{"product_id":10409,"v_id":10409,"product_name":"3eTI Airguard Wireless Network Access System","certification_status":"Not Certified","certification_date":"2011-08-19T00:08:00Z","tech_type":"Wireless LAN","vendor_id":{"name":"3e Technologies International, Inc.","website":"http://www.3eti.com/"},"vendor_poc":"Chris Guo","vendor_phone":"301-944-1294","vendor_email":"chris.guo@ultra-3eti.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>The Target of Evaluation (TOE) is a system of wireless LAN Access Point products that includes one or more 3e-525A-3, 3e-525A-3EP, 3e-525A-3MP, 3e-525-V-3, 3e-525VE-4, 3e-523-F2 and 3e-523-3 Access Points (APs) and the optional 3eTI Security Server.&nbsp;&nbsp;&nbsp;</p>\r\n<p>There are two evaluated configurations of the TOE:</p>\r\n<ol>\r\n<li><strong>Access      Point(s) and 3eTI Security Server: </strong>In this configuration, the 3eTI      Security Server is included, which serves as the Authentication Server for      the TOE. This is the primary configuration of the TOE.</li>\r\n<li><strong>Access      Point(s) only</strong>: In this configuration, the TOE does not include the      3eIT Security Server, and the TOE relies upon an Authentication Server in      the Operational Environment. </li>\r\n</ol>\r\n<p>The Access Points require that a wireless client be authenticated before accessing the network and provides data encryption/decryption and integrity protection between the wireless link and the wired LAN.&nbsp; All Access Points are ruggedized devices intended for use in industrial and outdoor environments.&nbsp;</p>\r\n<p>The 3eTI Security Server performs the Authentication Server (AS) function identified by IEEE 802.1x. The role of the AS is to verify the credentials of a wireless client known as the supplicant before the client is granted access to the network.&nbsp;</p>\r\n<p style=\"padding-left: 90px;\">An Access Point only TOE relies upon an external RADIUS Authentication Server, an NTP Server and an Audit Server in its Operational Environment. The TOE may also be configured to interface with DHCP and SNMP Management Servers in the Operational Environment, but does not depend upon them to support its security functionality.&nbsp;</p>\r\n<p>The second configuration of the TOE includes the 3eTI Security Server. The 3eTI Security Server is installed on a Linux platform.&nbsp; The Security Server communicates with a Lightweight Directory Access Protocol (LDAP) Server to download CA certificates and Certificate Revocation Lists.&nbsp; If so configured, the Security Server can communicate with an Online Certificate Status Protocol (OCSP) Responder to determine if a user&rsquo;s certificate is still valid.&nbsp; The TOE also relies upon a NTP Server and Audit Server in the Operational Environment.&nbsp; The TOE may also be configured to interface with DHCP and SNMP Management Servers in the Operational Environment, but does not depend upon them to support its security functionality.&nbsp;</p>","evaluation_configuration":"<p>The TOE physical boundary defines all hardware and software that is required to support the TOE&rsquo;s logical boundary and the TOE&rsquo;s security functions.</p>\r\n<p>The TOE includes the following Access Points appliance models:</p>\r\n<ul>\r\n<li>3e-525-A-3 Access Point; Hardware Version      2.0(A) and 2.1, Firmware Version 4.4</li>\r\n<li>3e-525-A-3EP Access Point; Hardware      Version 2.1, Firmware Version 4.4</li>\r\n<li>3e-525A-3MP Access Point; Hardware Version      2.0(A) and 2.1, Firmware Version 4.4</li>\r\n<li>3e-525-V-3&nbsp;&nbsp; Access Point; hardware version 2.0(A)      and 2.1, Firmware Version 4.4</li>\r\n<li>3e-525-VE-4 Access Point; hardware version      2.0(A) and 2.1, firmware version 4.4</li>\r\n<li>3e-523-F2 Access Point; hardware version      1.0, 1,1, 1.2, and 2.0; firmware version 4.4 </li>\r\n<li>3e-523-3 Access Point, hardware version      1.0, 1,1, 1.2, and 2.0; firmware version 4.4 </li>\r\n</ul>\r\n<p>The TOE also includes the software only 3eTI Security Server:</p>\r\n<ul>\r\n<li>3e-030-2 Security Server </li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R3.</p>\r\n<p>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 R2.</p>\r\n<p>CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of Evaluation Assurance Level (EAL) 4 augmented with ALC_FLR.2.</p>\r\n<p>A team of validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in July 2011.</p>","environmental_strengths":"<p>The following security functions are in the scope of the evaluation:</p>\r\n<ul>\r\n<li><strong>Audit</strong></li>\r\n</ul>\r\n<ul>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The TOE generates auditable events for actions on the APs with the capability of selective audit record generation. The records of these events can be viewed within the TOE Management Interface or they can be exported to audit systems in the Operational Environment. The TOE generates records for its own actions, containing information about the user/process associated with the event, the success or failure of the event, and the time that the event occurred. Additionally, all administrator actions relating to the management of TSF data and configuration data are logged by the TOE&rsquo;s audit generation functionality.</p>\r\n<ul>\r\n<li><strong>Cryptographic Services</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The TOE implements the following cryptographic algorithms: AES, RSA, SHA, HMAC, and a random number generator.</p>\r\n<ul>\r\n<li><strong>User Data Protection</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The Access Point Component provides user data protection by encrypting/decrypting authenticated user data between the wireless client and the Access Point.&nbsp; The Security Server provides user data protection in the form of a certificate path validation capability that includes Certificate Revocation Lists checking and an Online Certificate Status Protocol client.&nbsp; The TOE provides X.509 public key certificate verification.</p>\r\n<ul>\r\n<li><strong>Identification and Authentication</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The TOE provides Identification and Authentication security functionality to ensure that all wireless clients/users and administrators are properly identified and authenticated before accessing TOE functionality. The wireless user can be authenticated either by the TOE (via the Security Server) or via a trusted RADIUS server in the Operational Environment.&nbsp; The administrator is authenticated locally with a username and password.&nbsp;</p>\r\n<ul>\r\n<li><strong>Management</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The Web Management Application of the TOE provides the capabilities for an authorized administrator to modify, edit, and delete security parameters such as audit data, configuration data, and user authentication data.&nbsp; The Web Management Application also offers an authorized administrator the capability to manage security functions; for example: enable/disable certain audit functions, query and set encryption/decryption algorithms for network packets, change cryptographic keys and allow/disallow the use of a remote authentication server.&nbsp; The Security Server is managed by the Remote Management GUI.</p>\r\n<ul>\r\n<li><strong>Protection of the TSF</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">The TOE protects the TSF by ensuring that no access is granted to TOE functions without authorization. By controlling a user session and the actions carried out during a user session, the TOE provides for non-bypassability and domain separation of functions. Internal testing of the TOE hardware and software against tampering ensures that all security functions are running and available before the TOE will accept any communications.</p>\r\n<ul>\r\n<li><strong>TOE Access</strong></li>\r\n</ul>\r\n<p style=\"padding-left: 30px;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The TOE provides the following TOE Access functionality:</p>\r\n<ul style=\"padding-left: 30px;\">\r\n<li>&nbsp;  \r\n<ul>\r\n<li>Configurable MAC&nbsp; address and/or IP address filtering with      remote management session establishment &nbsp;</li>\r\n<li>TSF-initiated session termination when a      connection is idle for a configurable time period</li>\r\n<li>TOE Access Banners </li>\r\n</ul>\r\n</li>\r\n</ul>","features":[]}