Cisco ISR 4000 Family Routers Administrator Guidance
Page
10
of
66
Component
Required
Usage/Purpose Description for TOE performance
Certification
Authority
No
This includes any IT Environment Certification Authority on the TOE
network. This can be used to provide the TOE with a valid certificate during
certificate enrolment.
Remote VPN
Endpoint
Yes
This includes any VPN peer or client with which the TOE participates in
VPN communications. Remote VPN Endpoints may be any device or
software client that supports IPsec VPN communications. Both VPN clients
and VPN gateways are considered to be Remote VPN Endpoints by the TOE.
NTP Server
No
The TOE supports communications with an NTP server in order to
synchronize the date and time on the TOE with the NTP server’s date and
time. A solution must be used that supports secure communications with up
to a 32 character key.
Syslog Server Yes
This includes any syslog server to which the TOE would transmit syslog
messages.
1.6
Excluded Functionality
The following functionality is excluded from the evaluation.
Table 4 Excluded Functionality
Excluded Functionality
Exclusion Rationale
Non-FIPS 140-2 mode of operation
This mode of operation includes non-FIPS allowed
operations.
Telnet for management purposes.
Telnet passes authentication credentials in clear text.
SSHv2 is to be used instead.
These services will be disabled by configuration. The exclusion of this functionality does not
affect compliance to the U.S. Government Protection Profile for Security Requirements for
Network Devices.