Aruba 800 Series Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Punkty dostępu do sieci WLAN Aruba 800 Series. Aruba 800 Series User manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 36
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 0
FIPS 140-2 Non-Proprietary Security Policy
for Aruba AP-120 Series and Dell W-AP120 Series
Wireless Access Points
Version 1.4
February 2012
Aruba Networks™
1322 Crossman Ave.
Sunnyvale, CA 94089-1113
Przeglądanie stron 0
1 2 3 4 5 6 ... 35 36

Podsumowanie treści

Strona 1 - Wireless Access Points

FIPS 140-2 Non-Proprietary Security Policy for Aruba AP-120 Series and Dell W-AP120 Series Wireless Access Points Version 1.4 February 20

Strona 2

10 3 Module Objectives This section describes the assurance levels for each of the areas described in the FIPS 140-2 Standard. In addition, it prov

Strona 3

11 3.2.2 Aruba AP-124 TEL Placement This section displays all the TEL locations on the Aruba AP-124. The AP124 requires a minimum of 3 TELs to be

Strona 4

12 Figure 2: AP-124 Back view Figure 3: AP-124 Left view Figure 4: AP-124 Right view Figure 5: AP-124 Top view

Strona 5 - 1 Introduction

13 Figure 6: AP-124 Bottom view 3.2.3 Aruba AP-125 TEL Placement This section displays all the TEL locations on the Aruba AP-125. The AP125 requ

Strona 6

14 Figure 7: AP-125 Front view Figure 8: AP-125 Back view Figure 9: AP-125 Left view

Strona 7 - 2 Product Overview

15 Figure 10: AP-125 Right view Figure 11: AP-125 Top view

Strona 8

16 Figure 12: AP-125 Bottom view 3.2.4 Inspection/Testing of Physical Security Mechanisms Physical Security Mechanism Recommended Test Frequency

Strona 9

17 3.3 Modes of Operation The module has the following FIPS approved modes of operations: • Remote AP (RAP) FIPS mode – When the module is conf

Strona 10 - 3 Module Objectives

18 5. Enable FIPS mode on the AP. This accomplished by going to the Configuration > Wireless > AP Configuration > AP Group page. There, yo

Strona 11

19 6. If the staging controller does not provide PoE, either ensure the presence of a PoE injector for the LAN connection between the module and th

Strona 13

20 represents the only exception. That is, nothing other than a PoE injector should be present between the module and the staging controller. 8. On

Strona 14

21 select AP > AP System Profile. Then, check the “Fips Enable” box, check “Apply”, and save the configuration. 6. If the stag

Strona 15 - Figure 11: AP-125 Top view

22 Linux implementation is not provided directly. Only Aruba-provided Crypto Officer interfaces are used. There is no user interface provided. 3

Strona 16

23 4 Roles, Authentication and Services 4.1 Roles The module supports the roles of Crypto Officer, User, and Wireless Client; no addi

Strona 17 - 3.3 Modes of Operation

24 4.1.2 User Authentication Authentication for the User role depends on the module configuration. When the module is configured as a Mesh AP, the

Strona 18

25 Authentication Mechanism Mechanism Strength Wireless Client WPA2-PSK (Wireless Client Role) For WPA2-PSK there are at least 95^16 (=4.4 x 10^31)

Strona 19

26 4.2 Services The module provides various services depending on role. These are described below. 4.2.1 Crypto Officer Services The CO role in e

Strona 20

27 Service Description CSPs Accessed (see section 6 below for complete description of CSPs) Creation/use of secure management session between mo

Strona 21 - 3.4 Operational Environment

28 Service Description CSPs Accessed (see section 6 below for complete description of CSPs)  802.11i AES-CCM key  802.11i GMK  802.11i GT

Strona 22 - 3.5 Logical Interfaces

29 4.2.4 Unauthenticated Services The module provides the following unauthenticated services, which are available regardless of role. No CSPs

Strona 23 - 4.1 Roles

1 INTRODUCTION ... 5

Strona 24 - 4.1.2 User Authentication

30 5 Cryptographic Algorithms FIPS-approved cryptographic algorithms have been implemented in hardware and firmware. The firmware supports the fo

Strona 25

31 6 Critical Security Parameters The following Critical Security Parameters (CSPs) are used by the module: CSP CSP TYPE GENERATION STORAGE And

Strona 26 - 4.2 Services

32 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE IKEv1/IKEv2 Diffie-Hellman Private key 1024-bit Diffie-Hellman private key Generated inte

Strona 27 - 4.2.2 User Services

33 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE WPA2 PSK 16-64 character shared secret used to authenticate mesh connections and in remo

Strona 28

34 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE 802.11i Group Master Key (GMK) 256-bit secret used to derive GTK Generated from approved

Strona 29

35 7 Self Tests The module performs the following Self Tests after being configured into either Remote AP mode or Remote Mesh Portal

Strona 30 - 5 Cryptographic Algorithms

36 For an ArubaOS OpenSSL AP module and ArubaOS cryptographic module KAT failure: AP rebooted [DATE][TIME] : Restarting System, SW FIPS KAT failed

Strona 31

4 4.2.2 User Services ...2

Strona 32

1 Introduction This document constitutes the non-proprietary Cryptographic Module Security Policy for the AP-120 series Wireless Access Points with

Strona 33

6 LAN Local Area Network LED Light Emitting Diode SHA Secure Hash Algorithm SNMP Simple Network Management Protocol SPOE Serial &

Strona 34

7 2 Product Overview This section introduces the various Aruba Wireless Access Points, providing a brief overview and summary of the physical featu

Strona 35 - 7 Self Tests

8 2.1.1.1 Dimensions/Weight The AP has the following physical dimensions:  4.9” x 5.13” x 2.0” (124mm x 130mm x 51mm)  15oz (0.42 Kgs) 2.1.1.2

Strona 36

9 Label Function Action Status Flashing 2.4GHz Air monitor WLAN 5Ghz 5GHz Radio Status Off 5GHz radio disabled On - Amber 5GHz radio enabled in WL

Komentarze do niniejszej Instrukcji

Brak uwag