Dell W-AP92 Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Punkty dostępu do sieci WLAN Dell W-AP92. DELL PowerConnect W-AP92 Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 45
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 0
1
FIPS 140-2 Non-Proprietary Security Policy
for Aruba AP-92, AP-93, AP-105, AP-175 Dell W-
AP92, W-AP93, W-AP105 and W-AP175
Wireless Access Points
Version 1.2
Feb. 2012
Aruba Networks™
1322 Crossman Ave.
Sunnyvale, CA 94089-1113
Przeglądanie stron 0
1 2 3 4 5 6 ... 44 45

Podsumowanie treści

Strona 1 - Wireless Access Points

1 FIPS 140-2 Non-Proprietary Security Policy for Aruba AP-92, AP-93, AP-105, AP-175 Dell W-AP92, W-AP93, W-AP105 and W-AP175 Wireless A

Strona 2

10 The plastic case physically encloses the complete set of hardware and software components and represents the cryptographic boundary of the module

Strona 3

11 Label Function Action Status Flashing Ethernet link activity 11b/g/n 2.4GHz Radio Status Off 2.4GHz radio disabled On – Amber 2.4GHz radio ena

Strona 4

12 2.3.1 Physical Description The Aruba AP-105 Access Point is a multi-chip standalone cryptographic module consisting of hardware and software, al

Strona 5 - 1 Introduction

13 ENET Ethernet Network Link Status / Activity Off Ethernet link unavailable On – Amber 10/100Mbs Ethernet link negotiated On – Green 1000Mbs Eth

Strona 6

14 2.4.1 Physical Description The Aruba AP-175 Access Point is a multi-chip standalone cryptographic module consisting of hardware and software, al

Strona 7 - 2 Product Overview

15 2.4.1.3 Indicator LEDs There is an array of LEDs which operate as follows: Table 5- AP-175 Indicator LEDs Label LED Position Function Action Sta

Strona 8

16 3 Module Objectives This section describes the assurance levels for each of the areas described in the FIPS 140-2 Standard. In addition, it prov

Strona 9 - 2.2 AP-93

17 3.2.2 AP-92 TEL Placement This section displays all the TEL locations of the Aruba AP-92. The AP-92 requires a minimum of 3 TELs to be applied

Strona 10

18 Figure7 - Aruba AP-92 Tel placement right view Figure 8 - Aruba AP-92 Tel placement top view

Strona 11 - 2.3 AP-105 Series

19 Figure 9 - Aruba AP-92 Tel placement bottom view 3.2.3 AP-93 TEL Placement This section displays all the TEL locations of the Aruba AP-93. T

Strona 13 - 2.4 AP-175 Series

20 Figure 11 - Aruba AP-93 Tel placement left view Figure 12 - Aruba AP-93 Tel placement right view Figure 13 - Aruba AP-93 Tel placement botto

Strona 14 - 2.4.1 Physical Description

21 Figure 14 - Aruba AP-93 Tel placement top view 3.2.4 AP-105 TEL Placement This section displays all the TEL locations of the Aruba AP-105. T

Strona 15

22 Figure 16 - Aruba AP-105 Tel placement left view Figure 17 - Aruba AP-105 Tel placement right view Power Input Inlet Figure 18 - Aruba AP-105

Strona 16 - 3 Module Objectives

23 Figure 19 - Aruba AP-105 Tel placement bottom view 3.2.5 AP-175 TEL Placement This section displays all the TEL locations of the Aruba AP-175.

Strona 17 - 3.2.2 AP-92 TEL Placement

24 Figure 20 - Aruba AP-175 Tel placement back view Figure 21 - Aruba AP-175 Tel placement left view Figure 22 - Aruba AP-175 Tel placement rig

Strona 18

25 Figure 23 - Aruba AP-175 Tel placement top view Figure 24 - Aruba AP-175 Tel placement bottom view 3.2.6 Inspection/Testing of Physical Secu

Strona 19 - 3.2.3 AP-93 TEL Placement

26 3.3 Modes of Operation The module has the following FIPS approved modes of operations: • Remote AP (RAP) FIPS mode – When the module is config

Strona 20

27 6. If the staging controller does not provide PoE, either ensure the presence of a PoE injector for the LAN connection between the module and th

Strona 21 - 3.2.4 AP-105 TEL Placement

28 7. Connect the module via an Ethernet cable to the staging controller; note that this should be a direct connection, with no intervening network

Strona 22

29 the AP as Remote Mesh Portal by filling in the form appropriately. Detailed steps are listed in Section “Provisioning an Individual AP” of C

Strona 24

30 represents the only exception. That is, nothing other than a PoE injector should be present between the module and the staging controller. 8. On

Strona 25

31 3.5 Logical Interfaces The physical interfaces are divided into logical interfaces defined by FIPS 140-2 as described in the foll

Strona 26 - 3.3 Modes of Operation

32 4 Roles, Authentication and Services 4.1 Roles The module supports the roles of Crypto Officer, User, and Wireless Client; no addi

Strona 27

33 4.1.2 User Authentication Authentication for the User role depends on the module configuration. When the module is configured as a Remote Mesh P

Strona 28

34 Authentication Mechanism Mechanism Strength Wireless Client WPA2-PSK (Wireless Client role) For WPA2-PSK there are at least 95^16 (=4.4 x 10^31)

Strona 29

35 4.2 Services The module provides various services depending on role. These are described below. 4.2.1 Crypto Officer Services The CO role in e

Strona 30 - 3.4 Operational Environment

36 Service Description CSPs Accessed (see section 6 below for complete description of CSPs) Creation/use of secure management session between module

Strona 31 - 3.5 Logical Interfaces

37 Service Description CSPs Accessed (see section 6 below for complete description of CSPs)  802.11i AES-CCM key  802.11i GMK  802.11i GTK Us

Strona 32 - 4.1 Roles

38  System status – SYSLOG and module LEDs  802.11 a/b/g/n  FTP  TFTP  NTP  GRE tunneling of 802.11 wireless user frames (when acting a

Strona 33 - 4.1.2 User Authentication

39 5 Cryptographic Algorithms FIPS-approved cryptographic algorithms have been implemented in hardware and firmware. The firmware supports the fol

Strona 34

4 3.2.5 AP-175 TEL Placement ...23 3.2.5.1

Strona 35 - 4.2 Services

40 6 Critical Security Parameters The following Critical Security Parameters (CSPs) are used by the module: CSP CSP TYPE GENERATION STORAGE And

Strona 36

41 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE IKEv1/IKEv2 Diffie-Hellman Private key 1024-bit Diffie-Hellman private key Generated inte

Strona 37

42 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE WPA2 PSK 16-64 character shared secret used to authenticate mesh connections and in remo

Strona 38

43 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE 802.11i Group Master Key (GMK) 256-bit secret used to derive GTK Generated from approved

Strona 39 - 5 Cryptographic Algorithms

44 7 Self Tests The module performs the following Self Tests after being configured into either Remote AP mode or Remote Mesh Portal

Strona 40

45 Self-test results are written to the serial console. In the event of a KATs failure, the AP logs different messages, depending on the error. F

Strona 41

5 1 Introduction This document constitutes the non-proprietary Cryptographic Module Security Policy for the AP-92, AP-93, AP-105 and AP-175 Wireles

Strona 42

6 GE Gigabit Ethernet GHz Gigahertz HMAC Hashed Message Authentication Code Hz Hertz IKE Internet Key Exchange IPSec Internet

Strona 43

7 2 Product Overview This section introduces the various Aruba Wireless Access Points, providing a brief overview and summary of the physical featu

Strona 44 - 7 Self Tests

8 The exact firmware versions tested were:  ArubaOS_6xx_6.1.2.3-FIPS  Dell_PCW_6xx_6.1.2.3-FIPS 2.1.1.1 Dimensions/Weight The AP has the follo

Strona 45

9 Label Function Action Status On – Green 2.4GHz radio enabled in 802.11n mode Flashing - Green 2.4GHz Air monitor or RF protect sensor 11a/n 5G

Komentarze do niniejszej Instrukcji

Brak uwag