Cisco Cat4K NDPP ST
11 March 2014
EDCS-1228241
73
TOE SFRs
How the SFR is Met
Ability to manage routing tables - allows the authorized
administrator the ability to create, modify, and delete the
routing tables to control the routed network traffic
Ability to manage security attributes belonging to
individual users - allows the authorized administrator to
create, modify, and delete other administrative users
Ability to manage the default values of the security
attributes - allows the authorized administrator to specify
the attributes that are used control access and/or manage
users
Ability to manage the warning banner message and
content – allows the authorized administrator the ability
to define warning banner that is displayed prior to
establishing a session (note this applies to the interactive
(human) users; e.g. administrative users
Ability to manage the time limits of session inactivity –
allows the authorized administrator the ability to set and
modify the inactivity time threshold;
Ability to update the TOE and verify the updates are
valid.
FMT_SMR.1
The TOE switch platform maintains administrative privilege level
and non-administrative access. Non-administrative access is
granted to authenticated neighbor routers for the ability to receive
updated routing tables per the information flow rules. There is no
other access or functions associated with non-administrative
access. The administrative privilege levels include:
Administrators are assigned to privilege levels 0 and 1.
Privilege levels 0 and 1 are defined by default and are
customizable. These levels have a very limited scope and
access to CLI commands that include basic functions
such as login, show running system information, turn
on/off privileged commands, logout.
Semi-privileged administrators equate to any privilege
level that has a subset of the privileges assigned to level
15; levels 2-14. These levels are undefined by default
and are customizable. The custom level privileges are
explained in the example below.
Privileged
administrators
are
equivalent
to
full
administrative access to the CLI, which is the default
access for IOS privilege level 15.
Note, the levels are not hierarchical.
For levels, level 0 is the most restrictive and 15 is the least
restrictive.