Specifications
© Copyright 2007 Cisco Systems, Inc.
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
2
Table of Contents
1 INTRODUCTION.................................................................................................................. 3
1.1 P
URPOSE
............................................................................................................................. 3
1.2 R
EFERENCES
....................................................................................................................... 3
1.3
T
ERMINOLOGY
.................................................................................................................... 3
1.4
D
OCUMENT
O
RGANIZATION
................................................................................................ 3
2 CISCO 1841 AND 2801 ROUTERS......................................................................................... 5
2.1
T
HE
1841
C
RYPTOGRAPHIC
M
ODULE
P
HYSICAL
C
HARACTERISTICS
...................................... 5
2.2
T
HE
C
ISCO
2801
C
RYPTOGRAPHIC
M
ODULE
P
HYSICAL
C
HARACTERISTICS
............................ 7
2.3
R
OLES AND
S
ERVICES
........................................................................................................... 11
2.3.1. User Services................................................................................................ 11
2.3.2 Crypto Officer Services .................................................................................. 11
2.3.3 Unauthenticated Services............................................................................... 12
2.3.4 Strength of Authentication .............................................................................. 12
2.4
P
HYSICAL
S
ECURITY
............................................................................................................. 13
2.5
C
RYPTOGRAPHIC
K
EY
M
ANAGEMENT
.................................................................................. 17
2.6
S
ELF
-T
ESTS
....................................................................................................................... 25
2.6.1 Self-tests performed by the IOS image ....................................................... 25
2.6.2 Self-tests performed by Onboard FPGA...................................................... 25
2.6.3 Self-tests performed by AIM........................................................................ 26
3 SECURE OPERATION OF THE CISCO 1841 OR 2801 ROUTER ............................. 27
3.1
I
NITIAL
S
ETUP
................................................................................................................... 27
3.2
S
YSTEM
I
NITIALIZATION AND
C
ONFIGURATION
................................................................. 27
3.3
IPS
EC
R
EQUIREMENTS AND
C
RYPTOGRAPHIC
A
LGORITHMS
............................................. 28
3.4
P
ROTOCOLS
.......................................................................................................................... 28
3.5
SSL
V
3.1/TLS
R
EQUIREMENTS AND
C
RYPTOGRAPHIC
A
LGORITHMS
................................ 28
3.6
R
EMOTE
A
CCESS
............................................................................................................... 28