
Cisco Intrusion Prevention System Security Target
1.2.4 Supported non-TOE Hardware/ Software/ Firmware
The TOE supports (in some cases optionally) the following hardware, software, and firmware in
its environment:
Table 3: Operational Environment Components
Usage/Purpose Description for TOE performance
Management
Workstation with SSH
Client and/or TLS client
This includes any management workstation with a SSH client
supporting SSHv2, or TLS/HTTPS client (web browser) supporting
TLSv1.2. These clients are used for remote administration of the TOE.
Audit Retrieval
Software/Server
Audit retrieval software such as Cisco IPS Manager Express (IME)
capable of initiating TLS/HTTPS connection to the TOE to retrieve
audit log files.
The TOE supports communications with an NTP server for clock
updates.
WICs (wide-area-network interface cards) provide the network
interfaces used by port adaptors to communicate on wide area networks
(WANs). Any Cisco WIC is supported. Examples include, Ethernet
High-Speed WICs, Wireless High-Speed WICs, Serial WICs, CSU/DSU
WICs, and ISDN BRI WICs.
Any of 5512-X, 5515-X, 5525-X, 5545-X, or 5555-X running ASA
8.6(1) or later is required to support the IPS software module.
ASA 5585-X running ASA 8.4(2) is required to the support the IPS
hardware modules IPS SSP-10, SSP-20, SSP-40, or SSP-60.
When an IPS 4300 or 4500 is not installed in-line (with traffic flowing
through the IPS appliance), the IPS sensor works in tandem with an
ASA to facilitate blocking of traffic. Compatible ASA models include
5505, 5510, 5520, 55040, 5550, 5580, 5500-X, and 5585-X.
1.3 TOE DESCRIPTION
This section provides an overview of the Cisco Intrusion Prevention System Target of Evaluation
(TOE). The TOE configurations include both software and hardware. The hardware is
comprised of the following: IPS 4300 and 4500 Series Sensors; and ASA 5585-X SSP hardware
modules. The software is comprised of the IPS software image Release 7.2(1).
The following figure provides a visual depiction of an example TOE deployment.
Comentarios a estos manuales