Specifications

Cisco Aggregation Services Router (ASR) 900 Series Security Target
Page 18 of 52
1.6.1 User Data Protection
The TOE ensures that all information flows from the TOE do not contain residual information
from previous traffic. Packets are padded with zeros. Residual data is never transmitted from
the TOE.
1.6.2 Identification and Authentication
The TOE performs two types of authentication: device-level authentication of the remote device
(VPN peers) and user authentication for the Authorized Administrator of the TOE. Device-level
authentication allows the TOE to establish a secure channel with a trusted peer. The secure
channel is established only after each device authenticates the other. Device-level authentication
is performed via IKE/IPsec mutual authentication. The IKE phase authentication for the IPsec
communication channel between the TOE and authentication server and between the TOE and
syslog server is considered part of the Identification and Authentication security functionality of
the TOE.
The TOE provides authentication services for administrative users to connect to the TOEs secure
CLI administrator interface. The TOE requires Authorized Administrators to authenticate prior
to being granted access to any of the management functionality. The TOE can be configured to
require a minimum password length of 15 characters as well as mandatory password complexity
rules. The TOE provides administrator authentication against a local user database. Password-
based authentication can be performed on the serial console or SSH interfaces. The SSHv2
interface also supports authentication using SSH keys. The TOE optionally supports use of a
RADIUS or TACACS+ AAA server (part of the IT Environment) for authentication of
administrative users attempting to connect to the TOE’s CLI.
1.6.3 Security Management
The TOE provides secure administrative services for management of general TOE configuration
and the security functionality provided by the TOE. All TOE administration occurs either
through a secure SSHv2 session or via a local console connection. The TOE provides the ability
to securely manage:
All TOE administrative users;
All identification and authentication;
All audit functionality of the TOE;
All TOE cryptographic functionality;
The timestamps maintained by the TOE;
Update to the TOE; and
TOE configuration file storage and retrieval.
The TOE supports two separate administrator roles: non-privileged administrator and privileged
administrator. Only the privileged administrator can perform the above security relevant
management functions.