{"product_id":11225,"v_id":11225,"product_name":"Citrix ADC (MPX FIPS and VPX FIPS) Version 12.1","certification_status":"Certified","certification_date":"2022-01-26T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Citrix Systems Inc.","website":"www.citrix.com"},"vendor_poc":"Arvind Gangadharan Ramalingam","vendor_phone":"1-800-424-8749","vendor_email":"arvind.gangadharan@citrix.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-size: 10.0pt; line-height: 106%; mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">The Citrix Application Delivery Controllers (ADC) are purpose-built networking appliances whose function is to improve the performance, security and resiliency of applications delivered over the web. The ADC intelligently distributes, optimizes application performance, enhances application availability with advanced Layer 4 &ndash; Layer 7 load balancing, secures applications from attacks, and lowers server expenses by offloading computationally intensive tasks. The TOE comprises Citrix ADC 12.1 software running on the following:</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-size: 10.0pt; line-height: 106%; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">- Physical Platforms&nbsp; </span></p>\r\n<p class=\"MsoListParagraphCxSpFirst\" style=\"margin-left: 22.5pt; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><!-- [if !supportLists]--><span style=\"mso-bidi-font-size: 10.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';\">&nbsp;&nbsp; </span></span><!--[endif]-->MPX 8900 FIPS</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 22.5pt; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><!-- [if !supportLists]--><span style=\"mso-bidi-font-size: 10.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';\">&nbsp;&nbsp; </span></span><!--[endif]-->MPX 15000-50G FIPS</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-size: 10.0pt; line-height: 106%; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">- Virtual Platforms </span></p>\r\n<p class=\"MsoListParagraph\" style=\"margin-left: 22.5pt; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><!-- [if !supportLists]--><span style=\"mso-bidi-font-size: 10.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o</span> <!--[endif]-->VPX FIPS on ESXi 6.5 running on a Dell PowerEdge R630 Server&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-size: 10.0pt; line-height: 106%; mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">Citrix ADC MPX FIPS and Citrix ADC VPX FIPS are network devices and virtual network devices that combine Layer 4 - Layer 7 load balancing and content switching with application acceleration, data compression, static and dynamic content caching, SSL acceleration, network optimization, application performance monitoring, application visibility, and robust application security via an application firewall. The Citrix ADC MPX FIPS &amp; Citrix ADC VPX FIPS appliances support all the NIST-approved FIPS 140-2 algorithms.</span></p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; line-height: normal;\"><span style=\"mso-bidi-font-size: 10.0pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">The TOE evaluated configuration consists of the physical platforms, MPX 8900 FIPS and MPX 15000-50G FIPS. Both, the MPX 8900 FIPS and the MPX 15000-50G FIPS, operate using the </span><span style=\"mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">Intel&reg; Xeon E5-2620 v4 </span><span style=\"mso-bidi-font-size: 10.0pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">(Broadwell) </span><span style=\"mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;\">processor. Additionally, the evaluated configuration includes the VPX FIPS virtual platform. This virtual platform is hosted within a Dell PowerEdge R630 Server running an instance of VMware ESXi 6.5 hypervisor. The VPX is hosted on a server which operates on an Intel&reg; Xeon E5-2680 v4 (Broadwell) processor.</span></p>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Citrix ADC (MPX FIPS and VPX FIPS) Version 12.1 was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered configured as identified in the <em>Citrix ADC (MPX FIPS and VPX FIPS) Version 12.1 Common Criteria Configuration Guide</em>, Version 1.4, January 24, 2022, satisfies all of the security functional requirements stated in the <em>Citrix ADC (MPX FIPS and VPX FIPS) Version 12.1 Security Target</em>, Version 1.6, 1/24/2022. The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in January 2022.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report <span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">(report number CCEVS-VR-VID11225-2022) </span>prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\">The TOE provides the security functions required by NDcPP v2.2e, as identified below.</p>\r\n<p class=\"MsoNormal\"><strong>- Security Audit</strong> - The TOE keeps local and remote audit records of security relevant events. Remote audit records are transferred via TLS to the external audit server.</p>\r\n<p class=\"MsoNormal\"><strong>- Cryptographic Support</strong> - The TOE provides cryptographic support for the SSH for remote administrative access and TLS connections to external IT devices.The cryptography for the TOE is provided by Citrix ADC CP Cryptographic Library v3.0 and Citrix ADC CP Cryptographic Library v4.0 running on FreeBSD 8.4. This is the underlying OS of the TOE on which the firmware runs.</p>\r\n<p class=\"MsoNormal\"><!-- [if !supportLists]--><strong>- Identification and Authentication </strong>- The TOE provides two types of authentication to provide a trusted means for Security Administrators and remote endpoints to interact:</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Password-based or public-key authentication for Security Administrators</p>\r\n<p class=\"MsoListParagraphCxSpLast\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o</span>&nbsp;X.509v3 certificate-based authentication for remote devices</p>\r\n<p class=\"MsoNormal\" style=\"line-height: 107%; margin: 0in 0in 0in .5in;\">Device-level authentication allows the TOE to establish a secure communication channel with a remote endpoint. Security Administrators can set a minimum length for passwords (between 4 and 127 characters). Additionally, the TOE detects and tracks consecutive unsuccessful remote authentication attempts and will prevent the offending attempts from authenticating when a Security Administrator defined threshold is reached.</p>\r\n<p class=\"MsoNormal\"><strong>- Security Management</strong> - The TOE enables secure local and remote management of its security functions, including:</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o</span>&nbsp;&nbsp;Local console CLI administration</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Remote CLI administration via SSHv2</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Administrator authentication using a local database</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Timed user lockout after multiple failed authentication attempts</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Password complexity enforcement</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Role Based Access Control - the TOE supports several types of administrative user roles. Collectively these sub-roles comprise the &ldquo;Security Administrator&rdquo;</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Configurable banners to be displayed at login</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;</span></span>Timeouts to terminate administrative sessions after a set period of inactivity</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"margin-left: 1.0in; mso-add-space: auto; text-indent: -.25in; mso-list: l0 level2 lfo1;\"><span style=\"font-size: 11.0pt; font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';\">o</span>&nbsp;Protection of secret keys and passwords</p>\r\n<p class=\"MsoNormal\"><strong style=\"text-indent: -24px;\">- Protection of the TSF</strong><span style=\"text-indent: -24px;\">&nbsp;- The TOE ensures the authenticity and integrity of software updates through hash comparison and requires administrative intervention prior to the software updates being installed.</span></p>\r\n<p class=\"MsoNormal\"><!-- [if !supportLists]--><strong>- TOE Access</strong> - Prior to login, the TOE displays a banner with a message configurable by the Security Administrator. The TOE terminates user connections after an Authorized Administrator configurable amount of inactivity time.</p>\r\n<p class=\"MsoNormal\"><strong style=\"text-indent: -24px;\">- Trusted path/channels</strong><span style=\"text-indent: -24px;\">&nbsp;-&nbsp;</span><span style=\"text-indent: -24px;\">The TOE uses TLS to provide a trusted channel between itself and remote syslog and LDAP servers. The TOE uses SSH to provide a trusted path between itself and remote administrators.</span></p>","features":[]}