{"product_id":11414,"v_id":11414,"product_name":"Architecture Technology Corporation Machete Router","certification_status":"Certified","certification_date":"2024-02-15T00:00:00Z","tech_type":"Network Device, Virtual Private Network, Wireless LAN","vendor_id":{"name":"Architecture Technology Corporation","website":"https://www.atcorp.com"},"vendor_poc":"Jordan Bonney","vendor_phone":"952-829-5864 x104","vendor_email":"jbonney@atcorp.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"Body\">The Architecture Technology Corporation Machete Router is a ruggedized, compact, secure and high-performance router that also provides VPN gateway functionality. The functions of Machete are implemented in a software suite called ATCorp Routing and Encryption Suite (ARES).</p>","evaluation_configuration":"<p class=\"Body\">The evaluated configuration consists of the following hardware running ARES v2.0:</p>\r\n<div align=\"center\">\r\n<table class=\"MsoTableGrid\" style=\"border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: #E5B8B7; mso-background-themecolor: accent2; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\"><strong>Model Identification</strong></p>\r\n</td>\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #E5B8B7; mso-background-themecolor: accent2; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\"><strong>Platform</strong></p>\r\n</td>\r\n<td style=\"width: 135.0pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #E5B8B7; mso-background-themecolor: accent2; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\"><strong>CPU Architecture</strong></p>\r\n</td>\r\n<td style=\"width: 99.0pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #E5B8B7; mso-background-themecolor: accent2; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\"><strong>CPU Part Number</strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-FIT2</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Fitlet2</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Apollo Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x7-E3950</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-OTN4</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">OnTime 4000 Series</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Apollo Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x7-E3950</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-OTN6</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">OnTime 6000 Series</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Apollo Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x7-E3950</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-OTN7</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">OnTime 7000 Series</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Apollo Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x7-E3950</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 5;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-DCS2</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">DCS003289</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Apollo Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x7-E3950</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 6;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-V1</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">VMware ESXi v7.0</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">AMD Embedded Ryzen 4000</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Ryzen 4600G</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 7;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-AMD-R1</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">OL-ML100 Series</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">AMD Ryzen V1000</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">V1605B</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 8;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-WL1</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">BKNUC8V5PNB</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Whiskey Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Core i5-8365U</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 9; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 103.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"138\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">MACHETE-FIT3</p>\r\n</td>\r\n<td style=\"width: 94.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Fitlet3</p>\r\n</td>\r\n<td style=\"width: 135.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"180\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Intel Elkhart Lake</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Body\" style=\"margin-bottom: .0001pt;\">Atom x6425E</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n</div>","security_evaluation_summary":"<p class=\"Body\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation demonstrated that <span style=\"mso-bidi-font-style: italic;\">the TOE </span>meets the security requirements contained in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered and configured as identified in the Machete Router Common Criteria Operational Guidance, Version 1.6, December 14, 2023, satisfies all of the security functional requirements stated in the <span style=\"mso-no-proof: yes;\">Architecture Technology Corporation Machete Router Security Target</span>, Version <span style=\"mso-no-proof: yes;\">0.6</span>, <span style=\"mso-no-proof: yes;\">November 29, 2023</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in <span style=\"mso-no-proof: yes;\">January 2024</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID<span style=\"mso-no-proof: yes;\">11414-2023</span>) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\">The logical boundaries of the <span style=\"mso-no-proof: yes;\">Architecture Technology Corporation Machete Router</span> are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p class=\"MsoNormal\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Security audit:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE is capable of auditing all required events and information. Each audit record includes the identity of the user that caused the event (if applicable), date and time of the event, type of event, and the outcome of the event.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE protects storage of audit information from modification or deletion. The TOE can transmit audit records to a remote syslog server using either SSH or IPsec.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Cryptographic support:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE contains CAVP-tested cryptographic support that provides key management, random bit generation, encryption/decryption, digital signature and secure hashing and key-hashing features in support of higher-level cryptographic protocols including IPsec and SSH.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Identification and authentication:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE supports passwords consisting of alphanumeric and special characters. The TSF also allows administrators to set a minimum password length of 6 to 100 characters.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE requires all administrative users to authenticate before allowing the user to perform any actions other than:</span></p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Times New Roman',serif;\">Viewing the warning banner.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">After an administrator-specified number of failed attempts, the user account is locked out. The TOE also protects, stores and allows authorized administrators to load X.509.v3 certificates for use to support authentication for IPsec connections</span>.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Security management:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE provides a custom CLI that allows users with the Security Administrator role to administer the TOE locally and remotely. This interface allows the Security Administrator to initiate manual updates, manage cryptographic keys, manage the TOE configuration, and configure audit data transmission.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Packet filtering:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE provides extensive packet filtering capabilities for IPv4, IPv6, TCP, and UDP.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The authorized administrator can define packet filtering rules that apply to most every field within the identified packet types. The authorized administrator can define each rule to permit, deny, and log each decision.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Protection of the TSF:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE prevents the reading of secret keys, private keys, and passwords.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE maintains a local real-time clock to provide accurate timestamps. This clock can be periodically updated by synchronizing with an NTP server and/or manually set by a Security Administrator.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE performs a suite of power-up self-tests that verify the correct operation of the entropy source, RAM, and cryptographic algorithms as well as the integrity of the firmware.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE verifies the authenticity and integrity of all firmware updates using ECDSA signature verification. The TOE shuts down if any of these tests fail.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>TOE access:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">Before establishing an administrative session, the TOE displays an administrator configurable warning banner. The TOE locks inactive local administrative sessions and terminates inactive remote administrative sessions.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE allows the administrator to configure restrictions on the establishment of client IPsec tunnels based on the client IP address, time of day, date, day of week, or day of month. The TOE assigns a private IP address (internal to the trusted network for which the TOE is the headend) to a VPN client upon successful establishment of a session.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Trusted path/channels:</strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Times New Roman',serif;\">The TOE supports either SSH or IPsec to provide a trusted communication channel between itself and all authorized IT entities that is logically distinct from other communication channels and provides assured identification of its end points and protection of the channel data from disclosure and detection of modification of the channel data. The TOE uses SSH or IPsec to provide the trusted path with remote administrative users as well.</span></p>","features":[]}