{"product_id":11514,"v_id":11514,"product_name":"Cisco Nexus 9000 Series Switches Running NX-OS 10.4","certification_status":"Certified","certification_date":"2025-01-27T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":"Petra Manche","vendor_phone":"4085264000","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE is comprised of both software and hardware. The hardware is comprised of the following model series: 9200, 9300, 9400, 9500, and 9800. The software is comprised of the NX-OS software image Release10.4.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The Cisco Nexus 9000 Series Switches that comprise the TOE have common hardware characteristics. These characteristics affect only non-TSF relevant functions of the switches (such as throughput and amount of storage) and therefore support security equivalency of the switches in terms of hardware. All security functionality is enforced on the Nexus 9000 Series switches.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">NX-OS is a Cisco-developed highly configurable proprietary operating system that provides for efficient and effective routing and switching. Although NX-OS performs many networking functions, this TOE only addresses the functions that provide for the security of the TOE itself.</p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE consists of one or more switches and includes the NX-OS software. The TOE has two or more network interfaces and is connected to at least one internal and one external network. The Cisco NX-OS configuration determines how packets are handled to and from the TOE&rsquo;s network interfaces. The switch configuration will determine how traffic flows received on an interface will be handled. Typically, packet flows are passed through the internetworking device and forwarded to their configured destination.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">If the TOE is to be remotely administered, then the management workstation must be connected to an internal network and SSHv2 must be used to securely connect to the TOE. Audit records are stored locally and are also remotely backed up to a remote syslog server. If these servers are used, they must be attached to the internal (trusted) network. The internal (trusted) network is meant to be separated effectively from unauthorized individuals and user traffic; one that is in a controlled environment where implementation of security policies can be enforced.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The following models are included in the TOE:</p>\r\n<table class=\"MsoTableGrid\" style=\"border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong><span style=\"font-family: 'Times New Roman', serif; color: white;\">Series</span></strong></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border: solid #C00000 1.0pt; border-left: none; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong><span style=\"font-family: 'Times New Roman', serif; color: white;\">Models</span></strong></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Nexus 9200</span></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K- C92348GC-X</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Nexus 9300</span></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C93108TC-FX, N9K-C9348GC-FXP, N9K-C93216TC-FX2, N9K-C93180YC-FX,</span></p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C93240YC-FX2, N9K-C93360YC-FX2, N9K-C9364C, N9K-C9332C, N9K-C9336C-FX2,</span></p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C9364C-GX, N9K-C9316D-GX, N9K-C93600CD-GX, N9K-C93400LD-H1</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Nexus 9400</span></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C9400-Sup-A</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Nexus 9500</span></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C9504, N9K-C9508, N9K-C9516, N9K-SUP-A+, N9K-SUP-B+, N9K-SC-A</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 62.75pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Nexus 9800</span></p>\r\n</td>\r\n<td style=\"width: 404.75pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">N9K-C9804, N9K-C9808</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Cisco Nexus 9000 Series Switches Running NX-OS 10.4 Common Criteria Operational User Guidance and Preparative Procedures, Version 0.9, January 21, 2025 document, satisfies all of the security functional requirements stated in the Cisco Nexus 9000 Series Switches running on NX-OS 10.4 Security Target, Version 0.9, January 21, 2025.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in January 2025.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11514-2025) prepared by CCEVS.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Cisco Nexus 9000 Series Switches Running NX-OS 10.4 are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 12pt; font-size: 12pt; font-family: Cambria, serif;\"><span style=\"font-size: 10pt; font-family: 'times new roman', times, serif;\">The TOE provides extensive capabilities to generate audit data targeted at detecting such activity.&nbsp; The TOE generates an audit record for each auditable event.&nbsp; Each security relevant audit event has the date, timestamp, event description, and subject identity.&nbsp; The administrator configures auditable events, performs back-up operations, and manages audit data storage.&nbsp; The TOE provides circular audit trail.&nbsp; Audit logs are transmitted to an external audit server over a trusted channel protected with TLS.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The auditable events include:</p>\r\n<ul style=\"margin-bottom: 3pt; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">failure on invoking cryptographic functionality such as establishment, termination and failure of cryptographic session establishments and connections;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">modifications to the group of users that are part of the authorized administrator roles;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">all use of the user identification mechanism;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">any use of the authentication mechanism;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Administrator lockout due to excessive authentication failures;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">any change in the configuration of the TOE;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">changes to time;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">initiation of TOE update;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">indication of completion of TSF self-test;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">maximum sessions being exceeded;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">termination of a remote session;</li>\r\n<li style=\"margin: 0in 0in 3pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">attempts to unlock a termination session and</li>\r\n<li style=\"margin: 0in 0in 12pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">initiation and termination of a trusted channel.</li>\r\n</ul>\r\n<p><span style=\"font-size: 10pt; font-family: 'times new roman', times, serif;\">The authorized administrator configures auditable events, performs back-up operations, and manages audit data storage. The TOE is configured to transmit the audit messages to an external syslog server. Communication with the syslog server is protected by using TLS and the TOE can determine when communication with the syslog server fails.&nbsp; In the presence of a TLS communication failure, the TOE will continuously and automatically re-attempt to reestablish the syslog connection in case of a network disruption. In the case of a TLS protocol failure the administrator should review the configuration of both the TOE and the syslog server.</span></p>\r\n<p><span style=\"font-size: 10pt; font-family: 'times new roman', times, serif;\">The audit logs can be viewed on the TOE using the appropriate NX-OS commands.&nbsp; The records include the date/time the event occurred, the event/type of event, the user associated with the event, and additional information of the event and its success and/or failure.&nbsp; The TOE does not have an interface to modify audit records, though there is an interface available for the authorized administrator to clear (delete) audit data stored locally on the TOE.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides cryptography in support of other TOE security functionality.&nbsp; All the algorithms claimed have CAVP certificates (Operation Environment &ndash; Intel Xeon processor).&nbsp; All the algorithms claimed have CAVP certificates.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The NX-OS software calls the CiscoSSL FOM Cryptographic implementation version 7.3a and has been validated for conformance to the requirements of FIPS 140-2 Level 1.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides cryptography in support of remote administrative management via SSHv2 and secure the session between the TOE and remote syslog server using TLS.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE performs one type of authentication: authentication for the Authorized Administrator of the TOE using a local user database.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides authentication services for administrative users wishing to connect to the TOE&rsquo;s secure CLI administrator interface.&nbsp; The TOE requires Authorized Administrators to authenticate prior to being granted access to any of the management functionality.&nbsp; The TOE is configured to require a minimum password length of 8 characters as well as password-strength checking that disables the use of weak passwords.&nbsp; The TOE provides administrator authentication against a local user database.&nbsp; Password-based authentication can be performed on the serial console or SSH interfaces.&nbsp; The SSHv2 interface also supports authentication using SSH keys.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">After a configurable number of incorrect login attempts, Cisco Nexus 9K Series will lockout the account until an Authorized Administrator takes action.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE uses X.509v3 certificates as defined by RFC 5280 to support authentication for TLS connections.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE. All TOE administration occurs either through a secure SSHv2 session or via a local console connection. The TOE provides the ability to securely manage:</span></p>\r\n<ul style=\"margin-bottom: 4pt; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to administer the TOE locally and remotely;&nbsp; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure the access banner;&nbsp; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure the session inactivity time before session termination or locking;&nbsp; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to update the TOE, and to verify the updates using [digital signature] capability prior to installing those updates;&nbsp; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure the authentication failure parameters for FIA_AFL.1;&nbsp; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure audit behaviour (e.g. changes to storage locations for audit; changes to behaviour when local audit storage space is full); </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to modify the behaviour of the transmission of audit data to an external IT entity; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to manage the cryptographic keys; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure the cryptographic functionality; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure thresholds for SSH rekeying; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to re-enable an Administrator account; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to set the time which is used for time-stamps; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to configure the reference identifier for the peer; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to manage the TOE's trust store and designate X509.v3 certificates as trust anchors; </span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to import X.509v3 certificates to the TOE's trust store;</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: windowtext;\">Ability to manage the trusted public keys database; </span></li>\r\n</ul>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: Arial, sans-serif; color: black;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The Cisco Nexus 9K Series switch supports the following predefined roles:</span></p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 4.0pt;\">\r\n<li style=\"margin: 0in 0in 4pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">network-admin &ndash; This role is a super administrative role. This role has read and write privileges for any configuration item on the Nexus 9000 Series.</span></li>\r\n<li style=\"margin: 0in 0in 4pt 0px; font-size: 12pt; font-family: Arial, sans-serif; color: black;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">network-operator - This role has read access to the entire NX-OS device.</span></li>\r\n<li style=\"margin: 0in 0in 12pt 0px; font-size: 10pt; font-family: 'Times New Roman', serif;\">server-admin - Complete read access to the entire NX-OS device and upgrade capability.</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">All administrators are considered to be security administrators in this ST. The Cisco Nexus 9K Series has a CLI that can be administered either remotely using SSHv2 or locally via a console that is directly connected via a serial cable.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication, and access controls to limit configuration to Authorized Administrators.&nbsp; The TOE prevents reading of cryptographic keys and passwords.&nbsp; Additionally, Cisco NX-OS is not a general-purpose operating system and access to Cisco NX-OS memory space is restricted to only Cisco NX-OS functions.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE internally maintains the date and time. This date and time are used as the timestamp that is applied to audit records generated by the TOE. Administrators can update the TOE&rsquo;s clock manually.&nbsp; Finally, the TOE performs testing to verify correct operation of the router itself and that of the cryptographic module.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE can verify any software updates prior to the software updates being installed on the TOE to avoid the installation of unauthorized software.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>TOE access:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE can terminate inactive sessions after an Authorized Administrator configurable time-period.&nbsp; Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session.&nbsp; The administrator can also terminate their own session by exiting out of the CLI.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE can also display an Authorized Administrator specified banner on the CLI management interface prior to allowing any administrative access to the TOE.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE allows trusted paths to be established to itself from remote administrators over SSHv2 for remote CLI access. Nexus 9K also allows a trusted channel to be established with a syslog server using TLS.</p>","features":[{"id":542,"feature_name":"Asymmetric Key Generation"},{"id":539,"feature_name":"Auditing"},{"id":556,"feature_name":"Certificate Authentication"},{"id":547,"feature_name":"Certificate Validation"},{"id":545,"feature_name":"Cryptographic Hashing"},{"id":543,"feature_name":"Cryptographic Key Establishment"},{"id":544,"feature_name":"Cryptographic Signature Verification"},{"id":541,"feature_name":"DRBG"},{"id":540,"feature_name":"Key Destruction"},{"id":546,"feature_name":"Keyed-hash message authentication"},{"id":625,"feature_name":"Network Switch"},{"id":552,"feature_name":"SSH Server"},{"id":549,"feature_name":"TLS 1.2"},{"id":548,"feature_name":"TLS Client"}]}