
4
Cisco 1721, 1760, 2621XM, 2651XM, 2691, 3725, and 3745 Modular Access Routers and 7206-VXR NPE-400 Router FIPS 140-2 Non-Proprietary
OL-6083-01
The Cisco 1721, 1760, 2621XM, 2651XM, 2691, 3725, 3745, and 7206 VXR NPE-400 Routers
The Cisco 1721/1760 Cryptographic Module
Figure 1
The Cisco 1721 and Cisco 1760 Routers
The cryptographic boundary is defined as encompassing the "top," "front," "left," "right," and "bottom"
surfaces of the case; all portions of the "backplane" of the case which are not designed to accommodate
a WIC; and the inverse of the three-dimensional space within the case that would be occupied by an
installed WIC. The cryptographic boundary includes the connection apparatus between the WIC and the
motherboard/daughterboard that hosts the WIC, but the boundary does not include the WIC itself. In
other words, the cryptographic boundary encompasses all hardware components within the case of the
device except any installed modular WICs. All of the functionality discussed in this document is
provided by components within this cryptographic boundary.
The 1760 requires that a special opacity shield be installed over the right-hand side air vents in order to
operate in FIPS-approved mode. The shield decreases the effective size of the vent holes, reducing
visibility within the cryptographic boundary to FIPS-approved specifications. The shield is
self-adhering to the side of the chassis. To install the shield, remove it from its paper backing and apply
the shield to the chassis, aligning the holes on the shield with the vent-holes on the side of the chassis.
Figure 2
demonstrates the proper application of the shield.
Figure 2
Cisco 1760 Opacity Shield Application
99390
Cisco 1700
Series
PWR
ACT
ACT/CH
0
ACT/CH
1
OK
ACT/CH
0
WIC0
WIC1
ETH
ACT/CH
1
COL
Cisco
1 7 0 0
S E R I E
S
ROUTE
R
10/100 ETHE
RNET
AUX
CONSOLE
PVDM 0
OK
OK
PWR
1
0
SLOT 0
OK
PVDM 1
OK
MOD
OK
1
0
SLOT 1
OK
LINK
100
FDX
ACT
COL
1
0
SLOT 2
OK
1
0
SLOT 3
OK
99395