ZXR10M6000&T8000&8900ESecurityTarget
TheeventlogisconguredtosendeventstooneSYSLOGdestination.SYSLOG
destinationshavethefollowingproperties:
1.SYSLOGserverIPaddress.
2.TheUDPportusedtosendtheSYSLOGmessage.
3.TheSYSLOGFacilityCode(0-23):default16(local0).
4.TheSYSLOGSeverityThreshold(0-7)-eventsexceedingtheconguredlevelwill
besent.
TheAdministratorusesCLIsyntaxtoconguretheTOEtosendSNMPtrap.
Subjectandinformationsecurityattributesusedare:
1.Sourcesubjectsecurityattributes:and
2.Destinationsubjectsecurityattributes:
3.IPaddressoftheSNMPtrapreceiver;
4.UDPportusedtosendtheSNMPtrap;
5.SNMPv3usedtoformattheSNMPnotication;and
6.SecuritynameandlevelforSNMPv3trapreceivers;
lFMT_MSA.3Staticattributeinitialization
Bydefault,thereisnorouting/lterruleconguredontherouterforUNAUTHENTICATED
SFP ,alsothereisnologserversetupforEXPORTSFP .
lFMT_SMF.1Specicationofmanagementfunctions
TheAdministratorperformsthefollowingsecuritymanagementfunctions:
1.start-upandshutdown;
2.create,modify,delete,andviewcongurationdata
3.empty,andreviewtheauditlog
4.create,delete,modify,andviewlteringrules;
5.performcongurationbackupandrestore;
6.useraccountmanagement;
7.modifydate/time;
8.trustedroutermanagementand
9.securitymanagementfunctionslistedinFMT_MOF .1Managementofsecurity
functionsbehavior.
FMT_SMR.1Securityroles
TheTOEallowsallauthorizedadministratorswiththeneededauthoritytocongureand
controltheassociatedfeatures.Onlyauthenticatedadministratorsarepermittedtouse
ormanagetheTOEresources.OnlyauthenticatedadministratorsexecutecertainCLI
commands.Authorizationfeaturesallowadministratorstocongureadministratorproles
whichareusedtolimitwhatCLIcommandsareexecutedbythespecicauthenticated
administrator.OnceanadministratorhasbeenauthenticatedtheTOEisconguredto
performauthorization.Eachcommandhasacorrespondingprivilegelevel(0-15)which
canbemodiedbytheadministrator.Theselevelsassociatewithusers.Anauthenticated
usermustbelongtoacertainprivilegelevel.Anauthenticatedadministratorshallonly
6-6
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION