{"product_id":11463,"v_id":11463,"product_name":"Cisco Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12","certification_status":"Certified","certification_date":"2024-08-20T00:00:00Z","tech_type":"Network Device, Network Encryption","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":"Petra Manche","vendor_phone":"(408) 526-4000","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12 Target of Evaluation (TOE) is a purpose-built, switching and routing platform enabling connected devices to communicate over a network at layer 2 or 3.&nbsp; The TOE provides Administrative control and management of the network.&nbsp; For communicating with other network devices, the TOE provides AES-128 and AES-256 MACsec encryption.&nbsp; The TOE also provides Layer 3 capabilities, including OSPF, EIGRP, ISIS, RIP, and routed access.</span></p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Deployment of the TOE in its evaluated configuration consists of at least one TOE switch model following the CC installation and configuration guidance document (AGD).&nbsp; The TOE has two or more network interfaces and is connected to at least one internal and one external network. The Cisco IOS-XE configuration determines how packets are handled to and from the TOE&rsquo;s network interfaces. The switch configuration will determine how traffic flows received on an interface will be handled. Typically, packet flows are passed through the internet working device and forwarded to their configured destination.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The Cisco Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12 TOE is composed of hardware and software with the following specifications:</span></p>\r\n<table class=\"MsoTableGrid\" style=\"width: 606px; margin-left: 4.25pt; border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; break-after: avoid; margin: 0in; line-height: 11pt; font-size: 9pt; font-family: CiscoSans, sans-serif; color: rgb(56, 70, 126);\"><strong><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Series</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; break-after: avoid; margin: 0in; line-height: 11pt; font-size: 9pt; font-family: CiscoSans, sans-serif; color: rgb(56, 70, 126);\"><strong><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Models</span></strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Catalyst 9300</span></strong></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Hardware Models:</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">Chassis:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9300-24T, C9300-48T, C9300-24P, C9300-48P, C9300-24U, C9300-48U, C9300-24UX, C9300-48UXM, C9300-48UN, C9300-24S, C9300-48S, C9300D-24UB, C9300D-48UB, C9300D-24UXB, C9300-24H, C9300-48H</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following network modules</span></em></strong><span style=\"font-size: 10.0pt;\">:</span></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9300-NM-4G, C9300-NM-8X, C9300-NM-2Q, C9300-NM-4M, C9300-NM-2Y</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Catalyst 9300L</span></strong></p>\r\n<p style=\"text-align: center; break-after: avoid; margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Hardware Models:</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">Chassis:</span></em></strong></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9300L-24T-4G, C9300L-48T-4G, C9300L-24P-4G, C9300L-48P-4G,</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9300L-24T-4X, C9300L-48T-4X, C9300L-24P-4X, C9300L-48P-4X,</span></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9300L-48PF-4G, C9300L-48PF-4X, C9300L-24UXG-4X, C9300L-24UXG-2Q, C9300L-48UXG-4X, C9300L-48UXG-2Q</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Catalyst 9400</span></strong></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Hardware Models:</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">Chassis:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9404R, C9407R, C9410R</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following Supervisor models:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9400-SUP-1, C9400-SUP-1XL, C9400-SUP-1XL-Y</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following Line Card models</span></em></strong><strong><span style=\"font-size: 10.0pt;\">:</span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9400-LC-24S, C9400-LC-48S, C9400-LC-24XS, C9400-LC-48P, C9400-LC-48T, C9400-LC-48U, C9400-LC-48UX, C9400-LC-48H</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Catalyst 9500</span></strong></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Hardware Models:</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">Chassis:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9500-16X, C9500-32C, C9500-32QC, C9500-24Y4C, C9500-48Y4C</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following network modules:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9500-NM-8X, C9500-NM-2Q</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 94.5pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Catalyst 9600</span></strong></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 10.0pt;\">Hardware Models:</span></strong></p>\r\n</td>\r\n<td style=\"width: 5.0in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">Chassis:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9606R</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following Supervisor models:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9600-SUP-1</span></p>\r\n<p style=\"margin: 0in; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><strong><em><span style=\"font-size: 10.0pt;\">With the following Line Card models:</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 9pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 10.0pt;\">C9600-LC-24C, C9600-LC-48YL, C9600-LC-48TX, C9600-LC-24S</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p style=\"margin: 0in 0in 9pt 0.25in; line-height: 11pt; font-size: 9pt; font-family: CiscoSans, sans-serif; color: black;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 9pt; line-height: 11pt; font-size: 9pt; font-family: CiscoSans, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE includes the <strong>cat9k_iosxe.17.12.03.SPA.bin </strong>software image available for download on Cisco Software Central at </span><a href=\"https://software.cisco.com/\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">https://software.cisco.com/</span></a><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">.&nbsp; Customers can use their Cisco Care Online (CCO) or SMART account to download the software in a binary image format.</span></p>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Cisco Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12 CC Configuration Guide, Version 0.7, July 16, 2024 document, satisfies all of the security functional requirements stated in the Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12 Security Target, Version 0.9, July 29, 2024.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in August 2024.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11463-2024) prepared by CCEVS.</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Cisco Catalyst 9300/9300L/9400/9500/9600 Series Switches 17.12 are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">Auditing allows Security Administrators to discover intentional and unintentional issues with the TOE&rsquo;s configuration and/or operation.&nbsp; Auditing of administrative activities provides information that may be used to hasten corrective action should the system be configured incorrectly.&nbsp; Security audit data can also provide an indication of failure of critical portions of the TOE (e.g. a communication channel failure or anomalous activity (e.g. establishment of an administrative session at a suspicious time, repeated failures to establish sessions or authenticate to the TOE) of a suspicious nature.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides extensive capabilities to generate audit data targeted at detecting such activity.&nbsp; The TOE generates an audit record for each auditable event.&nbsp; Each security relevant audit event has the date, timestamp, event description, and subject identity.&nbsp; The TOE stores audit messages in a circular audit trail configurable by the Security Administrator.&nbsp; All audit logs are transmitted to an external audit server over a trusted channel protected with IPsec</span><span style=\"font-family: Calibri, sans-serif;\">.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides cryptographic functions to implement SSH, IPsec, and MACsec protocols.&nbsp; The cryptographic algorithm implementation has been validated for CAVP conformance.&nbsp; This includes key generation and random bit generation, key establishment methods, key destruction, and the various types of cryptographic operations to provide AES encryption/decryption, signature verification, hash generation, and keyed hash generation.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE supports MACsec using the proprietary Unified Access Data Plane (UADP) 2.0 Application-Specific Integrated Circuit (ASIC). The MACsec Controller (MSC) v1.0 is embedded within the ASICs that are utilized within Cisco hardware platforms.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">SSH and IPsec protocols are implemented using the IOS Common Cryptographic Module (IC2M) version Rel5a cryptographic modules. Refer to Table 21 of the ST for identification of the relevant CAVP certificates.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE implements three types of authentication to provide a trusted means for Security Administrators and remote servers/endpoints to securely communicate: &nbsp;X.509v3 certificate-based authentication for remote syslog servers, password-based authentication for Security Administrators, and pre-shared keys for MACsec endpoints.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">Security Administrators have the ability to compose strong passwords which are stored using a SHA-2 hash.&nbsp; Additionally, the TOE detects and tracks successive unsuccessful remote authentication attempts and will prevent the offending account from making further attempts until a Security Administrator defined time period has elapsed or until the Administrator manually unblocks the account.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides secure remote administrative interface and local interface to perform security management functions.&nbsp; This includes ability to configure cryptographic functionality; an access banner containing an advisory notice and consent warning message; a session inactivity timer before session termination as well as an ability to update TOE software.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides a Security Administrator role and only the Security Administrator can perform the above security management functions.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE protects critical security data including keys and passwords against tampering by untrusted subjects. The TOE provides reliable timestamps to support monitoring local and remote interactive administrative sessions for inactivity, validating X.509 certificates (to determine if a certificate has expired), and to support accurate audit records.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides self-tests to ensure it is operating correctly, including the ability to detect software integrity failures.&nbsp; Additionally, the TOE provides an ability to perform software updates and to verify those software updates are from Cisco Systems, Inc.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>TOE access:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE monitors both local and remote admin sessions for inactivity and terminates when a threshold time period is reached.&nbsp; Once a session has been terminated the TOE requires the user to re-authenticate.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE also displays a Security Administrator specified advisory notice and consent warning message prior to initiating identification and authentication for each administrative user.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides encryption (protection from disclosure and detection of modification) for communication paths between itself and remote endpoints.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: Calibri, sans-serif;\">In addition, the TOE provides two-way authentication of each endpoint in a cryptographically secure manner, meaning that even if there was a malicious attacker between the two endpoints, any attempt to represent themselves to either endpoint of the communications path as the other communicating party would be detected.</span></p>","features":[{"id":3522,"feature_name":"Asymmetric Key Generation"},{"id":3521,"feature_name":"Auditing"},{"id":3551,"feature_name":"Certificate Authentication"},{"id":3550,"feature_name":"Certificate Validation"},{"id":3546,"feature_name":"Cryptographic Hashing"},{"id":3531,"feature_name":"Cryptographic Key Establishment"},{"id":3545,"feature_name":"Cryptographic Signature Generation"},{"id":3544,"feature_name":"Cryptographic Signature Verification"},{"id":3523,"feature_name":"DRBG"},{"id":3564,"feature_name":"IKEv2"},{"id":3556,"feature_name":"IPsec"},{"id":3532,"feature_name":"Key Destruction"},{"id":3547,"feature_name":"Keyed-hash message authentication"},{"id":3514,"feature_name":"MACsec"},{"id":3568,"feature_name":"Network Switch"},{"id":3560,"feature_name":"SSH Server"}]}