Cisco Cat4K NDPP ST
11 March 2014
EDCS-1228241
11
Protection of the TOE from physical tampering is ensured by its environment. It is
assumed that the switches will remain attached to the physical connections made by an
administrator so that the switch cannot be bypassed. The TOE is completely self-
contained. The hardware, software and firmware provided by Catalyst Switches provide
all of the services necessary to implement the TOE. There are no external interfaces into
the TOE other than the physical ports provided. No general purpose operating system,
user interface, disk storage, or programming interface is provided by the TOE.
The Catalyst Switches that comprise the TOE have common hardware characteristics.
These characteristics affect only non-TSF relevant functions of the switches (such as
throughput, line-card slots, and amount of storage) and therefore support security
equivalency of the switches in terms of hardware:
Central processor that supports all system operations
Dynamic memory, used by the central processor for all system operations
Flash memory (EEPROM), used to store the Cisco IOS image (binary program)
USB slot, used to connect USB devices to the TOE (not relevant as none of the
USB devices are included in the TOE)
Non-volatile read-only memory (ROM) is used to store the bootstrap program and
power-on diagnostic programs
Non-volatile random-access memory (NVRAM) is used to store switch
configuration parameters used to initialize the system at start-up
Physical network interfaces (minimally two) (e.g. RJ45 serial and standard 10/100
Ethernet ports). Some models have a fixed number and/or type of interfaces; some
models have slots that accept additional network interfaces
10 Gigabit Ethernet (GE) uplinks and supports Power over Ethernet Plus (PoE+)
and Universal POEP (UPOE). (Universal POEP is an enhancement to the PoEP
(802.3at) standard to allow powered devices up to 60W to connect over a single
Cat 5e cable. Standard PoEP uses only 2 twisted pairs (out of 4) in the Ethernet
cable. UPOE uses all 4 twisted pairs to deliver 60W to the port.)
Redundant power supplies and fans
Cisco IOS XE is a Cisco-developed highly configurable proprietary operating system that
provides for efficient and effective routing and switching. Although IOS XE performs
many networking functions, this TOE only addresses the functions that provide for the
security of the TOE itself as described in Section 1.7 Logical Scope of the TOE below.
1.5 TOE Environment and Configuration
The TOE consists of one or more physical devices; the Catalyst Switch with Cisco IOS
XE software. The Catalyst Switch has two or more network interfaces and is connected
to at least one internal and one external network. The Cisco IOS configuration determines
how packets are handled to and from the switches’ network interfaces. The switch
configuration will determine how traffic flows received on an interface will be handled.
Typically, packet flows are passed through the network device and forwarded to their