
Cisco ISR-800 Security Target
AGN-A-K9
Architecture
Generation –
890-A
Onboard DRAM
– 256 MB
Flash memory –
256 MB
12.8 x
10.4 in.
Universal 100 to 240 VAC
• Frequency: 50 to 60 Hz
• Maximum output power:
60W
• Output voltages: 12 VDC
Ethernet WAN port
(1) 10/100BASE-T Fast
Ethernet WAN port
(1)CON/AUX port for
configuration and
management
(8) 10-/100-Mbps LAN
interface
(1) Ethernet Local
Management Interface (E-
LMI)
(2) USB 2.0 ports for
security eToken credentials,
booting, and loading
configuration from USB
1.6 Logical Scope of the TOE
The TOE is comprised of several security features. Each of the security features identified above
consists of several security functionalities, as identified below.
1. Security Audit
2. Cryptographic Support
3. Full Residual Information Protection
4. Identification and Authentication
5. Security Management
6. Packet Filtering
7. Protection of the TSF
8. TOE Access
9. Trusted Path/Channels
These features are described in more detail in the subsections below. In addition, the TOE
implements all RFCs of the NDPP v1.1 and VPNGWEP v1.1 as necessary to satisfy
testing/assurance measures prescribed therein.
1.6.1 Security Audit
The Cisco ISR-800 provides extensive auditing capabilities. The TOE can audit events related to
cryptographic functionality, identification and authentication, and administrative actions. The
Cisco ISR-800 generates an audit record for each auditable event. Each security relevant audit
event has the date, timestamp, event description, and subject identity. The administrator
configures auditable events, performs back-up operations, and manages audit data storage. The
TOE provides the audit trail protection by providing remote backup to a syslog server over an
encrypted channel.
Comentarios a estos manuales