Compliant Product - Check Point VPN-1 Power/UTM NGX R65
Certificate Date: 25 March 2009
Validation Report Number: CCEVS-VR-VID10329-2009
Product Type: Firewall, IDS/IPS, VPN
Conformance Claim: EAL4 Augmented with
US Department of Defense Application-Level Firewall Protection Profile for Medium Robustness Environments, Version 1.0
US Department of Defense Traffic-Filter Firewall Protection Profile for Medium Robustness Environments, Version 1.4 (Archived)
Intrusion Detection System System Protection Profile, Version 1.6, dated April 4, 2006 (Archived)
CC Testing Lab: SAIC Common Criteria Testing Laboratory
The TOE is one or more network boundary devices managed remotely by a management server, using management GUI interfaces. The product provides controlled connectivity between two or more network environments. It mediates information flows between clients and servers located on internal and external networks governed by the firewalls.
The claimed security functionality described in the Security Target is a subset of the product's full functionality. The evaluated configuration is a subset of the possible configurations of the product, established according to the evaluated configuration guidance.
The security functionality within the scope of the evaluation included information flow control using stateful inspection and application proxies, IKE/IPSec Virtual Private Networking (VPN) and SSL VPN in both gateway to gateway and Remote Access configurations, Intrusion Detection and Prevention (IDS/IPS). Additionally, the TOE provides auditing and centralized management functionality
Check Point VPN-1 Power/UTM NGX R65 with HFA 30
Hardware/Operating System Identification:
The evaluated configuration consists of TOE security policy enforcement software running on any of the appliance platforms and operating system combinations listed in Appendix A – TOE Hardware Platforms. This includes the following classes of appliances:
- Check Point Power-1 and UTM-1 security appliances
- Open Servers supporting the Check Point SecurePlatform operating system
- Nokia Firewall/VPN appliances
Management software is always installed on a separate platform running the Check Point SecurePlatform operating system, selected from the list given in Section A. The platform selected for this purpose is not used for TOE identification.
The software also includes a Management GUI product (SmartConsole) that is installed on a standard PC (outside the TOE) running a Microsoft Windows operating system. The evaluated version is: SmartConsole NGX R65 with HFA 01.
Support Program Identification:
Enterprise Software Subscription
 The TOE software identification is a combination of the product name (Check Point VPN-1 Power/UTM), the product version (NGX R65), and a Hot Fix Accumulator (HFA) number. This combination uniquely identifies a software build for each of the supported appliance classes. Throughout this document, the product is referred to as Check Point VPN-1 Power/UTM, omitting the HFA number identified here.
 Enterprise Software Subscription is required for receiving software upgrades, as part of Check Point’s flaw remediation procedures. Note that Enterprise Software Subscription is a prerequisite to purchasing all Check Point Enterprise Support Programs.
SECURITY EVALUATION SUMMARY
The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the TOE meets the security requirements contained in the Security Target. The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the TOE is EAL 4 augmented with ALC_FLR.3. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target. Several validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in February 2009. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Check Point VPN-1 Power/UTM NGX R65 HFA 30 prepared by CCEVS.
Check Point VPN-1 Power/UTM NGX R65 HFA 30 is a commercial network perimeter device that provide information flow control, security management, Protection of the TSF, cryptographic functionality, audit security functions, and explicit intrusion detection functionality. Check Point VPN-1 Power/UTM NGX R65 HFA 30 provides a level of protection that is appropriate for IT environments that require that information flows be controlled and restricted among network nodes where the Check Point components can be appropriately protected from physical attacks.