ON THIS PAGE
Understanding the Common Criteria Evaluated Configuration
This document describes the steps required to duplicate the configuration of the device running Junos OS when the use case requires a variant of the device which is certified against Common Criteria. The configuration is referred to as the evaluated configuration. The following list describes the standards against which the device has been evaluated by Teron Labs Pty Ltd, an accredited and licensed Common Criteria Technical Laboratory (CCTL):
Collaborative Protection Profile for Network Devices, NDcPPv3.0e—https://commoncriteriaportal.org/files/ppfiles/NDcPP_v3_0.pdf.
The Protection Profile Modules used with CPP_ND_V3.0E are as follows:
PP-Module for Intrusion Prevention Systems (IPS) v1.0 (MOD_IPS_v1.0) - https://www.niap-ccevs.org/protectionprofiles/460
PP-Module for Stateful Traffic Filter Firewalls Version 1.4+Errata 20200625 (MOD_CPP_FW_V1.4E) - https://www.niap-ccevs.org/protectionprofiles/448
PP-Module for VPN Gateways Version: 1.3 (MOD_VPNGW_v1.3) - https://www.niap-ccevs.org/protectionprofiles/481
Functional Package for Secure Shell (SSH) Version 1.0 (PKG_SSH_V1.0) - https://www.niap-ccevs.org/protectionprofiles/459
The cryptographic module incorporated in the device is also validated against the Federal Information Processing Standard FIPS 140-3 — https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf.
The certification of the Junos OS Release 24.4R1 is only valid with FIPS mode enabled on the devices. For each use of the product in the certified configuration, the FIPS mode must be enabled.
Understanding Common Criteria
Common Criteria for information technology is an international agreement signed by several countries that permits the evaluation of security products against a common set of standards. In the Common Criteria Recognition Arrangement (CCRA) at http://www.commoncriteriaportal.org/ccra/, the participants agree to mutually recognize evaluations of products performed in other countries. All evaluations are performed using a common methodology for information technology security evaluation.
For more information on Common Criteria, see http://www.commoncriteriaportal.org/.
Supported Platforms
-
For the features described in this document, the following platforms are supported:
-
SRX300 devices,
-
SRX320 devices,
-
SRX340 devices,
-
SRX345 devices,
-
SRX345-DUAL-AC devices.
-