{"product_id":11513,"v_id":11513,"product_name":"Quantum Force R81.20","certification_status":"Certified","certification_date":"2025-04-30T00:00:00Z","tech_type":"Firewall,Network Device,Virtual Private Network","vendor_id":{"name":"Check Point Software Technologies Ltd.","website":"https://www.checkpoint.com"},"vendor_poc":"Malcolm Levy","vendor_phone":"972545713450","vendor_email":"mlevy@checkpoint.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">Check Point Gateway appliances provide a broad range of services, features and capabilities. &nbsp;This ST makes a set of claims regarding the product's security functionality, in the context of an evaluated configuration. The claimed security functionality is a subset of the product's full functionality. The evaluated configuration is a subset of the possible configurations of the product, established according to the evaluated configuration guidance.</p>","evaluation_configuration":"<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE is Check Point software Security Gateway Appliances running software version R81.20.  The TOE includes the following components:</p><ul style=\"margin-top: 0in; margin-bottom: 0in;\" type=\"disc\" data-mce-style=\"margin-top: 0in; margin-bottom: 0in;\"><li style=\"text-align: justify; margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"text-align: justify; margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 10pt; font-family: Times, serif;\">Check Point Security Gateway Appliances; and</li><li style=\"text-align: justify; margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"text-align: justify; margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 10pt; font-family: Times, serif;\">Security Management Servers;</li></ul><p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><br data-mce-bogus=\"1\"></p><p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">All products are running Checkpoint version R81.20 software. <a name=\"_Hlk5239538\" contenteditable=\"false\"></a>All platforms are x86 based hardware. These platforms can be installed as a Security Gateway and all are running the R81.20 software.</p><ul style=\"margin-bottom: 0in; margin-top: 0px;\" data-mce-style=\"margin-bottom: 0in; margin-top: 0px;\"><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Check Point 3600, 3800</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Check Point 6200, 6400, 6600, 6700, 6900</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Check Point 7000</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Check Point 16200, 16600</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Checkpoint 26000, 28000, 28600</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">QLS250, QLS650</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">19200</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">29100, 29200</li><li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">ESXi 7.0 (HPE D360 G10)</li></ul><p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><br data-mce-bogus=\"1\"></p><p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\" data-mce-style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">The following Check Point “Smart-1” Security Management Servers are included in the evaluated configuration, running the same R81.20 software.  The below platform and virtualized platform run the same software but provide Security Management Server functionality and do not operate as a Security Gateway.</p><ul style=\"margin-bottom: 10pt; margin-top: 0px;\" data-mce-style=\"margin-bottom: 10pt; margin-top: 0px;\"><li style=\"margin: 0in 0in 10pt 0px; line-height: 120%; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"margin: 0in 0in 10pt 0px; line-height: 120%; font-size: 10pt; font-family: 'Times New Roman', serif;\">Smart-1 600-M, Smart-1 6000-L, Smart-1 6000-XL</li><li style=\"margin: 0in 0in 10pt 0px; line-height: 120%; font-size: 10pt; font-family: 'Times New Roman', serif;\" data-mce-style=\"margin: 0in 0in 10pt 0px; line-height: 120%; font-size: 10pt; font-family: 'Times New Roman', serif;\">ESXi 7.0 (HPE D360 G10)</li></ul>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Check Point Software Technologies LTD. Quantum Force R81.20 Common Criteria Supplement, Version 1.0, April 23, 2025 and Check Point Software Technologies LTD. Quantum Force R81.20 NIAP Installation Guide, Version 1.0, March 21, 2025 documents, satisfies all of the security functional requirements stated in the Check Point Software Technologies LTD. Quantum Force R81.20 Security Target, version 0.4, April 23, 2025.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in April 2025.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11509-2025) prepared by CCEVS</span></p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Quantum Force R81.20 are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE generates audit logs and has the capability to store them internally or to send them to an external audit server.&nbsp; The connection between the TOE and the remote audit server is protected with IPsec.&nbsp; The TOE has a disk cleanup procedure where it removes old audit logs to allow space for new ones.&nbsp; When disk space falls below a predefined threshold (the cleanup procedure cannot keep up with the audit collection), the TOE stops collecting audit records.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Communication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE is a distributed solution consisting of Quantum Force as well as a Security Management Server.&nbsp; The Security Management Server can manage one or more Quantum Force Appliances.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE uses the Check Point Cryptographic Library version 1.1 that has received Cryptographic Algorithm Validation Program (CAVP) certificates for all cryptographic functions claimed in this ST.&nbsp; Cryptographic services include key management, random bit generation, encryption/decryption, digital signature and secure hashing.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE ensures that residual information is protected from potential reuse in accessible objects such as network packets.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Firewall:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE supports many protocols for packet filtering including icmpv4, icmpv6, ipv4, ipv6, tcp and udp.&nbsp; The firewall rules implement the SPD rules (permit, deny, bypass).&nbsp; Each rule can be configured to log status of packets pertaining to the rule. All codes under each protocol are implemented.&nbsp; The TOE supports FTP for stateful filtering.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Routed packets are forwarded to a TOE interface with the interface&rsquo;s MAC address as the layer-2 destination address.&nbsp; The TOE routes the packets using the presumed destination address in the IP header, in accordance with route tables maintained by the TOE.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">IP packets are processed by the Check Point R81.20 software, which associates them with application-level connections, using the IP packet header fields: source and destination IP address and port, as well as IP protocol. &nbsp;Fragmented packets are reassembled before they are processed.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE mediates the information flows according to an administrator-defined policy. &nbsp;Some of the traffic may be either silently dropped or rejected (with notification to the presumed source).</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE's firewall and VPN capabilities are controlled by defining an ordered set of rules in the Security Rule Base. &nbsp;The Rule Base specifies what communication will be allowed to pass and what will be blocked. &nbsp;It specifies the source and destination of the communication, what services can be used, at what times, whether to log the connection and the logging level.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10pt;\">The TOE implements a password-based authentication mechanism for authenticating users and requires identification and authentication before allowing access.&nbsp; Only the banner may be presented before authentication is complete.&nbsp; The TOE supports passwords of varying length and allows an administrator to specify a minimum password length between 8 and 100 characters long.&nbsp; The password composition can contain all special characters as required by FIA_PMG_EXT.1.1.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Internally, the TOE keeps track of failed login attempts and if the configured number of attempts is met, the administrator is either locked out for a period of time or until the primary administrator unlocks the account.&nbsp; The local CLI remains available when the remote account is locked out.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE&rsquo;s IPsec implementation supports X.509 certificates (both RSA and ECDSA) for IKE authentication.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE allows both local and remote administration for management of the TOE&rsquo;s security functions.&nbsp; The TOE creates and maintains roles for configured administrators.&nbsp; An administrator can log in locally to the TOE using a serial connection. The local login operates in a Command Line Interface (CLI). There is one remote administration interface that can be used once the TOE is in its evaluated configuration. The remote administration interface is executed through a Graphical User Interface program named SmartConsole using a connection protected by IPsec.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Packet filtering:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">Please see the prior&nbsp;<em>Firewall</em> section for a description of the TOE&rsquo;s packet filtering mechanism.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE includes capabilities to protect itself from unwanted modification as well as protecting its persistent data.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE does not store passwords in plaintext; they are obfuscated. &nbsp;The TOE does not support any command line capability to view any cryptographic keys generated or used by the TOE.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE only allows updates after their signature is successfully verified.&nbsp; The TOE update mechanism uses ECDSA with SHA-512 and P-521 to verify the signature of the update package.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE&rsquo;s FIPS executables are signed using ECDSA with SHA-512 and P-521. For all other executables a hash is computed during system installation and configuration and during updates.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">During power-up the integrity of all executables is verified. &nbsp;If an integrity test fails in the cryptographic module, the system will enter a kernel panic and will fail to boot up. &nbsp;If an integrity test fails due to a non-matching hash, a log is written. &nbsp;Also during power-up, algorithms are tested in the kernel and user-space.&nbsp; If any of these test fail, the TOE is not operational for users.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE protects all communications among its distributed components with IPsec.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides a timestamp for use with audit records, timing elements of cryptographic functions, and inactivity timeouts.</p>\r\n<p style=\"text-align: justify; break-after: avoid; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>TOE access:</strong></p>\r\n<p style=\"text-align: justify; break-after: avoid; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE is able to terminate interactive sessions if the session is inactive for an administrator configured period of time.&nbsp; The TOE also allows a session to be disconnected via a logout command.&nbsp; An administrator can configure a login banner to be displayed before authentication is completed.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE protects all communications with outside entities using IPsec communications only.&nbsp; The TOE employs IPsec when it sends audit data to an audit server, and when allowing remote administration connections.&nbsp; Any protocol that is part of the distributed TOE must be protected in an IPsec connection.</p>","features":[{"id":2657,"feature_name":"Asymmetric Key Generation"},{"id":2660,"feature_name":"Auditing"},{"id":2652,"feature_name":"Certificate Authentication"},{"id":2654,"feature_name":"Certificate Validation"},{"id":2672,"feature_name":"Cryptographic Hashing"},{"id":2670,"feature_name":"Cryptographic Key Establishment"},{"id":2671,"feature_name":"Cryptographic Signature Verification"},{"id":2669,"feature_name":"DRBG"},{"id":2668,"feature_name":"Firewall"},{"id":2651,"feature_name":"IPsec"},{"id":2662,"feature_name":"Key Destruction"},{"id":2673,"feature_name":"Keyed-hash message authentication"},{"id":2649,"feature_name":"VPN Gateway"}]}