Validated Product - CyberGuard Firewall/VPN Version 6.1.2Certificate Date: 24 June 2005 Validation Report Number: CCEVS-VR-05-0104 Product Type: Firewall Conformance Claim: EAL4 Augmented with ALC_FLR.3
PP Identifiers:
US Department of Defense Application-Level Firewall Protection Profile for Basic Robustness Environments, Version 1.0
(Archived) CC Testing Lab: CygnaCom Solutions, Inc PRODUCT DESCRIPTIONCyberGuard Firewall/VPN Product represents integrated firewall appliances that utilize hybrid firewall architecture, consisting of packet filtering and application proxy techniques to inspect, control and protect the flow of network traffic in and out of an organization’s network and to protect the integrity of organizations’ internal networks. It consists of CyberGuard Firewall/VPN version 6.1.2 software, CG Linux Version 6.1.2 kernel enhancements, Authentication Server, Management Station and the CG compliance tested hardware (CyberGuard Firewall/VPN Appliances). Currently the following configurations of the CG Compliance Tested Hardware are available:
All the models run the CGLinux 6.1.2 operating system and the CyberGuard Firewall/VPN 6.1.2 software with the same core features and therefore provide the same security functionality. The Authentication Server that is used for single-use password authentication for the ftp and telnet proxies as require by the protection profiles is the ‘RSA Authentication Manager Version 6.0’ that interacts with the ‘CyberGuard Firewall/VPN version 6.1.2 ’ via the RADIUS authenticator plug-in module. In the evaluated version of the TOE the ‘Authentication Server’ shall be dedicated for single use authentication of users and shall not be connected/interfaced to any other network or product. The CyberGuard Firewall/VPN version 6.1.2 software and CG Linux Version 6.1.2 kernel enhancements together provide controlled and audited access to services, both from inside and outside an organization’s network, by inspecting and allowing, denying and/or redirecting the flow of data (IP packets) that pass through the barrier and protection against bypassibility. The CG Firewall/VPN version 6.1.2 software provides the following:
The components of the CG Linux version 6.1.2 operating system that are part of the evaluated TOE are the enhancements that help the operating system achieve the following:
The Management Station GUI utilizes Microsoft Internet Explorer (IE) revision 6.0 or above as a front-end to display the configurable features of the TOE so that the site security policy can be implemented. The GUI features a modular design and although it presents many default secure options, it also enables the administrator to define objects and utilize those objects in defining the rule set that will represent the security policy for the TOE. SECURITY EVALUATION SUMMARYThe evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL 4 augmented by ALC_FLR.3. A team of validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in June 2005. ENVIRONMENTAL STRENGTHSThe CyberGuard Firewall/VPN version 6.1.2 sits as a barrier between an organization's network and external networks. It provides controlled and audited access to services, both from inside and outside an organization's network, by inspecting and allowing, denying and/or redirecting the flow of data (IP packets) that pass through the barrier. The management station, Firewall hardware and the single use authentication server should be afforded appropriate protection from physical attack. Secure Computer Corporation (Formerly Cyberguard Coporation) Soheila Amiri954.375.3611 samiri@securecomputing.com |