{"product_id":10508,"v_id":10508,"product_name":"Motorola Solutions AirDefense 9.0 and AP-7131N Wireless Access Point","certification_status":"Not Certified","certification_date":"2014-03-31T00:03:00Z","tech_type":"Wireless LAN","vendor_id":{"name":"Motorola Mobility LLC","website":"www.motorola.com"},"vendor_poc":"Chris Hinsz","vendor_phone":"408-528-2452","vendor_email":"chris.hinsz@motorolasolutions.com","assigned_lab":{"cctl_name":"UL Verification Services"},"product_description":"<p>The TOE is a distributed system, comprised of the Air Defense Services Platform (ADSP) software and one or more AP-7131N Wireless Access Point devices simultaneously operating as wireless access points and Wireless Intrusion Detection System (WIDS) sensors. The TOE is a system that manages inbound and outbound traffic on an 802.11a/b/g/n wireless network and analyzes the wireless environment for potential security threats.</p>\r\n<p>The Air Defense Services Platform 9.0 (ADSP 9.0) portion of the TOE is a wireless networking security, assurance and management solution, designed to monitor and analyze the 802.11a/b/g/n metadata received from the attached AP-7131N devices. By analyzing this metadata, the ADSP system can detect violations of site-specific wireless security policies.</p>\r\n<p>The AP-7131N Access Point (AP) portion of the TOE is a hardware device that operates both as an Access Point and a wireless IDS sensor. As an AP, the AP-7131N manages inbound and outbound traffic on an 802.11a/b/g/n wireless network providing secure Wireless Local Area Network (WLAN) connectivity to a set of wireless client devices. As a sensor, the AP-7131N monitors network traffic and forwards information to the ADSP server for analysis. The module protects data exchanged with wireless client devices using IEEE 802.11i wireless security protocol. The TOE has one (1) physical LAN port supporting two (2) unique LAN interfaces, one (1) physical WAN port, one (1) serial port, six (6) LEDs, one (1) reset button and six (6) antennas.</p>\r\n<p>The Motorola Solutions ADSP Version 9.0 software runs on a pre-configured version of Community Enterprise Operating System (CENTOS) version 6.2; CENTOS runs only the required communications services with all unused ports and functions closed and/or turned off. The required services include SNMPv3, TLS 1.0, SSHv2, NTPv4, SCP, and HTTPS. The ADSP CENTOS is a guest OS that runs on a virtualization engine in the IT environment.</p>\r\n<p>The following Security Functions are supported by the TOE:</p>\r\n<ul>\r\n<li>Security Audit &ndash; The      AP-7131N portion of the TOE has the ability to selectively generate audit      records for potentially security relevant events and transmit these      records to the audit server in the environment.&nbsp; The ADSP portion of the TOE has the      ability to generate audit records for potentially security relevant      events. The ADSP portion of the TOE utilizes its underling CENTOS services      to provide an audit capability that allows generating audit records for      security critical events; the events that are audited are preconfigured      and are not selectable by an administrator.</li>\r\n<li>Cryptographic      Support &ndash; The TOE      provides cryptographic mechanisms to protect TSF code and data, including      mechanisms to encrypt, decrypt, hash, digitally sign data, and perform cryptographic key agreement. The      evaluated configuration uses NIST CAVP validated cryptographic algorithms.</li>\r\n<li>User      Data Protection &ndash; The TOE ADSP Application provides attribute access      control to limit access of users to allowed functions based on the      permissions assigned each user. The      AP-7131N portion of the TOE protects user data, i.e., only      that data exchanged with wireless client devices, using the IEEE 801.11i      standard wireless security protocol, mediates the flow of information      passing to and from the WAN port, and ensures that resources used to pass      network packets through the TOE do not contain any residual information.</li>\r\n<li>Identification      and Authentication &ndash; The TOE requires the system administrators be      authenticated before access to the TOE is granted</li>\r\n<li>Security      Management &ndash; The AP-7131N&rsquo;s SNMPv3 interface supports a limited set of      administrative functions; these allow an administrator to manage network      performance, find and solve network problems, plan for network growth, and      gather information from its network components.&nbsp; The ADSP portion of the TOE provides a      limited CLI that is used for basic device management functions such as      setting the network configuration and restarting the server</li>\r\n<li>TOE      Access &ndash; The TOE displays an advisory/warning message before establishing      a user session.&nbsp; The TOE terminates      administrative sessions after an administrator configurable time interval      of inactivity is reached for SSH, Local CLI, and Web UI sessions.</li>\r\n<li>Trusted      Path/Channel &ndash; The TOE provides both trusted paths for authorized      administrators and trusted channels for system functions.</li>\r\n<li>Intrusion      Detection &ndash; The TOE provides WIDS functions including traffic analysis,      reaction, restricted data review, and data collection.</li>\r\n<li>Protection      of the TSF &ndash; The TOE provides the capability to run a set of self-tests on      power-on and on demand to verify the correct operation of the TOE&rsquo;s      underlying hardware, TOE software and cryptographic modules.</li>\r\n</ul>","evaluation_configuration":"<p>The evaluation covers ADSP Version 9.0.0-83 and two models of the AP-7131N, the AP-7131N-66040-FGR Rev. D and the AP-7131N-66040-FWW Rev. F; both are shipped with identical software, version 4.0.4.0-045GRN. The two models are identical except that the radio frequency bands of the FGR are preconfigured for use in the USA only; the radio frequency bands of the FWW are configurable for all supported countries except the USA. The differences between the two models are limited to the frequency bands supported and the menu used to select the country of use; all security functions are identical. The software detects the model on startup.</p>\r\n<p>The AP-7131N portion of the TOE supports the following LAN, WAN, and WLAN interfaces:</p>\r\n<ul>\r\n<li>LAN port - The physical interface provided to connect a physical wire to the AP LAN. The access point has one LAN (GE1/POE) port with a single MAC address.</li>\r\n<li>WAN port - The physical interface provided to connect a physical wire to the AP WAN. The access point has one WAN (GE2) port with a single MAC address.</li>\r\n<li>WLAN port - There is not a physical connector associated with the WLAN port; this represents the physical radio antenna(s) for the WLAN.</li>\r\n</ul>\r\n<p><span style=\"text-decoration: underline;\">Environment Dependencies</span></p>\r\n<p>The AP-7131N portion of the TOE requires the following support from the IT environment:</p>\r\n<ul>\r\n<li>Wireless clients connected via 802.11a/b/g/n</li>\r\n<li>Local administration connected via RS-232 \r\n<ul>\r\n<li>Access to management functions via Command Line Interface (CLI) </li>\r\n</ul>\r\n</li>\r\n<li>Remote administration connected by LAN or WAN port \r\n<ul>\r\n<li>Supports  \r\n<ul>\r\n<li>SSHv2 access to management functions via Command Line Interface (CLI)</li>\r\n<li>HTTPS access to Java based Web UI management functions via web browser supporting TLSv1.0</li>\r\n<li>SNMPv3 access to limited management functions</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n</li>\r\n<li>Servers \r\n<ul>\r\n<li>SFTP server connected via SSHv2</li>\r\n<li>NTP&nbsp; Server connected via IPsec tunnel</li>\r\n<li>Audit (Syslog) Server tunnel connected via IPsec tunnel</li>\r\n<li>RADIUS (AAA) Server connected via IPsec tunnel</li>\r\n<li>LDAP Server connected via IPsec tunnel</li>\r\n<li>SNMP Server (Manager) using SNMPv3</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p>The ADSP portion of the TOE requires the following support from the IT environment:</p>\r\n<ul>\r\n<li>VM Server running (Minimum 2GB Memory and 2 vCPUs): \r\n<ul>\r\n<li>Red Hat Linux 6.2 with KVM Virtualization Engine or</li>\r\n<li>VMWare ESXi 5.0</li>\r\n<li>Administrative interfaces: \r\n<ul>\r\n<li>Must support a SSHv2 client for CLI access and</li>\r\n<li>A web browser with Adobe Flash 10 or higher that supports TLS v1.0 for the ADSP GUI</li>\r\n<li>NTPv4 Server</li>\r\n<li>Audit/Configuration Back Repository &ndash; SCP/SFTP server supporting SSHv2</li>\r\n<li>Infrastructure Switch &ndash; Supporting SNMPv3 with q-bridge SNMP MIB variables (for port suppression)</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that Motorola Solutions ADSP virtual server and AP-7131N device meets the security requirements contained in the Security Target. The criteria against which ADSP and AP-7131N were assessed are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 3 and National and International Interpretations effective 2 November 2012. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 3. InfoGard Laboratories determined that ADSP and AP-7131N Access Point provides the security assurance required by Evaluation Assurance Level 2 (EAL2) and ALC_FLR.2.</p>\r\n<p>The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target. Validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by InfoGard Laboratories, Inc. The evaluation was completed in March of 2014.</p>","environmental_strengths":"<p>The Motorola Solutions AP-7131N is a commercial wireless LAN (WLAN) access point. It utilizes National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CAVP) validated cryptographic algorithms to provide secure management and secure wireless networking functions.</p>\r\n<p>The Motorola Solutions ADSP is a Wireless IDS system. It utilizes NIST Cryptographic Module Validation Program (CMVP) validated cryptographic modules which implement CAVP validated cryptograph algorithms. These algorithms provide secure management.</p>\r\n<p>Both ADSP and AP-7131N require remote administrative users to be authenticated over a trusted path prior to performing any administrative functions. ADSP locks out a user&rsquo;s account after an administrator configured number of failed authentication attempts, while the AP locks out a remote interface type (i.e., HTTPS or SSH) if that interface type receives 3 consecutive failed login attempts.</p>\r\n<p>The AP-7131N utilizes trusted channels to protect communications with trusted IT entities (i.e., authentication server, NTP server, Syslog server, SFTP server, SNMPv3 Manager).</p>\r\n<p>The AP-7131N audits both wireless user and administrator actions to an external syslog server to aid in detecting suspicious behavior.</p>","features":[]}