Aruba AP-5XX Wireless Access Points with ArubaOS FIPS Firmware FIPS 140-2 Level 2 Security Policy |25
4. Physical Security
The Aruba Wireless Access Point is a scalable, multi-processor standalone network device and is enclosed in a
hard, opaque plastic case. The AP enclosure is resistant to probing (please note that this feature has not been
validated as part of the FIPS 140-2 validation) and is opaque within the visible spectrum. The enclosure of the AP
has been designed to satisfy FIPS 140-2 Level 2 physical security requirements.
The Aruba AP-504, AP-505, AP-514, AP-515, AP-534, AP-535 and AP-555 Wireless Access Points require
Tamper-Evident Labels (TELs) to allow the detection of the opening of the device and to block the Serial console
port
(on the bottom of the device)
.
To protect the Aruba AP-504, AP-505, AP-514, AP-515, AP-534, AP-535 and AP-555 Wireless Access Points from
any tampering with the product, TELs should be applied by the Crypto Officer as covered under section 12,
Tamper-Evident Labels
.
5. Operational Environment
The operational environment is non-modifiable. The control plane Operating System (OS) is Linux, a real-time,
multi-threaded operating system that supports memory protection between processes. Access to the underlying
Linux implementation is not provided directly. Only Aruba Networks provided interfaces are used, and the
Command Line Interface (CLI) is a restricted command set. The module only allows the loading of trusted and
verified firmware that is signed by Aruba. Any firmware loaded into this module that is not shown on the module
certificate is out of the scope of this validation and requires a separate FIPS 140-2 validation.
6. Logical Interfaces
All of these physical interfaces are separated into logical interfaces defined by FIPS 140-2, as described in the
following table.
Table 6 - FIPS 140-2 Logical Interfaces
FIPS 140-2 Logical Interface
Module Physical Interface
Data Input Interface
10/100/1000/2500/5000 Ethernet Ports
802.11a/b/g/n/ac/ax Antenna Interfaces
USB Port
Bluetooth and Zigbee Radio Interfaces
Data Output Interface
10/100/1000/2500/5000 Ethernet Ports
802.11a/b/g/n/ac/ax Antenna Interfaces
USB Port
Bluetooth and Zigbee Radio Interfaces
Control Input Interface
10/100/1000/2500/5000 Ethernet Ports
802.11a/b/g/n/ac/ax Antenna Interfaces
Reset button
Status Output Interface
10/100/1000/2500/5000 Ethernet Ports
802.11a/b/g/n/ac/ax Antenna Interfaces
LED Status Indicators
Power Interface
Power Input
Power-Over-Ethernet (POE)