Chapter6TOESUMMARYSPECIFICATION
executecommandsallowedbyhisprivilegelevelandcannotexecutecommandsofhigher
level.
6.1.4TOEAccess
Mechanismsplacecontrolsonadministrator’ssessions.Localandremoteadministrator’s
sessionsaredroppedafteranAdministrator-denedtimeperiodofinactivity.Droppingthe
connectionofalocalandremotesession(afterthespeciedtimeperiod)reducestherisk
ofsomeoneaccessingthelocalandremotemachineswherethesessionwasestablished,
thusgainingunauthorizedaccesstothesession.
lFTA_SSL.3TSF-initiatedtermination
TheTOEallowsconguringlogincontrolparametersforconsoleandremoteadministration
sessions.
TheTOEhastheabilitytoterminatestaleconnections.TheTOEterminatesinteractive
sessionafteranadministratordenedperiodofinactivitywithadefaultvalueof2minutes,
andwithinarangeof1to1000minutes.AndtheTOEcanconguremandatorytermination
absolute-timewithinfrom1to10000minuteswithadefaultvalueof1440minutes.
Thisidle-timeparametercongurestheidletimeoutforconsole,orremotesessionsbefore
thesessionisterminatedbythesystem.Theidle-timeandabsolute-timewouldreduce
thechancefortheunauthorizedadministratorstoaccesstheTOEthroughanunattended
openedsession.Bydefault,anidleconsole,orremotesessiontimesoutafter2minutes
ofinactivity.Thistimerissetforallsession.
lFTA_TSE.1TOEsessionestablishment
TheTOEwilldenysessionestablishmentafterthecongurednumber(1~15)ofactive
sessionsisreached.AnadministratorcancongureACLstorefusetoestablishmentofa
connection,toensureonlyconnectionsfromtrustedaddressorportistrustable.
TheTOEhasadirectconnectionviathephysicalRS232consoleinterfaceandaremote
consoleconnectiontoperformsecuritymanagementfunctions.
6.1.5Userdataprotection
TheTOEprovidesanInformationFlowControlmechanismthatsupportscontrolofthe
owoftrafcgeneratedbythenetworkdevices.TheInformationFlowControlPoliciesare
conguredoneachnetworkdevicestoallowtrafctoonlyowbetweentheauthorized
sourcesandauthorizeddestinations.AlsotheTOEprovideexportinglogtoSYSLOGand
SNMPservers.
lFDP_IFC.1(1)Subsetinformationowcontrol(unauthenticatedpolicy)
TheTOEenforcesanUNAUTHENTICATEDSFPwherebythenetworkpacketssentand/or
receivedthroughtheTOEtoITentity.
lFDP_IFC.1(2)Subsetinformationowcontrol(exportpolicy)
6-7
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION