Integrated services router with aim-vpn/bpii-plus integrated services router with aim-vpn/epii-plus fips 140-2 non proprietary security policy (29 pages)
Self-tests performed by the IOS image ............27 2.6.2 Self-tests performed by NetGX Chip ............27 2.6.3 Self-tests performed by AIM ................ 28 SECURE OPERATION OF THE CISCO 2811 OR 2821 ROUTER ......28 3.1 I ........................28 NITIAL ETUP 3.2 S...
(http://csrc.nist.gov/groups/STM/cmvp/validation.html) contains contact information for answers to technical or sales-related questions for the module. Terminology In this document, the Cisco 2811 or 2821 routers are referred to as the router, the module, or the system. Document Organization The Security Policy document is part of the FIPS 140-2 Submission Package. In addition to this...
The Cisco 2811 and 2821 routers provide a scalable, secure, manageable remote access server that meets FIPS 140-2 Level 2 requirements. This section describes the general features and functionality provided by the routers.
Page 6
Figure 3 – Rear Panel Physical Interfaces The Cisco 2811 router features a console port, an auxiliary port, two Universal Serial Bus (USB) ports, four high-speed WAN interface card (HWIC) slots, two10/100 Gigabit Ethernet RJ45 ports, an Enhanced Network Module (ENM) slot, and a Compact Flash (CF) drive. The 2811...
Page 9
Figure 5 – 2821 Front Panel Physical Interfaces Figure 6 – 2821 Rear Panel Physical Interfaces The Cisco 2821 router features a console port, an auxiliary port, two Universal Serial Bus (USB) ports, four high-speed WAN interface card (HWIC) slots, two10/100 Gigabit Ethernet RJ45 ports, a Enhanced Network Module (ENM) slot, a Voice Network Module (VeNoM) slot, and a Compact Flash (CF) drive.
Tamper evident seal will be placed over the card in the drive. 2.3 Roles and Services Authentication in Cisco 2811 and 2821 is role-based. There are two main roles in the router that operators can assume: the Crypto Officer role and the User role. The administrator of the router assumes the Crypto Officer role in order to configure and maintain the router using Crypto Officer services, while the Users exercise only the basic User services.
AIM slot, and expansion slots. The Cisco 2811 and 2821 routers require that a special opacity shield be installed over the side air vents in order to operate in FIPS-approved mode. The shield decreases the surface area of the vent holes, reducing visibility within the cryptographic boundary to FIPS-approved specifications.
Page 23
“# no radius-server key” secret shared secret is zeroized by executing the “no radius-server key” command. secret_1_0_0 The fixed key used in Cisco vendor NVRAM Deleted by erasing the ID generation. This key is Flash. embedded in the module binary image and can be deleted by erasing the Flash.
Continuous RNG test for the hardware RNG Secure Operation of the Cisco 2811 or 2821 router The Cisco 2811 and 2821 routers meet all the Level 2 requirements for FIPS 140-2. Follow the setting instructions provided below to place the module in FIPS-approved mode. Operating this router without maintaining the following settings will remove the module from the FIPS approved mode of operation.
Page 31
CISCO EDITOR’S NOTE: You may now include all standard Cisco information included in all documentation produced by Cisco. Be sure that the following line is in the legal statements at the end of the document: By printing or making a copy of this document, the user agrees to use this information for product evaluation purposes only.
Need help?
Do you have a question about the 2811 - Voice Security Bundle Router and is the answer not in the manual?
Questions and answers