Chapter6TOESUMMARYSPECIFICATION
ManagementofTSFData(Auditlogs):TheTOEcanbeconguredtoclearauditlogs
andspecifytheloglevelbyanadministrator.
ManagementofTSFData(UserAccount):TheTOErestrictstheabilitytoadminister
userdatatoonlyadministrators.TheCLIprovidesadministratorswithatext-based
interfacefromwhichalluserdatacanbemanaged.Fromthisinterfacenewaccountscan
becreated,andexistingaccountscanbemodiedordeleted.
lFMT_MOF.1Managementofsecurityfunctionsbehavior
Theadministratorwillperformthefollowing:
1.CongureadministratorprolesusedtodenyorpermitaccesstoCLIcommandtree
permissions,orspecicCLIcommands.
2.Congureauthenticationfailurehandlingcongurableintegerofunsuccessful
authenticationattemptswithincongurablerangeoftime,andcongurablelockout
periodoftimethatoccursrelatedtoaadministrator’sauthentication.
3.Congureauthentication-orderforlocal,RADIUSandTACACS+authentication
EnablesRADIUSorTACACS+(TOEclient-side).
4.Congurepasswordcomplexity[numeric][special-character][capital][lowercase]and
congurepasswordminimum-lengthvalue.
5.CongureACLsandcontrolswhere(e.g.,fromaspecicnetworkaddressorlocal
managementinterface)administrators,andauthorizedITentitiesaccesstheTOE.
6.Conguresauditlogs.
7.CongureSNMP/SYSLOG
8.CongureNTP
9.Congureanti-DoSattack
10.CongureURPF
11.CongureCPUprotectionpolicies
lFMT_MSA.1Managementofsecurityattributes
Simplesecurityattributes(unauthenticatedpolicy)
Theadministratorspeciesinformationowpolicyrules(i.e.,routingprotocolsand
ingress/egresstrafclteringandpeerltering)thatcontaininformationsecurityattribute
values,andassociatewiththatruleanactionthatpermitstheinformationowordisallows
theinformationow.Whenapacketarrivesatthesourceinterface,theinformation
securityattributevaluesofthepacketarecomparedtoeachinformationowpolicyrule
andwhenamatchisfoundtheactionspeciedbythatruleistaken.
Subjectandinformationsecurityattributesusedare:
1.IPnetworkaddressandportofsourcesubject;
2.IPnetworkaddressandportofdestinationsubject;
3.transportlayerprotocolandtheiragsandattributes(UDP ,TCP);
4.networklayerprotocol(IP ,ICMP);
5.interfaceonwhichtrafcarrivesanddeparts;and
6.routingprotocolsandtheircongurationandstate.
Simplesecurityattributes(exportpolicy)
6-5
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION