Cisco Systems 7206VXR NPE-400 manual Roles and Services

Page 6

Roles and Services

Table 1

FIPS 140-2 Logical Interface

 

 

 

Router Physical Interface

FIPS 140-2 Logical Interface

 

 

10/100BASE-TX LAN Port

Data Input Interface

Port Adapter Interface

 

Console Port

 

Auxiliary Port

 

PCMCIA Slot

 

 

 

10/100BASE-TX LAN Port

Data Output Interface

Port Adapter Interface

 

Console Port

 

Auxiliary Port

 

PCMCIA Slot

 

 

 

Power Switch

Control Input Interface

Console Port

 

Auxiliary Port

 

 

 

10/100BASE-TX LAN Port LEDs

Status Output Interface

Enabled LED

 

PCMCIA LEDs

 

IO Pwr Ok LED

 

VAM LEDs

 

Console Port

 

Auxiliary Port

 

 

 

 

Power Plug

 

Power Interface

 

 

 

In addition to the built-in interfaces, the router also has additional port adapters that can optionally be placed in an available slot. These port adapters have many embodiments, including multiple Ethernet, token ring, and modem cards to handle frame relay, ATM, and ISDN connections.

Note These additional port adapters were excluded from this FIPS 140-2 Validation.

Roles and Services

Authentication is role-based. There are two main roles in the router that operators may assume: the Crypto Officer role and the User role. The administrator of the router assumes the Crypto Officer role to configure and maintain the router using Crypto Officer services, while Users exercise only the basic User services. Both roles are authenticated by providing a valid username and password. The configuration of the encryption and decryption functionality is performed only by the Crypto Officer after authentication to the Crypto Officer role by providing a valid Crypto Officer username and password. Once the Crypto Officer configured the encryption and decryption functionality, the User can use this functionality after authentication to the User role by providing a valid User username and password. The Crypto Officer can also use the encryption and decryption functionality after authentication to the Crypto Officer role. The module supports RADIUS and TACACS+ for authentication and they are used in the FIPS mode. See the Cisco 7206VXR Installation and Configuration Guide for more configuration information.

FIPS 140-2 Nonproprietary Security Policy for Cisco 7206VXR NPE-400 Router with VAM

6

OL-3959-01

 

 

Image 6
Contents Introduction Fips 140-2 Submission Package OverviewCryptographic Module Module InterfacesIO Power OK Indication DescriptionError EnableBoot LED Label Color State FunctionRoles and Services Router Physical Interface Fips 140-2 Logical InterfaceCrypto Officer Role User RolePhysical Security Cryptographic Key Management Cryptographic Key ManagementCSP Name Description Storage CSP16 CSP14CSP15 CSP17CSP27 CSP25CSP26 CSP28Role and Service Access to CSPs Cryptographic Key Management DES KAT Tdes KAT AES KAT SHA-1 KAT Prng KAT Self-TestsKey Zeroization HMAC-SHA-1 KATInitial Setup System Initialization and ConfigurationSecure Operation IPSec Requirements and Cryptographic Algorithms Remote AccessObtaining Documentation ProtocolsDocumentation Feedback Obtaining Technical AssistanceOrdering Documentation Submitting a Service Request Definitions of Service Request SeverityCisco Technical Support Website Obtaining Additional Publications and Information Obtaining Additional Publications and Information OL-3959-01