{"product_id":11656,"v_id":11656,"product_name":"Extreme Networks Fabric Engine Switches v9.1.100","certification_status":"Certified","certification_date":"2026-06-02T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Extreme Networks, Inc.","website":"www.extremenetworks.com"},"vendor_poc":"Craig Ficik","vendor_phone":"603-952-5922","vendor_email":"cficik@extremenetworks.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE is the Extreme Networks Fabric Engine Switches v9.1.100.&nbsp; The TOE is a standalone network device that facilitates Data Link Layer data transfer between network nodes connected to its physical ports.&nbsp; TOE consists of a hardware appliance with embedded firmware.&nbsp; The TOE evaluated configuration is one instance of one of those listed models running Fabric Engine 9.1.100.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">All TOE appliances are shipped ready for immediate access through a Command Line Interface [CLI], with some basic features enabled by default.&nbsp; However, to ensure secure use, the product must be configured prior to being put into a production environment as specified in the user guidance.&nbsp; The CLI is a text based interface which is accessible from a directly connected terminal or via a remote terminal using SSH.&nbsp; All of the remote management interfaces are protected using encryption.</p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE consists of the hardware models shown in the table below:</p>\r\n<div align=\"center\">\r\n<div align=\"center\">\r\n<table class=\"MsoNormalTable\" style=\"width: 377.75pt; border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"height: 5.35pt;\">\r\n<td style=\"width: 112.25pt; border: solid #C00000 1.0pt; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: white;\">Platform</span></strong></p>\r\n</td>\r\n<td style=\"width: 112.5pt; border: solid #C00000 1.0pt; border-left: none; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: white;\">Series</span></strong></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border: solid #C00000 1.0pt; border-left: none; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif; color: white;\">Processor</span></strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"height: 3.55pt;\">\r\n<td style=\"width: 112.25pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"6\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">Fabric Engine 9.1.100</span></p>\r\n</td>\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U5320</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\">BCM56175, BCM56274</p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.1pt;\">\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U5420</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\">BCM56274, BCM56275</p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 6.25pt;\">\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U5520</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">BCM56375</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 2.9pt;\">\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U5720</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">Intel Atom C3338, C3538</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 2.9pt;\">\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U7520</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">Intel Atom C3758</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 2.9pt;\">\r\n<td style=\"width: 112.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">U7720</span></p>\r\n</td>\r\n<td style=\"width: 153.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">Intel Atom C3758</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n</div>\r\n</div>\r\n<p style=\"margin: 0in 0in 12pt; text-align: center; font-size: 10pt; font-family: 'Times New Roman', serif; font-weight: bold;\"><a name=\"_Ref112245964\"></a><a name=\"_Toc228806183\"></a>Extreme networking appliances &ndash; hardware</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE links the Mocana v6.5.2f 32-bit libraries for cryptographic operations using non-PAA operations only with the Mocana GCM 64k feature enabled</span>.&nbsp; Each model includes an out of band management port that is Intel-based and a set of in band network interfaces that are all Broadcom-based.&nbsp; Therefore, all models have equivalent network interfaces.</p>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Extreme Fabric Engine Common Criteria Configuration Guide 9.1.100, May 2026 document, satisfies all of the security functional requirements stated in the Extreme Networks Fabric Engine Switches v9.1.100 Security Target, Version 0.5, May 28, 2026.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in June 2026.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11656-2026) prepared by CCEVS.</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Fabric Engine Switches v9.1.100 are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\">The Network Appliances provide extensive auditing capabilities.&nbsp; The TOE generates a comprehensive set of audit logs that identify specific TOE operations.&nbsp; For each event, the TOE records the date and time of each event, the type of event, the subject identity, and the outcome of the event.&nbsp; Auditable events include: failure on invoking cryptographic functionality such as establishment, termination and failure of a TLS session; establishment, termination and failure of an SSH session; all use of the user identification mechanisms; any use of the authentication mechanism; any change in the configuration of the TOE, changes to time, initiation of TOE update, indication of completion of TSF self-test, termination of a remote session; and initiation and termination of a trusted channel.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10pt;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE is configured to transmit its audit messages to an external syslog server.&nbsp; Communication with the syslog server is protected using TLS.&nbsp; The logs for all appliances can be viewed the CLI.&nbsp; The records include the date/time the event occurred, the event/type of event, the user ID associated with the event, and additional information of the event and its success and/or failure</span>.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE utilizes CAVP-tested cryptographic implementations to provide key management, random bit generation, encryption/decryption, digital signature and secure hashing and key-hashing features in support of higher level cryptographic protocols.&nbsp; This cryptography is used to support the following features</span>:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">TLS client in support of secure channel with remote syslog server,</li>\r\n<li style=\"margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">SSH server in support of secure CLI remote management interface,</li>\r\n<li style=\"margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">X.509 certificate validation, and</li>\r\n<li style=\"margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">NTP support.</li>\r\n</ul>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE provides authentication services for administrative users to connect to the TOEs administrator interfaces (local CLI, and remote CLI).&nbsp; The TOE requires Security Administrators to authenticate prior to being granted access to any of the management functionality.&nbsp; In the Common Criteria evaluated configuration, the TOE requires a minimum password length be configured between 8 and 32 characters, as well as a minimum RSA key length of 2048 bits.&nbsp; The TOE provides administrator authentication against a local user database</span>.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 3pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\">The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE.&nbsp; Management can take place over a variety of interfaces including:</p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 0in;\">\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">Local console command line administration;</li>\r\n<li style=\"text-align: left; margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Remote command line administration via SSHv2;</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 3pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\">The TOE provides multiple interfaces to perform administration.&nbsp; While in the CLI command mode, the administrator has access to six distinct modes, or privileges, that provide access to a specific set of commands.&nbsp; Depending on RBAC configuration, not every administrative account would have access to all modes.&nbsp; The CLI modes are as follows:</p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 0in;\">\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">User EXEC Mode: Initial mode of access.</li>\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">Privileged EXEC Mode: User mode and password combination determines access level.</li>\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">Global Configuration Mode: Use this mode to make changes to the running configuration.</li>\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">Interface Configuration Mode: Use this mode to modify or configure logical interface, VLAN or a physical interface.</li>\r\n<li style=\"margin: 0in 0in 0in 24px; text-align: left; font-size: 10pt; font-family: 'Times New Roman', serif;\">Router Configuration Mode: Use this mode to modify protocol settings.</li>\r\n<li style=\"text-align: left; margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: 'Times New Roman', serif;\">Application Configuration Mode: Use this mode to access the applications.</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\">The system allows Security Administrators to view audit records in EXEC mode.</p>\r\n<p style=\"margin: 0in 0in 3pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10pt;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">All administrative functionality is accessed via the CLI.&nbsp; The TOE audits all administrative access.&nbsp; The TOE displays login banners and inactivity timeouts to terminate idle administrative sessions after a set period of inactivity</span>.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication, and access controls restrictions to management and configuration functionality to Security Administrators.&nbsp; The TOE prevents reading of private keys and plaintext passwords by any user.&nbsp; The TOE internally maintains the date and time.&nbsp; This date and time are used as a timestamp that is part of each audit record generated by the TOE.&nbsp; Security Administrators can update the TOE&rsquo;s clock manually or can configure the TOE to synchronize with an external time source.&nbsp; The TOE performs testing to verify correct operation of the security appliances themselves.&nbsp; The TOE verifies all software updates via digital signature (2048-bit RSA/SHA-256) and requires administrative intervention prior to the software updates being installed on the TOE to avoid the installation of unauthorized firmware</span>.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>TOE access:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE can terminate inactive sessions after a configurable period.&nbsp; Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session.&nbsp; The TOE can also display specified banner on the local and remote CLI interfaces prior to allowing any administrative access to the TOE.&nbsp; The TOE allows users to manually terminate an established management session with the TOE</span>.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 3pt; font-size: 10pt; font-family: Times, serif;\">The TOE supports several types of secure communications:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: left; line-height: normal; margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">Trusted paths with remote administrators over SSH,</li>\r\n<li style=\"text-align: left; line-height: normal; margin: 0in 0in 6pt 24px; font-size: 10pt; font-family: Times, serif;\">Trusted channels with remote IT environment syslog servers over TLS.</li>\r\n</ul>","features":[{"id":5263,"feature_name":"Certificate Validation"},{"id":5264,"feature_name":"Cryptograhic Hashing"},{"id":5265,"feature_name":"Cryptograhic Key Generation"},{"id":5266,"feature_name":"Cryptographic Signature Generation"},{"id":5267,"feature_name":"Cryptographic Signature Verification"},{"id":5268,"feature_name":"Keyed-hash message authentication"},{"id":5269,"feature_name":"Network Device"},{"id":5270,"feature_name":"SSH Server"},{"id":5271,"feature_name":"TLS 1.2"},{"id":5272,"feature_name":"Trusted Update Function"}]}