Common Criteria certification for a device enforces a set of security standards and
feature limitations on a device to be compliant with the Common Criteria standards,
similar to placing the device in FIPS mode. These restrictions are in addition to
the requirements of FIPS mode. When the device is placed in Common Criteria mode,
several security features that are available in FIPS mode are unavailable on the device.
Because Common Criteria mode enforces security restrictions additional to FIPS mode,
procedures and information are provided in relation to those for the FIPS mode.
For information about enabling FIPS mode on the device, refer to
FIPS Configuration.
For additional information on features available in both FIPS and CC mode and their
configuration, refer to the related FIPS sections.
For information on SSH, refer to the following sections:
Note: Common Criteria mode becomes available once a device is FIPS-enabled.
Note: To determine if the
FastIron device and current software version is Common Criteria-certified, refer to
https://www.niap-ccevs.org/CCEVS_Products/pcl.cfm. The Security Targets identified in the
RUCKUS PCL entries define the scope of features that were evaluated. Refer to the release
notes for the software version running on the device to verify that the software is
FIPS- and Common Criteria-certified.
Note: Administrators must be careful to use features only applicable to the evaluation of
interest. Instructions throughout this document to configure IPsec and packet filtering
features should be followed only if the evaluation of interest is a VPN Gateway and
the administrator is configuring an ICX 7450 w/ VPN module.
Note: MACsec is supported on ICX 7450, ICX 7550,
ICX 7650, and ICX 7850 devices but was not part of the Common Criteria
evaluation.
The following table summarizes support for Common Criteria protection profiles by
FastIron device.
Common Criteria protection profiles supported by device
Platform
NDcPP2.1
VPNGW1.0
ICX7150
Yes
No
ICX7250
Yes
No
ICX7450
Yes
Yes
Note: VPNGW1.0
is supported only on ICX 7450 devices with an IPsec service
module installed.
ICX7650
Yes
No
ICX7750
Yes
No
ICX7850
Yes
No
You can enable Common Criteria mode on a device directly from non-FIPS mode, or on
a device already in FIPS mode. The following table summarizes the transitions.
Transition to Common Criteria mode
From
To non-FIPS mode
To FIPS mode
To Common Criteria mode
Non-FIPS mode
Not applicable
Use the
fips enable command
Use the
fips enable common-criteria command
FIPS mode
Use the
no fips enable command
Not applicable
Use the
fips enable common-criteria command
Common Criteria mode
Use the
no fips enable or
no fips enable common-criteria command
Use the following commands in a sequence:
no fips enable
reload device
fips enable
Not applicable
Be advised of the following considerations:
Disabling FIPS mode from the Common Criteria mode using the
no fips enable command downgrades the device directly into non-FIPS mode.
You cannot directly transition from Common Criteria mode to FIPS mode. To transition
to FIPS mode, you must disable FIPS mode, reload the device, and then enable FIPS
mode.