Cisco 3845 - Security Bundle Router Non Proprietary Security Policy - Page 16

Browse online or download pdf Non Proprietary Security Policy for Network Router Cisco 3845 - Security Bundle Router. Cisco 3845 - Security Bundle Router 30 pages. Integrated services routers
Also for Cisco 3845 - Security Bundle Router: Quick Start Manual (38 pages), Troubleshooting Manual (15 pages), Quick Start Manual (40 pages)

Cisco 3845 - Security Bundle Router Non Proprietary Security Policy
Cisco 3825 and Cisco 3845 Routers
The routers support the following FIPS 140-2 approved algorithm implementations:
The router is in the approved mode of operation only when FIPS 140-2 approved algorithms are used
(except DH which is allowed for use in FIPS approved mode for key establishment). The following are
not FIPS 140-2 approved algorithms: RC4, MD5, HMAC-MD5, RSA and DH. DH is allowed for use in
key establishment. The key establishment methodology provides between 80-bits and 96-bits of
encryption strength.
The module supports two types of key management schemes:
The module supports commercially available methods of key establishment, including Diffie-Hellman
and IKE. See Document 7A, Cisco IOS Reference Guide.
All pre-shared keys are associated with the CO role that created the keys, and the CO role is protected
by a password. Therefore, the CO password is associated with all the pre-shared keys. The Crypto
Officer needs to be authenticated to store keys. All Diffie-Hellman (DH) keys agreed upon for individual
tunnels are directly associated with that specific tunnel only via the IKE protocol.

Key Zeroization:

Each key can be zeroized by sending the "no" command prior to the key function commands. This will
zeroize each key from the DRAM, the running configuration.
"Clear Crypto IPSec SA" will zeroize the IPSec DES/3DES/AES session key (which is derived using
the Diffie-Hellman key agreement technique) from the DRAM. This session key is only available in the
DRAM; therefore this command will completely zeroize this key. The following command will zeroize
the pre-shared keys from the DRAM:
Cisco 3825 and Cisco 3845 Integrated Services Routers FIPS 140-2 Non Proprietary Security Policy
16
Software (IOS) implementations
AES
DES (for legacy use only)
3DES
SHA-1
HMAC-SHA-1
X9.31 PRNG
Onboard hardware implementations (Safenet chip)
AES
DES (for legacy use only)
3DES
SHA-1
HMAC-SHA-1
Pre-shared key exchange via electronic key entry. DES/3DES/AES key and HMAC-SHA-1 key are
exchanged and entered electronically.
Internet Key Exchange method with support for pre-shared keys exchanged and entered
electronically.
The pre-shared keys are used with Diffie-Hellman key agreement technique to derive DES,
3DES or AES keys.
The pre-shared key is also used to derive HMAC-SHA-1 key.
no set session-key inbound ah spi hex-key-data
OL-8662-01