{"product_id":10616,"v_id":10616,"product_name":"Aruba VIA Client 2.3","certification_status":"Certified","certification_date":"2015-05-27T00:00:00Z","tech_type":"Virtual Private Network","vendor_id":{"name":"Aruba, a Hewlett Packard Enterprise Company","website":"www.arubanetworks.com"},"vendor_poc":"Steve Weingart","vendor_phone":"210-516-5736","vendor_email":"sweingart@arubanetworks.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"Body\">The Target of Evaluation (TOE) is the Aruba Networks, Inc. Virtual Intranet Access (VIA) Client Version 2.3.0.0.&nbsp;</p>\r\n<p>The TOE provides secure remote network connectivity for Linux, Android, and Windows mobile devices and workstations. The TOE is designed for two primary purposes:</p>\r\n<ul>\r\n<li>To provide secure      corporate access to employee workstations and smartphones from anywhere</li>\r\n</ul>\r\n<ul>\r\n<li>To provide ease-of-use for the end users and network administrators</li>\r\n</ul>\r\n<p>The TOE is a hybrid Internet Protocol Security (IPsec)/Secure Sockets Layer (SSL) VPN client available for multiple client operating systems. &nbsp;IPsec is the sole means of securing network traffic; SSL functionality involves encapsulation of IPsec inside HTTPS-formatted packets in order to traverse firewalls and proxies where required. SSL functionality is not included in this evaluation.</p>\r\n<p>VIA can be downloaded directly from an Aruba Mobility Controller, pushed out using enterprise management tools, installed manually, or installed from the Google Play Store. An Aruba Mobility Controller is required to terminate connections from a VIA client &ndash; VIA is not a general-purpose VPN client that works with third-party VPN gateways.</p>","evaluation_configuration":"<p>The evaluated configuration consists of the following:</p>\r\n<p class=\"Body\">Aruba Virtual Intranet Access (VIA) client version 2.3.0.0. on the following platforms:</p>\r\n<ul>\r\n<li>MDFPP Evaluated Android 4.4 devices</li>\r\n<li>Microsoft Windows (Windows Vista, Windows 7, Windows 8, Windows 8.1)</li>\r\n<li>Linux (Red Hat Enterprise Linux 6.6 and CentOS Linux 6.6)</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Aruba Virtual Intranet Access (VIA) Client was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp; Gossamer Security Solutions determined that the evaluation assurance level (EAL) for the product is EAL 1.&nbsp; The product, when delivered and configured as identified in the Aruba Networks Federal Deployment Guide,&nbsp; 9/11/14, Revision: FDG-63-1-7-v5 &nbsp;&nbsp;document, satisfies all of the security functional requirements stated in the Aruba Networks, Inc. Virtual Intranet Access (VIA) Client Version 2.3 &nbsp;(IVPNCPP14) Security Target, Version 0.8, May 26, 2015.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in May 2015.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID10616-2015) prepared by CCEVS.</p>","environmental_strengths":"<p>The logical boundaries of the Aruba Virtual Intranet Access (VIA) Client TOE are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p><strong>Cryptographic Support</strong> - The IPsec implementation is the primary function of the TOE. IPSec is used by the TOE to protect communication between itself and a VPN Gateway over an unprotected network.</p>\r\n<p><strong>User Data Protection</strong> - The TOE ensures that residual information is protected from potential reuse in accessible objects such as network packets.</p>\r\n<p class=\"Body\"><strong>Identification and Authentication</strong> - The TOE provides the ability to use, store, and protect X.509 certificates and pre-shared keys that are used for IPsec Virtual Private Network (VPN) connections.&nbsp; In some cases, the storage and protection of X.509 certificates and keys is provided by the underlying operating system.</p>\r\n<p><strong>Security Management</strong> - The TOE provides all the interfaces necessary to manage the security functions identified throughout this Security Target. In particular, the IPsec VPN is fully configurable by a combination of functions provided directly by The TOE and those available to the associated VPN gateway.</p>\r\n<p class=\"Body\"><strong>TSF Protection</strong> - The TOE performs self-tests that cover the TOE as well as the functions necessary to securely update the TOE.</p>\r\n<p><strong>Trusted Path/Channels</strong> - The TOE acts as a VPN client using IPsec to established secure channels to corresponding VPN gateways.</p>","features":[]}