{"product_id":10116,"v_id":10116,"product_name":"Cisco IOS IPSec on the Integrated Services Routers, VPN Services Module (VPNSM) and IPSec VPN Shared Port Adapter (SPA), including VLAN Separation","certification_status":"Not Certified","certification_date":"2008-05-31T00:05:00Z","tech_type":"Network Switch, Router","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":null,"vendor_phone":"+1 410 309 4862","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Arca CCTL"},"product_description":"<p><span style=\"font-size: 10pt\">The TOE consists of hardware and software used to construct Virtual Private Networks (VPNs) between networks or a remote access client.&nbsp;The TOE is made up of a Cisco router or Catalyst 6500 switch, inclusive of IOS software and hardware modules used to accelerate the performance of the IPSec protocol.&nbsp;The included Cisco hardware provides options for deploying VPNs from the small office to the large Enterprise.&nbsp;IPSec provides confidentiality, authenticity and integrity for IP data transmitted between trusted (private) networks or remote clients over untrusted (public) links or networks.</span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p>&nbsp;</p>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 10pt\">The evaluation was carried out in accordance with the Arca Common Criteria Test Laboratory processes and procedures that are compliant with the Common Criteria Evaluation and Validation Scheme (CCEVS). The evaluation demonstrated that Cisco IOS-IPSec meets the security requirements contained in the Security Target.&nbsp;The criteria against which the Cisco IOS-IPSec TOE was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3 Parts 2 and 3 and the International Interpretations effective on 8 August 2005.&nbsp;The evaluation methodology used by the Evaluation Team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3.&nbsp;Arca CCTL determined that the evaluation assurance level (EAL) for the product is EAL 4 set of assurance components augmented with ALC_FLR.1.&nbsp;The product, when configured as specified in the installation guide, satisfies all of the security functional requirements stated in the IOS-IPSec Security Target, Version 1.0.&nbsp;The evaluation was completed in April 2008. Results of the evaluation can be found in the Validation Report prepared by the National Information Assurance Partnership (NIAP) CCEVS Validation Team.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<p><span style=\"font-size: 10pt\">For this evaluation, it was appropriate for the Security Target to claim compliance with the external standard for FIPS 140 for the definition of the encryption algorithm. There are many ways of determining compliance with a standard. Cisco IOS IPSec has chosen to make a developer claim of compliance. This means that there has been no independent verification (by either the evaluators or a third party standards body, such as a FIPS laboratory) that the implementation of the cryptographic algorithms actually meets the claimed standards. Potential users of this product should confirm that the cryptographic capabilities are suitable to meet the user's requirements.</span></p>","environmental_strengths":"<p>&nbsp;</p>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 10pt\">The TOE provides confidentiality, authenticity and integrity for IP data transmitted between a combination of Cisco Systems routers, Catalyst switches, and VPN clients (located in IT Environment).</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Specifically, the TOE ensures:</span></div>\r\n<ul style=\"margin-top: 0pt\" type=\"disc\">\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Packet flows are received/transmitted from/to known, trusted sources.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">The confidentiality of packet flows is maintained during transmission.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Packet flows cannot be modified without being detected by the TOE.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Protection of cryptographic keys stored within the TOE.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Packet flows transmitted to the TOE has not been copied by an eavesdropper and retransmitted to the TOE<b>.</b></span></li>\r\n</ul>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Consumers of the product are expected to do the following:</span></div>\r\n<ul style=\"margin-top: 0pt\" type=\"disc\">\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Place the TOE in a controlled access facility that mitigates unauthorized physical access.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Ensure administrators identify which interfaces are to be considered untrusted and trusted. An untrusted interface is one that is connected to an untrusted network over which the administrator wishes to send and receive trusted traffic protected by IPSec encryption.&nbsp;</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Ensure that administrators have been trained to securely configure the TOE.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">If the TOE is configured to use digital certificates, the issuing CA is trusted or evaluated to at least the same level as the TOE.&nbsp;This trusted CA must support 3DES for encryption.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Pre-shared keys are securely communicated between disparate administrators.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Ensure the VPN external IT entity is able to encrypt data transmitted to the TOE and decrypt data received from the TOE in accordance with the negotiated IKE/IPSec policy for the established VPN tunnel.</span></li>\r\n    <li style=\"margin: 0pt\"><span style=\"font-size: 10pt\">Ensure remote management is initiated from a management station connected to a trusted network and protected using the security functions of the TOE.</span></li>\r\n</ul>","features":[]}