Cisco ISR 4000 Family Routers Administrator Guidance
Page
61
of
66
Service or
Protocol
Description
Client
(initiating)
Allowed
Server
(terminating)
Allowed Allowed use in the certified configuration
SSL (not
TLS)
Secure Sockets Layer
Yes
No
Yes
No
Use TLS instead. Protocol is not considered part of the
evaluation.
Telnet
A protocol used for
terminal emulation
Yes
No
Yes
No
Use SSH instead.
TFTP
Trivial File Transfer
Protocol
Yes
Yes
No
n/a
Recommend using SCP instead, or tunneling through
IPsec. Protocol is not considered part of the evaluation.
Note:
The table above does not include the types of protocols and services listed here:
OSI Layer 2 protocols such as CDP, VLAN protocols like 802.11q, Ethernet encapsulation protocols like PPPoE, etc. The certified configuration places
no restrictions on the use of these protocols; however evaluation of these protocols was beyond the scope of the Common Criteria product evaluation.
Follow best practices for the secure usage of these services.
Routing protocols such as EIGRP, OSPF, and RIP. The certified configuration places no restrictions on the use of these protocols, however evaluation of
these protocols was beyond the scope of the Common Criteria product evaluation, so follow best practices for the secure usage of these protocols.