ZXR10M6000&T8000&8900ESecurityTarget
Themajordifferencebetweenmodelsisthetype,capacityandnumberofthephysical
interfacesdescribedintheabovetable.
1.3TOEOVERVIEW
1.3.1IntendedusageandsecurityfeaturesoftheTOE
TheTOEisZXR10M6000&T8000&8900Eseriesroutersandswitchesrunningthe
ZXROSNG1.00.20.
TheTOEenablesthedeliveryofmetroEthernetservicesandhigh-densityservice-aware
EthernetaggregationoverIP/MPLS-basednetworks.
Thesupportedprotocolsarelayer2/layer3encapsulationandInternetProtocol(IP),and
Ethernet.Otherprotocolsmaybesupportedbytheproduct,butarenotevaluated(see
section1.4.3).
ThemajorsecurityfeaturesoftheTOEare:
lHandlingofpacketowsusingtheRIPv2,OSPFv2,IS-ISandBGPv4protocols
lLocalandremoteadministration
lAuthentication,eitherintheTOEorthroughTACACS+orRADIUS.
lAdministratorProlestopermitordenyaccesstoahierarchicalbranchorspecic
commands.
lAudit
lManagementandcongurationoftheTOE
lMitigateDoSattacks
lURPF(UnicastReversePathForwarding)tolimitthemalicioustrafc
1.3.2Non-TOEcomponents
TheTOErequiresthefollowingITinitsenvironment:
Alocalorremoteconsoleforadministration(required)
Atleastoneisneeded,butbothareallowed.
lForalocalconsole:AnyplatformthatsupportsterminalemulationtotheANSIX3.64
standard;
lForaremoteconsole,anyplatformthatsupportsterminalemulationtotheANSIX3.64
standardandtheSSHprotocol.
ASNMP/SYSLOGserverforlogging(required)
Thismaybetwoplatformsoronecombinedplatform.
lFortheSNMPserver,anyplatformthatsupportsRFC3411-RFC3418(SNMPv3)
lFortheSYSLOGserver,anyplatformthatsupportsRFC3164(SYSLOGProtocol);
1-4
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION