Cisco ISR 4000 Family Routers Administrator Guidance
Page
60
of
66
Service or
Protocol
Description
Client
(initiating)
Allowed
Server
(terminating)
Allowed Allowed use in the certified configuration
IKE
Internet Key Exchange
Yes
Yes
Yes
Yes
As described in Section 4.6.1 of this document.
IMAP4S
Internet Message Access
Protocol Secure version 4
Yes
Over TLS
No
n/a
No restrictions. Protocol is not considered part of the
evaluation.
IPsec
Internet Protocol Security
(suite of protocols including
IKE, ESP and AH)
Yes
Yes
Yes
Yes
Used for securing both traffic that originates from or
terminates at the TOE, as well as for “VPN Gateway”
functionality to secure traffic through the TOE. See
IKE and ESP for usage restrictions.
Kerberos
A ticket-based
authentication protocol
Yes
Over
IPsec
No
n/a
If used for authentication of TOE administrators,
tunnel this authentication protocol secure with TLS or
IPsec. Protocol is not considered part of the evaluation.
LDAP
Lightweight Directory
Access Protocol
Yes
Over
IPsec
No
n/a
Use LDAP-over-SSL instead. Protocol is not
considered part of the evaluation.
LDAP-over-
SSL
LDAP over Secure Sockets
Layer
Yes
Over TLS
No
n/a
If used for authentication of TOE administrators,
configure LDAP to be tunneled over IPsec. Protocol is
not considered part of the evaluation.
NTP
Network Time Protocol
Yes
Yes
No
n/a
Any configuration. Use of key-based authentication is
recommended.
RADIUS
Remote Authentication Dial
In User Service
Yes
Yes
No
n/a
If used for authentication of TOE administrators,
secure through IPsec.
SDI (RSA
SecureID)
RSA SecurID
authentication
Yes
Over
IPsec
No
n/a
If used for authentication of TOE administrators,
secure through IPsec. Protocol is not considered part of
the evaluation.
SMTP
Simple Mail Transfer
Protocol
Yes
Yes
No
n/a
Recommended to use SMTPS instead. Protocol is not
considered part of the evaluation.
SNMP
Simple Network
Management Protocol
Yes (snmp-
trap)
Yes
Yes
No
Outbound (traps) only. Recommended to tunnel
through IPsec. Protocol is not considered part of the
evaluation.
SSH
Secure Shell
Yes
Yes
Yes
Yes
As described in the
Error! Reference source not f
ound.
section of this document.