Brocade Communications Systems FCX Series User Manual Page 36

  • Download
  • Add to my manuals
  • Print
  • Page
    / 53
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 35
Version 1.1, 05/19/2014
GSS CCT Evaluation Technical Report Page 36 of 53
© 2014 Gossamer Security Solutions, Inc.
Document: AAR-BrocadeFastIron8010
All rights reserved.
Testing Assurance Activities: None Defined
2.5.3.3 FMT_SMR.2.3
TSS Assurance Activities: None Defined
Guidance Assurance Activities: None Defined
Testing Assurance Activities: None Defined
Component Assurance Activities: The evaluator shall review the operational guidance to ensure that it contains
instructions for administering the TOE both locally and remotely, including any configuration that needs to be
performed on the client for remote administration.
The FIPS Configuration Guide refers to instructions to configure SSHv2 It suggests that in FIPS mode telnet and
HTTP are disallowed. In CC mode, HTTPS is also disallowed. The CLI is the default initial interface and no
configuration is needed.
The Security Configuration Guide, section 1 Securing Access Methods, indicates that Serial CLI, telnet, SSH, SNMP,
and TFTP. Of these telnet and TFTP are disabled in FIPS mode and SNMP access to critical security parameters is
also disabled. Instructions are provided specifically to manage access to the available management interfaces
including CLI using a local connection and SSHv2.
Note that the local CI and remote SSH interfaces are identical in that the same commands can be issued in each
case.
In the course of performing the testing activities for the evaluation, the evaluator shall use all supported
interfaces, although it is not necessary to repeat each test involving an administrative action with each interface.
The evaluator shall ensure, however, that each supported method of administering the TOE that conforms to the
requirements of this PP be tested; for instance, if the TOE can be administered through a local hardware interface;
SSH; and TLS/HTTPS; then all three methods of administration must be exercised during the evaluation team’s test
activities.
The evaluator performed administration using the console as well as the SSH connection. Both resulted in a
command line interface so both were addressed thoroughly.
Page view 35
1 2 ... 31 32 33 34 35 36 37 38 39 40 41 ... 52 53

Comments to this Manuals

No comments