Specifications

14
Table 3 Required Number & Versions
Component
Name
Required
Quantity
Model Number and Versions
Part of
TOE
AP
One or
more
Cisco Aironet 1131 AG Series Access Points
Cisco Aironet 1142AGN Series Access Points
Cisco Aironet 1242 AG Series Access Points
Cisco Aironet 1252 AGN Series Access Points
Cisco Aironet 1262 AGN Series Access Points
Cisco Aironet 1522 AG Series Access Points
Cisco Aironet 1524 AG Series Access Points
Cisco Aironet 1552 Series Access Points
Cisco Aironet 3502e AGN Series Access Points or
Cisco Aironet 3502i AGN Series Access Points
each running IOS version 12.4(23c)JA7 (downloaded to the
AP from the Controller) and including the Cisco FIPS kit
part number AIRLAP-FIPSKIT
Yes
4400 Controller
or
5508 Controller
or
WiSM
or
WiSM2
One or
more
Cisco 4400 Series Wireless LAN Controller running
software version 7.0.240.0; and the Cisco FIPS kit part
number AIRWLC4400FIPSKIT;
Cisco 5508 Series Wireless LAN Controller running
software version 7.0.240.0; and the Cisco FIPS kit part
number AIR-CT5508FIPSKIT; or
Cisco Wireless Integrated Service Module (WiSM) or
WiSM2 w/software version 7.0.240.0, and Cisco FIPS kit
as appropriate for the 6500 chassis.
Yes
6500 Chassis and
Supervisor 720
One or
more
(with
WiSM or
WiSM2
only)
6500 Catalyst chassis; and the Cisco FIPS kit part number
CVPN6500FIPS/KIT.
720 Supervisor w/software IOS versions 12.2(18)SXF2 or
12.2(18)SXF5
No
Cisco ACS or ISE
One or
more
Cisco Secure Access Control Server (ACS) version 5.3 or
later on any of the following platforms:
Cisco 1120 Secure ACS appliance
Cisco 1121 Secure ACS appliance
Virtual appliances running VMware version ESX 3.5 or 4.0
Or
Cisco Identity Services Engine (ISE) version 1.1 or
later on any supported hardware or virtual appliance.
No
Syslog server
One or
more
Any syslog server that supports receiving syslog over TLS,
and meets pre-filtering requirements specified in
FAU_SEL.1(2), including:
Kiwi Syslog Daemon version 9.2 or later, or
Syslog-ng version 2.0 or later.
No
Wireless Client
One or
more
No specific version requirements
No
Cisco MSE
One
Release 5.1.30.0 (or greater)
No
Cisco WCS or
NCS
One
WCS release 5.1.64.0 (or greater)
NCS release 1.0 (or greater)
No
Certificate
Authority
One
This CA does not need to be dedicated for use by the TOE,
nor managed by the TOE administrators, it only needs to be
available to generate certificates for use with the syslog
server (for syslog over TLS), and when using EAP-TLS, or
EAP-FAST.
No
LDAP Server or
Active Directory
Server
None or
One
If ISE is being used as the RADIUS server to authenticate
Controller Management Users, an LDAP, AD, or additional
RADIUS server (such as ACS) is also required.
No