Chapter6TOESUMMARYSPECIFICATION
Subjectandinformationsecurityattributesusedare:
1.[Sourcesubjectsecurityattributes:sourcenetworkidentier;and
2.Destinationsubjectsecurityattributes:
a.IPaddressofSYSLOGserver;
b.UDPportusedtosendtheSYSLOGmessage;
c.SYSLOGFacilityCode;
d.SYSLOGSeverityThreshold;
e.Setofdestinationnetworkidentiers;
f.IPaddressoftheSNMPtrapreceiver;
g.UDPportusedtosendtheSNMPtrap;
h.SNMPv3usedtoformattheSNMPnotication;and
i.SecuritynameandlevelforSNMPv3trapreceivers
ForSNMPtrapssentpacketthroughtheportoftheTOE,thesourceIPaddressofthetrap
istheportIPaddressoftheTOE.
TheSYSLOGprotocolisusedtoconveyeventnoticationmessages.Parametersare
denedidentiedinRFC3164TheSYSLOGProtocolwhichdescribestheformatofa
SYSLOGmessage.
TheTOEshallpermitthelogdatatobeexportedtotheSNMP/SYSLOGserverwhenthe
destinationIPaddressandportofthelogpacketsmatchtheconguredserverinformation.
lFDP_UIT.1Dataexchangeintegrity
TheTOEtransmitsandreceivesroutingdata(RIPv2,OSPFv2mode2,IS-ISandBGPv4)
to/fromtrustedroutersinthemannerofprotectingtheroutinginformationfrommodication.
6.1.6TrustedChannel
TheTOEprovidesecurechannelforRADIUS/TACACS+server,NTPserverandthe
remoteterminaltoconnecttotheTOE.
lFTP_ITC.1
TheTSFshallprovideacommunicationchannelbetweenitselfandaremote
administrationclient.SecureremoteadministrationisprovidedbySSH.The
communicationbetweenTOEandRADIUS/TACACS+/NTPserverisprotectedbythe
trustedchannel.
6-9
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION