Common Criteria Overview

Common Criteria certification for a device enforces a set of security standards and feature limitations on a device to be compliant with the Common Criteria standards, similar to placing the device in FIPS mode. These restrictions are in addition to the requirements of FIPS mode. When the device is placed in Common Criteria mode, several security features that are available in FIPS mode are unavailable on the device. Because Common Criteria mode enforces security restrictions additional to FIPS mode, procedures and information are provided in relation to those for the FIPS mode.

For information about enabling FIPS mode on the device, refer to FIPS Configuration.

For additional information on features available in both FIPS and CC mode and their configuration, refer to the related FIPS sections.

For information on SSH, refer to the following sections:

For information on self-tests, refer to Running FIPS self-tests.

Note: Common Criteria mode becomes available once a device is FIPS-enabled.
Note: To determine if the FastIron device and current software version is Common Criteria-certified, refer to https://www.niap-ccevs.org/CCEVS_Products/pcl.cfm. The Security Targets identified in the RUCKUS PCL entries define the scope of features that were evaluated. Refer to the release notes for the software version running on the device to verify that the software is FIPS- and Common Criteria-certified.
Note: Administrators must be careful to use features only applicable to the evaluation of interest. Instructions throughout this document to configure IPsec and packet filtering features should be followed only if the evaluation of interest is a VPN Gateway and the administrator is configuring an ICX 7450 w/ VPN module.
Note: MACsec is supported on ICX 7450, ICX 7550, ICX 7650, and ICX 7850 devices but was not part of the Common Criteria evaluation.

The following table summarizes support for Common Criteria protection profiles by FastIron device.

Common Criteria protection profiles supported by device

Platform NDcPP2.1 VPNGW1.0
ICX7150 Yes No
ICX7250 Yes No
ICX7450 Yes Yes
Note: VPNGW1.0 is supported only on ICX 7450 devices with an IPsec service module installed.
ICX7650 Yes No
ICX7750 Yes No
ICX7850 Yes No

You can enable Common Criteria mode on a device directly from non-FIPS mode, or on a device already in FIPS mode. The following table summarizes the transitions.

Transition to Common Criteria mode

From

To non-FIPS mode

To FIPS mode

To Common Criteria mode

Non-FIPS mode

Not applicable

Use the fips enable command

Use the fips enable common-criteria command

FIPS mode

Use the no fips enable command

Not applicable

Use the fips enable common-criteria command

Common Criteria mode

Use the no fips enable or no fips enable common-criteria command

Use the following commands in a sequence:

  1. no fips enable
  2. reload device
  3. fips enable

Not applicable

Be advised of the following considerations:

  • Disabling FIPS mode from the Common Criteria mode using the no fips enable command downgrades the device directly into non-FIPS mode.
  • You cannot directly transition from Common Criteria mode to FIPS mode. To transition to FIPS mode, you must disable FIPS mode, reload the device, and then enable FIPS mode.