Network Device Collaborative Protection Profile

The Network Collaborative Device Protection Profile (NDcPP) standards provide a set of rules that define the security requirements for network devices. The main purpose of these requirements is to minimize and reduce threats to network devices. NDcPP requires SSH or TLS for syslog and authentication server communications.

Note: The connections syslog and AAA servers need to be over TLS. For more information, see the output of fips enable common-criteria command with lines prefixed with "CC".

Audit Logging

FastIron devices support logging of PKI transaction details. The logs are automatically generated syslog messages that contain the PKI transaction details.

There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional PKI transaction details.