EasyManua.ls Logo

Juniper SSG 320M User Manual

Juniper SSG 320M
22 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
FIPS 140-2 SECURITY POLICY
Juniper Networks, Inc.
SSG 320M and SSG 350M
HW P/N SSG-320M-SB, SSG-320M-SH, SSG-320M-SB-TAA, SSG-320M-SH-TAA, SSG-320M-SB-DC-N-TAA,
SSG-320M-SH-DC-N-TAA, SSG-350M-SB, SSG-350M-SH, SSG-350M-SB-TAA, SSG-350M-SH-TAA, SSG-
350M-SB-DC-N-TAA, SSG-350M-SH-DC-N-TAA , FW Version ScreenOS 6.3.0r6
Question and Answer IconNeed help?

Do you have a question about the Juniper SSG 320M and is the answer not in the manual?

Juniper SSG 320M Specifications

General IconGeneral
Maximum Concurrent Sessions64, 000
New Sessions Per Second10, 000
Maximum Number of Users SupportedUnrestricted
Mini-Physical Interface Module (Mini-PIM) Slots2
Onboard Memory512 MB
CompactFlash Slot1
Fixed I/O8 x 10/100/1000

Summary

Overview

Validation Level

Lists validation level for each FIPS 140-2 area.

Roles and Services

Roles

Defines three distinct roles: Crypto-Officer, User, Read-Only User.

Services

Lists available services like Configuration, Status, Zeroize, Manage, Self-tests.

Authentication

Strength of Authentication

Details password complexity requirements and login attempt limits.

Interfaces

Operation In FIPS Mode

Initial configuration

Steps for initial device setup and connecting to it.

Loading and authenticating firmware

Process for loading and verifying firmware integrity for FIPS.

Security rules

Enabling FIPS mode

Command-line instructions to enable FIPS mode.

Determining the current mode

CLI command to check the current operating mode (FIPS or non-FIPS).

Operating restrictions in FIPS mode

Lists limitations imposed when the device operates in FIPS mode.

Self tests

Device Specific Self-Tests

Firmware integrity self-test via DSA signature.

Critical Function Self-Tests

Includes SDRAM and FLASH tests.

Algorithm Self-Tests

Lists Cryptographic Algorithm tests like KATs.

FIPS Approved Algorithms

Bypass tests

Explains bypass state and traffic matching for conditional tests.

Non-FIPS Approved Algorithms

Zeroization

Physical Security Policy

Inspection/Testing of Physical Security Mechanisms

Details inspection of tamper labels, enclosure, and seal application.

Tamper Seal Placement – SSG320M

Tamper Seal Placement – SSG350M

Tamper Seal Placement – SSG350M (Continued)

Continues seal placement for SSG350M, including rear seals.

Cryptographic Algorithm Validation

Critical Security Parameter (CSP) Definitions

Public Key Definitions

Defines the public keys utilized by the module.

Matrix Creation of Critical Security Parameter (CSP) versus the Services (Roles & Identity)

Mitigation of Other Attacks Policy

Definitions List

Related product manuals