Common Criteria certification for a device enforces a set of security standards and
feature limitations on a device to be compliant with the Common Criteria standards,
similar to placing the device in FIPS mode. These restrictions are in addition to
the requirements of FIPS mode. When the device is placed in Common Criteria mode,
several security features that are available in FIPS mode are unavailable on the device.
Because Common Criteria mode enforces security restrictions additional to FIPS mode,
procedures and information are provided in relation to those for the FIPS mode.
For information about enabling FIPS mode on the device, refer to
FIPS Configuration.
For additional information on features available in both FIPS and CC mode and their
configuration, refer to the related FIPS sections.
For information on SSH, refer to the following sections:
Note: Common Criteria mode becomes available once a device is FIPS-enabled.
Note: To determine if the FastIron device and current
software version is Common Criteria-certified, refer to https://www.niap-ccevs.org/Product/index.cfm. The Security Targets identified in the RUCKUS PCL entries define the
scope of features that were evaluated. Refer to the release notes for the software
version running on the device to verify that the software is FIPS- and Common
Criteria-certified.
Note: MACsec is supported on ICX 7550, ICX 7650,
and ICX 7850 devices.
The following table summarizes support for Common Criteria protection profiles by
FastIron device.
Common Criteria protection profiles supported by device
Platform
NDcPP2.2e
MACsec (ndcpp_macsec_ep_v1.2)
ICX7150
Yes
No
ICX7550
Yes
Yes
ICX7650
Yes
Yes
ICX7850
Yes
Yes
ICX8200
Yes
No
You can enable Common Criteria mode on a device directly from non-FIPS mode, or on
a device already in FIPS mode. The following table summarizes the transitions.
Transition to Common Criteria mode
From
To non-FIPS mode
To FIPS mode
To Common Criteria mode
Non-FIPS mode
Not applicable
Use the
fips enable command
Use the
fips enable common-criteria command
FIPS mode
Use the
no fips enable command
Not applicable
Use the
fips enable common-criteria command
Common Criteria mode
Use the
no fips enable or
no fips enable common-criteria command
Use the following commands in a sequence:
no fips enable
reload device
fips enable
Not applicable
Be advised of the following considerations:
Disabling FIPS mode from the Common Criteria mode using the
no fips enable command downgrades the device directly into non-FIPS mode.
You cannot directly transition from Common Criteria mode to FIPS mode. To transition
to FIPS mode, you must disable FIPS mode, reload the device, and then enable FIPS
mode.