{"product_id":11527,"v_id":11527,"product_name":"SonicWall Secure Mobile Access (SMA) v12.4","certification_status":"Certified","certification_date":"2024-08-14T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"SonicWall, Inc.","website":"www.sonicwall.com"},"vendor_poc":"Mike Vache","vendor_phone":"408-962-6760","vendor_email":"mvache@SonicWall.com","assigned_lab":{"cctl_name":"DEKRA Cybersecurity Certification Laboratory"},"product_description":"<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The Target of Evaluation [TOE] is a Network Device as defined by the collaborative Protection Profile for Network Devices v2.2e [NDcPP]: &ldquo;A network device in the context of this cPP is a device composed of both hardware and software that is connected to the network and has an infrastructure role within the network&rdquo;.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE name is SonicWall Secure Mobile Access (SMA) v12.4, and the evaluated version of the TOE is 12.4.3. In the evaluated configuration it includes SMA 6210, SMA 7210 appliances and SMA 8200v virtual appliance. SonicWall SMA is a unified secure access gateway that enables organizations to provide anytime, anywhere and any device access to corporate resources.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">All SMA hardware appliances are shipped ready for immediate access through a Command Line Interface (CLI) and after basic network configuration through a web-based Appliance Management Console (AMC). Virtual appliance requires installation into hypervisor environment and supports configuration through AMC. To ensure secure use of the product, it must be appropriately configured prior to being put into a production environment as specified in the user guidance.</p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"text-align: justify;\"><span style=\"mso-bidi-font-weight: bold;\">The TOE is a hardware and software solution composed of the Cisco Catalyst Industrial Ethernet IE3x00 Rugged Series Switches running IOS-XE 17.12. <span style=\"mso-spacerun: yes;\">&nbsp;</span></span></p>\r\n<p class=\"MsoBodyText\">The evaluated configuration consists of the following devices:</p>\r\n<table class=\"MsoNormalTable\" style=\"margin-left: 13.25pt; border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes; page-break-inside: avoid; height: 21.1pt;\">\r\n<td style=\"width: 94.25pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 21.1pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"TableHeaderText\" style=\"text-align: left;\" align=\"left\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Catalyst IE3200 Hardware Models</span></p>\r\n</td>\r\n<td style=\"width: 332.4pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 21.1pt;\" valign=\"top\" width=\"443\">\r\n<p class=\"TabletextCxSpFirst\" style=\"text-align: left; page-break-after: avoid;\" align=\"left\"><span style=\"font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">IE-3200-8T2S, IE-3200-8P2S</span></p>\r\n<p class=\"TabletextCxSpLast\"><span style=\"font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">&nbsp;</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1; page-break-inside: avoid; height: 21.1pt;\">\r\n<td style=\"width: 94.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 21.1pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"TableHeaderText\" style=\"text-align: left;\" align=\"left\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Catalyst IE3300 Hardware Models</span></p>\r\n</td>\r\n<td style=\"width: 332.4pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 21.1pt;\" valign=\"top\" width=\"443\">\r\n<p class=\"Tabletext\"><span style=\"font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">IE-3300-8T2S, IE-3300-8P2S, IE-3300- 8T2X, IE-3300- 8U2X</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2; page-break-inside: avoid;\">\r\n<td style=\"width: 94.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"TableHeaderText\" style=\"text-align: left;\" align=\"left\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Catalyst IE3400 Hardware Models</span></p>\r\n</td>\r\n<td style=\"width: 332.4pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"443\">\r\n<p class=\"TableText10Point\"><span lang=\"EN-GB\" style=\"mso-bidi-font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">IE-3400-8T2S, IE-3400-8P2S</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3; page-break-inside: avoid;\">\r\n<td style=\"width: 94.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"TableHeaderText\" style=\"text-align: left;\" align=\"left\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Catalyst IE3400H Hardware Models</span></p>\r\n</td>\r\n<td style=\"width: 332.4pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"443\">\r\n<p class=\"TableText10Point\"><span lang=\"EN-GB\" style=\"mso-bidi-font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">IE-3400H-8FT, IE-3400H-8T, IE-3400H-16FT, IE-3400H-16T, IE-3400H-24FT, IE-3400H-24T</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4; mso-yfti-lastrow: yes; page-break-inside: avoid;\">\r\n<td style=\"width: 94.25pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"126\">\r\n<p class=\"TableHeaderText\" style=\"text-align: left;\" align=\"left\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Software Version</span></p>\r\n</td>\r\n<td style=\"width: 332.4pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"443\">\r\n<p class=\"TableText10Point\"><span lang=\"EN-GB\" style=\"mso-bidi-font-size: 10.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">IOS-XE 17.12</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R5.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 R5.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">Dekra Certification has determined that the product meets the security criteria in the Security Target, which specifies compliance with <em>collaborative Protection Profile for Network Devices v2.2e.</em></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">A team of validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in August 2024.</p>","environmental_strengths":"<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Security Audit</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE generates audit records for all security-relevant events. For each event, the TOE records the date and time, the type of event, the subject identity, and the outcome of the recoded event. The resulting records can be stored locally or securely sent to a designated audit server for archiving. Security Administrators using the appropriate AMC menu can also view audit records locally. The TOE also implements timestamps based on a local system clock to ensure reliable audit information produced.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Cryptographic Support</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE performs the following cryptographic functionality:</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">Encryption, decryption, hashing, keyed-hash message authentication, random number generation, signature generation and verification utilizing dedicated cryptographic library.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">Cryptographic functionality is utilized to implement secure channels.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">TLSv1.2</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">Entropy is collected from multiple entropy sources and used to support PRNG seeding with full entropy.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">Critical Security Parameters (CSPs) internally stored and cleared when no longer in use.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">X.509v3 certificate-based authentication integrated with TLS protocol.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE is certified as a FIPS 140-2 level 2 cryptographic module, it internally manages CSPs and implements deletion procedures to mitigate the possibility of disclosure or modification of CSPs. Additionally, the TOE provides functionality to manually clear CSPs (e.g. host RSA keys), that can be invoked by a Security Administrator with appropriate permissions.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Identification and Authentication</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE supports Role-Based Access Control (RBAC) managed by an AAA module that stores and manages permissions of all users and their roles. Before any other action, each user is identified with a login name and authenticated with a password. Each authorized user is associated with assigned role and specific permissions that determine access to TOE features.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Security Management</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE allows remote administration using a TLS session over an internal management Ethernet port and local administration using a console adapter via a separate RJ-45 running RS-232 signaling. Remote administration is conducted over web-based interface (AMC) and local administration conducted over CLI.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">All of the management functionality is restricted to the Security Administrators of the TOE. The Security Administrators are authorized to perform configuration and management of the TOE. The term &ldquo;Security Administrator&rdquo; is used to refer to any user with an administrative role and sufficient permissions.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Protection of the TSF</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE implements a number of measures to protect the integrity of its security features. The TOE protects CSPs, including stored passwords and cryptographic keys, so they are not directly viewable in plaintext. The TOE also ensures that reliable time information is available for both log accountability and synchronization with the operating environment.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE employs both dedicated communication channels as well as cryptographic means to protect the communication between itself and the other components in the operational environment.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE performs self-tests to detect internal failures and to protect itself from malicious updates.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>TOE Access</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE will display a customizable banner when an administrator initiates an interactive local or remote session. The TOE also enforces an administrator-defined inactivity timeout after which the inactive session is automatically terminated. Once a session (local or remote) has been terminated, the TOE requires the user to re-authenticate.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>Trusted Path/Channels</strong></p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\">The TOE protects remote sessions by establishing a trusted path secured with TLS between itself and the administrator. The TOE prevents disclosure or modification of audit records by establishing a trusted channel secured with TLS between itself and the audit server.</p>\r\n<p style=\"margin: 0cm; font-size: 11pt; font-family: Arial, sans-serif;\"><strong>&nbsp;</strong></p>","features":[{"id":3103,"feature_name":"Asymmetric Key Generation"},{"id":3099,"feature_name":"Auditing"},{"id":3113,"feature_name":"Certificate Authentication"},{"id":3109,"feature_name":"Certificate Validation"},{"id":3107,"feature_name":"Cryptographic Hashing"},{"id":3104,"feature_name":"Cryptographic Key Establishment"},{"id":3106,"feature_name":"Cryptographic Signature Verification"},{"id":3101,"feature_name":"DRBG"},{"id":3100,"feature_name":"Key Destruction"},{"id":3108,"feature_name":"Keyed-hash message authentication"},{"id":3116,"feature_name":"TLS 1.2"},{"id":3112,"feature_name":"TLS Client"},{"id":3111,"feature_name":"TLS Server with Mutual Authentication"},{"id":3102,"feature_name":"Virtual Network Device"}]}