{"product_id":11688,"v_id":11688,"product_name":"Extreme Networks Switching Engine version 33.4.100","certification_status":"Certified","certification_date":"2026-09-02T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Extreme Networks, Inc.","website":"www.extremenetworks.com"},"vendor_poc":"Craig Ficik","vendor_phone":"603-952-5922","vendor_email":"cficik@extremenetworks.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">The TOE is the Extreme Networks Switching Engine version 33.4.100.&nbsp; The TOE provides high density layer 2/3 switching with low latency cut-through switching and IPv4 and IPv6 unicast and multicast routing to enable enterprise aggregation and core backbone deployments. The TOE consists of a hardware appliance with embedded software components.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">All TOE appliances are shipped ready for immediate access through a Command Line Interface [CLI], with some basic features enabled by default. However, to ensure secure use the product must be configured prior to being put into a production environment as specified in the TOE guidance.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-family: 'Times New Roman', serif;\">&nbsp;</p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The TOE consists of the hardware models shown in the table below all running software version 33.4.100:</p>\r\n<div align=\"center\">\r\n<table class=\"MsoNormalTable\" style=\"width: 377.75pt; border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"height: 8.5pt;\">\r\n<td style=\"width: 94.25pt; border: solid #C00000 1.0pt; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: Times, serif; color: white;\">Platform</span></strong></p>\r\n</td>\r\n<td style=\"width: 76.5pt; border: solid #C00000 1.0pt; border-left: none; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: Times, serif; color: white;\">Model</span></strong></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border: solid #C00000 1.0pt; border-left: none; background: #C00000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><strong><span style=\"font-size: 10.0pt; font-family: Times, serif; color: white;\">Processor</span></strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"height: 13.15pt;\">\r\n<td style=\"width: 94.25pt; border: solid #C00000 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"6\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Switching Engine 33.4.100</span></p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U5320</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Broadcom BCM56175, BCM56274 (ARMv8)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 13.15pt;\">\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U5420</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Broadcom BCM56274, BCM56275 (ARMv8)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 13.15pt;\">\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U5520</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Broadcom BCM56375 (ARMv8)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 13.15pt;\">\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U5720</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Intel Atom C3338, C3538 Denverton</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 13.15pt;\">\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U7520</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Intel Atom C3758 Denverton</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 7.15pt;\">\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: center; margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">U7720</span></p>\r\n</td>\r\n<td style=\"width: 207.0pt; border-top: none; border-left: none; border-bottom: solid #C00000 1.0pt; border-right: solid #C00000 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Arial, sans-serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Intel Atom C3758 Denverton</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n</div>\r\n<p>&nbsp;</p>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Extreme Switch Engine Common Criteria Configuration Guide, 33.4.100, August 2026 document, satisfies all of the security functional requirements stated in the Extreme Networks Switching Engine version 33.4.100 Security Target, Version 0.4, August 4, 2026.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in September 2026.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11688-2026) prepared by CCEVS.</span></p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Extreme Networks Switching Engine version 33.4.100 are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE generates audit records for all security-relevant events. For each audited event, the TOE records the date and time, the type of event, the subject identity, and the outcome of the event. The resulting records are stored locally and can be sent securely to a designated audit server for archiving. Security Administrators, using the appropriate CLI commands, can also view audit records locally. The TOE provides a reliable timestamp relying on the appliance&rsquo;s built-in clock or using an NTP server.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE performs the following cryptographic functionality:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Encryption, decryption, hashing, keyed-hash message authentication, random number generation, signature generation and verification utilizing a dedicated cryptographic library</span></li>\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Cryptographic functionality is utilized to implement secure channels</span>\r\n<ul style=\"list-style-type: circle; margin-top: 0in; margin-bottom: 0in;\">\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">SSHv2</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">TLS v1.2</span></li>\r\n</ul>\r\n</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Entropy is collected and used to support seeding with full entropy</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Critical Security Parameters (CSPs) internally stored and cleared when no longer in use</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">X509 Certificate authentication integrated with TLS protocol.</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE uses a dedicated cryptographic module to manage CSPs and implements deletion procedures to mitigate the possibility of disclosure or modification of CSPs. Additionally, the TOE provides commands to on-demand clear CSPs (e.g. host RSA keys), that can be invoked by a Security Administrator with appropriate permissions.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">The TOE supports Role-Based Access Control (RBAC) managed by an Authentication, Authorization, and Accounting (AAA) module that stores and manages permissions of all users and their roles. The TOE requires users to provide their assigned unique username and password before any administrative access to the system is granted. <a name=\"_Hlk189124703\"></a>Alternatively, the TOE can be configured to rely on an external Radius server for authentication.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">Each authorized user is associated with an assigned role and role-specific permissions that determine their access to TOE features. The AAA module stores the assigned role of each user along with all other information required for that user to access the TOE. All TOE management functions are restricted to the Security Administrator.</p>\r\n<p><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE supports X509v3 certificate validation during negotiation of TLS protected syslog, TLS protected Radius, and SSH X509 authentication. Certificates are validated as part of the authentication process when they are presented to the TOE and when they are loaded into the TOE</span></p>","features":[{"id":5934,"feature_name":"Auditing"},{"id":5935,"feature_name":"Certificate Validation"},{"id":5937,"feature_name":"Cryptograhic Key Generation"},{"id":5936,"feature_name":"Cryptographic Hashing"},{"id":5938,"feature_name":"Cryptographic Signature Generation"},{"id":5939,"feature_name":"Cryptographic Signature Validation"},{"id":5940,"feature_name":"Keyed hash Message Authentication"},{"id":5941,"feature_name":"Network Device"},{"id":5942,"feature_name":"SSH Server"},{"id":5943,"feature_name":"TLS 1.2"},{"id":5944,"feature_name":"TLS Client with Mutual Authentication"},{"id":5945,"feature_name":"Trusted Update Function"}]}