6.
Network Services and Protocols
The table below lists the network services/protocols available on the TOE as a client (initiated outbound) and/or server (listening for
inbound connections), all of which run as system-level processes. The table indicates whether each service or protocol is allowed to be
used in the certified configuration.
For more detail about each service, including whether the service is limited by firewall mode (routed or transparent), or by context
(single, multiple, system), refer to the
Command Reference
guides listed in
Table 2
.
Table 9 Protocols and Services
Service or
Protocol
Description
Client
(initiating)
Allowed
Server
(terminating)
Allowed Allowed use in the certified configuration
AH
Authentication Header (part
of IPsec)
Yes
Yes
Yes
Yes
No restrictions. ESP must be used in all IPsec
connections. Use of AH in addition to ESP is optional.
Protocol is not considered part of the evaluation.
DHCP
Dynamic Host
Configuration Protocol
Yes
Yes
Yes
Yes
No restrictions. Protocol is not considered part of the
evaluation.
DNS
Domain Name Service
Yes
Yes
No
n/a
No restrictions. Protocol is not considered part of the
evaluation.
ESP
Encapsulating Security
Payload (part of IPsec)
Yes
Yes
Yes
Yes
Configure ESP as described in Section 4.6.2 of this
document.
FTP
File Transfer Protocol
Yes
No
No
n/a
Use SCP or HTTPS instead.
HTTP
Hypertext Transfer Protocol Yes
For OCSP
or copy
Yes
No
Used implicitly for OCSP. For other HTTP functions,
such as “copy”, recommend using HTTPS instead, or
tunneling through IPsec. Protocol is not considered
part of the evaluation.
HTTPS
Hypertext Transfer Protocol
Secure
Yes
Yes
Yes
Yes
No restrictions. Protocol is not considered part of the
evaluation.
ICMP
Internet Control Message
Protocol
Yes
Yes
Yes
Yes
No restrictions. Protocol is not considered part of the
evaluation.