EasyManuals Logo

Cisco 2811 User Manual

Cisco 2811
30 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #23 background imageLoading...
Page #23 background image
23
Cisco 2811 and Cisco 2821 Integrated Services Router FIPS 140-2 Non Proprietary Security Policy
OL-8663-01
Related Documentation
RADIUS and TACACS+ shared secret key sizes must be at least 8 characters long, and must include
at least one number and one letter.
IPSec Requirements and Cryptographic Algorithms
The only type of key management that is allowed in FIPS mode is Internet Key Exchange (IKE).
Although the IOS implementation of IKE allows a number of algorithms, only the following
algorithms are allowed in a FIPS 140-2 configuration:
ah-sha-hmac
esp-des
esp-sha-hmac
esp-3des
esp-aes
The following algorithms are not FIPS approved and should not be used during FIPS-approved
mode:
RSA
MD-5 for signing
MD-5 HMAC
Protocols
SNMP v3 over a secure IPSec tunnel may be employed for authenticated, secure SNMP gets and
sets. Since SNMP v2C uses community strings for authentication, only gets are allowed under
SNMP v2C.
SSL is not an Approved protocol, and shall not be used in FIPS mode.
Remote Access
Telnet access to the module is only allowed via a secure IPSec tunnel between the remote system
and the module. The Crypto officer must configure the module so that any remote connections via
telnet are secured through IPSec, using FIPS-approved algorithms. Note that all users must still
authenticate after remote access is granted.
SSH access to the module is only allowed if SSH is configured to use a FIPS-approved algorithm.
The Crypto officer must configure the module so that SSH uses only FIPS-approved algorithms.
Note that all users must still authenticate after remote access is granted.
Related Documentation
For more information about the Cisco 2811 and Cisco 2821 Integrated Services Routers, refer to the
following documents:
Cisco 2800 Series Integrated Services Routers Quick Start Guides
Cisco 2800 Series Hardware Installation documents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2811 and is the answer not in the manual?

Cisco 2811 Specifications

General IconGeneral
Full duplexYes
Networking standards-
Ethernet LAN data rates10, 100 Mbit/s
Supports ISDN connectionNo
SafetyUL 60950, CAN/CSA C22.2 No. 60950, IEC 60950, EN 60950-1, AS/NZS 60950
Flash memory128 MB
Internal memory256 MB
I/O ports2 x USB\\r 2 x 10/100 Base-T
Ethernet LAN (RJ-45) ports2
Storage temperature (T-T)-40 - 70 °C
Firewall securityCisco IOS
Security algorithms128-bit AES, 192-bit AES, 256-bit AES, 3DES, DES
Product colorBlue, Stainless steel
Rack capacity1U
Weight and Dimensions IconWeight and Dimensions
Depth416.6 mm
Width438.2 mm
Height44.5 mm
Weight6400 g

Related product manuals