{"product_id":11482,"v_id":11482,"product_name":"Palo Alto Networks PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 11.1","certification_status":"Certified","certification_date":"2024-09-19T00:00:00Z","tech_type":"Firewall, Network Device, Remote Access, Virtual Private Network, Wireless Monitoring","vendor_id":{"name":"Palo Alto Networks, Inc.","website":"https://www.paloaltonetworks.com"},"vendor_poc":"Jake Bajic","vendor_phone":"408-753-3901","vendor_email":"jbajic@paloaltonetworks.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">Palo Alto Networks provides a suite of enterprise-level next-generation firewalls, with a range of security features for the enterprise network.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">The Palo Alto next-generation firewalls are network firewall appliances and virtual appliances on specified hardware used to manage enterprise network traffic flow using function-specific processing for networking, security, and management. The next-generation firewalls let the administrator specify security policies based on an accurate identification of each application seeking access to the protected network. The next-generation firewall uses packet inspection and a library of applications to distinguish between applications that have the same protocol and port, and to identify potentially malicious applications that use non-standard ports. The next-generation firewall also supports the establishment of Virtual Private Network (VPN) connections to other next-generation firewalls or third-party security devices.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif; color: windowtext;\">The Target of Evaluation (TOE) comprises the following Palo Alto Networks next-generation firewall series and specific appliances:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-410R-5G </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-415</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-415-5G</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-440</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-445</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-450</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-450R</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-450R-5G </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-455</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-460</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-800 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-820</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-850</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-1400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-1410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-1420</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3200 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3220</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3250</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3260</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3420</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3430</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3440</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5200 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5220</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5250</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5260</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5280<a title=\"\" href=\"#_ftn1\" name=\"_ftnref1\"><sup><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">[1]</span></sup></a></span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5420</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5430</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5440</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5445</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5450<a title=\"\" href=\"#_ftn2\" name=\"_ftnref2\"><sup><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">[2]</span></sup></a></span></li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-7000 Series<a title=\"\" href=\"#_ftn3\" name=\"_ftnref3\"><sup><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">[3]</span></sup></a></span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-7050</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-7080</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-7500</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-Series </span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-50</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-100 </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-300 </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-500</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VM-700</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The Palo Alto VM-Series is supported on the following hypervisors:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VMware</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VMware ESXi with vSphere 7.0 </span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Linux KVM</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Ubuntu: 18.04 LTS </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Ubuntu: 20.04 LTS </span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Microsoft Hyper-V Server 2016, or Server 2019 ---- The VM-Series firewall can be deployed on a server running Microsoft Hyper-V.&nbsp; Hyper-V is packaged as a standalone hypervisor, called Hyper-V Server 2019, or as an add-on/role for Windows Server 2019.</span></li>\r\n</ul>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The CCTL conducted evaluation testing of the VM-Series on the following platforms:</span></p>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">VMware ESXi 7.0:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Memory: 128 GB RDIMM</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Microsoft Hyper-V Server 2019:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Memory: 128 GB RDIMM</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Linux KVM 4 Ubuntu 20.04:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"margin: 0in 0in 6pt 24px; text-align: justify; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Memory: 128 GB RDIMM.</span></li>\r\n</ul>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Evaluation testing covered the following hardware and processors:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-3260: Cavium Octeon CN7360 MIPS64 (DP) / Intel Pentium D1517 (MP)</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">PA-5430: AMD EPYC 7642 (DP/MP)</span></li>\r\n</ul>\r\n<p><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">PA-5450: Intel Xeon D-2187NT (DP/MP).</span></p>\r\n<div><br clear=\"all\"><hr align=\"left\" size=\"1\" width=\"33%\">\r\n<div id=\"ftn1\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\"><a title=\"\" href=\"#_ftnref1\" name=\"_ftn1\"><span style=\"vertical-align: super;\"><span style=\"font-family: Calibri, sans-serif;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">[1]</span></span></span></span></a><span style=\"font-family: Calibri, sans-serif;\"> PA-5280 can operate in Express or Secure mode. Secure mode just means it&rsquo;s 5G-ready and requires a license upgrade. </span></p>\r\n</div>\r\n<div id=\"ftn2\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\"><a title=\"\" href=\"#_ftnref2\" name=\"_ftn2\"><span style=\"vertical-align: super;\"><span style=\"font-family: Calibri, sans-serif;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">[2]</span></span></span></span></a><span style=\"font-family: Calibri, sans-serif;\"> PA-5450 firewall supports the following cards: PA-5400 MPC-A, PA-5400 NC-A, and PA-5400 DPC-A.</span></p>\r\n</div>\r\n<div id=\"ftn3\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\"><a title=\"\" href=\"#_ftnref3\" name=\"_ftn3\"><span style=\"vertical-align: super;\"><span style=\"font-family: Calibri, sans-serif;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">[3]</span></span></span></span></a><span style=\"font-family: Calibri, sans-serif;\"> Palo Alto Networks PA-7000 Series firewalls support different Network Processing Cards (NPC) and Switch Management Cards (SMC): PAN-PA-7050-SMC-B, PAN-PA-7080-SMC-B, PAN-PA-7000-LFC-A, PAN-PA-7000-100G-NPC-A-K2-EXP, PAN-PA-7000-100G-NPC-A-K2-SEC, and PAN-PA-7000-100G-NPC. </span></p>\r\n</div>\r\n</div>","evaluation_configuration":"<p style=\"margin: 0in 0in 3pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">The evaluated version of the TOE consists of Palo Alto PAN-OS 11.1.4 running on the following physical and virtual appliances:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-410R-5G</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-415</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-415-5G</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-440</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-445</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-450</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-450R</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-450R-5G </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-455</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-460</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-800 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-820</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-850</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-1400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-1410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-1420</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3200 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3220</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3250</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3260</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3420</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3430</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3440</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5200 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5220</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5250</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5260</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5280<a title=\"\" href=\"#_ftn1\" name=\"_ftnref1\"><sup><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif; color: black;\">[1]</span></sup></a></span></li>\r\n</ul>\r\n</li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5400 Series</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5410</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5420</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5430</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5440</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5445</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5450<a title=\"\" href=\"#_ftn2\" name=\"_ftnref2\"><sup><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif; color: black;\">[2]</span></sup></a></span></li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-7000 Series<a title=\"\" href=\"#_ftn3\" name=\"_ftnref3\"><sup><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif; color: black;\">[3]</span></sup></a></span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-7050</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-7080</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-7500</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-Series </span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-50</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-100 </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-300 </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-500</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VM-700.</span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">The Palo Alto VM-Series is supported on the following hypervisors:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VMware</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VMware ESXi with vSphere 7.0 </span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Linux KVM</span>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Ubuntu: 18.04 LTS </span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Ubuntu: 20.04 LTS </span></li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul style=\"margin-top: 0in; margin-bottom: 6.0pt;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Microsoft Hyper-V Server 2016, or Server 2019 ---- The VM-Series firewall can be deployed on a server running Microsoft Hyper-V.&nbsp; Hyper-V is packaged as a standalone hypervisor, called Hyper-V Server 2019, or as an add-on/role for Windows Server 2019.</span></li>\r\n</ul>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">The CCTL conducted evaluation testing of the VM-Series on the following platforms:</span></p>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">VMware ESXi 7.0:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Memory: 128 GB RDIMM</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Microsoft Hyper-V Server 2019:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Memory: 128 GB RDIMM</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 0in 0.25in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Linux KVM 4 Ubuntu 20.04:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 24px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Dell PowerEdge R740 Processor:&nbsp; Intel Xeon Gold 6248 (Cascade Lake microarchitecture) with Broadcom 57416 NIC</span></li>\r\n<li style=\"margin: 0in 0in 6pt 24px; text-align: justify; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Memory: 128 GB RDIMM.</span></li>\r\n</ul>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">Evaluation testing covered the following hardware and processors:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-3260: Cavium Octeon CN7360 MIPS64 (DP) / Intel Pentium D1517 (MP)</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5430: AMD EPYC 7642 (DP/MP)</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 12pt; font-family: Calibri, sans-serif; color: black;\"><span style=\"font-size: 11.0pt;\">PA-5450: Intel Xeon D-2187NT (DP/MP).</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE must be deployed as described in section 5.1 of this Validation Report and be configured in accordance with the <em>Palo Alto Networks Common Criteria Evaluated Configuration Guide (CCECG) for Next-Generation Firewall with PAN-OS 11.1</em> [16].</p>\r\n<p><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Per NIAP Scheme Policy Letter #22, user installation of vendor-delivered bug fixes and security patches is encouraged between completion of the evaluation and the Assurance Maintenance Date; with such updates properly installed, the product is still considered by NIAP to be in its evaluated configuration.</span></p>\r\n<div><br clear=\"all\"><hr align=\"left\" size=\"1\" width=\"33%\">\r\n<div id=\"ftn1\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Calibri, sans-serif;\"><a title=\"\" href=\"#_ftnref1\" name=\"_ftn1\"><span style=\"vertical-align: super;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; font-family: Calibri, sans-serif;\">[1]</span></span></span></a> PA-5280 can operate in Express or Secure mode. Secure mode just means it&rsquo;s 5G-ready and requires a license upgrade.</p>\r\n</div>\r\n<div id=\"ftn2\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Calibri, sans-serif;\"><a title=\"\" href=\"#_ftnref2\" name=\"_ftn2\"><span style=\"vertical-align: super;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; font-family: Calibri, sans-serif;\">[2]</span></span></span></a> PA-5450 firewall supports the following cards: PA-5400 MPC-A, PA-5400 NC-A, and PA-5400 DPC-A.</p>\r\n</div>\r\n<div id=\"ftn3\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Calibri, sans-serif;\"><a title=\"\" href=\"#_ftnref3\" name=\"_ftn3\"><span style=\"vertical-align: super;\"><span style=\"vertical-align: super;\"><span style=\"font-size: 10.0pt; font-family: Calibri, sans-serif;\">[3]</span></span></span></a> Palo Alto Networks PA-7000 Series firewalls support different Network Processing Cards (NPC) and Switch Management Cards (SMC): PAN-PA-7050-SMC-B, PAN-PA-7080-SMC-B, PAN-PA-7000-LFC-A, PAN-PA-7000-100G-NPC-A-K2-EXP, PAN-PA-7000-100G-NPC-A-K2-SEC, and PAN-PA-7000-100G-NPC.</p>\r\n</div>\r\n</div>","security_evaluation_summary":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the <em>PP-Configuration for Network Devices, Stateful Traffic Filter Firewalls, Virtual Private Network (VPN) Gateways, and Intrusion Prevention System</em>, version 2.0, 25 April 2024, which comprises the following components:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"line-height: 11pt; margin: 0in 0in 6pt 0px; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif; text-indent: 3.3333px;\"><em><span style=\"font-family: Calibri, sans-serif;\">collaborative Protection Profile for Network Devices</span></em><span style=\"font-family: Calibri, sans-serif;\">, Version 3.0e, 6 December 2023&nbsp;<a name=\"m_-6404467673251960978_NDcPP\"></a>[NDcPP]</span></li>\r\n<li style=\"line-height: 11pt; margin: 0in 0in 6pt 0px; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif; text-indent: 3.3333px;\"><em><span style=\"font-family: Calibri, sans-serif;\">PP-Module for Stateful Traffic Filter Firewalls</span></em><span style=\"font-family: Calibri, sans-serif;\">, Version 1.4 + Errata 20200625, 25 June 2020 [FW-Module]</span></li>\r\n<li style=\"line-height: 11pt; margin: 0in 0in 6pt 0px; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif; text-indent: 3.3333px;\"><em><span style=\"font-family: Calibri, sans-serif;\">PP-Module for Virtual Private Network (VPN) Gateways</span></em><span style=\"font-family: Calibri, sans-serif;\">, Version 1.3, 16 August 2023 [VPNGW-Module]&nbsp;</span></li>\r\n<li style=\"line-height: 11pt; margin: 0in 0in 6pt 0px; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif; text-indent: 3.3333px;\"><em><span style=\"font-family: Calibri, sans-serif;\">PP-Module for Intrusion Prevention System (IPS)</span></em><span style=\"font-family: Calibri, sans-serif;\">, Version 1.0, 11 May 2021 [IPS-Module]&nbsp;</span></li>\r\n<li style=\"line-height: 11pt; margin: 0in 0in 6pt 0px; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif; text-indent: 3.3333px;\"><em><span style=\"font-family: Calibri, sans-serif;\">Functional Package for Secure Shell (SSH)</span></em><span style=\"font-family: Calibri, sans-serif;\">, Version 1.0, 13 May 2021 [SSHPKG]&nbsp;</span></li>\r\n</ul>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><strong><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">&nbsp;</span></strong></p>\r\n<p><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 release 5. The product, when delivered configured as identified in the guidance document, satisfies all of the security functional requirements stated in the </span><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Palo Alto Networks PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 11.1</span><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\"> Security Target. The evaluation was completed in <span style=\"background: yellow;\">August 2024.</span> Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<p style=\"margin: 0in; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Security Audit</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110267141\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE is able to generate audit records of security-relevant events including the events specified in [NDcPP], [FW-Module], [VPNGW-Module], [IPS-Module], and [SSHPKG]. By default, the TOE stores the logs locally so they can be accessed by an administrator. The TOE can also be configured to send the logs securely to a designated external log server.&nbsp; </span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Cryptographic Support</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110267157\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE implements NIST-validated cryptographic algorithms that provide key management, random bit generation, encryption/decryption, digital signature and cryptographic hashing and keyed-hash message authentication features in support of higher-level cryptographic protocols, including IPsec, SSH, HTTPS, and TLS. Note that to be in the evaluated configuration, the TOE must be configured in FIPS-CC mode, which ensures the TOE&rsquo;s configuration is consistent with the FIPS standard and the PP claims.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">User Data Protection</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110267176\"></a><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">The TOE is designed to ensure that it does not inadvertently reuse data found in network traffic.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Identification and Authentication</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110247723\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE requires all users accessing the TOE user interfaces to be successfully identified and authenticated before they can access any security management functions available in the TOE. The TOE offers network accessible (HTTPS, SSH, IPsec) connections to the GUI and SSH for interactive administrator sessions and HTTPS for XML and REST API.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE supports the local (i.e., on device) definition and authentication of administrators with username, password or public-key, and role (set of privileges), which it uses to authenticate the user and to associate that user with an authorized role. In addition, the TOE can authenticate users using X.509v3 certificates and can be configured to lock a user out after a configurable number of unsuccessful authentication attempts.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Security Management</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110247744\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE provides a GUI, CLI, or API (XML and REST) to access the security management functions. Security management commands are limited to administrators and are available only after they have provided acceptable user identification and authentication data to the TOE. The TOE provides access to the GUI/API/CLI using an HTTPS/TLS, IPsec, or SSHv2 client.&nbsp;&nbsp;&nbsp; </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE provides a number of management functions and restricts them to users with the appropriate privileges.&nbsp; The management functions include the capability to configure the login banner, configure the idle timeout, configure IKE/IPsec VPN gateways, configure threat signature rules, and other management functions. The TOE provides pre-defined Security Administrator, Audit Administrator, and Cryptographic Administrator roles. These administrator roles are all considered Security Administrator as defined in [NDcPP] for the purposes of the evaluation.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Protection of the TSF</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110247772\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE implements a number of features designed to protect itself to ensure the reliability and integrity of its security features.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">It protects particularly sensitive data such as stored passwords and cryptographic keys so that they are not accessible even by an administrator. It also provides its own timing mechanism to ensure that reliable time information is available (e.g., for log accountability). </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif;\">The TOE includes functions to perform self-tests so that it can detect when it is failing and transition to a secure, maintenance state. It also includes a mechanism to verify TOE updates to prevent malicious or other unexpected changes in the TOE.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">TOE Access</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><a name=\"_Hlk110247790\"></a><span style=\"font-family: Calibri, sans-serif;\">The TOE can be configured to display an administrator-defined advisory banner before establishing an administrative user session and to terminate remote interactive sessions after a configurable period of inactivity. It also provides users the capability to terminate their own interactive sessions.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Trusted Path/Channels</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE protects interactive communication with remote administrators using SSH, HTTP over TLS (HTTPS), or IPsec. SSH, TLS, and IPsec ensure both integrity and disclosure protection. Note: HTTPS traffic can be tunneled through an IPsec secure channel. </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE uses IPsec or TLS to protect communication with an external log server and protects remote VPN gateways/peers using IPsec to prevent unintended disclosure or modification of the transferred data. The TOE also uses TLS to protect communications with GlobalProtect TLS client applications.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Stateful Traffic Filtering</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE provides a stateful traffic filter firewall for layers 3 and 4 (IP and TCP/UDP) network traffic optimized through the use of stateful packet inspection.&nbsp;&nbsp; </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">An administrator can configure the TOE to control the type of information that is allowed to pass through the TOE. The administrator defines the security zone and applies security policies to network traffic attempting to traverse the TOE to determine what actions to take.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE groups interfaces into security zones. Each zone identifies one or more interfaces on the TOE. Separate zones must be created for each type of interface (Layer 2, Layer 3, or virtual wire), and each interface must be assigned to a zone before it can process traffic. Security policies provide the firewall rule sets that specify whether to block or allow network connections, based on the source and destination zones, and addresses, and the application service (such as UDP port 67 or TCP port 80). Security policy rules are processed in sequence, applying the first rule that matches the incoming traffic.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Packet Filtering</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: 'Times New Roman', serif;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE provides packet filtering and secure IPsec tunneling. The tunnels can be established between two trusted VPN peers as well as between remote VPN clients and the TOE. An administrator can configure security policies that determine whether to block, allow, or log a session based on traffic attributes such as the source and destination security zone, the source and destination IP address, the application, user, and the service.&nbsp;&nbsp; </span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Intrusion Prevention System</span></em></strong></p>\r\n<p><span style=\"font-size: 10.0pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">The TOE provides IPS functionalities such as malicious list blocking, reconnaissance and Denial of Service (DoS) flooding protection, anomaly-based and signature-based traffic detection and response mechanisms.</span></p>","features":[{"id":3448,"feature_name":"Asymmetric Key Generation"},{"id":3444,"feature_name":"Auditing"},{"id":3458,"feature_name":"Certificate Authentication"},{"id":3453,"feature_name":"Certificate Validation"},{"id":3451,"feature_name":"Cryptographic Hashing"},{"id":3449,"feature_name":"Cryptographic Key Establishment"},{"id":3450,"feature_name":"Cryptographic Signature Verification"},{"id":3446,"feature_name":"DRBG"},{"id":3463,"feature_name":"Firewall"},{"id":3443,"feature_name":"Flaw Remediation"},{"id":3456,"feature_name":"HTTPS Client"},{"id":3457,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":3460,"feature_name":"IKEv2"},{"id":3464,"feature_name":"Intrusion Prevention"},{"id":3459,"feature_name":"IPsec"},{"id":3452,"feature_name":"Keyed-hash message authentication"},{"id":3445,"feature_name":"SSH Server"},{"id":3461,"feature_name":"TLS 1.2"},{"id":3462,"feature_name":"TLS 1.3"},{"id":3454,"feature_name":"TLS Client"},{"id":3455,"feature_name":"TLS Server without Mutual Authentication"},{"id":3447,"feature_name":"Virtual Network Device"},{"id":3465,"feature_name":"VPN Gateway"}]}