{"product_id":6012,"v_id":6012,"product_name":"Cisco Systems Catalyst Switches and Cisco Secure ACS for Windows Server Version 4.1.4.13","certification_status":"Not Certified","certification_date":"2008-05-27T00:05:00Z","tech_type":"Network Switch, Router","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":null,"vendor_phone":"+1 410 309 4862","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Arca CCTL"},"product_description":"<p class=\"MsoNormal\" style=\"margin: 0pt; mso-layout-grid-align: none\"><b><span style=\"font-size: 9.5pt\"><o:p></o:p></span></b></p>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">The TOE is the Cisco Systems </span><span style=\"font-size: 9pt\">Catalyst Switches (</span><span style=\"font-size: 9pt\">2900, 3500, 3750, 4500, 4948, 6500) running IOS and a </span><span style=\"font-size: 9pt\">Cisco Secure Access Control Server for Windows Server (ACS).&nbsp; A Catalyst switch running IOS software loaded on the Supervisor operates as a Layer-2 switch (some of which offer Layer-3 traffic-filtering capabilities). As a Layer-2 switch, it analyzes incoming frames, makes forwarding decisions based on information contained in the frames, and forwards the frames toward the destination. The switches that are part of the TOE that also include Layer-3 capabilities are the 3500s, 3750s, 4500s, 4948s, and 6500s.&nbsp;The Layer-3-enabled switch supports routing of traffic.&nbsp;These devices may create or maintain a table of available routes and their conditions, and use this information. along with distance and cost algorithms, to determine the best route for a given packet. Routing protocols include: BGP, RIP, and OSPF.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 6pt 0pt 3pt\"><span style=\"font-size: 9pt\">The TOE also includes ACS, which provides authentication, authorization, and accounting (AAA) services to network devices that function as AAA clients, including switches.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switches that support the TOE have the following common hardware characteristics. These characteristics affect only non-TSF-relevant functions of the switches (such as throughput and amount of storage) and therefore support security equivalency of the switches in terms of hardware: </span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Central processor that supports all system operations</span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Dynamic memory, used by the central processor for all system operations</span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Flash memory (EEPROM), used to store the IOS image (binary program)</span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">USB slot, used to connect USB devices to the TOE (not relevant as none of the USB devices are included in the TOE)</span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Non-volatile read-only memory (ROM), used to store the bootstrap program and power-on diagnostic programs</span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Non-volatile random-access memory (NVRAM), used to store switch configuration parameters used to initialize the system at startup </span></div>\r\n<div style=\"margin: 0pt 0pt 0pt 36pt; text-indent: -18pt\"><span style=\"font-size: 9pt\">&middot;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 9pt\">Physical network interfaces (minimally two). Some models have a fixed number and/or type of interfaces; some models have slots that accept additional network interfaces.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Users of the TOE are Switch and ACS Administrators, who will hereafter be referred to generically as Authorized Administrators, or by the roles of Privileged Administrator (switch), Semi-privileged Administrator (switch), and Authentication Administrator (ACS). Privileged Administrators configure the Cisco switches using the global configuration commands to apply the features that affect the system as a whole. To initiate global configuration mode, the Privileged Administrator enters the configure command at the Privileged EXEC Mode prompt. The user interface is run from either the console port on the switch, or by connecting to the switch using secure shell. The user interface is a Command Line Interface (CLI) running the Command Interpreter (EXEC).</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">The Cisco Systems TOE hardware models are:</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div align=\"center\">\r\n<table style=\"border-collapse: collapse\" cellspacing=\"0\" cellpadding=\"0\" border=\"0\">\r\n    <tbody>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\" align=\"center\"><b><span style=\"font-size: 9pt\">Switch Series</span></b></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\" align=\"center\"><b><span style=\"font-size: 9pt\">Switch Models</span></b></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\" align=\"center\"><b><span style=\"font-size: 9pt\">IOS Version</span></b></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\" align=\"center\"><b><span style=\"font-size: 9pt\">Switch Type</span></b></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst </span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">2940, 2950, 2950RLE, 2955</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.1(22)EA10</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch </span></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst </span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">2960, 2970</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.2(25)SEE4 </span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch </span></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst </span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">3550, 3560, 3750, 3750-METRO</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.2(25)SEE4 </span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch</span></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">CAT4500-SUP2-PLUS, CAT4500-SUP2-PLUS-10GE, CAT4500-SUP2-PLUS-TS, CAT4500-SUP4, CAT4500-SUP5, CAT4500-SUP5-10GE</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.2(31)SG2</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch Modular</span></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">CAT4948, CAT4948-10GE</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.2(31)SG2</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch</span></div>\r\n            </td>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 99.9pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"133\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Catalyst</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 151.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"201\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">CAT6500-SUP2/MSFC2, CAT6500-SUP32/MSFC2A, CAT6500-SUP720/MSFC3</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 102.8pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"137\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">12.2(18)SXF11</span></div>\r\n            </td>\r\n            <td style=\"border-right: #ece9d8; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0pt; border-left: #ece9d8; width: 125.05pt; padding-top: 0pt; border-bottom: #ece9d8; background-color: transparent\" valign=\"top\" width=\"167\">\r\n            <div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">Switch</span></div>\r\n            </td>\r\n        </tr>\r\n    </tbody>\r\n</table>\r\n</div>\r\n<div style=\"margin: 6pt 0pt\" align=\"center\"><a name=\"_Toc164072274\"><span><span style=\"font-size: 9pt\"><strong>Table 1: TOE Switch Hardware Models</strong></span></span></a></div>\r\n<div style=\"margin: 6pt 0pt 3pt\"><span style=\"font-size: 9pt\">The 4500, 4948, and 6500 models listed above rely on a supervisor module for security functionality. This supervisor module is part of the TOE.</span></div>\r\n<div style=\"margin: 0pt\"><b><span style=\"font-size: 9.5pt\">&nbsp;</span></b></div>","evaluation_configuration":null,"security_evaluation_summary":"<p>&nbsp;</p>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt; color: #333333\">The evaluation was carried out in accordance with the Arca Common Criteria Test Laboratory processes and procedures that are compliant with the Common Criteria Evaluation and Validation Scheme (CCEVS). The evaluation demonstrated that the Auditing, Identification and Authentication, Traffic Filtering and Switching (VLAN Processing), Security Management/Access Control (Authorization), and Protection of TSF functions of the Cisco IOSAAA Catalyst Switches met the security requirements contained in the Security Target. The criteria against which the Cisco IOSAAA Catalyst Switches was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2 Part II and Part III. The evaluation team conducted the evaluation using the Common Methodology for Information Technology Security Evaluation, Version 2.2.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<p><span style=\"font-size: 9pt; color: #333333\">Arca determined the product to be CC version 2.2 Part 2 and Part 3 conformant, including all Information Technology Security Evaluation Final Interpretations from January 2004 through September 30, 2004, and concluded that the Common Criteria requirements for Evaluation Assurance Level (EAL) 3 have been met with the addition of ALC_FLR.1. The product, configured as outlined in the Secure Installation Guidance, satisfies all of the security functional requirements stated in the Security Target. A Validator, on behalf of the CCEVS Validation Body, monitored the evaluation carried out by Arca. The evaluation was completed in February 2008. Results of the evaluation can be found in the Validation Report prepared by the National Information Assurance Partnership (NIAP) CCEVS.</span></p>","environmental_strengths":"<p>&nbsp;</p>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-size: 9pt\">The TOE consists of one or more physical internetworking devices (switch(es) running IOS software) and one server running ACS software. ACS software runs on a Windows 2000 Server. It should be noted that the Windows PC is not considered part of the TOE, only the ACS software operating on it. The Windows OS leverages its host-based firewall to protect the OS and the ACS. When the TOE-enabled switch is in use, at least two of the network interfaces of the internetworking device will be attached to different networks.&nbsp;The switch configuration will determine how traffic flows received on an interface will be handled. Typically, packet flows are passed through the internetworking device and forwarded to their configured destination.&nbsp;BGP, RIP, and OSPF Routing Protocols are used on the 3500s, 3750s, 4500s, 4948s, and 6500s switch models.</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">The ACS will be connected to the switch either via an internal, protected network or via a crossover cable.&nbsp;The TOE Boundary includes the switch hardware, the IOS software, and the ACS Server software, but not the operating system of the server platform utilized by the ACS.&nbsp;</span></div>\r\n<div style=\"margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><span style=\"font-size: 9pt\">The TOE can optionally connect to an NTP server on its internal network for time services. Also, if the Catalyst Switch or ACS Server are to be remotely administered, then the management station must be connected to an internal network, SSH must be used to connect to the switch, and SSL must be used to connect to the ACS. The ACS, remote management, and NTP boxes (if used) must all be attached to the internal (protected) network.</span></div>","features":[]}