Cisco ISR 4000 Family Routers Administrator Guidance
Page
23
of
66
TOE-common-criteria(config-if)#
crypto map sample
TOE-common-criteria(config-if)#
exit
TOE-common-criteria(config)#
ip route 12.1.1.0 255.255.255.0 11.1.1.4
TOE-common-criteria(config)#
access-list 115 permit ip 10.1.1.0 0.0.0.255 12.1.1.0
0.0.0.255 log
TOE-common-criteria(config)#
logging host 12.1.1.1
Recovery from an event where the connection is unintentionally broken is to follow the steps to
establish a connection as listed above.
3.3.6 Base Firewall Rule set Configuration
The Network Device PP VPN Gateway Extended Package (VPNGW EP) contains requirements
for the TOE basic packet filtering. Packet filtering is able to be done on many protocols by the
TOE, including but not limited to (although the evaluation only covers IPv4, IPv6, TCP and UDP):
IPv4 (RFC 791)
IPv6 (RFC 2460)
TCP (RFC 793)
UDP (RFC 768)
IKEv1 (RFCs 2407, 2408, 2409, RFC 4109)
IKEv2 (RFC 5996)
IPsec ESP (RFCs 4301, 4303)
SSH (RFCs 4251, 4252, 4253, and 4254)
The following attributes, at a minimum, are configurable within Packet filtering rules for the
associated protocols:
IPv4
o
Source address
o
Destination Address
o
Protocol
IPv6
o
Source address
o
Destination Address
o
Next Header (Protocol)
TCP
o
Source Port
o
Destination Port
UDP