{"product_id":10489,"v_id":10489,"product_name":"Cisco Catalyst Switches (4503-E, 4506-E, 4507R+E, 4507R-E, 4510R+E, 4510R-E, and 4500X) running IOS XE 3.3.1SG","certification_status":"Not Certified","certification_date":"2012-12-13T00:12:00Z","tech_type":"Network Switch","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":"Cisco Cert Team","vendor_phone":"+1 410 309 4862","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The Target of Evaluation (TOE) is Cisco Catalyst Switches (4503-E, 4506-E, 4507R+E, 4507R-E, 4510R+E, 4510R-E, and 4500X).&nbsp; The following models were evaluated as part of the Cisco Catalyst 4500 Series TOE configuration:</p>\r\n<p>&nbsp;</p>\r\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead> \r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Feature</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Cisco    Catalyst</strong></p>\r\n<p><strong>WS-C4503-E    Chassis</strong><strong>&nbsp;</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Cisco    Catalyst</strong></p>\r\n<p><strong>WS-C4506-E    Chassis</strong><strong>&nbsp;</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Cisco    Catalyst</strong></p>\r\n<p><strong>WS-C4507R+E    Chassis</strong><strong>&nbsp;</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Cisco    Catalyst</strong></p>\r\n<p><strong>WS-C4510R+E    Chassis</strong><strong>&nbsp;</strong></p>\r\n</td>\r\n</tr>\r\n</thead> \r\n<tbody>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Total   number of slots</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>3</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>6</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>7</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>10</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Line-card   slots</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>5</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>5</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>8</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Supervisor   engine slots</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Dedicated   supervisor engine slot numbers</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>3 and 4</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>5 and 6</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Supervisor   engine redundancy</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>No</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>No</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes (Supervisor V-10GE, 6-E and 7-E)</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Supervisor   engines supported</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Supervisor 7-E</p>\r\n<p>Supervisor 7L-E</p>\r\n<p>&nbsp;</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Supervisor 7-E</p>\r\n<p>Supervisor 7L-E</p>\r\n<p>&nbsp;</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Supervisor 7-E</p>\r\n<p>Supervisor 7L-E</p>\r\n<p>&nbsp;</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Supervisor 7-E</p>\r\n<p>&nbsp;</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Maximum   PoE per slot</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1,500W</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1,500W</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1,500W</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1,500W slots 1 and 2,</p>\r\n<p>750W slots 3,4,7-10</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Bandwidth   scalability per line-card slot</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Up   to 48 Gbps on all slots</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Up   to 48 Gbps on all slots</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Up   to 48 Gbps on all slots</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Up   to 48 Gbps on all slots<a href=\"#_ftn1\"><sup><sup>[1]</sup></sup></a></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Number   of power supply bays</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>2</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>AC   input power</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>DC   Input power</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Integrated   Power over Ethernet</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Yes</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Minimum   number of power supplies</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Power   supplies supported</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>? 1000W AC</p>\r\n<p>? 1400W AC</p>\r\n<p>? 1300W ACV</p>\r\n<p>? 2800W ACV</p>\r\n<p>? 4200W ACV</p>\r\n<p>? 6000W ACV</p>\r\n<p>? 1400W DC (triple input)</p>\r\n<p>? 1400W-DC-P</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>? 1000W AC</p>\r\n<p>? 1400W AC</p>\r\n<p>? 1300W ACV</p>\r\n<p>? 2800W ACV</p>\r\n<p>? 4200W ACV</p>\r\n<p>? 6000W ACV</p>\r\n<p>? 1400W DC (triple input)</p>\r\n<p>? 1400W-DC-P</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>? 1000W AC</p>\r\n<p>? 1400W AC</p>\r\n<p>? 1300W ACV</p>\r\n<p>? 2800W ACV</p>\r\n<p>? 4200W ACV</p>\r\n<p>? 6000W ACV</p>\r\n<p>? 1400W DC (triple input)</p>\r\n<p>? 1400W-DC-P</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>? 1400W AC</p>\r\n<p>? 2800W ACV</p>\r\n<p>? 4200W ACV</p>\r\n<p>? 6000W ACV</p>\r\n<p>? 1400W DC (triple input)</p>\r\n<p>? 1400W-DC-P</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Number   of fan-tray bays</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>1</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Location   of 19-inch rack mount</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"118\" valign=\"top\">\r\n<p><strong>Location   of 23-inch rack mount</strong></p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front (option)</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front (option)</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front (option)</p>\r\n</td>\r\n<td width=\"118\" valign=\"top\">\r\n<p>Front (option)</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p>&nbsp;</p>\r\n<p>The Cisco Catalyst 4500-X Series Switch is a fixed 10 Gigabit Ethernet aggregation platform that provides flexibility through two versions of base switches along with optional uplink module. Both the 32- and 16-port versions can be configured with optional network modules and offer similar features. The Small Form-Factor Pluggable Plus (SFP+) interface supports both 10 Gigabit Ethernet and 1 Gigabit Ethernet ports, allowing upgrades to 10 Gigabit Ethernet when organizational demands change. The uplink module is hot swappable.</p>\r\n<p>Deployment Options include:</p>\r\n<ul>\r\n<li>16- and 32-port 10 Gigabit      Ethernet Small Form-Factor Pluggable Plus (SFP+) models</li>\r\n<li>8-port 10 Gigabit Ethernet SFP+      removable uplink module</li>\r\n<li>Dual-redundant AC/DC power supply      and five field-replaceable unit (FRU) fans</li>\r\n</ul>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which Cisco Catalyst 4500 Series TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 revision 3.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 revision 3.&nbsp; Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 2 augmented with ALC_FLR.2 and ALC_DVS.1.&nbsp; The product, when delivered and configured as identified in <em>Cisco Catalyst Switches (4503-E, 4506-E, 4507R+E, 4507R-E, 4510R+E, 4510R-E, and 4500X) Common Criteria Operational User Guidance and Preparative Procedures</em> document (version .7), satisfies all of the security functional requirements stated in the <em>Cisco Catalyst Switches (4503-E, 4506-E, 4507R+E, 4507R-E, 4510R+E, 4510R-E, and&nbsp; 4500X) Security Target</em> (version 0.098). The project underwent three Validation Oversight Panel (VOR) panel reviews.&nbsp; The evaluation was completed in November 2012.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-10489-0001, dated 13 August 2012) prepared by CCEVS.</p>","environmental_strengths":"<p>The logical boundaries of Cisco Catalyst Switches (4503-E, 4506-E, 4507R+E, 4507R-E, 4510R+E, 4510R-E, 4500X) TOE are realized in the security functions that it implements. These security functions are realized at the network interfaces that service clients and via the administrator commands. Each of these security functions is summarized below.</p>\r\n<p><strong>Security Audit &mdash;</strong> The TOE generates a comprehensive set of audit logs that identify specific TOE operations. For each event, the TOE records the date and time of each event, the type of event, the subject identity, and the outcome of the event. Auditable events include; modifications to the group of users that are part of the authorized administrator roles (assigned the appropriate privilege level), all use of the user identification mechanism, any use of the authentication mechanism, any change in the configuration of the TOE, any matching of packets to access control entries in ACLs when traversing the TOE; and any failure of a packet to match an access control list (ACL) rule allowing traversal of the TOE.&nbsp; The TOE will write audit records to the local logging buffer by default and can be configured to send audit data via syslog to a remote audit server, or display to the local console.&nbsp; The TOE does not have an interface to modify audit records, though there is an interface available for the authorized administrator to delete audit data stored locally on the TOE.</p>\r\n<p><strong>Cryptographic Support</strong> &mdash; The TOE provides cryptography support for secure communications and protection of information when operated in FIPS mode.&nbsp; The crypto module is FIPS 140-2 SL2 validated. The cryptographic services provided by the TOE include: symmetric encryption and decryption using AES; digital signature using RSA; cryptographic hashing using SHA1; keyed-hash message authentication using HMAC-SHA1.The TOE also implements SSHv2 secure protocol for secure remote administration.&nbsp; In the evaluated configuration, the TOE must be operated in FIPS mode of operation per the FIPS Security Policy.</p>\r\n<p><strong>Traffic Filtering and Switching (VLAN Processing and ACLs) &mdash;</strong> VLANs control whether Ethernet frames are passed through the switch interfaces based on the VLAN tag information in the frame header.&nbsp; IP ACLs or ICMP ACLs control whether routed IP packets are forwarded or blocked at Layer 3 TOE interfaces (interfaces that have been configured with IP addresses). VACLs (using access mapping) control whether non-routed frames (by inspection of MAC addresses in the frame header) and packets (by inspection of IP addresses in the packet header) are forwarded or blocked at Layer 2 ports assigned to VLANs. The TOE examines each frame and packet to determine whether to forward or drop it, on the basis of criteria specified within the VLANs access lists and access maps applied to the interfaces through which the traffic would enter and leave the TOE. For those interfaces configured with Layer-3 addressing the ACLs can be configured to filter IP traffic using: the source address of the traffic; the destination address of the traffic; and the upper-layer protocol identifier. Layer-2 interfaces can be made part of Private VLANs (PVLANs), to allow traffic to pass in a pre-defined manner among a primary, and secondary (&lsquo;isolated&rsquo; or &lsquo;community&rsquo;) VLANs within the same PVLAN.</p>\r\n<p>VACL access mapping is used to match IP ACLs or MAC ACLs to the action to be taken by the TOE as the traffic crosses the interface, causing the packet to be forwarded or dropped. The traffic is matched only against access lists of the same protocol type; IP packets can be matched against IP access lists, and any Ethernet frame can be matched against MAC access lists.&nbsp; Both IP and MAC addresses can be specified within the VLAN access map.</p>\r\n<p>Use of Access Control Lists (ACLs) also allows restriction of remote administration connectivity to specific interfaces of the TOE so that sessions will only be accepted from approved management station addresses identified as specified by the administrator.</p>\r\n<p>The TOE supports routing protocols including BGPv4, EIGRP, EIGRPv6 for IPv6, RIPv2, and OSPFv2 to maintain the routing tables.&nbsp; The routing tables can also be configured and maintained manually.&nbsp; Since routing tables are used to determine which egress ACL is applied, the authority to modify the routing tables is restricted to authenticated administrators and authenticated neighbor routers.&nbsp; The only aspects of the routing protocol that is security relevant in this TOE is the&nbsp; ability to authenticate neighbor routers using shared passwords.&nbsp; Other security features and configuration options of routing protocols are beyond the scope of this Security Target and are described in administrative guidance.</p>\r\n<p>The TOE supports VACLs (VLAN ACLs), which can filter traffic traversing VLANs on the TOE based on IP addressing and MAC addressing.</p>\r\n<p>The TOE also ensures that packets transmitted from the TOE do not contain residual information from previous packets.&nbsp; Packets that are not the required length use zeros for padding so that residual data from previous traffic is never transmitted from the TOE.</p>\r\n<p><strong>Identification and Authentication</strong> &mdash; The TOE performs authentication, using Cisco IOS platform authentication mechanisms, to authenticate access to user EXEC and privileged EXEC command modes.&nbsp; All users wanting to use TOE services are identified and authenticated prior to being allowed access to any of the services. Once a user attempts to access the management functionality of the TOE (via EXEC mode), the TOE prompts the user for a user name and password. Only after the administrative user presents the correct identification and authentication credentials will access to the TOE functionality be granted.</p>\r\n<p>The TOE supports use of a remote AAA server (RADIUS and TACACS+) as the enforcement point for identifying and authenticating users, including login and password dialog, challenge and response, and messaging support. For RADIUS, only the password is encrypted, while TACACS+ encrypts the entire packet body except the header. Note the remote authentication server is not included within the scope of the TOE evaluated configuration, it is considered to be provided by the operational environment.&nbsp;&nbsp;</p>\r\n<p>The TOE can be configured to display an advisory banner when administrators log in and also to terminate administrator sessions after a configured period of inactivity.</p>\r\n<p>The TOE also supports authentication of other routers using router authentication supported by BGPv4, EIGRP, EIGRPv6 for IPv6, RIPv2, and OSPFv2.&nbsp; Each of these protocols supports authentication by transmission of MD5-hashed password strings, which each neighbor router uses to authenticate others.&nbsp; It is noted that per the FIPS Security Policy, that MD5 is not a validated algorithm during FIPS mode of operation.&nbsp; For additional security, it is recommended router protocol traffic also be isolated to separate VLANs.</p>\r\n<p><strong>Security Management &mdash;</strong> The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE. All TOE administration occurs through either a secure session via SSHv2, a terminal server directly connected to the Catalysis Switch (RJ45), or a local console connection (serial port). The TOE provides the ability to perform the following actions:</p>\r\n<ul>\r\n<li>allows authorized administrators to add new administrators, </li>\r\n<li>start-up and shutdown the device, </li>\r\n<li>create, modify, or delete configuration items, </li>\r\n<li>create, modify, or delete information flow policies,</li>\r\n<li>create, modify, or delete routing tables,</li>\r\n<li>modify and set session inactivity thresholds,</li>\r\n<li>modify and set the time and date, </li>\r\n<li>and create, delete, and review the audit trail&nbsp; </li>\r\n</ul>\r\n<p>All of these management functions are restricted to the authorized administrator of the TOE.</p>\r\n<p>The TOE switch platform maintains administrative privilege level and non-administrative access. Non-administrative access is granted to authenticated neighbor routers for the ability to receive updated routing tables per the information flow rules.&nbsp; There is no other access or functions associated with non-administrative access. The administrative privilege levels include:</p>\r\n<ul>\r\n<li>Administrators are assigned to privilege levels 0 and 1.&nbsp; Privilege levels 0 and 1 are defined by default and are customizable.&nbsp; These levels have a very limited scope and access to CLI commands that include basic functions such as login, show running system information, turn on/off privileged commands, logout.</li>\r\n<li>Semi-privileged administrators equate to any privilege level that has a subset of the privileges assigned to level 15; levels 2-14.&nbsp; These levels are undefined by default and are customizable.&nbsp; The custom level privileges are explained in the example below.</li>\r\n<li>Privileged administrators are equivalent to full administrative access to the CLI, which is the default access for IOS privilege level 15.</li>\r\n</ul>\r\n<p>The term &ldquo;authorized administrator&rdquo; is used in this ST to refer to any user which has been assigned to a privilege level that is permitted to perform the relevant action; therefore has the appropriate privileges to perform the requested functions.&nbsp; &nbsp;</p>\r\n<p><strong>Protection of the TSF &mdash;</strong> The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication and access controls to limit configuration to authorized administrators. Additionally Cisco IOS is not a general-purpose operating system and access to Cisco IOS memory space is restricted to only Cisco IOS functions.</p>\r\n<p>The TOE provides secure transmission when TSF data is transmitted between separate parts of the TOE (encrypted sessions for remote administration (via SSHv2)).&nbsp; A separate VLAN should be used to ensure the routing protocol communications between the TOE and neighbor routers (including routing table updates and neighbor router authentication) is logically isolated from the traffic on other VLANs.</p>\r\n<p>The TOE also supports replay detection, though it is only applicable to the encrypted sessions for remote administration via SSHv2.&nbsp; If replay is detected, the packets are discarded.&nbsp;</p>\r\n<p>In addition, the TOE internally maintains the date and time. This date and time is used as the time stamp that is applied to TOE generated audit records.&nbsp; Alternatively, an NTP server can be used to synchronize the date-timestamp.&nbsp; Finally, the TOE performs testing to verify correct operation of the switch itself and that of the cryptographic module.</p>\r\n<p>&nbsp;</p>\r\n<p><strong>TOE Access &mdash;</strong> The TOE can terminate inactive sessions after an authorized administrator configurable time-period.&nbsp; Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session.&nbsp;</p>\r\n<p>The TOE can also display a Security Administrator specified banner on the CLI management interface prior to allowing any administrative access to the TOE.</p>","features":[]}