{"product_id":10480,"v_id":10480,"product_name":"BlueCat Networks Adonis DNS/DHCP Appliance Version 6.7.1-P3 and Proteus IPAM Appliance Version 3.7.2-P2","certification_status":"Certified","certification_date":"2013-08-09T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"BlueCat Networks™ (USA) Inc.","website":"http://www.bluecatnetworks.com"},"vendor_poc":"Branko Miskov, Director, Product Management","vendor_phone":"416-646-8398","vendor_email":"bmiskov@bluecatnetworks.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>The Target of Evaluation (TOE) is BlueCat Networks<em> </em>Adonis DNS/DHCP Appliance - and Proteus IPAM Appliance. The TOE is an IP Address Management (IPAM) Solution, which provides network management of an organization&rsquo;s IP infrastructure along with DNS and DHCP core services.</p>\r\n<p>&nbsp;</p>\r\n<p>The BlueCat Networks Proteus IPAM Appliance provides organizations with a scalable platform to manage their IP infrastructure. Proteus tightly integrates IP Address Management (IPAM), DNS and DHCP. The Proteus IPAM Appliance gives enterprises the ability to centrally manage, monitor and administer their entire IP address and DNS name spaces. Proteus also allows organizations to manage change and growth with support for both IPv4 and IPv6 networks and DNSSEC.</p>\r\n<p>&nbsp;</p>\r\n<p>The BlueCat Networks Adonis DNS/DHCP Appliances deliver DNS and DHCP core services. The Adonis Appliances enable organizations to streamline the implementation and management of complex DNS and DHCP infrastructures in IPv4 and IPv6 networks. Adonis also supports DNSSEC.</p>\r\n<p>&nbsp;</p>\r\n<p>The evaluated configuration includes the following:</p>\r\n<p>&nbsp;</p>\r\n<ul>\r\n<li>Adonis      DNS/DHCP Appliance Version 6.7.1-P3 </li>\r\n<li>Proteus      IPAM Appliance Version 3.7.2-P2 </li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p>All appliance hardware and the software installed on the appliances are included in the TOE.</p>\r\n<p>&nbsp;</p>\r\n<p>The evaluated configuration consists of a Proteus IPAM Appliance managing two or more Adonis DNS/DHCP Appliances.</p>","evaluation_configuration":"","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R3.</p>\r\n<p>&nbsp;</p>\r\n<p>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 R3.</p>\r\n<p>&nbsp;</p>\r\n<p>CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of Evaluation Assurance Level (EAL) <em>2</em> augmented with augmented with ALC_FLR.1.</p>\r\n<p>&nbsp;</p>\r\n<p>A team of validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in August 2013.</p>","environmental_strengths":"<p><strong>Security Audit</strong><strong> Functions</strong></p>\r\n<p><strong><br /></strong></p>\r\n<p>The TOE is able to audit the use of the administration/management functions. This function records successful and failed authentication of TOE users, as well as the actions taken by TOE users once they are authenticated. The TOE also audits system events.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE can be configured to send an alarm when a designated system event occurs.</p>\r\n<p>&nbsp;</p>\r\n<p>The audit data is protected by the access control mechanisms of the OS of the TOE components and by the TOE management interface. Only users with direct access to the appliances&rsquo; OS have access to the audit records. Authorized users can view and sort the audit records via the TOE management interface.</p>\r\n<p>&nbsp;</p>\r\n<p>NOTE: If the environment requires long-term storage of audit records, then the TOE should be configured to offload audit records to an external Syslog server for external storage. The TOE also supports an administrative function that allows for the manual downloading of audit trails for off appliance long-term storage.</p>\r\n<p>&nbsp;</p>\r\n<p><strong>Identification and Authentication</strong><strong> Functions</strong></p>\r\n<p><strong><br /></strong></p>\r\n<p>The TOE requires all users to provide unique identification and authentication data before any access to the TOE is granted. User identification and authentication is done by the TSF through username/password authentication or optionally by an external authentication server.</p>\r\n<p>&nbsp;</p>\r\n<p>All authorized TOE users must have a user account with security attributes that control the user&rsquo;s access to TSF data and management functions. These security attributes include user name, password, and level(s) of authorization (roles, privileges, access rights) for TOE users.</p>\r\n<p>&nbsp;</p>\r\n<p>Identification and Authentication depends on the Operational Environment to provide an external authentication server if that feature is configured. It also depends on the Operational Environment to provide secure communications between the TOE and the external authentication server.</p>\r\n<p>&nbsp;</p>\r\n<p><strong>Security Management</strong><strong> Functions</strong></p>\r\n<p><strong><br /></strong></p>\r\n<p>The TOE provides a web-based management interface for all run-time TOE administration. The ability to manage various security attributes, system parameters and all TSF data, and to run the administrative functions is controlled and limited to those users who have been assigned the appropriate administrative roles, permissions and access rights.</p>\r\n<p>&nbsp;</p>\r\n<p>Security management relies on a platform in the Operational Environment with a properly configured Web Browser to support the web-based management interfaces.</p>\r\n<p>&nbsp;</p>\r\n<p><strong>Protection of Security Functions</strong></p>\r\n<p><strong><br /></strong></p>\r\n<p>The TOE ensures that data transmitted between separate parts of the TOE are protected from disclosure or modification. This protection is ensured through various methods including encryption and mutual, certificate-based authentication.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE provides NTP capabilities for its own use.</p>\r\n<p><strong>&nbsp;</strong></p>\r\n<p><strong>TOE Access Functions</strong></p>\r\n<p><strong><br /></strong></p>\r\n<p>The TOE will terminate a user&rsquo;s administrative session after a specified period of inactivity.</p>\r\n<p><strong>&nbsp;</strong></p>\r\n<p><strong>Network Management Functions</strong></p>\r\n<p><strong>&nbsp;</strong></p>\r\n<p>The TOE will issue alarms when a DHCP range is above or below defined watermarks.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE implements DNSSEC in accordance with Internet Engineering Task Force (IETF) specifications to secure DNS data transmission.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE provides automatic discovery and IP reconciliation for both IPv4 and IPv6. The TOE identifies conflicts based on DNS host names, IP addresses and MAC addresses for network devices. After discovery, the TOE compares the changes to identify unused IP addresses for reclamation and help uncover unauthorized IP addresses that can create security vulnerabilities.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE implements a basic form of Network Access Control based on the requesting client&rsquo;s MAC address. A request for a dynamic IP address (and therefore access to the network) can be allowed or denied based on the client&rsquo;s MAC address being present in an access list.</p>","features":[]}