Specifications

Cisco Aggregation Services Router (ASR) 900 Series Security Target
Page 16 of 52
These features are described in more detail in the subsections below. In addition, the TOE
implements all RFCs of the NDPP as necessary to satisfy testing/assurance measures prescribed
therein.
1.6.1 Security audit
The Cisco Aggregation Services Router (ASR) 900 Series provides extensive auditing
capabilities. The TOE generates a comprehensive set of audit logs that identify specific TOE
operations. For each event, the TOE records the date and time of each event, the type of event,
the subject identity, and the outcome of the event. Auditable events include: failure on invoking
cryptographic functionality such as establishment, termination and failure of an IPsec SA;
establishment, termination and failure of an SSH session; modifications to the group of users that
are part of the authorized administrator roles; all use of the user identification mechanism; any
use of the authentication mechanism; any change in the configuration of the TOE, changes to
time, initiation of TOE update, indication of completion of TSF self-test, maximum sessions
being exceeded, termination of a remote session and attempts to unlock a termination session;
and initiation and termination of a trusted channel.
The TOE is configured to transmit its audit messages to an external syslog server.
Communication with the syslog server is protected using IPsec and the TOE can determine when
communication with the syslog server fails. If that should occur, the TOE can be configured to
block new permit actions.
The logs can be viewed on the TOE using the appropriate IOS commands. The records include
the date/time the event occurred, the event/type of event, the user associated with the event, and
additional information of the event and its success and/or failure. The TOE does not have an
interface to modify audit records, though there is an interface available for the authorized
administrator to clear audit data stored locally on the TOE.
1.6.2 Cryptographic support
The TOE provides cryptography in support of other Cisco Aggregation Services Router (ASR)
900 Series security functionality. The algorithms shown in Table 9 FIPS References are
implemented in the Cisco IOS Common Cryptographic Module (IC2M) Algorithm Module
firmware version 2.0.
This cryptography has been validated for conformance to the requirements of FIPS 140-2 (see
Table 9 for certificate references).
Table 9 FIPS References
Algorithm
Cert. #
AES
2817
DRBG
481
SHS (SHA-1, 256, 384,
512)
2361
HMAC SHA-1, 256, 384,
512
1764