Network Device Collaborative Protection Profile
The Network Collaborative Device
Protection Profile (NDcPP) standards provide a set of rules that define the security
requirements for network devices. The main purpose of these requirements is to minimize
and
reduce threats to network devices. NDcPP requires SSH or TLS for syslog and authentication
server communications.
Note: The connections syslog and AAA servers need
to be over TLS. For more information, see the output of
fips enable
common-criteria command with lines prefixed with "CC". Audit Logging
FastIron devices support logging of PKI transaction details. The logs are automatically generated syslog messages that contain the PKI transaction details.
There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional PKI transaction details.