Expanding the System Section 2 System 800xA Installation Expansion based on Nodes can be done using the System nodes tab of the Configure System task. To expand a system by adding new nodes: 1. Prepare and configure the node according to the instructions in Appendix A, Prerequisites. 1. Launch the preparation tool by starting the 'Setup.exe' from the root level of the installation media. 2. Go to Configure System > System nodes and click Add node.... 3. Enter the node name and select the node type. 4. Go to System functions tab, click Edit functions and add the required system functions. 5. In the System nodes tab, click Allocate functions to select and allocate the application and service functions to the node. 6. Click Apply to save the configuration or go to Node actions... and click Deploy. Deploying the system might cause the nodes to be rebooted based on the functions selected. Expansion based on the 800xA products can be done by allocating new functions to the System and the nodes. To expand the nodes by adding new system functions to the existing nodes: 1. Go to System functions tab, click Edit functions and add the required system functions. 2. In the System nodes tab, click Allocate functions to select and allocate the application and service functions to the node. 3. Click Apply to save the configuration or go to Node actions... and click Deploy. Deploying the system might cause the nodes to be rebooted based on the functions selected. f 32 Ensure that there are no reserved entities in a system before deploying the system with new System functions. Use the Find Tool to identify the reserved entities and release them. Refer System 800xA Operations 6.0 Operator Workplace Configuration (3BSE030322*) manual for more information. 2PAA111708-600 F Section 2 System 800xA Installation Repairing the Local Media Repository (LMR) Repairing the Local Media Repository (LMR) System 800xA allows the user to repair the LMR to include other installation types by: 1. Navigate to ...\Tools\System Installer\Node Preparation Tool and open the command prompt. 2. Enter the command " ABB Node Preparation Tool.exe /Repair" in the prompt and press Enter 3. Select any new options for extending the node or just start the node preparation for repairing the LMR without modifying the installation types. While repairing the LMR all the previously selected options will be deselected in the NPT. Ensure to reselect any previously selected options and/or select the new options. 4. The content applicable for the selected Installation Type option will be copied to LMR. Excluding a node It might be needed to exclude a node or nodes from being deployed either because: • it is disconnected from the system • is in an error state • the user does not want to deploy on a particular node. It is possible to exclude the erroneous node and continue the system deploy process. A node can be excluded only if it is not already deployed. It is highly recommended to include all the nodes for a system to be fully deployed. Excluding a node before deploy To exclude a node before initiating the deploy phase: 1. 2PAA111708-600 F Go to the Node functions tab in the SCC. 33 Replacing a node Section 2 System 800xA Installation 2. Select the node to be excluded and click on Exclusions... in the Node actions... button. 3. Follow the screen prompts to complete the node exclusion. Once the excluded node is available, it can be deployed at a later stage by the user. Excluding a node during deploy A node might have to be excluded during the deploy phase if the node has failed. To exclude a node during the deploy phase: 1. Abort the deploy. 2. Go to the Node functions tab in the SCC. 3. Select the node to be excluded and click on Exclusions... in the Node actions... button. 4. Follow the screen prompts to complete the node exclusion Once the erroneous node has been excluded and the deploy process is complete on the other nodes in the system. Follow the procedure as documented in the section Replacing a node to make an excluded node operable again. Replacing a node A node can be replaced by using the Replace node button. It can be used to redeploy nodes that for example: • have become corrupt • have hardware issues. Replacing a node will reset the node's installation status but it will retain its configuration (the configured Node Functions and their property values). Once the replace node process has been initiated, the node status will change to “Needs Redeploy”. When a node is replaced, the replacement node needs to have the same computer name and network configuration. To replace a node: 34 2PAA111708-600 F Section 2 System 800xA Installation Removing Nodes from the System 1. Restore the faulty node to a clean Windows installation. Prepare it according to the instructions in Appendix A, Prerequisites. 2. Ensure that it has the same computer name and network configuration as earlier. 3. Run the Node Preparation Tool on it. 4. Go to the node where the deploy was initiated and from the System nodes tab of the Configure System task, and click on Replace node command on the node. Once completed, the node's status will be 'Needs Redeploy' 5. Click the Deploy command to install the configuration on the node once again. 6. The node will have the same configuration installed as previously. Removing Nodes from the System A node may be removed when reducing the system footprint. Use the Remove node function from the System nodes tab of the Configure System task to remove a node and deploy for the change to take effect. Removing the node from the system causes all the configuration data on the node to be removed as well. Once removed the node can no longer connect to the system. To reconnect the node to the system the node must be prepared, added and the functions allocated to the node. Renaming a node A node maybe renamed when restoring a backup from a development or an engineering system into a production system or due to some other reason. To rename the node and reconnect it to the system: the node must be prepared, added and the functions allocated to the node. 2PAA111708-600 F 35 Renaming a node 36 Section 2 System 800xA Installation 2PAA111708-600 F Section 3 System 800xA Update Section 3 System 800xA Update Updates can be executed using the System Installer as described in the System 800xA 6.0 Update Manual (2PAA114580*). 2PAA111708-600 F 37 Section 3 System 800xA Update 38 2PAA111708-600 F Section 4 System 800xA Upgrade Section 4 System 800xA Upgrade Upgrades can be executed using the System Installer as described in following upgrade manuals. Choose the user manual that applies to the system being upgraded. • System 800xA 5.1 to 6.0 Upgrade (2PAA111694*) • System 800xA 5.0 SP2 to 6.0 Upgrade (2PAA111695*) • System 800xA 4.1 to 5.0 SP2 Upgrade (2PAA113553*) • System 800xA 3.1 SP2 to 5.0 SP2 Upgrade (2PAA113440*) A direct upgrade from System Version 3.1 Service Pack 3 to System Version 6.0 is not supported. The System Version 3.1 Service Pack 3 800xA System must be upgraded to 800xA 5.0 SP2 and then to 800xA 6.0. A direct upgrade from System Version 4.1 to System Version 6.0 is not supported. The System Version 4.1 800xA System must be upgraded to 800xA 5.0 SP2 and then to 800xA 6.0. VB based Process Graphics are not supported in System 800xA 6.0. The VB editor is not supported and VBPG graphics can no longer be edited in 800xA 6.0. It is mandatory to migrate all VB process graphics to PG2 graphics before upgrading to System 800xA 6.0. The upgrade instruction contains procedures for upgrade preparation and post upgrade. Upgrading most Base System and Functional Area software requires referring back to the installation instruction Creating a system to install that software. This does not include information on site planning, engineering planning, software configuration, network design, security measures, tools, maintenance, and so on that can be found in other 800xA User Manuals. 2PAA111708-600 F 39 Section 4 System 800xA Upgrade 40 2PAA111708-600 F Appendix A Prerequisites Windows Operating System Appendix A Prerequisites The user performing the procedures in this section must be proficient in the use of Windows Operating Systems. This section may not include detailed procedures on how to perform the described settings. There may be differences in accessing the Microsoft Operating System settings described in this section depending on the selected operating system. It is the responsibility of the user to consult Microsoft documentation and online help to accurately make the settings. Use the System 800xA 6.0 System Planning (3BSE041389*) document to help plan the requirements, both hardware and software, for the 800xA System. This section lists the prerequisites required to configure a node for an 800xA System. It is recommended to make a full backup of all disks. With such a backup all work will be saved in the event of a disk crash or other serious malfunction. Make sure to place proper identification on the backup media or backup files. Install optional hardware drivers if not supplied by the Windows Operating System (video card, network adapter, sound card, etc.). Windows Operating System This section describes: • • • • Selecting the Windows Operating System. Considerations for Disks and File System. Windows Installation Guidelines. Windows Operating System Updates. Selecting the Windows Operating System System 800xA 6.0 version runs only on 64-bit (x64) operating systems. 2PAA111708-600 F 41 Considerations for Disks and File System Appendix A Prerequisites The supported operating systems, service packs, and hot fixes are listed in System 800xA 6.0, 5.1, 5.0, 4.x, 3.1 Third Party Software (3BUA000500). For security updates refer System 800xA - Third Party Security Updates Validation Status (3BSE041902). These documents can be found in ABB SolutionsBank. The US English version of the operating system is required even if a translation NLS package for System 800xA is used. The following conditions affect the decision on which operating system to use: • Server roles can be allocated to nodes running either a workstation or server operating system of Windows. Using workstation operating system helps in keeping the cost down for smaller installations. Refer to the System 800xA 6.0 System Guide Technical Data and Configuration (3BSE041434*) for rules that apply in selecting the type of Operating System. • There are limitations on number of nodes used in the system when using the Workstation Operating System for Server nodes. These limitations depend on Microsoft licensing rules for the Workstation Operating System. Refer to System 800xA System Guide Technical Data and Configuration (3BSE041434*) for the details on the limitations. • The Windows Operating System may be purchased from any Microsoft reseller. • The nodes with pre-installed operating system shall be checked and configured as per the system 800xA specifications. Considerations for Disks and File System There are several factors that may have an impact on 800xA System performance, for example: where the software is installed, the tendency toward fragmentation. The following are some recommendations regarding these factors: Multiple Disks and Partitions Some types of 800xA servers can use significant disk I/O. Creating partitions that are hosted by different disks or disk arrays can improve performance for these servers. Aspect Servers, Connectivity Servers, Information Management Servers and Batch Servers can benefit from additional partitions when configuration data is distributed over multiple partitions that are hosted by separate disks or disk arrays. 42 2PAA111708-600 F Appendix A Prerequisites Considerations for Disks and File System At least two of these partitions are recommended for Information Management Servers. See the System 800xA System Guide Technical Data and Configuration (3BSE041434*) for specific details for Information Management and other server types. Installation Directory It is generally recommended to use the Windows default location, the program files directory on the boot disk, for installation. A faster disk subsystem will improve performance. Defragmenting Disks The file system must be in a consistent state at all times. Size disks so they will be 25 percent empty for defragmentation purposes. Defragment disks on a regular basis using the defragmentation software provided with the operating system. Check the system for fragmented files and defragment them as required: • On all nodes where trend and history logs reside. • History Server disks and disks on the Connectivity Servers where trend or history logs reside as History configuration impacts not only the History Server disks. • Extensive use of the Bulk Configuration tool may cause associated disks to become fragmented. • Configuration procedures that involve creating, deleting, and then recreating of a large quantity of objects may cause associated disks to become fragmented. • Deleting and then creating the Aspect System may cause associated disks to become fragmented. 2PAA111708-600 F 43 Windows Installation Guidelines Appendix A Prerequisites Windows Installation Guidelines Make a fresh installation of the Windows Operating System. Before adding applicable service packs, it is important that all the latest device drivers are installed to match the hardware. This is especially important for elite server hardware with special RAID hard drives and server specific hardware that requires the latest drivers or drivers not included in the operating system media. Follow the installation procedure as described in the documentation provided by Microsoft. Table 2 indicates the settings specifically required for the 800xA System installation. Table 2. Windows Installation Requirements Step Description Choosing a partition for It is recommended that all server nodes (Aspect Directory, Connectivity installing the operating Servers, Applications Servers, etc.) use at least one additional partition for system. the operateITData and operateITTemp folders. For best performance, the additional partition should be on a separate disk or disk array from the operating system. There may be additional disk requirements for Applications Servers. If installing the Information Management Server function on this node, at least one additional NTFS partition is needed for storing historical data. This partition can be the same as the operateITData and operateITTemp partition or be a separate partition. The amount of disks, disk space, and disk I/O needed for the Information Management node are dependent on the final configuration for the node. To maximize the performance for any server, any additional partitions should be a separate disk or disk array from the root partition. Selecting Regional Settings Refer to Regional and Language Options on page 69. Time Zone Make sure the Automatically adjust clock for daylight saving changes check box is enabled (if daylight saving time is used). 44 2PAA111708-600 F Appendix A Prerequisites Windows Operating System Updates Windows Operating System Updates Install Windows hot fixes, and Security Updates approved by ABB (refer to Third Party Software System 800xA (3BUA000500) and System 800xA Third Party Security Validation Status (3BSE041902) after installing other third party software. ABB System 800xA Qualified Security Updates (9ARD183777*) can be used to install the latest qualified security updates. The tool and the document are accessible from ABB SolutionBank. The Windows Operating System Updates (Service Packs, Feature Packs) must be installed immediately after installing the operating system, and before performing any other procedures in this instruction. Configuring Network Adapters If the Network Adapter supports Receive Side Scaling this feature must be disabled. Refer to the Network Adapter documentation for information on how to disable the feature. Network adapters must be installed and configured to support communication on the client/server network. This is required on the Domain Server node, and all 800xA System nodes. Typically one network adapter will be provided with the server or workstation hardware. It may be necessary to install a second network adapter for redundancy. All network adapters may be installed and configured at the same time during system installation; however, the network will not run with redundancy until Redundant Network Routing Protocol (RNRP) is installed (refer to Product Installation section for a separate Domain Server node). If the network adapters are not plug-and-play devices, the installation must be done manually. If the Windows installation does not include the drivers for the network adapters the driver software must be installed before the network adapters can be configured. The 800xA System relies on TCP/IP as its transport protocol. It is strongly recommended that TCP/IP is the only protocol in use. If other protocols need to be installed, make sure that TCP/IP is configured as the primary protocol. 2PAA111708-600 F 45 Configuring Network Adapters Appendix A Prerequisites Refer to Windows Help > Networking for more information on how to install and configure TCP/IP network adapters. Refer to System 800xA Network Configuration (3BSE034463*) for configuration of DNS. The following procedure applies to the Workstation Operating System nodes. The procedure for the Server Operating System nodes may vary from the one shown here. To configure the network adapters: 1. Open Windows Control Panel. 2. Double-click Network and Sharing Center to open the Network and Sharing Center. 3. Click Change Adapter Settings. 4. Right-click on the network adapter and select Properties from the context menu to open the Connection Properties dialog box. 5. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties to open the Internet Protocol (TCP/IP) Properties dialog box. 6. Select Use the following IP address. 7. Enter the IP address in the IP address and the subnet mask in the Subnet fields according to the planning done in Installation and Configuration Parameter Worksheet. 8. Enter the IP address of the default gateway in the Default gateway field (if required by topology). 9. Enter the IP address of the Primary Domain Server in the Preferred DNS server field. 10. Enter the IP address of the Secondary Domain Server in the Alternate DNS server field. Always specify the Domain Servers with their primary client/server network addresses. This is true for all network adapters, including the ones for secondary client/server networks. 46 2PAA111708-600 F Appendix A Prerequisites Configuring Network Adapters 11. Repeat for all network adapters in the servers and workstations. Use the same DNS settings for all network adapters. 12. For all interfaces on separate Control Networks three configuration changes (compared to the default settings) must be done to reduce the amount of traffic on the Control Network. a. Disable IPv6 by clearing the check box Internet Protocol Version 6 (TCP/IPv6). b. Click Properties in the Internet Protocol (TCP/IP) Properties dialog to open the Advanced TCP/IP settings dialog. c. Click the DNS tab. d. Clear the check box Register this connection's addresses in DNS. e. Click the WINS tab. f. Select Disable NetBIOS over TCP/IP. 13. Click OK as necessary to save the newly configured values, and then click Close to close the Connection Properties dialog box. 14. Connect the Ethernet cables. Match each of the icons with its corresponding Ethernet connector on the server or workstation. 15. Use ping -a from a Windows command prompt to verify the server or workstation has contact with the Domain Controller: C:\>ping -a 172.16.40.1 Pinging MM-DC1 [172.16.40.1] with 32 bytes of data: Reply from 172.16.40.1: bytes=32 time<1ms TTL=128 Reply from 172.16.40.1: bytes=32 time<1ms TTL=128 Reply from 172.16.40.1: bytes=32 time<1ms TTL=128 Reply from 172.16.40.1: bytes=32 time<1ms TTL=128 Ping statistics for 172.16.40.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: 2PAA111708-600 F 47 Configuring Domain Controller and DNS Server Appendix A Prerequisites Minimum = 0ms, Maximum = 0ms, Average = 0ms The connection may not work through more than one network adapter before RNRP is installed. Verify the port speed and duplex configuration on both ends (Network Adapter and network switch). Refer to System 800xA Network Configuration (3BSE034463*). 16. Verify the primary Client Server network is bound first for RNRP configurations. From the Change Adapter Settings: a. Use the Alt key to expose the Advanced Settings menu. b. Select Advanced Settings. c. Verify the Primary Client Server Network is bound first and the Redundant Client Server Network is second. d. Make corrections as needed. 17. Disable all unused NIC cards. The primary NIC card can only have one TCP/IP address. If the card consists more than one TCP/IP address, RNRP will not function correctly. Configuring Domain Controller and DNS Server If the Domain Controller uses any network interface in addition to the ones for the client/server network, the DNS Server need to be configured to only listen to DNS requests on the client/server network. Perform the following for all Domain Controllers. • Open the Interfaces tab under Properties for the DNS Server. • Make sure that only the IP addresses for the client/server network are selected. The below 800xA software must be installed on the standalone domain controllers manually browsing the media for: 48 2PAA111708-600 F Appendix A Prerequisites Configuring Domain Controller and DNS Server • ABB 800xA Common Third Party Install: go to 3rd_Party_Software->ABB>ABB 800xA Common 3rd Party Install and run Setup.exe. • RNRP: go to Core Functionalities > RNRP and run the ABB 800xA RNRP.msi • Diagnostics Collection Tool (DCT): Go to Core Functionalities > Diagnostics Collection Tool > Diagnostics Collection Tool.msi. To install the DCT plug ins go to Core Functionalities > Diagnostics Collection Tool > Diagnostics Collection Tool Plugins.msi. Specify an Administrative user name and password for the DCT Service account during installation of the Diagnostics Collection Tool on a Domain Controller node. Use domain\user name syntax to specify the domain account. For an 800xA System installation to be used as a production system, set up a new Domain Server with a domain specifically for the 800xA System, that will exist independent of any other corporate domains that may already exist. Follow the procedure in this section, starting at Active Directory Domain Services on First Forest Root Domain Controller on page 50. The following are general recommendations: • One 800xA System may share the same domain with other 800xA Systems having the same system versions. • Generally, it is better to create a new, dedicated domain for an 800xA System as opposed to reusing an old domain. • Do not create subdomains and avoid complex solutions. • Generally, it is not recommended to split two redundant Domain Controllers to host engineering and production systems on two different locations (i.e. network islands). Splitting two Domain Controllers will make one of the parts incomplete since the Flexible Single Master Operations (FSMO) roles and Global Catalog services are not redundant within Microsoft Windows. Additional guidelines for setting up the 800xA System domain are provided in System 800xA Network Configuration (3BSE034463*). Before setting up a new domain, verify that the server hardware being used as the Domain Server has the Server Operating System installed. The Workstation Operating System can not be used for a Domain Controller or DNS server. 2PAA111708-600 F 49 Configuring Domain Controller and DNS Server Appendix A Prerequisites Ensure that Internet Protocol Version 4 (TCP/IP V4) is the only protocol configured on the node. Create a new domain by setting up a new Domain Controller and DNS server using the Server Manager. To set up a new domain, configure the IP addresses of the Domain Server node if this is not already done. • Set the IP addresses. • Set the IP address of this computer as the Preferred DNS Server on the primary network adapter. • If using, or planning on using two Domain Servers, set the IP address of the other Domain Server as the Alternate DNS Server on the primary network adapter. • If using a redundant network, use the same DNS settings on the secondary network adapter. Active Directory Domain Services on First Forest Root Domain Controller The following procedure was prepared using Install AD DS on the First Forest Root Domain Controller as provided by Microsoft at: http://technet.microsoft.com/en-us/library/hh472162.aspx The instructions included here are for the preferred method of installing Active Directory Domain Services (AD DS). Refer to the Microsoft article if planning on using alternate methods. Membership in the local Administrator account is the minimum required to complete this procedure. Details about using the appropriate accounts and group memberships can be found at: http://technet.microsoft.com/en-us/library/dn487460.aspx. To install AD DS: 50 1. Go to Server Manager. 2. Select Add roles and features. 2PAA111708-600 F Appendix A Prerequisites Configuring Domain Controller and DNS Server 3. On Before you begin page, click Next. 4. On Select installation type page, select Role-based or feature-based installation. 5. Click Next. 6. On Select destination server page, click select a server from the pool for new roles. 7. Select current node, click Next. 8. On Select server roles page, select Active Directory Domain Services (AD DS) as additional role. 9. Click Add Features on the pop-up to add other AD DS tools. 10. Click Next. 11. On Select features page, Group Policy Management feature is automatically selected. 12. Click Next. 13. On Active Directory Domain Services page, basic information is displayed 14. Click Next. 15. On Confirm installation selections page, verify and click Install. 16. Click Notification Flag once the installation is complete. 17. Select Promote this server to a domain controller. AD DS configuration wizard appears. 18. On Deployment Configuration page, select Add a new forest. 19. Enter Root domain name. (For Example: ABB.local) 20. Click Next. 21. On Domain Controller Options page, keep the default values. 22. Enter Directory Services Restore Mode (DSRM) password. 23. Click Next. 24. On DNS Options page, a warning message appears. 2PAA111708-600 F 51 Configuring Domain Controller and DNS Server Appendix A Prerequisites 25. Ignore and click Next. 26. On Additional Options page, verify NetBOIS name assigned to the domain. 27. Click Next. 28. On Paths page, keep default values and click Next. 29. On Review Options page, verify all the selections made. 30. On Prerequisites Check page, verify all the checks passed. 31. Click Install. Active Directory Domain Services on Second Forest Root Domain Controller The following procedure was prepared using Install AD DS on the Second Domain Controller as provided by Microsoft at: http://technet.microsoft.com/en-us/library/jj574134.aspx The instructions included here are for the preferred method of installing Active Directory Domain Services (AD DS). Refer to the Microsoft article if planning on using alternate methods. Membership in the Domain Admins group for the domain in which the second Domain Controller is being installed is the minimum required to complete this procedure. Details about using the appropriate accounts and group memberships can be found at http://technet.microsoft.com/en-us/library/dn487460.aspx. To install AD DS on a Domain Controller in an existing domain: 52 1. Go to Server Manager 2. Click Add Roles in the Roles Summary dialog box. 3. Review the information in the Before You Begin dialog box (if necessary) and click Next. 4. Select the Active Directory Domain Services check box in the Select Server Roles dialog box and click Next. 5. Review the information in the Active Directory Domain Services dialog box and click Next. 2PAA111708-600 F Appendix A Prerequisites Configuring Domain Controller and DNS Server 6. Click Install in the Confirm Installation Selections dialog box. 7. Click Close this wizard and launch the Active Directory Domain Services Installation Wizard in the Installation Results dialog box. 8. Click Next in the Welcome to the Active Directory Domain Services Installation Wizard dialog box. 9. Select Existing Forest and Add a domain controller to an existing domain in the Choose a Deployment Configuration dialog box. Type the name of the existing domain in the forest and then take the following actions: a. Select My current logged on credentials or Alternate credentials under Specify the account credentials to use to perform the installation and click Set. b. Provide the user name and password for an account that can install the additional Domain Controller (it must be a member of the Enterprise Admins group or the Domain Admins group) in the Windows Security dialog box and click Next. 10. Select the domain of the new Domain Controller in the Select a Domain dialog box and click Next. 11. Select a site from the list, or select the option to install the Domain Controller in the site that corresponds to its IP address in the Select a Site dialog box and click Next. 12. Make the following selections in the Additional Domain Controller Options dialog box and click Next. – DNS Server: This option is selected by default when AD DS integrates the DNS server service in to the domain so that the Domain Controller can function as a DNS server (this is the preferred method). It is recommended that DNS be installed when the Active Directory Domain Services Installation Wizard is run (keep the default selected), so that the wizard creates the DNS zone delegation automatically. – 2PAA111708-600 F Global Catalog: This option is selected by default. It adds the global catalog, read-only directory partitions to the Domain Controller, and it enables global catalog search functionality. 53 Adding Nodes to a Domain – Appendix A Prerequisites Read-only domain controller: This option is not selected by default. It makes the additional Domain Controller read-only. For more information about read-only domain controllers, refer to: http://technet.microsoft.com/en-in/library/jj574152.aspx 13. In Active Directory Domain Services Installation Wizard, navigate to Additional Option, and in Replicate From select the Domain Node. 14. Use the default locations in the Location for Database, Log Files, and SYSVOL dialog box and click Next. 15. Type and confirm the restore mode password in the Directory Services Restore Mode Administrator Password dialog box and click Next. This password must be used to start AD DS in Directory Service Restore Mode for tasks that must be performed offline. 16. Review the selections in the Summary dialog box. Click Back if it is necessary to change any selections. 17. Click Export settings to save the selected settings to an answer file that can be used to automate subsequent AD DS operations. 18. Type the name for the answer file and click Save. 19. Click Next to install AD DS when the selections are accurate. 20. Click Finish in the Completing the Active Directory Domain Services Installation Wizard dialog box. 21. A prompt appears asking to restart the server. Select either the Reboot on Completion check box to restart the server automatically or clear the check box to restart the server manually to complete the AD DS installation. System 800xA Network Configuration (3BSE034463*) includes examples of a correctly configured DNS Server. Adding Nodes to a Domain This is required for all member nodes in the 800xA System (not applicable for single node installations, for example Information Management consolidation node, 54 2PAA111708-600 F Appendix A Prerequisites Configuring Users and Groups or Windows Workgroups). Perform this procedure at each node that needs to be added to the domain. This procedure requires an administrator user name and password defined for the domain. Have this information available before proceeding. 1. Log on to the node as a local administrator. 2. Configure the IP address of this node and ensure the DNS server address points to the IP address of the DNS server. 3. From the desktop, right-click on Start and select System from the context menu that appears. 4. Select Change Settings. 5. Select the Computer Name tab and click Change. 6. In the Computer Name Changes dialog box, select Domain Controller. 7. Type the name of the domain in the Domain field. 8. Click OK until all dialog boxes are closed. 9. Click Yes when asked to reboot. Repeat this procedure to add additional nodes to the domain. Configuring Users and Groups This section describes how to create the Windows domain users and groups in the Active Directory on the Domain Server node. The prerequisites to configure Users and Groups in a Domain: • Before setting up Industrial IT users and user groups, verify that a domain has been created by setting up a Domain Controller and DNS server as described in Configuring Domain Controller and DNS Server on page 48. • This procedure requires being logged in as domain administrator. A default domain administrator is created when the Domain Controller and domain is set up as described in Configuring Domain Controller and DNS Server on page 48. Refer to System 800xA Administration and Security (3BSE037410*) for detailed descriptions of users, user groups, and user roles and permissions. 2PAA111708-600 F 55 Configuring Users and Groups Appendix A Prerequisites Refer to Users, Groups, and Rights Assignments on page 60 for listings of mandatory users and user groups for the 800xA System. Since the 800xA System user credential concept is built on Windows domains, local user accounts must never be created and used on the client nodes. Clients will always connect to the 800xA System using domain accounts. The only exception is Windows Workgroups where domains are not used. In these cases all users and groups are local For 800xA Systems in a Windows Workgroup all the users and groups shall be created locally on each node with same user group name, user name and password. The following procedure is used to create various domain accounts to be used in System 800xA. Create two domain accounts with administrator privileges. The 800xA Service User will be reserved for use by the 800xA System Services. This account will NOT be used for installation, administration, configuration, or any other system related procedures. The 800xA Installation account must be created to complete the 800xA System software installation and post installation procedures. Create other user accounts for other 800xA System activities such as Application Engineer, System Engineer, and Operator. Define separate accounts and different passwords for the 800xA Service User and the 800xA installing User. 56 2PAA111708-600 F Appendix A Prerequisites Configuring Users and Groups Domain Administrator users are powerful for administrative purposes but could by this also be dangerous from a security perspective. For security reasons the number of users in the Domain Administrator group should be kept to a minimum. The 800xA Service User and 800xA Installing User do not need to be members of the Domain Administrators group. They both need to be members of the Builtin Administrators group on the 800xA System nodes but not on the Domain Controller, unless it is combined with an 800xA Server. The 800xA Installing User could be a Domain Administrator but should be set to passive after the installation of the System. The 800xA Service User should not be a Domain Administrator and also not a local administrator on the Domain Controller. The various users and groups required by the 800xA System are described in Table 3. All groups/users must reside on the 800xA System domain. This setup may be performed by yourself, or the domain administrator may perform the setup. In either case, use the guidelines in Table 3, and follow the step-by-step procedures following Table 3. Table 3. Domain Groups/Accounts Required by 800xA System Groups/Users Description IndustrialITAdmin Group Create the IndustrialITAdmin Group. All 800xA System administrators (including the 800xA Service User) must be a member of the IndustrialITAdmin group. IndustrialITUser Group Create the IndustrialITUser Group. All 800xA System users must be a member of the IndustrialITUser group. 2PAA111708-600 F 57 Configuring Users and Groups Appendix A Prerequisites Table 3. Domain Groups/Accounts Required by 800xA System (Continued) Groups/Users 800xA Service User Description Create a new user for 800xA System services. Make this user a member of the IndustrialITAdmin Group, the IndustrialITUser Group, and the local administrator group on every system node. All 800xA System services will run under this account. Make the name easy to recognize (for example: 800xAService). NOTE 1: Creating this user requires being logged in as domain administrator. Adding this user to the local administrator group on every system node requires being logged in as local administrator. NOTE 2: The 800xA Service User must not be a member of the Domain Administrator group. These users should be members of the Built-in Administrators group on the Domain Controller node. Installing User Create a user for installing software, and performing system administration procedures. Make this user a member of the IndustrialITAdmin Group, the IndustrialITUser Group, and the local administrator group on every system node. NOTE 1: Creating this user requires being logged in as domain administrator. Adding this user to the local administrator group on every system node requires being logged in as local administrator. Other 800xA System users 58 Create additional users for system configuration and operation. These users are added to the IndustrialITUser Group. Refer the System 800xA 6.0 Administration and Security (3BSE037410*) for more information on user permissions. 2PAA111708-600 F Appendix A Prerequisites New Organizational Unit New Organizational Unit This organizational unit is not mandatory; however, it may be helpful to put all 800xA System groups and users into one container. To create a new unit: 1. Go to: Administrative Tools > Active Directory Users and Computers In the left pane, right-click on the newly created domain server name, and select: 2. New > Organizational Unit from the context menu that appears. Assign this organization unit the name Industrial IT. 3. Groups This procedure assumes the Industrial IT organization unit has been created. To create the required groups: Right-click on the Industrial IT folder in the left pane and select: 1. New > Group from the context menu that appears. 2. Use the New Object - group dialog box to assign the group a name (for example, IndustrialITAdmin). 3. Set the Group scope to Global, and the Group type to Security. 4. Perform Step 1 through Step 3 for each of the two required groups: – – IndustrialITAdmin. IndustrialITUser. It is recommended to keep the default names of these groups. Systems with Batch Management should create the groups with default names IndustrialITAdmin and IndustrialITUser. 2PAA111708-600 F 59 Users, Groups, and Rights Assignments Appendix A Prerequisites Users, Groups, and Rights Assignments This topic defines the default User Groups and Users for the 800xA System. Windows Workgroups set up the same groups and users as a domain. The user rights are also the same as in a domain, except all domain policies must be defined on each local node. No additional policies are required for Windows Workgroups. Ensure that the User Account names do not exceed the 20 character limit. 60 2PAA111708-600 F Appendix A Prerequisites Users, Groups, and Rights Assignments User Groups and Users All users must be members of the IndustrialITUser group if they require the ability to start a workplace. Table 4 lists the default User Groups and Users. Table 4. Default User Groups and Users Organizational Unit Industrial IT User Group User Account Description IndustrialITAdmin 800xAService 800xA System service account 800xAInstaller 800xA System installer account Administrator System installer default account Customer Admin Additional customer administrators 800xAService 800xA System service account 800xAInstaller 800xA System installer account Operator Default operator 1 Operator2 Default operator 2 Administrator Windows default administrator account IndustrialITUser NOTE: System 800xA does not require this account and it is disabled by default. Enable the account if needed. Customer Users 2PAA111708-600 F Additional customer users 61 Users, Groups, and Rights Assignments Appendix A Prerequisites Local Groups and Members on Each Node Table 5 lists the local and domain User Groups and Users for each system node. Table 5. Local Groups and Members on Each Node in System Local Group/User Administrators (standard default) Domain Group/User 800xAService 800xAInstaller HistoryAdmin 800xAService 800xAInstaller Customer Admin (User can add additional domain users to group to allow administration of Oracle and Information Management IM Services) ORA_DBA 800xAService 800xAInstaller Customer Admin (User can add additional domain users to group to allow administration of Oracle and Information Management IM Services) User Rights Assignment Table 6 lists the user rights assignment. In case of an Aspect Server combined with a Domain Controller, create a new Group Policy Object under the Domain Controller object and configure the security policies listed in Table 6. The user rights in the Windows security policies shall be configured in 800xA System to enable users with right permissions to perform various activities in the system. For systems using Domain Controllers the user rights assignment security policies are to be configured from the below location on the Primary Domain Controller: 1. 62 Go to Control Panel > Administrative Tools > Group Policy Management 2PAA111708-600 F Appendix A Prerequisites Users, Groups, and Rights Assignments 2. Right click Group Policy Management and select Edit... 3. Navigate to Computer Configurations > Policies > Windows Settings > Security Settings > Local Policies and click User Rights Assignment For Systems in Workgroup environment configure the user rights assignment security policies on each node in the below location: 1. Go to Control Panel > Administrative Tools >Local Security Policy. 2. Navigate to Security Settings > Local Policies > User Rights Assignments. The security policies listed in Table 6 can be configured by performing the following on each Security policy under User rights Assignment: 1. Double click on the policy 2. Click Add User or Group... button to add the user or groups as per Table 6. 3. Click OK to close the policy. Table 6. User Rights Assignments Policy Security Setting Local Security Policy (each node) Access this computer from the network IndustrialITUser Allow log on locally IndustrialITAdmin Change the system time IndustrialITAdmin Log on as a batch job 800xAService 800xAInstaller Log on as a service 800xAService 800xAInstaller Impersonate a client after authentication SERVICE (Default) Administrators (Default) Users that require logover (Process Portal) 2PAA111708-600 F 63 800xA Service User Appendix A Prerequisites Table 6. User Rights Assignments (Continued) Policy Security Setting Additional Local Security Policies on Batch Server Act as part of operating system 800xAService Adjust memory quotas for a process Bypass traverse checking Replace a process level token Additional Local Security Policies for Harmony/Melody Servers Act as part of operating system 800xAService Generate security audits Impersonate a Client after Authentication 800xA Service User Define separate accounts and different passwords for the 800xA Service User and the 800xA installing User. This procedure assumes the Industrial IT organization unit has been created. Creating this user requires being logged in as domain administrator. Adding this user to the local administrator group on every system node requires being logged in as local administrator. Create the 800xA Service User. This is the user account that all 800xA System services will run under. Make this new user a member of the following groups: • • • • IndustrialITAdmin Group IndustrialITUser Group Local Administrator group on every system node Built-in Administrators group on the Domain Controller node. To create this user: 1. 64 Right-click on the Industrial IT organizational unit in the left pane and select: 2PAA111708-600 F Appendix A Prerequisites 800xA Service User New > User from the context menu that appears. 2. In the New Object - User dialog box specify the user name and login name. Make the name meaningful and easy to recognize (for example: 800xAService). 3. Click Next when finished. 4. Specify the user password. Enable the Password never expires check box, and make sure the password for this user is NEVER CHANGED. 5. Click Next when finished with the password specification. 6. Click Finish in the next dialog box to complete the user specification. 7. Make this user a member of the IndustrialITAdmin Group. 8. 2PAA111708-600 F a. Select the Industrial IT organizational unit in the left pane. b. Right-click on the IndustrialITAdmin group in the right pane and choose Properties from the context menu that appears (or double-click the group name). c. Select the Members tab in the Properties dialog box. d. Click Add. This displays the Select Users, Contacts, or Computers dialog box. e. Select the new user (for example, 800xAService) and click Add. f. Repeat Step e to add other users to the IndustrialITAdmin group. g. Click OK when finished. h. Click OK on the Members tab of the Properties dialog box. Add this user to the Builtin Administrators group on the Domain Controller node. 65 User Account for Installation 9. Appendix A Prerequisites Add this user to the local administrator group on every system node. In order to limit the abilities of the 800xA Service User, the 800xA Service User may be included in the Deny Logon Locally policy on every system node. However, this will prevent logging in as the 800xA Service User on Report Scheduling Server nodes (Scheduling Server nodes that need to run Excel reports), on 800xA for Melody and 800xA for Harmony. On these nodes, the 800xA Service User must be logged in to add the DataDirect add-ins to Excel for this user; to carry out the post installation and configuration of Melody and Harmony. In such cases, the 800xA Service User may be included in the Deny Logon Locally policy after adding the add-ins, but not before. User Account for Installation Define separate accounts and different passwords for the 800xA Service User and the 800xA installing User. Create an administrator account for installing all 800xA System software and performing all post installation procedures. Follow the procedure for 800xA Service User on page 64. The only difference is that this account should be configured so that the password will expire, and will need to be changed periodically. Other Users Add other IndustrialIT users and make them members of the IndustrialIT User Group. Set passwords according to company policy, and change them frequently. Examples of users who can be members of the IndustrialITUser groups is as shown in Table 7. Ensure that the User Account names do not exceed the 20 character limit. Do not change the 800xAService user passwords. 66 2PAA111708-600 F Appendix A Prerequisites Adding 800xA Domain Users to the Local Administrator Group Table 7. Examples for User accounts User Account Descriptions ApplicationEng Default application engineer SystemEng Default system engineer MaintenanceSup Default maintenance supervisor MaintenanceEng Default maintenance engineer MaintenanceTech Default maintenance technician Adding 800xA Domain Users to the Local Administrator Group The 800xA Service User and 800xA Installing User accounts defined in the domain must be added to the local Administrator Group on every node in the domain, including the Domain Controller node. The different procedures to be followed depend on the node type: • Domain Controller Node • On All Other Nodes Domain Controller Node 1. Go to Control Panel > Administrative Tools 2. Select Active Directory Users and Computers to launch the Active Directory Users and Computers dialog box. 3. In the left pane, navigate to: Active Directory Users and Computers > Domain Name > Built-in 4. Select Administrators in the right pane to launch the Administrators Properties dialog box. 5. Select the Members tab. 6. Click Add. This opens the Select Users, Computers or Groups dialog box. 7. Click Locations, select the domain in the Locations dialog box and click OK. 2PAA111708-600 F 67 Operating System Setup Use with 800xA System Appendix A Prerequisites 8. Enter the names of the 800xA Service User and Installing User in the text box and click Check Names. 9. When the dialog box indicates the names have been found, click OK. 10. To finish, click OK in the Administrators Properties dialog box. On All Other Nodes 1. Log on as a local administrator. 2. From desktop right-click Start and select Computer Management from the context menu that appears. 3. The Computer Management dialog box appears. In the left pane, navigate to: Computer Management (Local) > System Tools > Local Users and Groups > Groups 4. Click Administrators to open the Administrators Properties dialog box. 5. Click Add. This opens the Select Users, Computers or Groups dialog box. 6. Click Locations, select the domain in the Locations dialog box and click OK. 7. Enter the names of the 800xA Service User and Installing User in the text box and click Check Names. 8. When the dialog box indicates the names have been found, click OK. 9. To finish, click OK in the Administrators Properties dialog box. Operating System Setup Use with 800xA System The following procedures should be carried out in domain account with Administrator rights (For example: 800xAinstaller). The following settings are required for use with the 800xA System: • • • • • 68 Regional and Language Options Enable Write Caching on Hard Disks Internet Explorer Enhanced Security Internet Security Settings for Digital Signature Validation Virus Scanning Configuration During Installation and Post Installation 2PAA111708-600 F Appendix A Prerequisites • • • • • • • • • • • • Regional and Language Options Disable Show Window Contents While Dragging Energy Saver and Screen Saver Configuration Virus Scanning Configuration During Installation and Post Installation Windows Update Configuration Enable the Change Sharing Options for Different Network Profiles Disable Server Manager Startup Hot fix for redundancy with IPSec enabled Set Date and Time for Batch Servers Disable ISATAP Setting Group Policy Management Adding Privileges to the 800xA Service User Remote (Thin) Client for the Server Operating System Regional and Language Options Perform the following procedure to set the regional and language options. These procedures must be performed for all users on all nodes in the 800xA System. The procedure differs depending on the operating system. The procedures described for all other supported operating systems: 1. Open Windows Control Panel. 2. Click Clock, Language, and Region to verify Region and Language preferences. 3. Click Region and select Formats tab. 4. Select and verify that English (United States) is selected in the Format section. 5. Click Additional settings... to launch the Customize Format dialog box. 6. Verify that the value in the Decimal symbol field drop-down list is a dot (.). If it is not, change it to a dot (.) and click Apply and then OK. 7. Click the Administrative tab. 8. Click Change system locale... to launch the Region Settings dialog box. 9. Verify that the value in the Current system locale drop-down list is English (United States). If it is not, change it to English (United States) and click OK to return to the Administrative tab of the Region dialog box. 2PAA111708-600 F 69 Enable Write Caching on Hard Disks Appendix A Prerequisites 10. Click Copy settings to launch the Welcome Screen and New User Accounts Settings dialog box. 11. Enable the Welcome screen and system accounts and New User Accounts check boxes and click OK. 12. Click OK to exit the Region dialog box. 13. Close Windows Control Panel. Enable Write Caching on Hard Disks To ensure Aspect Directory integrity, the write cache buffer flushing must be left enabled in the Microsoft Windows Operating System. Depending on the configuration, choice of driver, type of hard disks, etc, Windows may allow disabling the write cache buffer flushing on the hard disks to improve performance. For data integrity this otherwise performance increasing option must not be used. System 800xA configuration and application data is stored in the Aspect Directory. The Aspect Directory is transaction driven and enforces a two-phase-commit scheme. As part of that scheme it ensures that data is written to disk prior to considering the transaction complete. This behavior is used by several other thirdparty databases. A flush command is used to ensure that data is written to the disk.It is possible to configure the disk driver to neglect the flush command. This is normally configured in the Windows disk drives setting. A consequence of, for example, a power or hardware failure can be that a flushing is not performed. Potentially the Aspect Directory can then become inconsistent and the system will no longer start. Furthermore the data and applications become impossible to recover. Refer to Microsoft Knowledge Base article 234656 for more information. Perform the following procedure on all the Server Operating System hard disks: 70 1. Launch the Computer Management Console. 2. Select Device Manager in the left pane. 3. Select and navigate through Disk drives in the right pane. 2PAA111708-600 F Appendix A Prerequisites Internet Explorer Enhanced Security 4. Right-click the hard drive and select Properties from the context menu to launch the hard drive properties dialog box. 5. Select Policies tab. 6. Select the Enable write caching on the device check box for Server and Workstation Operating System. For Virtual Nodes: Select Better Performance check box to enable write caching. 7. Click OK. 8. Close the Computer Management Console. It may be necessary to verify the Enable write caching on the disk check box is still enabled after rebooting. Internet Explorer Enhanced Security The Internet Explorer Enhanced Security component must be disabled on all the Server Operating System nodes. Perform the following steps: 1. Open Server Manager. 2. Select Local Server. 3. In Properties, select Internet Explorer Enhanced Security Configuration. 4. Select Off radio button for Administrators and Users. 5. Click OK. Internet Security Settings for Digital Signature Validation Perform the following steps on all 800xA nodes: 1. Go to Control Panel. 2. On All Control Panel Items, select Internet Options. 3. In the Internet Properties, click Advanced tab. 4. Scroll to Security and under Security clear the Check for publisher’s certificate revocation check box. 2PAA111708-600 F 71 Disable Web Browser Popup Blocker 5. Appendix A Prerequisites Click Apply and OK. Disable Web Browser Popup Blocker Internet Explorer offers web browser popup blocker by default. Disable Popup Blocker where the thin client portions of the integrated applications (specifically Asset Optimization) are used, since these applications open child window browsers to display application data for the user. Disable Show Window Contents While Dragging To prevent CPU intensive redrawing of the window, disable the Windows Show Window Contents while dragging feature. 1. Open This PC. 2. Right-click and select Properties from the context menu to launch the System Properties dialog box. 3. Select the Advanced System Settings. 4. Click Settings in the Performance frame to launch the Performance Options dialog box. 5. Select the Visual Effects tab (this should be selected when the dialog box is launched). 6. Select the Custom option. 7. Clear the Show Window Content while Dragging check box. 8. Click Apply, wait, and then click OK to close the Performance Options dialog box. 9. Click OK to close the System Properties dialog box. Energy Saver and Screen Saver Configuration It is recommended to NOT have any Energy Saving and screen saver functionality activated on 800xA System nodes (especially operator Workplace Clients), as this might lead to longer reaction times in case of an emergency. If the server or workstation BIOS has an Energy Saver configuration, configure it on a node-bynode basis. The Windows energy saving data is user dependent. 72 2PAA111708-600 F Appendix A Prerequisites Virus Scanning Configuration During Installation and Post Installation The energy saving setting may be accessed in two ways. The BIOS setup is available whenever the server or workstation is powered up. It may also be accessed via Power Options in Windows Control Panel. The screen saver may be turned off in the Display Properties option in Windows Control Panel. Virus Scanning Configuration During Installation and Post Installation The user should make sure that the installation procedure completes without exposing the computers to malware or malicious network traffic of any sort. This can only be done by limiting the communication to the system and by performing separate virus scanning of any portable media or disks before connecting them to the system nodes during the installation. After completing the system installation and configuration (post installation) it is recommended to perform a full virus scan of all computers in the system. For better performance during 800xA installation and post installation procedures disable virus scanning software. For virus scanners recommended by ABB for use with System 800xA refer McAfee Integration on page 84 and Symantec on page 85. Windows Update Configuration Automatic Windows Updates are not recommended for the 800xA node. The information on service packs, hot fixes are listed in System 800xA 6.0, 5.1, 5.0, 4.x, 3.1 Third Party Software (3BUA000500). For security updates refer System 800xA Third Party Security Updates Validation Status (3BSE041902). These documents can be found in ABB SolutionsBank. To disable the automatic updates by setting the Windows Automatic Updates feature to never check for updates: 1. Open Windows Update 2. In the left pane, click Change Settings 3. Under Important Updates choose Never check for updates Enable the Change Sharing Options for Different Network Profiles Perform the following to enable the following parameters on all the nodes: 1. 2PAA111708-600 F Go to Control Panel. 73 Disable Server Manager Startup Appendix A Prerequisites 2. Click Network & Sharing Center. 3. Click Change Advance Sharing Settings. 4. Select the following in Private or Public or Domain profiles: – Turn on network discovery in the Network Discovery pane. If network discovery remains disabled (Turn off), then follow the procedure mentioned in the Microsoft KB article to enable (Turn on) network discovery. http://support.microsoft.com/kb/2722035 – Turn on file and printer sharing in the File and printer sharing pane. Disable Server Manager Startup Perform the following procedure to disable Server Manager not to start automatically. 1. Open Server Manager. 2. Click Manage tab and select Server Manager Properties. 3. Select Do not start Server Manager automatically at logon and click OK. Hot fix for redundancy with IPSec enabled For Client Server Network redundancy to work the following hot fix (KB3007072) needs to be installed on all nodes in an 800xA System. This hot fix is available on the 800xA media in the following path: …\3rd_Party_SW\Microsoft\Windows8.1-KB3007072-x64.msu Set Date and Time for Batch Servers Batch Primary and Redundant servers require a specific time format for the service account. All other users on the batch server and other nodes can keep the US English defaults. Perform the following to verify/modify the formats for the <800xA Service Account> on the batch servers: 1. 74 Login to the <800xA Service Account> on the Primary/Secondary Batch server. 2PAA111708-600 F Appendix A Prerequisites Disable ISATAP Setting 2. Open Windows Control Panel (Category view). 3. Click Clock, Language, and Region to set the date and time. 4. Click Date and Time, Date and Time dialog appears. 5. Click Change date and time.., to change the date and time. 6. Click OK and Apply to save the changes. 7. Click OK to close the window. 8. Click Region, Region dialog appears. Perform the following to set the formats for Date and Time: 9. a. Click the Format tab. b. The default value for the Short Date format is M/d/yyyy. Change the Short Date format to MM/dd/yyyy and click Apply. c. The default Short time format is hh:mm tt. Change the value to HH:mm and click Apply. Click Apply. Disable ISATAP Setting Perform the following procedure on all nodes (800xA or non-800xA) connected on the same network as the AC 800M Controllers: 1. Open Command prompt with “Run as administrator”. 2. At the command line, to check current ISATAP setting, enter: netsh interface isatap show state (Probably responds ISATAP State: default) 3. At the command line, to Disable ISATAP, enter: netsh interface isatap set state disabled Group Policy Management The group policy management procedures differ depending on the environment (domain or Windows Workgroup). 2PAA111708-600 F 75 Group Policy Management Appendix A Prerequisites Domain Environment Perform this procedure before installing 800xA System and Functional Area software. Group Policy. This procedure must be performed on the Primary Domain Controller. It should be performed after all 800xA System nodes have been added to the domain so that the new Group Policy will replicate out to all nodes in the selected domain via the active directory. However, if the system is expanded at a later time, the Group Policy will replicate to the nodes added during the expansion. 1. Open Group Policy Management Console. Do not modify the default Group Policy Object itself. Create, link and modify a new Group Policy Object. 2. Navigate to the following in the left pane of the Group Policy Object Editor: Forest:domain name >Domains >domain name >Group Policy Objects 3. Right-click on Group Policy Objects in the left pane of the Group Policy Management Console, and select Create a GPO in this domain from the context menu to open the New GPO dialog box. 4. Type in a name for the new Group Policy Object in the New GPO dialog box; for example, IntranetName and click OK to return to the Group Policy Management Console. 5. Right-click on the new Group Policy Object in the left pane of the Group Policy Management Console, and select Edit from the context menu to open the Group Policy Object Editor. 6. Navigate to the following in the left pane of the Group Policy Object Editor: User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page 76 7. Double-click Turn on automatic detection of intranet, a dialog box appears. 8. Click Disabled and click OK. 2PAA111708-600 F Appendix A Prerequisites 9. Group Policy Management Double-click Intranet Sites: Include all local (intranet) sites not listed in other zones, a dialog box appears. 10. Click Enabled and click OK. 11. Double-click Intranet Sites: Include all sites that bypass the proxy server, a dialog box appears. 12. Click Disabled and click OK. 13. Double-click Intranet Sites: Include all network paths (UNCs), a dialog box appears. 14. Click Disabled and click OK. 15. Close the Group Policy Object Editor. 16. Reboot the node. Adding Workstations to the Domain Policy Perform the following in order to prevent any user from being able to add workstations to the domain. 1. Open Group Policy Management Console. 2. Navigate to the following: Forest: Domain Name > Domains > Domain Name > Group Policy Objects > Default Domain Controllers Policy 3. Right-click Default Domain Controllers Policy and select Edit from the context menu to launch the Group Policy Management Editor. 4. Navigate to the following: Default Domain Controllers Policy > Computer Configuration Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment 5. In the right pane, double-click Add workstations to domain to launch the Add workstations to domain Properties dialog box. 6. Select Authenticated Users and click Remove. 7. Click Add User or Group to launch the Add User or Group dialog box. 2PAA111708-600 F 77 Group Policy Management Appendix A Prerequisites 8. Click Browse to launch the Select Users, Computers, or Groups dialog box. 9. Select the users and/or groups that are to have the authority to add workstations to the domain and click OK twice to return to the Add workstations to domain Properties dialog box. Click Find Now in the Select Users, Computers, or Groups dialog box to display the available users and groups. 10. Click Apply and then OK to close the dialog box. 11. Close the Group Policy Management Editor. Windows Workgroup Environment Perform this procedure before installing 800xA System and Functional Area software. Group Policy. This procedure must be performed on every node in the Windows Workgroup. If the system is expanded at a later time, this procedure must be performed on each node added during the expansion. 1. Open Local Group Policy Editor. 2. Navigate to the following in the left pane of the Group Policy Object Editor: User Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page 78 3. Double-click Turn on automatic detection of intranet, a dialog box appears. 4. Click Disabled and click OK. 5. Double-click Intranet Sites: Include all local (intranet) sites not listed in other zones, a dialog box appears. 6. Click Enabled and click OK. 7. Double-click Intranet Sites: Include all sites that bypass the proxy server, a dialog box appears. 8. Click Disabled and click OK. 2PAA111708-600 F Appendix A Prerequisites 9. Adding Privileges to the 800xA Service User Double-click Intranet Sites: Include all network paths (UNCs), a dialog box appears. 10. Click Disabled and click OK. 11. Close Local Group Policy Editor. 12. Reboot the node. Adding Privileges to the 800xA Service User This procedure only applies to the following node types. If these node types are not present in the system this procedure can be skipped. • • 800xA for AC 870P/Melody Configuration Server nodes. 800xA for AC 870P/Melody Connectivity Server nodes. There are some services that run under the 800xA Service User account for the listed node types. Perform the following procedure to add the proper privileges to the 800xA Service User account. 1. Log off the 800xA Installing User account. 2. Log on the 800xA Service User account. 3. Log off the 800xA Service User account. 4. Log on the 800xA Installing User account. Remote (Thin) Client for the Server Operating System Perform the following procedure to install the Terminal Server role service and configure the Terminal Server to host programs: 1. Go to Server Manager. 2. Select Add roles and features. 3. On Before you begin page, click Next. 4. On Select installation type page, select Role-based or feature-based installation. 5. Click Next. 2PAA111708-600 F 79 Other Third Party Software Appendix A Prerequisites 6. On Select destination server page, click select a server from the pool for new roles. 7. Click Next. 8. On Select server roles page, select Remote Desktop Services as additional role. If Terminal Services is already installed on the server, the Terminal Services check box will be selected and dimmed. 9. Click Next. 10. On Select features page, click Next without changing the features. 11. On Remote Desktop Services page, click Next. 12. On Select role services page, select Remote Desktop Licensing role. If installing the Terminal Server role service on a Domain Controller, a warning message indicating that Installing the Terminal Server role service on a Domain Controller is not recommended will appear. 13. Click Add Features and click Next. 14. Verify the added roles and features on Confirm installation selections page and click Install. 15. Restart the node when the installation is complete. Other Third Party Software This section details the installation of other third party software that are required for the 800xA System. All 800xA installation must be carried out in 800xA Installer account. Microsoft Office Professional The 800xA System supports the U.S. English, 32-bit version of the Microsoft Office Professional 2010 or 2013. 80 2PAA111708-600 F Appendix A Prerequisites Microsoft Word Microsoft Word When installing Microsoft Word it is required to select Office Shared Features from the Installation Options dialog box and to accept the default subfeatures under the Office Shared Features selection. Microsoft Word, which is part of the Microsoft Office Professional suite, must be installed on all nodes where the following functions will be used: • • • Process Graphics (for Reference Documentation Tool) Engineering Studio (for Document Manager Functions) Control Builder M (for Project Documentation Functions) This software is available from any Microsoft reseller. Follow the installation procedure described in the documentation provided by Microsoft. Macro Security for Microsoft Word Perform the following procedure for every Industrial IT User on every node, after installation of Microsoft Word and before continuing installing or working on the Engineering Platform: 1. Start Microsoft Word. 2. Click the File menu in the left corner. 3. Click Word Options to open the Word Options dialog box. 4. Select Trust Center in the left pane of the Word Options dialog box. 5. Click Trust Center Settings to open the Trust Center. 6. Select Macro Settings in the left pane of the Trust Center. 7. Select Disable all Macros Except Digitally Signed Macros in the right pane of the Trust Center. 8. Click OK to close the Trust Center. 9. Click OK to close the Word Options dialog box. 10. Repeat this procedure for every Industrial IT User on every node. 2PAA111708-600 F 81 Microsoft Excel Appendix A Prerequisites Microsoft Excel When installing Microsoft Excel 2010 or 2013 it is required to select Office Shared Features from the Installation Options dialog box and to accept the default subfeatures under the Office Shared Features selection. When installing Microsoft Excel, select the Custom installation. When the Installation Options dialog box appears. select the Visual Basic for Applications option under Shared Features. Open Microsoft Excel and perform the recommended settings, if prompted. Navigate to File > Options > General, and clear the Show the start screen when this application starts check box. Microsoft Excel, which is part of the Microsoft Office Professional suite, must be installed on all 800xA System nodes where engineering tools or Excel based reports will be used. This can include the following: • Process Graphics (for Display Documentation Tool) • Engineering Studio (for Bulk Data Manager Functions) • DataDirect - Excel Data Access • Information Management • Asset Optimization Server • Batch Management • 800xA for Harmony • 800xA for AC 870P/Melody This software is available from any Microsoft reseller. Follow the installation procedure described in the documentation provided by Microsoft. Initializing Microsoft Excel on the Information Management Servers Microsoft Excel must be initialized before the Information Management (IM) server is deployed to the IM server node. Perform the following steps for the 800xa Service account user on each node with Excel installed that will be used as an IM server: 82 1. Login as the 800xA Service User and Open MS Excel 2. Dismiss any start up dialogs and exit MS Excel 2PAA111708-600 F Appendix A Prerequisites Crystal Reports If the node is to be used as an Engineering node, follow the procedure listed in Macro Security for Microsoft Excel. Macro Security for Microsoft Excel Perform the following procedure for every Industrial IT User on every node, after installation of Microsoft Excel and before continuing installing or working on the Engineering Platform: 1. Start Microsoft Excel. 2. Click the File menu in the left corner. 3. Click Excel Options to open the Excel Options dialog box. 4. Select Trust Center in the left pane of the Excel Options dialog box. 5. Click Trust Center Settings to open the Trust Center. 6. Select Macro Settings in the left pane of the Trust Center. The macro security setting must be set to Enable all Macros for every Industrial IT User on every node in the 800xA System if any of the following are true: • 800xA for Harmony or 800xA for AC 870P/Melody is installed on any node in the 800xA System. • Engineering templates will be used on any node in the 800xA System. 7. Select Disable all Macros Except Digitally Signed Macros in the right pane of the Trust Center. 8. Click OK to close the Trust Center. 9. Click OK to close the Excel Options dialog box. Crystal Reports Crystal Reports can be used to create reports of System 800xA Data. When used with the application scheduler, the reports can be automatically executed. Crystal Reports will typically be installed on nodes where the, Information Manager, node function is allocated. However, it can be installed on any node that has access to 800xA data reporting interfaces (800xA DataDirect or ODBC). Follow the procedure to install Crystal Reports. 2PAA111708-600 F 83 Autocad Integration Appendix A Prerequisites System 800xA latest release supports Crystal Reports 2013 version. Table 8 lists the installed versions and available builds in the SAP portal. Table 8. Crystal Report Builds Build Crystal reports 2013 + Crystal Reports Runtime install (CRforVS_redist_install_32bit_13_0_14) Website It will be available as part of Crystal reports 2013 media. Download the Crystal Reports Runtime from the location specified below. • From the URL http://scn.sap.com/docs/DOC-7824 • Click 32bit.msi from MSI 32 bit column as shown in the Figure 8 to install. Figure 8. Crystal Reports Runtime Install Autocad Integration As a prerequisite to use AutoCAD for Document Manager and Parameter Manger, install AUTOCAD VBA Enabler by downloading the software from the AutoCAD website. < McAfee Integration McAfee VirusScan® Enterprise has been tested and qualified virus scanner that is used on all System 800xA servers and workstations. Refer to System 800xA 84 2PAA111708-600 F Appendix A Prerequisites Symantec Installing and Configuring McAfee ePO Server (9ARD107543-005), for more information. McAfee need not be disabled during installation, however this might impact Installation performance of 800xA Software. Symantec Symantec Endpoint Protection (SEP) has been tested and qualified virus scanner that is used on all System 800xA servers and workstations. Refer to System 800xA Using Symantec Endpoint Protection (9ARD119854-002), for more information. Bulk SPL Template To work with ABB Engineering Studio BulkSPLTemplate, perform the following: 1. Download and install the following software from Microsoft website: Microsoft Visual Studio 2010 Tools for Office Runtime (x64). During the VSTO installation following message may be displayed: Files in use Some files that need to be updated are in use by the applications shown below. Close these applications and click Retry to continue the installation. Selecting Ignore will result in a reboot at the end of installation. Select cancel to exit setup. Click Ignore to complete the installation. 2. 2PAA111708-600 F If VSTO is not installed before Engineering Studio installation, perform the following steps: a. Follow Step 1 to install VSTO. b. Open Command Prompt as Administrator and execute the following: "C:\Program Files (x86)\ABB Industrial IT\Engineer IT\Engineering Studio\Function Designer\bin\BulkSPLbin\BulkSPLInstall.exe" "C:\Program Files (x86)\ABB Industrial IT\Engineer IT\Engineering Studio\\" 85 Process Engineering Tool Integration Specific Requirements Appendix A Prerequisites Process Engineering Tool Integration Specific Requirements The following are requirements that exist only for Process Engineering Tool Integration. Before installing Process Engineering Tool Integration software, install the following prerequisites, if required: • INtools/SPI: Must be installed on a non-800xA node. If installing the Web Services component on this node, Microsoft IIS with FrontPage server extensions must be installed. • For viewing external CAD drawings, one of the following software components is required to be installed on the 800xA System node on which the 800xA Client component of Process Engineering Tool Integration is installed: – DWG TrueView 2015: Recommended to be used for viewing of AutoCAD files. The latest version of DWG TrueView 2015 can be downloaded free of charge at http://www.autodesk.com Backup Software It is recommended that a third party backup/restore and/or disk imaging utility be used to save (and restore if necessary) server and workstation hard drives. A valid backup insures that the system can be restored. 86 2PAA111708-600 F Appendix B Installation and Configuration Parameters Acquiring Installation and Configuration Parameters This section provides guidelines for acquiring the information needed for installation with regard to network parameters, software keys, and so on. Gather the required installation media needed to complete the installation, and confirm that all required hardware is in place and meets the system requirements. An organization should be in place to manage the domain with assigned responsibilities and methods handling users and security. Before installing and configuring (post installation) the 800xA System, there are several parameters and system settings whose values must be determined and available. Table 9 provides a worksheet for recording this information. It lists node types and their applicable parameters, and provides a Value column for recording the information. 2PAA111708-600 F 87 Acquiring Installation and Configuration Parameters Appendix B Installation and Configuration For guidelines on parameters related to network and domain setup, refer to System 800xA Network Configuration (3BSE034463*). Table 9. Installation and Configuration Parameter Worksheet Node Type All Nodes PC Nodes AC 800M Controllers Domain Server DNS Server Aspect Server 88 Parameter 800xA Installer Account name System Functions Node Functions Primary IP address Secondary IP address Subnet mask Node name Time sync protocols Time sync role and configuration (per protocol) RNRP network area, node number, and local flag DNS Server addresses Primary CPU primary and secondary IP address Backup CPU primary and secondary IP address Tool port IP address Communication modules IO modules Domain name User Groups Users Concept of 800xA roles and permissions on system, structures, and aspect object level Network adapter type Backup needs IP address of primary Affinity - Aspect Server Base Service Affinity - Aspect Server node name of clients Affinity - node name of redundant Aspect Servers Network adapter type Affinity - Connectivity Server Base Service Affinity - Connectivity Server node name of clients Affinity - node name of parallel Connectivity Server Value 2PAA111708-600 F Appendix B Installation and Configuration Parameters Acquiring Installation and Configuration Table 9. Installation and Configuration Parameter Worksheet (Continued) Node Type FIELDBUS Foundation Connectivity Server Parameter HSE Subnet address(es) Value HSE Subnet Id(s) 800xA for AC AF 100 Bus number 100 CI527A Station number Path to BCD file IP address for redundant server node (optional) 800xA for Network Group number Advant MB 300 network number1 Master MB 300 network number2 MB 300 node number Network interface IP address in PC used for PU410. Since the RTA unit default IP addresses are 172.16.168.50 and 172.17.168.50, do not configure network area 10 in the RNRP client/server topology. If the client server topology is configured as network area 10, the default IP address of the RTA unit must be changed as described in 800xA for Advant Master Configuration (3BSE030340*). Connectivity Server (Managed) Switches Disk Image Network adapter type IP address Server IP address Session names Backup identities and filenames 2PAA111708-600 F 89 Acquiring Installation and Configuration Parameters Appendix B Installation and Configuration Table 9. Installation and Configuration Parameter Worksheet (Continued) Node Type Parameter 800xA for MOD 300 RTA Unit Since the RTA unit default IP addresses are 172.16.168.50 and 172.17.168.50, do not configure network area 10 in the RNRP client/server topology. If the client server topology is configured as network area 10, the default IP address of the RTA unit must be changed as described in Industrial IT, System 800xA for MOD 300 - RTA Unit PU410 and PU412 User’s Guide, Technical Data and Installation Information (3BUA001442*). 800xA for Harmony IP addresses of IET Modules 800xA for Melody Onet IP address Value Melody Configuration Server Name 800xA for DCI ECC MUX IP address 90 2PAA111708-600 F Appendix C Related Documentation A complete list of all documents applicable to the 800xA System is provided in System 800xA Released User Documents (3BUA000263*). This document lists applicable Release Notes and User Instructions. It is provided in PDF format and is included on the Release Notes/Documentation media provided with your system. Released User Documents are updated with each release and a new file is provided that contains all user documents applicable for that release with their applicable document number. Whenever a reference to a specific instruction is made, the instruction number is included in the reference. Table 10. Related Documentation Item Where to go... When to go... [1] System 800xA 6.0 Release Notes New Functions and Known Problems (2PAA111899*) Used for information on the new functions and known problems that exist at the time of release. [2] System 800xA 6.0 Release Notes Resolved Issues (2PAA112277*) Used for information on the issues that have been fixed at the time of release. [3] System 800xA System Guide Technical Used to help plan the 800xA System Data and Configuration (3BSE041434*) based on the configuration rules and node functions. [4] System 800xA Site Planning (3BUA000285*) Used for site planning, preparation, power distribution, system grounding, and wiring practices for an 800xA System control system. [5] System 800xA System Planning (3BSE041389*) Used as a guideline for the engineering planning to be used in the early phases of a System 800xA project. 2PAA111708-600 F 91 Appendix C Related Documentation Table 10. Related Documentation Item Where to go... When to go... [6] System 800xA Licensing Information (2PAA111691*) Used to know more about the licensing mechanisms used in System 800xA such as, obtaining the machine IDs and licenses and applying the licenses. [7] System 800xA 6.0 Tools (2PAA101888*) Used to know more about the tools used to install, configure and verify an 800xA system. [8] System 800xA Network Configuration (3BSE034463*) Used to plan and setup the network topology. [9] System 800xA 6.0 Virtualization (3BSE056141*) Used to gain an overview of System 800xA virtualization. It helps plan for combining multiple 800xA Server nodes on a single computer. [10] System 800xA 6.0 Multisystem Integration (3BSE037076*) Used to install, configure, operate and maintain the 800xA Multisystem Integration system extension. [11] System 800xA 6.0 Post Installation (2PAA111693*) Used to carry out the manual post installation steps of System 800xA. [12] System 800xA 6.0 Configuration (3BDS011222*) Used to gain an overview on engineering and configuration workflow steps of the System 800xA in the context of an engineering project. Control [13] 92 System 800xA Control 6.0 AC 800M Getting Started (3BSE041880*) Used to get started with the Control Builder Professional for AC800M. 2PAA111708-600 F Appendix C Related Documentation Table 10. Related Documentation Item [14] Where to go... System 800xA Control 6.0 AC 800M Planning (3BSE043732*) When to go... Used as a guideline of what to consider when designing an automation solution using Control Software for AC 800M, such as memory consumption, CPU load, and task execution. The manual also contains advice to programmers regarding optimization of code. AC800M [15] AC 800M 6.0 AC 800M DriveBus (3BSE079696*) Used for installation and start-up of the CI858 communication interface. [16] AC 800M 6.0 FOUNDATION Fieldbus HSE (3BDD012903*) Used for configuration of control applications with FOUNDATION Fieldbus HSE using the CI860 module along with HSE Linking Devices and Fieldbus Builder FOUNDATION Fieldbus as FOUNDATION Fieldbus configuration tool. [17] AC800M 6.0 PROFIBUS DP Installation Used for application notes and advice (3BDS009029*) for wiring and installation of PROFIBUS networks. [18] AC 800M 6.0 PROFIBUS DP Configuration (3BDS009030*) Used for configuration of the PROFIBUS DP-V1 in the 800xA control system using CI854/CI854A/CI854B communication interface. [19] AC 800M 6.0 PROFINET IO Configuration (3BDS021515*) Used to configure PROFINET IO in the 800xA control system using the communication interface CI871. [20] AC 800M 6.0 Controller Hardware (3BSE036351*) Used to install, configure, operate and perform the necessary maintenance on all equipment making up the AC 800M or AC 800M HI controllers. 2PAA111708-600 F 93 Appendix C Related Documentation Table 10. Related Documentation Item Where to go... When to go... [21] AC 800M 6.0 Interfacing SATT I/O (3BSE042821*) Used to install the new hardware required on the field level, prepare for installation of the new controller on AC 800M and reuse the old SATT I/O units. [22] AC 800M 6.0 Ethernet/IP DeviceNet Installation (9ARD000015*) Used for application notes and procedures provided for the wiring and installation of DeviceNet networks. [23] AC 800M 6.0 IEC 61850 Configuration for CI868 (9ARD171385*) Used for engineering and configuration of the CI868 IED using Control Builder, IEC 61850 Wizard tool and other third party tool. [24] S900 I/O Manual DTM 6.0 (3BDD010407*) Used for installation and operation of the DTMs for S900 I/O and control systems. [25] S900 I/O S and N System with SA920 Installation (3BDD010421R0401) Used for mounting and installation procedures for S900 I/O System type S and type N. [26] S900 I/O Manual Installation-Guide S-N- Used for issues related to the installation of the I/O System S900. System SA920 CI920A (3BDD010421R0601*) [27] S900 I/O B-System with SA920 Installation (3BDD010432R0401*) Used for mounting and installation procedures for I/O System S900 type B. [28] S900 I/O Manual Installation-Guide BSystem SA920 CI920A (3BDD010432R0601*) Used for issues related to the installation of the I/O System S900 type B. [29] S800 I/O Getting Started (3BSE020923*) Used for general installation and configuration information for the S800 I/O system. [30] S800 I/O Modules and Termination Units Used for more information on S800 I/O (3BSE020924*) modules and termination units. IO 94 2PAA111708-600 F Appendix C Related Documentation Table 10. Related Documentation Item Where to go... When to go... [31] S800 I/O Fieldbus Communication Interface for PROFIBUSDP/DPV1(3BSE020926*) Used for more information on PROFIBUS-DP FCI in the S800 I/O system. [32] S800 I/O Modules and Termination Units Used to get information on the I/O with Intrinsic Safety Interface modules and termination units with I.S. (3BSE020927*) interface in the S800 I/O system. [33] S800 I/O DTM 6.0 (3BSE027630*) Used for instructions for installation and for operation of the DTMs in S800 I/O. [34] S200 I/O Hardware (3BSE021356*) Used to install, configure and maintain the S200 I/O system. [35] S200L I/O Hardware (3BSE021357*) Used to install, configure and maintain Compact I/O (S200L I/O and I/O 200C units). 800xA for TRIO [36] 800xA for TRIO/Genius 6.0 Getting Started (3BUR002459*) Used to install the CI862 TRIO/Genius Interface, connect TRIO/Genius I/O modules and considerations to migrate from the MOD 300 control system. 800xA for Advant Master [37] 800xA for Advant Master 6.0 Configuration (3BSE030340*) Used to connect the workplaces to a MasterBus 300 control network with connected AC 400 Controller Series, including MasterPiece 200/1, using 800xA for Advant Master. 800xA for Safeguard [38] 800xA for Safeguard 6.0 Configuration (3BNP004848*) Used to set up the safety system functionality (including defining displays, configuring control parameters etc.) and the safety system configuration. Operations 2PAA111708-600 F 95 Appendix C Related Documentation Table 10. Related Documentation Item Where to go... When to go... [39] System 800xA Operations 6.0 (3BSE036904*) Used to understand the 800xA Operator Workplace. [40] System 800xA 6.0 Snapshot Reports User Guide (3BSE060242*) Used to install, set up, configure and maintain the 800xA for Snapshot Report system extension. [41] VideoNet Connect for 800xA User Manual (2PAA109407*) Used to install, configure, and operate the VideoNet Connect for 800xA product that is a system extension to the 800xA system. 800xA for AC 100 [42] 800xA for AC 100 6.0 Configuration and Used to configure System 800xA in Operation (3BDS013989*) order to view and access the Advant Controller 100 Series objects. Hints for operation and maintenance is also included in this document. [43] AC 100 OPC Server 6.0 Configuration and Operation (3BDS013988*) Used to configure the AC 100 OPC Server, configure and build applications for controllers of AC 100 Series using the AC 100 OPC Server. Use for information on runtime and maintenance of the AC 100 OPC Server. 800xA for Freelance [44] 800xA 6.0 for Freelance Installation (3BDD011810*) Used to install and upgrade the connectivity software 800xA for Freelance. 800xA History [45] 800xA History 6.0 Installation (2PAA107280*) Used to install the History components using the History installer. 800xA Engineering 96 2PAA111708-600 F Appendix C Related Documentation Table 10. Related Documentation Item [46] Where to go... System 800xA Engineering 6.0 Application Change Management (2PAA108438*) When to go... Used to install and configure the Application Change Management (ACM) server. Reference manuals [47] System 800xA System Alarm Messages Used to find the System Alarms that are (2PAA114623*) generated when operating an 800xA System. 2PAA111708-600 F 97 Appendix C Related Documentation 98 2PAA111708-600 F Revision History This section provides information on the revision history of this User Manual. The revision index of this User Manual is not related to the 800xA 6.0 System Revision. The following table lists the revision history of this User Manual. Revision Index Description Date A Published for 800xA System Version 6.0 B December 2014 Added section on Installation process for 800xA System Version 6.0 and included information on accessing the System 800xA media from a virtual machine. C Added section for information on System Upgrade April 2015 support in this release. D Moved the Prerequisites section to the Appendix, October 2015 included the update workflow in this release and added the guidelines for acquiring the information needed for installation with regard to network parameters, software keys, and so on. E Added information on System 800xA Media; October 2015 included a section on installing the .NET hotfix and Excluding a node. F Updated a cross reference in Appendix A Prerequisites 2PAA111708-600 F December 2014 January 2016 99 100 2PAA111708-600 F Index Numerics 800xA service user Adding privileges 79 A Adding 800xA domain users 67 Adding nodes to domain 54 Adding privileges to 800xA service user 79 Automatic updates 73 B Backup software 86 D Default user groups and users 60 Defragmenting disks 43 Disks and file system 42 E Energy saver 72 Excel 82 M Microsoft Excel 82 Microsoft Word 81 N F Network adapters 45 G Other Third Party Software 80 File system 42 Groups 55 I IE enhanced security configuration 71 Installation Directory 43 Prerequisites Adding 800xA domain users 67 2PAA111708-600 F Adding nodes to domain 54 Adding privileges to 800xA service user 79 Backup software 86 Microsoft Excel 82 Microsoft Word 81 Miscellaneous Windows setup 68 Network adapters 45 Remote client 79 Terminal server 79 Users and groups 55 Windows 41 Windows installation guidelines 44 Installation data 87 Installation planning Planning and preparation 87 Installation data 87 O P Planning and preparation 87 Installation data 87 Preparing the node 25 101 Index R Remote client 79 T Terminal server 79 U User groups and users Default 60 Users 55 W Windows operating system 41 Installation guidelines 44 Miscellaneous setup 68 Word 81 102 2PAA111708-600 F www.abb.com/800xA www.abb.com/controlsystems Copyright © 2016 ABB. All rights reserved. Power and productivity for a better worldTM 2PAA111708-600 F Contact us