{"product_id":11312,"v_id":11312,"product_name":"Extreme Networks Virtual Services Platform (VSP) Series Switches v8.3.100","certification_status":"Certified","certification_date":"2022-12-19T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Extreme Networks, Inc.","website":"www.extremenetworks.com"},"vendor_poc":"Craig J Flick","vendor_phone":"6039525922","vendor_email":"eng-certificationpoc@extremenetworks.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The Target of Evaluation (TOE) is the Extreme Networks Virtual Services Platform (VSP) Series Switches v8.3.100.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE is a standalone network device that facilitates Data Link Layer data transfer between network nodes connected to its physical ports.<span style=\"mso-spacerun: yes;\">&nbsp; </span>TOE consists of a hardware appliance with embedded firmware.<span style=\"mso-spacerun: yes;\">&nbsp;</span></p>","evaluation_configuration":"<div class=\"WordSection1\">\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE consists of the following models of appliances all running VSP Operating System Software (VOSS) version 8.3.100:</p>\r\n</div>\r\n<div class=\"WordSection2\">\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP 4900-48P</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP4900-24S</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP4900-24XE</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP4900-12MXU-12XE</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP7400 -32C</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP7400-48Y-8C</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->VSP8404C</p>\r\n<p class=\"MsoListParagraphCxSpMiddle\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->XA1440</p>\r\n<p class=\"MsoListParagraphCxSpLast\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->XA1480</p>\r\n</div>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><span style=\"mso-bidi-font-family: Times;\">Each model provides a defined set of performance characteristics - switching bandwidth, latency, and port density while offering the same level of security features.</span></p>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered and configured as identified in the <span style=\"mso-no-proof: yes;\">Extreme VOSS Common Criteria Configuration Guide 8.3.100, December 2022</span> document, satisfies all of the security functional requirements stated in the <span style=\"font-family: 'Times New Roman',serif; mso-bidi-font-weight: bold;\">Extreme Networks Virtual Services Platform (VSP) Series Switches v8.3.100 Security Target, Version 0.7, </span><span style=\"mso-no-proof: yes;\">December </span><span style=\"font-family: 'Times New Roman',serif; mso-bidi-font-weight: bold;\">16, 2022</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in <span style=\"mso-no-proof: yes;\">December 2022</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11312-2022) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The logical boundaries of the TOE are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Security audit:</strong></p>\r\n<p class=\"MsoBodyText\">The Network Appliances provide extensive auditing capabilities.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE generates a comprehensive set of audit logs that identify specific TOE operations.<span style=\"mso-spacerun: yes;\">&nbsp; </span>For each event, the TOE records the date and time of each event, the type of event, the subject identity, and the outcome of the event.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Auditable events include: failure on invoking cryptographic functionality such as establishment, termination and failure of a TLS session; establishment, termination and failure of an SSH session; all use of the user identification mechanisms; any use of the authentication mechanism; any change in the configuration of the TOE, changes to time, initiation of TOE update, indication of completion of TSF self-test, termination of a remote session; and initiation and termination of a trusted channel.</p>\r\n<p class=\"MsoBodyText\">The TOE is configured to transmit its audit messages to an external syslog server.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Communication with the syslog server is protected using TLS.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The logs for all appliances can be viewed from the CLI.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The records include the date/time the event occurred, the event/type of event, the user ID associated with the event, and additional information of the event and its success and/or failure.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Cryptographic support:</strong></p>\r\n<p class=\"MsoBodyText\">The TOE utilizes CAVP-tested cryptographic implementations to provide key management, random bit generation, encryption/decryption, digital signature and secure hashing and key-hashing features in support of higher-level cryptographic protocols.<span style=\"mso-spacerun: yes;\">&nbsp; </span>This cryptography is used to support the following features:</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->TLS client in support of secure channel with remote syslog server,</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->SSH server in support of secure CLI remote management interface,</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->X.509 certificate validation and</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->NTP support.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Identification and authentication:</strong></p>\r\n<p class=\"MsoBodyText\">The TOE provides authentication services for administrative users to connect to the TOEs administrator interfaces (local CLI, and remote CLI).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE requires Administrators to authenticate prior to being granted access to any of the management functionality.<span style=\"mso-spacerun: yes;\">&nbsp; </span>In the Common Criteria evaluated configuration, the TOE requires a minimum password length be configured between 8 and 32 characters, as well as a minimum RSA key length of 2048 bits.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE provides administrator authentication against a local user database.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Security management:</strong></p>\r\n<p class=\"MsoBodyText\">The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Management can take place over a variety of interfaces including:</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l0 level1 lfo2; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Local console command line administration;</p>\r\n<p class=\"MsoBodyText\" style=\"margin-left: .75in; text-indent: -.25in; mso-list: l0 level1 lfo2;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Remote command line administration via SSHv2;</p>\r\n<p class=\"MsoBodyText\">The TOE provides multiple interfaces to perform administration.<span style=\"mso-spacerun: yes;\">&nbsp; </span>While in the CLI command mode, the administrator has access to six distinct modes, or privileges, that provide access to a specific set of commands.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Depending on RBAC configuration, not every administrative account would have access to all modes.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The CLI modes are as follows:</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l2 level1 lfo3; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->User EXEC Mode: Initial mode of access.</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l2 level1 lfo3; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Privileged EXEC Mode: User mode and password combination determines access level.</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l2 level1 lfo3; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Global Configuration Mode: Use this mode to make changes to the running configuration.</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l2 level1 lfo3; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Interface Configuration Mode: Use this mode to modify or configure logical interface, VLAN or a physical interface.</p>\r\n<p class=\"MsoBodyText\" style=\"mso-add-space: auto; text-indent: -.25in; mso-list: l2 level1 lfo3; margin: 0in 0in 0in .75in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Router Configuration Mode: Use this mode to modify protocol settings.</p>\r\n<p class=\"MsoBodyText\" style=\"margin-left: .75in; text-indent: -.25in; mso-list: l2 level1 lfo3;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Application Configuration Mode: Use this mode to access the applications.</p>\r\n<p class=\"MsoBodyText\">The system allows administrators to view audit records in EXEC mode.</p>\r\n<p class=\"MsoBodyText\">All administrative functionality is accessed via the CLI.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE audits all administrative access.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE displays login banners and inactivity timeouts to terminate idle administrative sessions after a set period of inactivity</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Protection of the TSF:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication, and access controls restrictions to management and configuration functionality to Administrators.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE prevents reading of private keys and plaintext passwords by any user.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE internally maintains the date and time.<span style=\"mso-spacerun: yes;\">&nbsp; </span>This date and time are used as a timestamp that is part of each audit record generated by the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Administrators can update the TOE&rsquo;s clock manually or can configure the TOE to synchronize with an external time source.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE performs testing to verify correct operation of the security appliances themselves.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE verifies all software updates via digital signature (2048-bit RSA/SHA-256) and requires administrative intervention prior to the software updates being installed on the TOE to avoid the installation of unauthorized firmware.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">TOE access:</strong></p>\r\n<p class=\"Body\">The TOE can terminate inactive sessions after configurable period.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Once a session has been terminated, the TOE requires the user to re-authenticate to establish a new session.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE can also display specified banner on the local and remote CLI interfaces prior to allowing any administrative access to the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE allows users to manually terminate an established management session with the TOE.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong style=\"mso-bidi-font-weight: normal;\">Trusted path/channels:</strong></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 12.0pt;\">The TOE supports several types of secure communications:</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; mso-add-space: auto; text-align: left; text-indent: -.25in; line-height: normal; mso-list: l3 level1 lfo4; tab-stops: list .5in; mso-layout-grid-align: auto; punctuation-wrap: hanging; text-autospace: ideograph-numeric ideograph-other; mso-vertical-align-alt: auto;\" align=\"left\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Trusted paths with remote administrators over SSH,</p>\r\n<p class=\"Body\" style=\"mso-add-space: auto; text-align: left; text-indent: -.25in; line-height: normal; mso-list: l3 level1 lfo4; tab-stops: list .5in; mso-layout-grid-align: auto; punctuation-wrap: hanging; text-autospace: ideograph-numeric ideograph-other; mso-vertical-align-alt: auto; margin: 0in 0in 0in .75in;\" align=\"left\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Trusted channels with remote IT environment audit (syslog) servers over TLS.</p>","features":[]}