{"product_id":11626,"v_id":11626,"product_name":"Juniper Networks® ACX7024 and ACX7024X routers with Junos® OS Evolved Version 24.4R2","certification_status":"Certified","certification_date":"2026-01-21T00:00:00Z","tech_type":"Network Device,Remote Access","vendor_id":{"name":"HPE Juniper Networking","website":"https://www.juniper.net"},"vendor_poc":"Geetha Naik","vendor_phone":"+91 98459 58258","vendor_email":"ngeetha@juniper.net","assigned_lab":{"cctl_name":"atsec information security corporation"},"product_description":"<p>The Target of Evaluation (TOE) is Juniper Networks&reg; ACX7024 and ACX7024X routers with Junos&reg; OS Evolved version 24.4R2. The TOE is a network switch composed of hardware and firmware. The firmware is named Junos&reg; OS Evolved which is the single purpose operating system that operates the management functions of all the Juniper Networks&reg; routers.&nbsp;</p>\r\n<p>The TOE is the entire network appliance. The TOE is connected to management workstations, to one or more NTP servers, and to a syslog server. The management workstations can be local or remote. The TOE is also connected to the networks which it interconnects.</p>\r\n<p>The TOE software is Junos&reg; OS Evolved, which is the Juniper Linux-based operating system for network devices. It implements a flexible Software Defined Networking (SDN) allowing the tailoring of the software to several applications. Junos&reg; OS Evolved is a horizontal software layer that decouples the application processes from the hardware on which the processes run. Effectively, this decoupling creates a general-purpose software infrastructure spanning all different computing resources on the system. Application processes (protocols, services, and so on) run on top of this infrastructure and communicate with each other by publishing and consuming (that is, subscribing to) the state. Junos&reg; OS Evolved implements the routing, filtering, management, and platform functions.</p>","evaluation_configuration":"<p>The TOE software is provided as an ISO image, as well as necessary TOE updates, running on the&nbsp; following hardware platforms:</p>\r\n<ul>\r\n<li>ACX7024: industrial-rated (I-Temp) multiservice router</li>\r\n<li>ACX7024X: commercial-rated (C-Temp), highscale multiservice router</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation &nbsp;&nbsp;&nbsp;&nbsp;Scheme (CCEVS) process. The criteria against which the ACX7024 and ACX7024X routers with Junos&reg; OS Evolved Version 24.4R2 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R5. The evaluation methodology used by the evaluation team to conduct the evaluation was the Common Methodology for Information Technology Security Evaluation, Version 3.1, R5 supplemented by that found in the Protection Profiles cited below. The evaluation was completed in January 2026. The product, when delivered and configured as identified in the <em>C</em><em>ommon Criteria Evaluated Configuration Guide for ACX7024 and ACX7024X Devices</em>, meets the requirements of the following:</p>\r\n<ul>\r\n<li>collaborative Protection Profile for Network Devices, Version 3.0e, 2023-12-06 with\r\n<ul style=\"list-style-type: circle;\">\r\n<li>Optional Security Assurance Requirements ALC_FLR.3</li>\r\n</ul>\r\n</li>\r\n<li>Functional Package for SSH, Version 1.0, 2021-05-13</li>\r\n</ul>","environmental_strengths":"<h3>Security Audit</h3>\r\n<p>The TOE implements an audit function. A rich set of audit data is collected and stored as audit records. Each audit record includes a time stamp stating the exact time at which the audit record was generated. Each audit record also includes sufficient information to allow administrators of the TOE to examine the events and investigate possible security violations and attempts thereof.</p>\r\n<p>Audit records are stored in log files within the TOE. The administrator also configures the TOE to forward the audit records to an external syslog server. The syslog server is not part of the TOE. Forwarding the audit records to a syslog server takes place over a trusted channel protected with the SSHv2 protocol.</p>\r\n<h3>Cryptographic Support</h3>\r\n<p>The TOE implements cryptographic functionality for the following purposes:</p>\r\n<ul>\r\n<li>protection of user passwords;</li>\r\n<li>establishment of trusted channels and trusted paths using the SSHv2 protocol;</li>\r\n<li>symmetric key authentication for the NTP protocol; and</li>\r\n<li>digital signature verification for TOE trusted updates.</li>\r\n</ul>\r\n<p>The TOE includes several cryptographic libraries for providing this functionality:</p>\r\n<ul>\r\n<li>The Junos&reg; OS Evolved Kernel Cryptographic Module provides a Deterministic Random Bit Generation (DRBG), compliant with SP800-90A, for the creation of random data and cryptographic keys; and hashing algorithms for the protection of user's passwords.</li>\r\n<li>The Junos&reg; OS Evolved OpenSSL Cryptographic Module, based on the open source OpenSSL library version 3.0.16, provides the rest of the cryptographic algorithms.</li>\r\n</ul>\r\n<p>The TOE also includes a physical, SP800-90B compliant Entropy Source implemented in the TOE hardware for seeding the DRBG with full entropy. In the evaluated configuration, the DRBG is only seeded by the entropy source claimed in FCS_RBG_EXT.1.</p>\r\n<p>All cryptographic algorithms implemented in the Junos&reg; OS Evolved OpenSSL Cryptographic Module and the Junos&reg; OS Evolved Kernel Cryptographic Module are validated by the Cryptographic Algorithm Validation Program (CAVP). This fulfills the requirements of NIAP Policy Letter #5. In addition, the SP800-90B compliant Entropy Source is validated by the Entropy Source Validation (ESV).</p>\r\n<p><strong>Identification and Authentication</strong></p>\r\n<p>The TOE ensures that access to administrative functions is only granted to successfully identified and authenticated users. Illegitimate users are deterred and prevented from gaining access.</p>\r\n<p>The TOE implements password-based authentication to local and remote users. Remote authentication, which is implemented over a trusted path using SSHv2, can be also performed using public-key authentication.</p>\r\n<p>The external syslog server establishes an SSHv2 session under NETCONF with the TOE so the TOE can send audit records. The TOE identifies and authenticates the external server using SSHv2 public-key authentication.</p>\r\n<p><strong>Security Management</strong></p>\r\n<p>Authorized administrators may use a Command Line Interface (CLI) for performing a wide range of security management tasks on the TOE. The CLI may be accessed locally from the console or remotely over a SSH connection. There are no alternative methods of administering the TOE.</p>\r\n<h3>Protection of the TSF</h3>\r\n<p>The TOE implements a set of security measures for protecting its TSF and the corresponding configuration parameters. The TOE implements integrity tests of the TOE and cryptographic algorithm self-tests at start-up and takes protective measures if the tests indicate that the TOE software has been tampered or there is a failure in the self-tests.</p>\r\n<p>The TOE protects passwords by hashing their values and not allowing direct access to where they are stored. The TOE also protects cryptographic keys by enforcing access control to the key containers.</p>\r\n<p>TOE access is restricted to authorized administrators and all administrator access goes through a CLI. Administrators have no root access to the underlying Linux operating system.</p>\r\n<p>The TOE also allows upgrading the software in case of vulnerabilities being discovered in the implementation. The integrity of the TOE software is ensured by using a digital signature that is verified before the TOE update.</p>\r\n<p>The TOE maintains a system clock that is used for generating time stamps used in the enforcement of security functions.</p>\r\n<p><strong>TOE Access</strong></p>\r\n<p>The TOE allows the display of a banner before and after a user logs in. The TOE also controls idle remote sessions and terminates the session after a period of time.</p>\r\n<h3>Trusted Path/Channels</h3>\r\n<p>The TOE implements a secure channel for administrators to manage the TOE remotely. Administrators can connect to the TOE from a remote management station using the SSHv2 protocol. Once successfully identified and authenticated, the administrator has access to the Command Line Interface (CLI).</p>\r\n<p>The TOE also establishes a secure channel using SSHv2 for sending audit records to an external syslog server.</p>\r\n<p>The TOE includes the OpenSSH library version 9.8p1 to implement the SSHv2 protocol. The TOE allows both password-based and public-key-based authentication. The underlying cryptographic algorithms needed for the protocol are provided by the Junos&reg; OS Evolved OpenSSL Cryptographic Module.</p>","features":[{"id":990,"feature_name":"Asymmetric Key Generation"},{"id":982,"feature_name":"Auditing"},{"id":986,"feature_name":"Cryptographic Hashing"},{"id":985,"feature_name":"Cryptographic Key Establishment"},{"id":988,"feature_name":"Cryptographic Signature Generation"},{"id":991,"feature_name":"Cryptographic Signature Verification"},{"id":989,"feature_name":"DRBG"},{"id":981,"feature_name":"Flaw Remediation"},{"id":992,"feature_name":"IPsec"},{"id":983,"feature_name":"Key Destruction"},{"id":987,"feature_name":"Keyed-hash message authentication"},{"id":12,"feature_name":"Network Router"},{"id":984,"feature_name":"SSH Server"}]}