Dell W-AP92 Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Pontos de acesso WLAN Dell W-AP92. DELL PowerConnect W-AP92 Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 45
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
1
FIPS 140-2 Non-Proprietary Security Policy
for Aruba AP-92, AP-93, AP-105, AP-175 Dell W-
AP92, W-AP93, W-AP105 and W-AP175
Wireless Access Points
Version 1.2
Feb. 2012
Aruba Networks™
1322 Crossman Ave.
Sunnyvale, CA 94089-1113
Vista de página 0
1 2 3 4 5 6 ... 44 45

Resumo do Conteúdo

Página 1 - Wireless Access Points

1 FIPS 140-2 Non-Proprietary Security Policy for Aruba AP-92, AP-93, AP-105, AP-175 Dell W-AP92, W-AP93, W-AP105 and W-AP175 Wireless A

Página 2

10 The plastic case physically encloses the complete set of hardware and software components and represents the cryptographic boundary of the module

Página 3

11 Label Function Action Status Flashing Ethernet link activity 11b/g/n 2.4GHz Radio Status Off 2.4GHz radio disabled On – Amber 2.4GHz radio ena

Página 4

12 2.3.1 Physical Description The Aruba AP-105 Access Point is a multi-chip standalone cryptographic module consisting of hardware and software, al

Página 5 - 1 Introduction

13 ENET Ethernet Network Link Status / Activity Off Ethernet link unavailable On – Amber 10/100Mbs Ethernet link negotiated On – Green 1000Mbs Eth

Página 6

14 2.4.1 Physical Description The Aruba AP-175 Access Point is a multi-chip standalone cryptographic module consisting of hardware and software, al

Página 7 - 2 Product Overview

15 2.4.1.3 Indicator LEDs There is an array of LEDs which operate as follows: Table 5- AP-175 Indicator LEDs Label LED Position Function Action Sta

Página 8

16 3 Module Objectives This section describes the assurance levels for each of the areas described in the FIPS 140-2 Standard. In addition, it prov

Página 9 - 2.2 AP-93

17 3.2.2 AP-92 TEL Placement This section displays all the TEL locations of the Aruba AP-92. The AP-92 requires a minimum of 3 TELs to be applied

Página 10

18 Figure7 - Aruba AP-92 Tel placement right view Figure 8 - Aruba AP-92 Tel placement top view

Página 11 - 2.3 AP-105 Series

19 Figure 9 - Aruba AP-92 Tel placement bottom view 3.2.3 AP-93 TEL Placement This section displays all the TEL locations of the Aruba AP-93. T

Página 13 - 2.4 AP-175 Series

20 Figure 11 - Aruba AP-93 Tel placement left view Figure 12 - Aruba AP-93 Tel placement right view Figure 13 - Aruba AP-93 Tel placement botto

Página 14 - 2.4.1 Physical Description

21 Figure 14 - Aruba AP-93 Tel placement top view 3.2.4 AP-105 TEL Placement This section displays all the TEL locations of the Aruba AP-105. T

Página 15

22 Figure 16 - Aruba AP-105 Tel placement left view Figure 17 - Aruba AP-105 Tel placement right view Power Input Inlet Figure 18 - Aruba AP-105

Página 16 - 3 Module Objectives

23 Figure 19 - Aruba AP-105 Tel placement bottom view 3.2.5 AP-175 TEL Placement This section displays all the TEL locations of the Aruba AP-175.

Página 17 - 3.2.2 AP-92 TEL Placement

24 Figure 20 - Aruba AP-175 Tel placement back view Figure 21 - Aruba AP-175 Tel placement left view Figure 22 - Aruba AP-175 Tel placement rig

Página 18

25 Figure 23 - Aruba AP-175 Tel placement top view Figure 24 - Aruba AP-175 Tel placement bottom view 3.2.6 Inspection/Testing of Physical Secu

Página 19 - 3.2.3 AP-93 TEL Placement

26 3.3 Modes of Operation The module has the following FIPS approved modes of operations: • Remote AP (RAP) FIPS mode – When the module is config

Página 20

27 6. If the staging controller does not provide PoE, either ensure the presence of a PoE injector for the LAN connection between the module and th

Página 21 - 3.2.4 AP-105 TEL Placement

28 7. Connect the module via an Ethernet cable to the staging controller; note that this should be a direct connection, with no intervening network

Página 22

29 the AP as Remote Mesh Portal by filling in the form appropriately. Detailed steps are listed in Section “Provisioning an Individual AP” of C

Página 24

30 represents the only exception. That is, nothing other than a PoE injector should be present between the module and the staging controller. 8. On

Página 25

31 3.5 Logical Interfaces The physical interfaces are divided into logical interfaces defined by FIPS 140-2 as described in the foll

Página 26 - 3.3 Modes of Operation

32 4 Roles, Authentication and Services 4.1 Roles The module supports the roles of Crypto Officer, User, and Wireless Client; no addi

Página 27

33 4.1.2 User Authentication Authentication for the User role depends on the module configuration. When the module is configured as a Remote Mesh P

Página 28

34 Authentication Mechanism Mechanism Strength Wireless Client WPA2-PSK (Wireless Client role) For WPA2-PSK there are at least 95^16 (=4.4 x 10^31)

Página 29

35 4.2 Services The module provides various services depending on role. These are described below. 4.2.1 Crypto Officer Services The CO role in e

Página 30 - 3.4 Operational Environment

36 Service Description CSPs Accessed (see section 6 below for complete description of CSPs) Creation/use of secure management session between module

Página 31 - 3.5 Logical Interfaces

37 Service Description CSPs Accessed (see section 6 below for complete description of CSPs)  802.11i AES-CCM key  802.11i GMK  802.11i GTK Us

Página 32 - 4.1 Roles

38  System status – SYSLOG and module LEDs  802.11 a/b/g/n  FTP  TFTP  NTP  GRE tunneling of 802.11 wireless user frames (when acting a

Página 33 - 4.1.2 User Authentication

39 5 Cryptographic Algorithms FIPS-approved cryptographic algorithms have been implemented in hardware and firmware. The firmware supports the fol

Página 34

4 3.2.5 AP-175 TEL Placement ...23 3.2.5.1

Página 35 - 4.2 Services

40 6 Critical Security Parameters The following Critical Security Parameters (CSPs) are used by the module: CSP CSP TYPE GENERATION STORAGE And

Página 36

41 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE IKEv1/IKEv2 Diffie-Hellman Private key 1024-bit Diffie-Hellman private key Generated inte

Página 37

42 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE WPA2 PSK 16-64 character shared secret used to authenticate mesh connections and in remo

Página 38

43 CSP CSP TYPE GENERATION STORAGE And ZEROIZATION USE 802.11i Group Master Key (GMK) 256-bit secret used to derive GTK Generated from approved

Página 39 - 5 Cryptographic Algorithms

44 7 Self Tests The module performs the following Self Tests after being configured into either Remote AP mode or Remote Mesh Portal

Página 40

45 Self-test results are written to the serial console. In the event of a KATs failure, the AP logs different messages, depending on the error. F

Página 41

5 1 Introduction This document constitutes the non-proprietary Cryptographic Module Security Policy for the AP-92, AP-93, AP-105 and AP-175 Wireles

Página 42

6 GE Gigabit Ethernet GHz Gigahertz HMAC Hashed Message Authentication Code Hz Hertz IKE Internet Key Exchange IPSec Internet

Página 43

7 2 Product Overview This section introduces the various Aruba Wireless Access Points, providing a brief overview and summary of the physical featu

Página 44 - 7 Self Tests

8 The exact firmware versions tested were:  ArubaOS_6xx_6.1.2.3-FIPS  Dell_PCW_6xx_6.1.2.3-FIPS 2.1.1.1 Dimensions/Weight The AP has the follo

Página 45

9 Label Function Action Status On – Green 2.4GHz radio enabled in 802.11n mode Flashing - Green 2.4GHz Air monitor or RF protect sensor 11a/n 5G

Comentários a estes Manuais

Sem comentários