ZXR10M6000&T8000&8900ESecurityTarget
TheTOEenforcesanEXPORTSFPwherebyinformationeventsaresentfromtheTOE
toSNMPtrapandSYSLOGdestinations.TheTOEwillonlysendauditandmanagement
datatoproperlycongureddestinations
lFDP_IFF.1(1)Simplesecurityattributes(unauthenticatedpolicy)
TheTOEsupportsroutingofthetrafcthatispermittedbytheinformationow
policies.AlltrafcpassingthroughtherouterisprocessedbytheACLattachedtothe
interface/protocol.TheACLisprocessedtop-down,withprocessingcontinuinguntilthe
rstmatchismadeaccordingtothesource/destinationandsecurityattributesinthe
packet.
AlltrafcthatsuccessfullypassedtheACLsisprocessedbytheroutingtables.Therouting
tablemaybestaticallyupdatedbyanadministratorordynamicallygeneratedaccordingto
RIPv2,OSPFv2,IS-ISandBGPv4routingprotocols.
TheTOEexplicitlydeniespacketsbasedonthefollowingrule:
1.wherethesourceidentityoftheinformationisnotincludedinthesetofsource
identiersforthesourcesubject;
2.requestsforaccessorserviceswherethesourceidentityofthepacketspeciesa
broadcastidentity;
3.requestsforaccessorserviceswherethepresumedsourceidentityofthepacket
speciesaloopbackidentier.
4.packetsdoesnotcorrespondtoanentryintheroutingtable.
5.packetsthatdonotconformtoIPprotocolortheassociatedroutingprotocol
specication(RFCsforRIPv2,OSPFv2,IS-IS,BGPv4)].
Aup-sendingpacketrateisalsousedforTOEprotection.Thereare3protection
mechanisms:
1.Iftheup-sendingowratefromthenetworkinterfaceexceedsthecongured
threshold,theexceededtrafcwillbedropped(Anti-DoS).
2.Iftheoutgoinginterfaceofthesourceroutingpacketisdifferentfromtheingoing
interface,thepacketwillbedropped.(URPF).
3.Ifthestatisticsofsemi-connectionoftheTCPSYNoodexceedsconguredthreshold,
theTOEsuppressestheseattacks.
Subjectandinformationsecurityattributesusedare:
1.IPnetworkaddressandportofsourcesubject;
2.IPnetworkaddressandportofdestinationsubject;
3.transportlayerprotocolandtheiragsandattributes(UDP ,TCP);
4.networklayerprotocol(IP ,ICMP);
5.interfaceonwhichtrafcarrivesanddeparts;
6.routingprotocolsandtheircongurationandstate;and
7.controltrafcandtrafcthreshold.
lFDP_IFF.1(2)Simplesecurityattributes(exportpolicy)
TheTOEalsoenforcesanEXPORTSFPwherebyinformationeventsaresentfromthe
TOEtoSNMPtrapandSYSLOGdestinations.
6-8
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION