EasyManuals Logo

Cisco 2811 User Manual

Cisco 2811
30 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #21 background imageLoading...
Page #21 background image
21
Cisco 2811 and Cisco 2821 Integrated Services Router FIPS 140-2 Non Proprietary Security Policy
OL-8663-01
Cisco 2811 and Cisco 2821 Routers
Self-Tests
In order to prevent any secure data from being released, it is important to test the cryptographic
components of a security module to insure all components are functioning correctly. The router includes
an array of self-tests that are run during startup and periodically during operations. All self-tests are
implemented by the software. An example of self-tests run at power-up is a cryptographic known answer
test (KAT) on each of the FIPS-approved cryptographic algorithms and on the Diffie-Hellman algorithm.
Examples of tests performed at startup are a software integrity test using an EDC, and a set of Statistical
Random Number Generator (RNG) tests. Examples of tests run periodically or conditionally include: a
bypass mode test performed conditionally prior to executing IPSec, and a continuous random number
generator test. If any of the self-tests fail, the router transitions into an error state. In the error state, all
secure data transmission is halted and the router outputs status information indicating the failure.
Examples of the errors that cause the system to transition to an error state:
IOS image integrity checksum failed
Microprocessor overheats and burns out
Known answer test failed
NVRAM module malfunction.
Temperature high warning
Self-tests performed by the IOS image
IOS Self Tests:
POST tests
AES Known Answer Test
Software/firmware test
Power up bypass test
RNG Known Answer Test
Diffie Hellman test
HMAC-SHA-1 Known Answer Test
SHA-1 Known Answer Test
DES Known Answer Test
3DES Known Answer Test
Conditional tests
Conditional bypass test
Continuous random number generation test
Self-tests performed by NetGX
NetGX Tests:
POST tests
AES Known Answer Test
DES Known Answer Test

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2811 and is the answer not in the manual?

Cisco 2811 Specifications

General IconGeneral
Full duplexYes
Networking standards-
Ethernet LAN data rates10, 100 Mbit/s
Supports ISDN connectionNo
SafetyUL 60950, CAN/CSA C22.2 No. 60950, IEC 60950, EN 60950-1, AS/NZS 60950
Flash memory128 MB
Internal memory256 MB
I/O ports2 x USB\\r 2 x 10/100 Base-T
Ethernet LAN (RJ-45) ports2
Storage temperature (T-T)-40 - 70 °C
Firewall securityCisco IOS
Security algorithms128-bit AES, 192-bit AES, 256-bit AES, 3DES, DES
Product colorBlue, Stainless steel
Rack capacity1U
Weight and Dimensions IconWeight and Dimensions
Depth416.6 mm
Width438.2 mm
Height44.5 mm
Weight6400 g

Related product manuals