Cisco ISR 4000 Family Routers Administrator Guidance
Page 2 of 66
Table of Contents
1. Introduction 7
1.1 Audience 7
1.2 Purpose 7
1.3 Document References 7
1.4 Supported Hardware and Software 9
1.5 Operational Environment 9
1.5.1 Supported non-TOE Hardware/ Software/ Firmware 9
1.6 Excluded Functionality 10
2. Secure Acceptance of the TOE 11
3. Secure Installation and Configuration 14
3.1 Physical Installation 14
3.2 Initial Setup via Direct Console Connection 14
3.2.1 Options to be chosen during the initial setup of the ISR 4000 Family Routers 14
3.2.2 Saving Configuration 15
3.2.3 Enabling FIPS Mode 15
3.2.4 Administrator Configuration and Credentials 15
3.2.5 Session Termination 16
3.2.6 User Lockout 16
3.3 Network Protocols and Cryptographic Settings 17
3.3.1 Remote Administration Protocols 17
3.3.2 Authentication Server Protocols 19
3.3.3 Logging Configuration 19
3.3.4 Usage of Embedded Event Manager 20
3.3.5 Logging Protection 21
3.3.6 Base Firewall Rule set Configuration 23
3.3.7 Routing Protocols 25
3.3.8 MACSEC and MKA Configuration 25
4. Secure Management 26
4.1 User Roles 26
4.2 Passwords 26
4.3 Clock Management 29