Specifications
© Copyright 2007 Cisco Systems, Inc.
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
2
Table of Contents
1 INTRODUCTION.................................................................................................................. 3
1.1 P
URPOSE
............................................................................................................................. 3
1.2 R
EFERENCES
....................................................................................................................... 3
1.3
T
ERMINOLOGY
.................................................................................................................... 3
1.4
D
OCUMENT
O
RGANIZATION
................................................................................................ 3
2 CISCO 2811 AND 2821 ROUTERS......................................................................................... 5
2.1
T
HE
2811
C
RYPTOGRAPHIC
M
ODULE
P
HYSICAL
C
HARACTERISTICS
...................................... 5
2.2
T
HE
2821
C
RYPTOGRAPHIC
M
ODULE
P
HYSICAL
C
HARACTERISTICS
...................................... 8
2.3
R
OLES AND
S
ERVICES
........................................................................................................... 12
2.3.1. User Services................................................................................................ 12
2.3.2 Crypto Officer Services .................................................................................. 12
2.3.3 Unauthenticated Services............................................................................... 13
2.3.4 Strength of Authentication .............................................................................. 14
2.4
P
HYSICAL
S
ECURITY
............................................................................................................. 14
2.5
C
RYPTOGRAPHIC
K
EY
M
ANAGEMENT
.................................................................................. 19
2.6
S
ELF
-T
ESTS
....................................................................................................................... 27
2.6.1 Self-tests performed by the IOS image ....................................................... 27
2.6.2 Self-tests performed by NetGX Chip ........................................................... 27
2.6.3 Self-tests performed by AIM........................................................................ 28
3 SECURE OPERATION OF THE CISCO 2811 OR 2821 ROUTER ............................. 28
3.1
I
NITIAL
S
ETUP
................................................................................................................... 28
3.2
S
YSTEM
I
NITIALIZATION AND
C
ONFIGURATION
................................................................. 29
3.3
IPS
EC
R
EQUIREMENTS AND
C
RYPTOGRAPHIC
A
LGORITHMS
............................................. 29
3.4
P
ROTOCOLS
....................................................................................................................... 30
3.5
SSL
V
3.1/TLS
R
EQUIREMENTS AND
C
RYPTOGRAPHIC
A
LGORITHMS
................................ 30
3.6
R
EMOTE
A
CCESS
............................................................................................................... 30