
Cisco ISR-800 Security Target
1.2 TOE Overview
The Cisco ISR-800 is a purpose-built, routing platform that combines data, security, unified
communications and wireless services on a single device. The TOE includes the hardware
models as defined in Table 4 in Section 1.5
1.2.1 TOE Product Type
The Cisco ISR-800s are fixed configuration routers that provide business solutions for secure
voice and data communications to enterprise small branch offices. They are designed to deliver
secure broadband, Metro Ethernet (MAN Ethernet) and wireless LAN (WLAN) connectivity.
The TOE is a VPN Gateway that terminates an IPsec tunnel, which provides device
authentication, confidentiality, and integrity of information traversing a public or untrusted
network.
1.2.2 Supported non-TOE Hardware/ Software/ Firmware
The TOE supports (in some cases optionally) the following hardware, software, and firmware in
its environment when the TOE is configured in its evaluated configuration:
Table 3 IT Environment Components
Usage/Purpose Description for TOE performance
TACACS+ AAA
Server
This includes any IT environment RADIUS or TACACS+ AAA server that
provides single-use authentication mechanisms. This can be any RADIUS AAA
server that provides single-use authentication. The TOE correctly leverages the
services provided by this RADIUS or TACACS+ AAA server to provide single-
use authentication to administrators.
Workstation with
SSH Client
This includes any IT Environment Management workstation with a SSH client
installed that is used by the TOE administrator to support TOE administration
through SSH protected channels. Any SSH client that supports SSHv2 may be
used.
This includes any IT Environment Console that is directly connected to the TOE
via the Serial Console Port and is used by the TOE administrator to support TOE
administration.
Authority (CA)
This includes any IT Environment Certification Authority on the TOE network.
This can be used to provide the TOE with a valid certificate during certificate
enrollment.
Gateway/Peer
This includes any VPN peer with which the TOE participates in VPN
communications. Remote VPN Endpoints may be any device that supports IPsec
VPN communications.
The TOE supports communications with an NTP server in order to synchronize
the date and time on the TOE with the NTP server’s date and time. A solution
must be used that supports secure communications with up to a 32 character key.
This includes any syslog server to which the TOE would transmit syslog
messages. Also referred to as audit server in the ST
Includes “another instance of the TOE” that would be installed in the evaluated
Comentarios a estos manuales