Security Audit:
The TOE generates audit records related to TOE operation and administration. These audit records are stored on the IPS Manager (and stored in a local database) and are also forwarded to an external audit server. The database stores 50,000 audit records. When the database reaches capacity, the oldest audit records are overwritten.
The Sensor generates audit records and forwards the audit records to the IPS Manager, the Sensor caches audit records in a local file. The audit file can be uploaded to Manager(or any other SCP server using the
auditlogupoloadCLI command). If the file reaches capacity, new events are dropped.Only authenticated users can view audit records.
Cryptographic Support:
The TOE uses symmetric key cryptography to secure communication between the Sensors and the Manager for the following functionality:
Exchange of configuration information (including IPS policies)
Time/date synchronization from the Manager to Sensors
Transfer of IPS data to the Manager
Transfer of audit records to the Manager
Distribution of TOE updates to Sensors
Connections between the Manager and Sensors are secured using TLS.
Connections between the Manager and the Audit Server (for audit record upload) are secured using TLS.
Connections between the Manager and the SCP Server is secured using SSH.
Sessions between the Management Workstation and the TOE are secured using SSH or HTTPS and authenticated using username and password. Local console connections between the Console Workstation and the TOE are physically secured. The Sensors also use SSH to securely copy a new image to update the Sensor.
Identification and Authentication:
Administrators connecting to the TOE are required to enter an IPS administrator username and password to authenticate the administrative connection prior to access being granted.
The Manager and Sensors authenticate to one another through a shared secret that is configured during the initial installation and setup process of the TOE. Although in the evaluated configuration, the Manager supports use of a default self-signed certificate for trust establishment with the sensor, such a channel is out of scope for this evaluation. The sensor-Manager channel must be established using CA-signed certificates.
Security Management:
An administrative CLI can be accessed via the Console port or SSH connection, and an administrative GUI can be accessed via HTTPS. These interfaces are used for administration of the TOE, including audit log configuration, upgrade of firmware and signatures, administration of users, configuration of SSH and TLS connections.
Only administrators authenticated to the admin role are considered to be authorized administrators.
Protection of the TSF:
The presence of the Sensors' components on the network is transparent (other than network packets sent as reactions to be configured IPS conditions). The Sensors are protected from the monitored networks as the system is configured to not accept any management requests or input via the monitored interfaces.
The TOE users must authenticate to the TOE before any administrative operations can be performed on the system.
The TOE ensures consistent timestamps are used by synchronizing time information on the Sensors with the Manager, so that all parts of the IPS system share the same relative time information.
Synchronization occurs over a secure communications channel. Time on the Manager may be configured by an administrator.
The administrator can query the currently installed versions of software on the Sensor using the
showcommand, which returns details about the software and hardware version. A trusted update of the TOE software can be performed from the Manager UI, which is then pushed out to the Sensors.A suite of self-tests is performed by the TOE at power on, and conditional self-tests are performed continuously.
TOE Access:
The TOE monitors local and remote administrative sessions for inactivity and terminates the session when a threshold time is reached. An advisory notice is displayed at the start of each session.
Trusted Path/Channels:
The TSF provides the following trusted communication channels:
TLS for an audit server
TLS for communication between Manager and Sensors
SSH for communication with an SCP Server for updates
The TOE implements TLS/HTTPS and SSH for protection of communications between itself and the administrators.
Security Functions Provided by the TOE
- Published on Oct 1, 2026
- 3 minute(s) read
Was this article helpful?