Cisco ISR 4000 Family Routers Administrator Guidance
Page 9 of 66
MACSEC and MKA
Configuration Guide
http://www.cisco.com/c/en/us/td/docs/ios-
xml/ios/macsec/configuration/xe-16/macsec-xe-16-book.html
IP Addressing: NAT
Configuration Guide
http://www.cisco.com/c/en/us/td/docs/ios-
xml/ios/ipaddr_nat/configuration/xe-16/nat-xe-16-book.html
1.4 Supported Hardware and Software
Only the hardware and software listed in section 1.5 of the Security Target (ST) is compliant with
the Common Criteria evaluation. Using hardware not specified in the ST invalidates the secure
configuration. Likewise, using any software version other than the evaluated software listed in the
ST will invalidate the secure configuration. The TOE is a hardware and software solution that
makes up the Cisco Integrated Services Routers (ISR) 4000 Family (4321, 4331 and 4351) model.
The network, on which they reside, is considered part of the environment. The software is pre-
installed and is comprised of the Cisco IOS-XE software image Release 16.3.2. In addition, the
software image is also downloadable from the Cisco web site.
1.5 Operational Environment
1.5.1 Supported non-TOE Hardware/ Software/ Firmware
The TOE supports (in some cases optionally) the following hardware, software, and firmware in
its environment:
Table 3 IT Environment Components
Usage/Purpose Description for TOE performance
This includes any IT environment RADIUS AAA server that provides single-
use authentication mechanisms. This can be any RADIUS AAA server that
provides single-use authentication. The TOE correctly leverages the services
provided by this RADIUS AAA server to provide single-use authentication
to administrators.
Management
Workstation
with SSH
Client
This includes any IT Environment Management workstation with a SSH
client installed that is used by the TOE administrator to support TOE
administration through SSH protected channels. Any SSH client that
supports SSHv2 may be used.
This includes any IT Environment Console that is directly connected to the
TOE via the Serial Console Port and is used by the TOE administrator to
support TOE administration.