ZXR10M6000&T8000&8900ESecurityTarget
isprocessedbetweenRADIUSandlocalorTACACS+andlocalpasswordsare
specicallycongured.TheorderofTACACS+andlocalcanbecongured.Theallowed
authenticationmodelsarelistedbelow:
1.Localonly
2.RADIUSonly
3.TACAS+only
4.RADIUSrst,ifRADIUSnotresponsethenlocalauthentication
5.TACACS+rst,ifTACACS+notresponsethenlocalauthentication
6.Localrst,iflocalauthenticationfailedthenRADIUSauthentication
7.Localrst,iflocalauthenticationfailedthenTACACS+authentication
Authenticationvalidatesanadministratornameandpasswordcombinationwhenan
administratorattemptstologin.Whenanadministratorattemptstologin,theTOEsends
anaccessrequesttoaRADIUS,TACACS+,orlocaldatabase.
lFIA_UID.2Useridenticationbeforeanyaction
TheTOEvalidatesanadministratornameandpasswordcombinationwhenan
administratorattemptstologin
lFIA_UAU.5Multipleauthenticationmechanisms
TheTOEsoftwaresupportsthreekindsofuserauthenticationmethods:Local
Authentication,RemoteAuthenticationDial-InUserService(RADIUS)andTerminal
AccessControllerAccessControlSystemPlus(TACACS+).Authenticationmechanism
canbecongured.Administratorcanbeauthenticatedanyoftheaboveauthentication
mechanismsbasedonthespecicationbyauthentication.
6.1.3SecurityManagement
TheTOEprovidesadministratorswiththecapabilitiestocongure,monitorandmanage
theTOEtofullltheSecurityObjectives.SecurityManagementprinciplesrelatetoSecurity
AuditandInformationFlowControl.AdministratorsconguretheTOEviaremote/localCLI.
lFMT_MTD.1ManagementofTSFData
ManagementofTSFData(CongurationItemandFilteringRule):TheTOErestricts
theabilitytoadministertheroutercongurationitemandlteringrule.TheCLIprovidesa
text-basedinterfacefromwhichtheroutercongurationcanbemanagedandmaintained.
Fromthisinterface,allTOEfunctionssuchasBGPv4,RIPv2IS-ISandOSPFv2protocols
canbemanaged.TheTOEautomaticallyroutestrafcbasedonavailablerouting
information,muchofwhichisautomaticallycollectedfromtheTOEenvironment.
ThisCLIinterfacealsoprovidestheadministratorwiththeabilitytocongureanexternal
authenticationserver,suchasaRADIUSorTACACS+server.Whenthisisassigned,
ausercanbeauthenticatedtotheexternalserverinsteadofdirectlytotheTOE.If
authentication-orderincludesRADIUSorTACACS+,thenthesewillbeconsultedinthe
conguredorderforallusers.
ManagementofTSFData(Date/time):TheTOEwillallowonlyanadministratortomodify
thedate/timesettingontheappliance.
6-4
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION