All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series)

Certificate#4966StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCisco Systems, Inc.
High review priority  ·  no TCB surface named  ·  last validated 17 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date2/13/2030
CaveatWhen installed, initialized and configured as specified in Section "Life-Cycle Assurance" of the Security Policy. The tamper evident seals and opacity shields installed as indicated in Section "Physical Security" of the Security Policy.
VendorCisco Systems, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cisco Systems, Inc. Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series) Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA © 2021-2025 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware6
Table 3: Modes List and Description7
Table 4: Approved Algorithms - CiscoSSL FOM Cryptographic Implementation9
Table 5: Approved Algorithms - Marvell Cavium Nitrox V9
Table 6: Vendor-Affirmed Algorithms10
Table 7: Security Function Implementations15
Table 8: Entropy Certificates16
Table 9: Entropy Sources16
Table 10: Ports and Interfaces17
Table 11: Authentication Methods19
Table 12: Roles19
Table 13: Approved Services36
Table 14: Mechanisms and Actions Required38
Table 15: Storage Areas43
Table 16: SSP Input-Output Methods44
Table 17: SSP Zeroization Methods44
Table 18: SSP Table 151
Table 19: SSP Table 258
Table 20: Pre-Operational Self-Tests58
Table 21: Conditional Self-Tests62
Table 22: Pre-Operational Periodic Information63
Table 23: Conditional Periodic Information65
Table 24: Error States65
Figure 1 FPR 3105, 3110, 3120, 3130, 31406
Figure 2 Module’s front view opacity shield39
Figure 3 Module’s back view39
Figure 4 Module’s top view with opacity shield39
Figure 5 Module’s bottom view with opacity shield40
Figure 6 Module’s left view with opacity shield40
Figure 7 Module’s right view with opacity shield40
Figure 8 Opacity Shield Brackets42
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication3
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

Appliance Cryptographic Module (FPR 3100 Series) (hereinafter referred to as ASA or Module), version 9.20. The following details how this module meets the security requirements of FIPS 140-3, SP 800-140 and ISO/IEC 19790 for a Security Level 2 Hardware cryptographic module. The security requirements cover areas related to the design and implementation of a cryptographic module. These areas include cryptographic module specification; cryptographic table indicates the actual security levels for each area of the cryptographic module.

1.2 Security Levels
2.1 Description

Purpose and Use: This module is a multi-chip standalone hardware cryptographic module deployed under the Next-Generation Firewall (NGFW) with Adaptive Security Appliance (ASA). The module’s ASA delivers enterprise-class firewall for businesses, improving security at the Internet edge, high performance and throughput for demanding enterprise data centers. The ASA solution offers the combination of the industry's most deployed stateful firewall with a comprehensive range of next-generation network security services, intrusion prevention system (IPS), content © 2021-2025 Cisco Systems, Inc.

Page 6
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
FRP 3105FPR-31059.20AMD EPYC 7272 (Zen2) & NITROX-V, Marvell Semiconductor, NITROX
FRP 3110FPR-31109.20AMD EPYC 7272 (Zen2) & NITROX-V, Marvell Semiconductor, NITROX
FRP 3120FPR-31209.20AMD EPYC 7282 (Zen2) & NITROX-V, Marvell Semiconductor, NITROX
FRP 3130FPR-31309.20AMD EPYC 7352 (Zen2) & NITROX-V, Marvell Semiconductor, NITROX
FRP 3140FPR-31409.20AMD EPYC 7452 (Zen2) & NITROX-V, Marvell Semiconductor, NITROX

security and secure unified communications, HTTPS/TLSv1.2, SSHv2, IPsec/IKEv2, SNMPv3 and Cryptographic Cipher Suite B using the ASA Cryptographic Module. Module Type: Hardware Module Embodiment: MultiChipStand Module Characteristics [O]: Cryptographic Boundary: The cryptographic boundary is defined as the entire chassis unit’s physical perimeter encompassing the "top," "front," "left," "right," “rear” and "bottom" surfaces of the case, and shown in the figures below and in the Physical Security section. The FPR 3105, FPR 3110, FPR 3120, FPR 3130 and FPR 3140 all have the same exterior appearance. Where they differ is in Firewall throughput, IPS throughput, IPsec VPN throughput and number of VPN peers allowed.

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 7
Mode NameDescriptionTypeStatus Indicator
Approved Mode of OperationThe module is always in the approved mode of operation after initial operations are performed.ApprovedApproved mode indicator: "FIPS is currently enabled."
AlgorithmCAVP CertPropertiesReference
AES-CBCA4446Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4446Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D

N/A for this module. Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 Excluded Components

N/A for this module. Modes List and Description: Table 3: Modes List and Description operation after initial operations are performed (See Section 11). The module does not claim implementation of a degraded mode of operation. Section 4 provides details on the service

2.5 Algorithms

Approved Algorithms: CiscoSSL FOM Cryptographic Implementation © 2021-2025 Cisco Systems, Inc.

Page 8
AlgorithmCAVP CertPropertiesReference
Counter DRBGA4446Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4446Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4446Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4446Curve - P-256, P-384, P-521FIPS 186-4
HMAC-SHA-1A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-224A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-256A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-384A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-512A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4446Domain Parameter Generation Methods - P- 256, P-384, P-521SP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4446Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp-4096SP 800-56A Rev. 3
KDF IKEv2 (CVL)A4446Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1SP 800-135 Rev. 1
KDF SNMP (CVL)A4446Password Length - Password Length: 256, 64SP 800-135 Rev. 1
KDF SSH (CVL)A4446Cipher - AES-128, AES-192, AES-256SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A4446Key Generation Mode - B.3.4 Modulo - 2048, 3072, 4096 Hash Algorithm - SHA2-256 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4446Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4446Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA4446Safe Prime Groups - modp-2048, modp-3072, modp-4096SP 800-56A Rev. 3
SHA-1A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
Page 9
AlgorithmCAVP CertPropertiesReference
SHA2-224A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4446Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AlgorithmCAVP CertPropertiesReference
AES-CBCC1026Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMC1026Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
Hash DRBGC1026Prediction Resistance - No Mode - SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1C1026-FIPS 198-1
HMAC-SHA2- 256C1026-FIPS 198-1
HMAC-SHA2- 384C1026-FIPS 198-1
HMAC-SHA2- 512C1026-FIPS 198-1
SHA-1C1026Message Length - Message Length: 0- 51200 Increment 8FIPS 180-4
SHA2-256C1026Message Length - Message Length: 0- 51200 Increment 8FIPS 180-4
SHA2-384C1026Message Length - Message Length: 0- 102400 Increment 8FIPS 180-4
SHA2-512C1026Message Length - Message Length: 0- 102400 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKGKey Type:AsymmetricCiscoSSL FOM Cryptographic ImplementationThe cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per sections 4 and 5 in SP800-133rev2 (vendor affirmed) and FIPS

Table 4: Approved Algorithms - CiscoSSL FOM Cryptographic Implementation Marvell Cavium Nitrox V Table 5: Approved Algorithms - Marvell Cavium Nitrox V © 2021-2025 Cisco Systems, Inc.

Page 10
NamePropertiesImplementationReference
140-3 IG D.H. A seed (i.e., the random value) used in asymmetric key generation is a direct output from SP800-90Arev1 CTR_DRBG (A4446) or HMAC_DRBG (C1026)
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC- KeyGen (SSHv2)KAS-KeyGenKAS ECC keygen used in SSHv2 serviceCounter DRBG Hash DRBG CKG
KAS-FFC- KeyGen (SSHv2)KAS-KeyGenKAS FFC keygen used in SSHv2 serviceCounter DRBG Safe Primes Key Generation Hash DRBG CKG
KAS-ECC- KeyGen (TLSv1.2)KAS-KeyGenKAS ECC keygen used in TLSv1.2 serviceCounter DRBG Hash DRBG CKG
KAS-FFC- KeyGen (TLSv1.2)KAS-KeyGenKAS FFC keygen used in TLSv1.2 serviceCounter DRBG Safe Primes Key Generation Hash DRBG CKG
KAS-ECC- KeyGen (IKEv2)KAS-KeyGenKAS ECC keygen used in IKE v2 serviceCounter DRBG Hash DRBG CKG
KAS-FFC- KeyGen (IKEv2)KAS-KeyGenKAS FFC keygen used in IKE v2 serviceCounter DRBG Safe Primes Key Generation

Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations
Page 11
NameTypeDescriptionPropertiesAlgorithms
Hash DRBG CKG
KAS-FFC (SSHv2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with KDF SSH. The module’s KAS (FFC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 112 to 152 bits of encryption strengthKDF SSH KAS-FFC-SSC Sp800-56Ar3 Domain Parameter Generation Methods:: modp- 2048
KAS-ECC (SSHv2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with KDF SSH. The module’s KAS (FFC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKDF SSH KAS-ECC-SSC Sp800-56Ar3
KAS-FFC (TLSv1.2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with TLS v1.2 KDF RFC7627. The module’s KAS (FFC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 112 to 152 bits of encryption strengthTLS v1.2 KDF RFC7627 KAS-FFC-SSC Sp800-56Ar3 Domain Parameter Generation Methods:: modp- 2048
KAS-ECC (TLSv1.2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with KDF IKEv2. The module’s KAS (ECC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthTLS v1.2 KDF RFC7627 KAS-ECC-SSC Sp800-56Ar3
Page 12
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC (IKEv2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with KDF IKEv2. The module’s KAS (ECC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 112 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 KDF IKEv2
KAS-FFC (IKEv2)KAS-FullKey Agreement Scheme per SP800-56Arev3 with KDF IKEv2. The module’s KAS (FFC) implementation is FIPS140-3 IG D.F Scenario 2 (path 2) compliantBit-strength Caveat:Provides between 112 and 152 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 KDF IKEv2
KTS (TLSv1.2 with AES and HMAC)KTS-WrapKTS via TLSv1.2 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-CBC Key Length: 128, 256 HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 384 SHA-1 SHA2-256 SHA2-384
KTS (TLSv1.2 with AES-GCM)KTS-WrapKTS via TLSv1.2 service by using AES-GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM Key Length: 128, 256 AES-CBC
KTS (SSHv2 with AES and HMAC)KTS-WrapKTS via SSHv2 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-CBC Key Length: 128, 256 HMAC-SHA-1 HMAC-SHA2- 256 SHA-1 SHA2-256
Page 13
NameTypeDescriptionPropertiesAlgorithms
KTS (SSHv2 with AES-GCM)KTS-WrapKTS via SSHv2 service by using AES-GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM Key Length: 128, 256 AES-CBC
RSA KeyGen (SSHv2, TLSv1.2, IKEv2)AsymKeyPair- KeyGenRSA KeyGen for SSHv2, TLSv1.2, and IKEv2 servicesRSA KeyGen (FIPS186-4) Counter DRBG Hash DRBG
ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)AsymKeyPair- KeyGenECDSA KeyGen for TLSv1.2 and IKEv2 servicesECDSA KeyGen (FIPS186-4) Counter DRBG Hash DRBG
RSA SigGen (SSHv2, TLSv1.2, IKEv2)DigSig-SigGenRSA SigGen for SSHv2, TLSv1.2, and IKEv2 servicesRSA SigGen (FIPS186-4)
ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2)DigSig-SigGenECDSA SigGen for TLSv1.2, and IKEv2 servicesECDSA SigGen (FIPS186-4)
RSA SigVer (SSHv2, TLSv1.2, and IKEv2)DigSig-SigVerRSA SigVer for SSHv2, TLSv1.2, and IKEv2 servicesRSA SigVer (FIPS186-4)
ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2)DigSig-SigVerECDSA SigVer for TLSv1.2 and IKEv2 servicesECDSA SigVer (FIPS186-4)
Block Cipher (SSHv2)BC-Auth BC-UnAuthBlock Cipher for SSHv2 serviceAES-CBC Key Length: 128, 256 AES-GCM Key Length: 128, 256
Block Cipher (TLSv1.2)BC-Auth BC-UnAuthBlock Cipher for TLSv1.2 serviceAES-GCM Key Length: 128, 256 AES-CBC Key Length: 128, 256
Block Cipher (IPSec/IKEv2)BC-Auth BC-UnAuthBlock Cipher for IPSec/IKEv2 serviceAES-CBC AES-GCM AES-CBC AES-GCM
Block Cipher (SNMPv3)BC-UnAuthBlock Cipher for SNMPv3 serviceAES-CBC KDF SNMP
Page 14
NameTypeDescriptionPropertiesAlgorithms
MAC (SSHv2)MACMAC for SSHv2 serviceHMAC-SHA-1 HMAC-SHA2- 256 SHA-1 SHA2-256
MAC (TLSv1.2)MACMessage Authentication for TLSv1.2 servicesHMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 384 SHA-1 SHA2-256 SHA2-384
MAC (IPSec/IKEv2)MACMessage Authentication for IPSec/IKEv2 servicesHMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512 HMAC-SHA-1 SHA-1
MAC (SNMPv3)MACMessage Authentication for SNMPv3 serviceHMAC-SHA-1 SHA-1 KDF SNMP HMAC-SHA2- 256 HMAC-SHA2- 384 SHA2-256 SHA2-384 HMAC-SHA2- 224 SHA2-224
Firmware Load TestMACMAC for firmware load testHMAC-SHA2- 512
Page 15
NameTypeDescriptionPropertiesAlgorithms
SSHv2 Keying Materials DevelopmentKAS-135KDFSSHv2 session keying materials, used to derive SSHv2 session keysKDF SSH
TLS Keying Materials DevelopmentKAS-135KDFTLS session keying materials, used to derive TLS session keysTLS v1.2 KDF RFC7627
IKEv2 Keying Materials DevelopmentKAS-135KDFIKEv2 session keying materials, used to derive IKEv2 session keysKDF IKEv2
SNMPv3 Keying Materials DevelopmentKAS-135KDFSNMPv3 session keying materials, used to derive SNMPv3 session keysKDF SNMP
DRBG FunctionDRBGDRBG generationCounter DRBG Hash DRBG

Table 7: Security Function Implementations

2.7 Algorithm Specific Information

There are some algorithm modes that were tested but not implemented by the module. Only the algorithms, modes, and key sizes that are implemented by the module are shown in this table. The module’s AES-GCM implementation conforms to Implementation Guidance C.H scenario #1 following RFC 5288 for TLS. The module is compatible with TLSv1.2 and provides support for the acceptable GCM cipher suites from SP 800-52 Rev1, Section 3.3.1. The operations of one of the two parties involved in the TLS key establishment scheme were performed entirely within the cryptographic boundary of the module being validated. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. The keys for the client and server negotiated in the TLSv1.2 handshake process (client_write_key and server_write_key) are compared and the module aborts the session if the key values are identical. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established. The module uses RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. When the IV exhausts the maximum number © 2021-2025 Cisco Systems, Inc.

Page 16
Cert NumberVendor Name
E3Cisco Systems, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Cisco Jitter Entropy SourceNon- PhysicalAMD EPYC 7272 (Zen2), AMD EPYC 7282 (Zen2), AMD EPYC 7352 (Zen2), AMD EPYC 7452 (Zen2)4 bits2 bitsA2810 (SHA3- 256)

of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. Two keys established by IKEv2 for one security association (one key for encryption in each direction between the parties) are not identical and abort the session if they are. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established. No parts of SSH, TLS, IKE and SNMP protocols, other than the KDFs, have been tested by the CAVP and CMVP.

2.8 RBG and Entropy

Table 8: Entropy Certificates Table 9: Entropy Sources

2.9 Key Generation

The module generates RSA, ECDSA, ECDH, and DH asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90A CTR DRBG for random number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5.1 of NIST SP 800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.).

2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation: • KAS-FFC Shared Secret Computation: The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (2) with KAS-FFC shared secret computation. The shared secret computation provides between 112 and

152 bits of encryption strength.

• KAS-ECC Shared Secret Computation: The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (2) with KAS-ECC

Page 17
Physical PortLogical Interface(s)Data That Passes
Ethernet Port, SFP (1G) port, SFP+ (10G) port, and Console PortData InputData input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.
Ethernet Port, SFP (1G) port, SFP+ (10G) port and Console PortData OutputData output from the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.
Ethernet Port, SFP (1G) port, SFP+ (10G) port, Console Port and RESETControl InputControl Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.
Ethernet Port, SFP (1G) port, SFP+ (10G) port, Console Port and LEDsStatus OutputStatus Information output from the module.
N/AControl OutputN/A
PowerPowerProvide the Power Supply to the module.
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
PasswordThe minimum length is eight (8) characters (94Password BasedThe probability that a randomThe probability of successfully

shared secret computation. The shared secret computation provides between 128 and

256 bits of encryption strength.
2.11 Industry Protocols

The module supports SSHv2, TLS v1.2, SNMPv3 and IPsec/IKEv2 industrial protocols. Please refer to SSPs Table for more information.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 10: Ports and Interfaces The module’s physical perimeter encompasses the case of the tested platform mentioned in Table 2. The module provides physical ports which are mapped to logical interfaces provided

4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 18
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
possible characters). The configuration supports at most ten failed attempts to authenticate in a one- minute period.attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000.authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000.
RSA- Based CertificateThe modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.RSA SigVer (FIPS186-4) (A4446)The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details
ECDSA- Based CertificateThe modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. ForECDSA SigVer (FIPS186-4) (A4446)The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in thisthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details
Page 19
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.table for more details
NameTypeOperator TypeAuthentication Methods
Crypto OfficerIdentityCOPassword RSA-Based Certificate ECDSA-Based Certificate
UserIdentityUserPassword RSA-Based Certificate ECDSA-Based Certificate
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusProvide Module’s current status (returnN/ACommand used to show Module's StatusModule's Operationa l StatusNoneCrypto Officer User

and the User role. The module also allows the concurrent operators.

4.2 Roles

Table 12: Roles Unauthenticated Users can run the self-test service by power-cycling the module by removing the power and re-applying.

4.3 Approved Services
Page 20
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
codes and/or syslog messages)
Show VersionProvide Module's name and version informationN/ACommand to show versionModule's ID and versioning informationNoneCrypto Officer User
Perform Self-TestsPerform Self-Tests (Pre- operational self-test and Conditional Self-Tests)N/ACommand to trigger Self-TestStatus of the self- tests resultsNoneCrypto Officer User Unauthentic ated
Perform ZeroizationPerform ZeroizationSyslog messageCommand to zeroize the moduleStatus of the SSPs zeroizationNoneCrypto Officer - DRBG Entropy Input: Z - DRBG Seed: Z - DRBG Internal State V value: Z - DRBG Key: Z - User Password: Z - Crypto Officer Password: Z - RADIUS Secret: Z - TACACS+ Secret: Z - Firmware Load Test Key: Z - SSH DH Private Key: Z - SSH DH Public Key: Z
Page 21

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH RSA Private Key: Z - SSH RSA Public Key: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticatio n Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public

Page 22

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key: Z - TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authenticatio n Key: Z - IPSec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH

Page 23

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEED: Z - IPSec/IKE Session Encryption Key: Z - IPSec/IKE Authenticatio n Key: Z - SNMPv3

Page 24
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticatio n Key: Z
Configure NetworkSets configurati on of the systemsNoneCommand s to configure the networkStatus of the completion of network configurati on statusNoneCrypto Officer
Crypto Officer Authenticat ionCO Role Authenticat ionN/ACO Authenticat ion RequestStatus of the CO authenticat ionNoneCrypto Officer - Crypto Officer Password: W,Z
User Authenticat ionUser Role Authenticat ionN/AUser role authenticat ion requestStatus of the User role authenticat ionNoneUser - User Password: W,Z
Configure Bypass CapabilitySets the Bypass capabilityNoneCLI Bypass commandsStatus of the completion of Bypass capability configurati onNoneCrypto Officer
Configure SSHv2 FunctionConfigure SSHv2 FunctionGlobal Indicator and SSHv2 configurat ion success status messageCommand s to configure SSHv2Status of the completion of the SSHv2 configurati onKAS-FFC (SSHv2) KAS-ECC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2,Crypto Officer - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key:
Page 25
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm entW,E - SSH ECDH Public Key: W,E - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E
Configure HTTPS overGlobal Indicator and HTTPSCommand s to configure TLSv1.2Status of the completion of TLSv1.2KAS-FFC (TLSv1.2) KAS-ECC (TLSv1.2)Crypto Officer - TLS DH Private Key:
Page 26
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
TLSv1.2 Functionover TLSv1.2 configurat ion success status messageconfigurati onKTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGenW,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E - TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E - TLS Session Authenticatio n Key: W,E - DRBG Entropy
Page 27
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(TLSv1.2) TLS Keying Materials Developm ent DRBG FunctionInput: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E
Configure IPsec/IKEv 2 FunctionConfigure IPSec/IKEv 2 FunctionGlobal Indicator with IPsec/IKE v2 configurat ion success status messageCommand s to configure IPsec/IKEv 2Status of the completion of IPsec/IKEv 2 configurati onKAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE v2) MAC (IPSec/IKECrypto Officer - IPSec/IKE DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key: W,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE
Page 28
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
v2) KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) IKEv2 Keying Materials Developm ent DRBG FunctionRSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E
Run SSHv2 FunctionExecute SSHv2 FunctionGlobal Indicator and successfu l SSHv2 log messageInitiate SSHv2 tunnel establishm entStatus of SSHv2 tunnel establishm entKAS-FFC (SSHv2) KAS-ECC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGenCrypto Officer - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key: W,E - SSH ECDH Public Key: W,E
Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm ent- SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public
Page 30

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key: W,E - SSH ECDH Public Key: W,E - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E

Page 31
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - DRBG Key: W,E
Run HTTPS over TLSv1.2 FunctionExecute HTTPS over TLSv1.2 functionGlobal Indicator and successfu l HTTPS over TLSv1.2 log messageInitiate TLSv1.2 tunnel establishm ent requestStatus of TLSv1.2 tunnel establishm entKAS-FFC (TLSv1.2) KAS-ECC (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MACCrypto Officer - TLS DH Private Key: W,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E - TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E
Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(TLSv1.2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm ent- TLS Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - TLS DH Private Key: W,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E
Page 33
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E - TLS Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E
Run IPSec/IKEv 2 FunctionExecute IPsec/IKEv 2 FunctionGlobal Indicator and succesful IPsec/IKE v2 log messageInitiate IPsec/IKEv 2 tunnel establishm ent requestStatus of IPSec/IKE v2 tunnel establishm entKAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2,Crypto Officer - IPSec/IKE DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key:
Page 34
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE v2) MAC (IPSec/IKE v2) KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) IKEv2 Keying Materials Developm ent DRBG FunctionW,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE RSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - IPSec/IKE
Page 35

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key: W,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE RSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE

Page 36
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E
Configure SNMPv3 FunctionConfigure SNMPv3 FunctionGlobal Indicator and SNMPv3 configurat ion success status messageCommand s to configure SNMPv3Status of the completion of SNMPv3 configurati onBlock Cipher (SNMPv3) MAC (SNMPv3) SNMPv3 Keying Materials Developm entCrypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: W,E - SNMPv3 Authenticatio n Key: W,E
Run SNMPv3 FunctionExecute SNMPv3 FunctionGlobal Indicator and successfu l SNMPv3 log messageInitiate SNMPv3 tunnel establishm ent requestStatus of SNMPv3 tunnel establishm entBlock Cipher (SNMPv3) MAC (SNMPv3) SNMPv3 Keying Materials Developm entCrypto Officer User
Firmware Load TestExecute the Firmware Load TestGlobal indicator and successfu l Firmware Loading status messageCommand s to load new firmware imageOutcome of the Firmware Load TestFirmware Load TestCrypto Officer - Firmware Load Test Key: R

W,E Table 13: Approved Services © 2021-2025 Cisco Systems, Inc.

Page 37
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

The module also supports the firmware load test by using HMAC-SHA2-512 (HMAC Cert. #A4446) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate to the module before loading the firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation.

4.6 Bypass Actions and Status

The module implements Bypass service. The operator shall assume Crypto Officer role and configure the Bypass capability. The module will conduct two independent internal actions activate the capability to prevent the inadvertent bypass of plaintext data due to a single error. To verify the module is in bypass state, the Crypto Officer needs to issue commands “show access-list” and “show ipsec sa” to verify the module is in bypass state.

4.7 Cryptographic Output Actions and Status

The module implements Self-initiated cryptographic output capability without external operator request. The Crypto Officer shall configure self-initiated cryptographic output capability. Prior to executing the self-initiated cryptographic output capability, the module conducts two independent internal actions to activate the capability to prevent the inadvertent output due to a single error.

4.8 Additional Information

The module supports unauthenticated service. The unauthenticated User/Operators can trigger the self-test service by power-cycling the module.

5 Software/Firmware Security
5.1 Integrity Techniques

The module is provided in the form of binary executable code. To ensure firmware security, the module is protected by RSA 2048 bits with SHA2-512 (RSA Cert. #A4446) algorithm. A Firmware Integrity Test Key (non-SSP) was preloaded to the module’s binary at the factory and used for firmware integrity test only at the pre-operational self-test. The module uses the RSA © 2021-2025 Cisco Systems, Inc.

Page 38
MechanismInspection FrequencyInspection Guidance
Tamper labels (9) with Part number: AIR-AP-FIPSKIT=Recommend 30 DaysVisible inspection of platform for residual evidence of tampering
Opacity shield (1) with Part number: FPR3K-FIPS-KIT=Recommend 30 DaysVisible inspection of platform for evidence of tampering, removal or access

2048 bits modulus public key to verify the digital signature. If the firmware integrity test fails, the

module would enter to an Error state with all crypto functionality inhibited.

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the tested platform to initiate the firmware integrity test on-demand.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited

7 Physical Security
7.1 Mechanisms and Actions Required

Table 14: Mechanisms and Actions Required The module utilizes a production-grade enclosure and removable cover along with tamper evidence labels as the physical security mechanisms. Step 1: Turn off and unplug the module. Step 2: Clean the chassis of any grease, dirt, oil or any other material other than the surface coating from manufacture before applying the tamper evident labels. Alcohol-based cleaning pads are recommended for this purpose. Step 3: Apply a label to cover the module as shown in the figures below. The tamper evident labels are produced from a special thin gauge vinyl with self-adhesive backing. Any attempt to open the module will damage the tamper evident labels or the material of the security appliance cover. Because the tamper evident labels have non-repeated serial numbers, they may be inspected for damage and compared against the applied serial numbers to verify that the security appliance has not been tampered with. Tamper evident labels can also be inspected for signs of tampering, which include the following: curled corners, rips, and slices. The word “FIPS” may appear if the label was peeled back. © 2021-2025 Cisco Systems, Inc.

Page 39
7.2 User Placed Tamper Seals

Number: Nine (9) Placement: Figure 2 Module’s front view opacity shield TEL 1 Figure 3 Module’s back view TEL 7 TEL 8 TEL 6 TEL 2 TEL 4 TEL 5 TEL 1 TEL 3 Figure 4 Module’s top view with opacity shield © 2021-2025 Cisco Systems, Inc.

Page 40

TEL 8 TEL 9 TEL 7 TEL 6 Figure 5 Module’s bottom view with opacity shield TEL 3 Figure 6 Module’s left view with opacity shield TEL 2 Figure 7 Module’s right view with opacity shield Surface Preparation: Clean the chassis of any grease, dirt, or oil before applying the tamper evident labels. Alcohol-based cleaning pads are recommended for this purpose. Operator Responsible for Securing Unused Seals: Must be stored in a secure location under controlled access

7.3 Filler Panels

3105, 3110, 3120, 3130, 3140 Opacity Shield FPR3K-FIPS-KIT= © 2021-2025 Cisco Systems, Inc.

Page 41

Step 1: Attach the Slide Rail Locking Bracket, #2 in diagram to the Side of the Chassis using the countersink screws #3 in diagram. Step 2: Attach the Cable Management Bracket (#1) to the Slide Rail Locking Bracket (#2) using the countersink screws (#3) Step 3: Route the Cables through the Cable Management Brackets Step 4: Attach the FIPS Opacity Shield (#1) to the Cable Management Brackets (#3) using the countersink screws (#2) © 2021-2025 Cisco Systems, Inc.

Page 42

Figure 8 Opacity Shield Brackets

8 Non-Invasive Security
9 Sensitive Security Parameters Management
9.1 Storage Areas
Page 43
Storage Area NameDescriptionPersistence Type
DRAMVolatile MemoryDynamic
FlashNon-Volatile MemoryStatic
NameFromToFormat TypeDistributio n TypeEntry TypeSFI or Algorith m
Password/Secre t Input via TLS encrypted by GCMExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (TLSv1.2 with AES- GCM)
Password/Secre t Input via TLS encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (TLSv1.2 with AES and HMAC)
Peer Public Key InputExternal (Outside of the Module's Boundary )ModulePlaintextAutomatedElectroni c
Module Public Key OutputModuleExternal (Outside of the Module's Boundary )PlaintextAutomatedElectroni c
Password/Secre t Input via SSHv2 encrypted by GCMExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (SSHv2 with AES- GCM)
Password/Secre t Input via SSHv2 encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (SSHv2 with AES and HMAC)
9.2 SSP Input-Output Methods
Page 44
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization CommandCO issues zeroization servicethe zeroization command will erase all SSPs stored in the DRAM or in the Flash of the module.'configure factory-default'
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
DRBG Entropy InputUsed to seed the DRBG384 bits - at least 256 bitsEntropy Input - CSPDRBG Function
DRBG SeedUsed in DRBG Generation256 bits - 256 bitsDRBG Seed - CSPDRBG Function
DRBG Internal State V valueUsed in DRBG Generation256 bits - 256 bitsDRBG Internal State V value - CSPDRBG Function
DRBG KeyUsed in DRBG Generation256 bits - 256 bitsDRBG Key - CSPDRBG Function
User PasswordUser authenticati on8-30 Characte rs - 8-30 Characte rsAuthenticati on Data - CSP
Crypto Officer PasswordCrypto Officer authenticati on8-30 Characte rs - 8-30 Characte rsAuthenticati on Data - CSP
RADIUS SecretRADIUS Server Authenticati on16 Characte rs - 16 Characte rsAuthenticati on Data - CSP

Table 16: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 17: SSP Zeroization Methods Please note that the Firmware Load Test Key is only used for Firmware Load Test Authentication and not subject to the zeroization requirement. © 2021-2025 Cisco Systems, Inc.

Page 45
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
TACACS+ SecretTACACS+ Authenticati on16 Characte rs - 16 Characte rsAuthenticati on Data - CSP
Firmware Load Test KeyUsed for Firmware Load Test112 bits - 112 bitsPublic Key - CSPFirmware Load Test
SSH DH Private KeyUsed to derive the SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPrivate Key - CSPKAS- FFC- KeyGen (SSHv2)KAS-FFC (SSHv2)
SSH DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- KeyGen (SSHv2)KAS-FFC (SSHv2)
SSH Peer DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC (SSHv2)
SSH DH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsShared Secret - CSPKAS-FFC (SSHv2)KAS-FFC (SSHv2)
SSH ECDH Private KeyUsed to derive the SSH ECDH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPrivate Key - CSPKAS- ECC- KeyGen (SSHv2)KAS-ECC (SSHv2)
SSH ECDH Public KeyUsed to derive SSH ECDHECurves: 256, 384, 521 bits -Public Key - PSPKAS-ECC- KeyGen (SSHv2)KAS-ECC (SSHv2)
Page 46
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
Shared Secret128-256 bits
SSH Peer ECDH Public KeyUsed to derive SSH DH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPublic Key - PSPKAS-ECC (SSHv2)
SSH ECDH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysCurves: 256, 384, 521 bits - 128 to 256 bitsShared Secret - CSPKAS-ECC (SSHv2)KAS-ECC (SSHv2)
SSH RSA Private KeyUsed for SSH session authenticati onModulus 2048 and 3072 bits - 112- 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigVer (SSHv2, TLSv1.2, and IKEv2)
SSH RSA Public KeyUsed for SSH sessions aiuthenticati onModulus 2048 and 3072 bits - 112- 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigVer (SSHv2, TLSv1.2, and IKEv2)
SSH ECDSA Private KeyUsed for SSH session authenticati onCurves: 256, 384, 521 bits - 128 to 256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2)
SSH ECDSA Public KeyUsed for SSH sessions aiuthenticati onCurves: 256, 384, 521 bits - 128 to 256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2)
SSH Session Encryption KeyUsed for SSH Session confidentialit y protection128-256 bits - 128-256 bitsSession Key - CSPSSHv2 Keying Materials Developme ntBlock Cipher (SSHv2)
SSH Session Authenticati on KeyUsed for SSH Session integrity protectionAt least 160 bits - At least 160 bitsSession Key - CSPSSHv2 Keying Materials Developme ntMAC (SSHv2)
TLS DH Private KeyUsed to Derive TLSModulus: 2048,Private Key - CSPKAS- FFC-KAS-FFC (TLSv1.2)
Page 47
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
DH Shared Secret3072, 4096 bits - 128- 152 bitsKeyGen (TLSv1.2 )
TLS DH Public KeyUsed to Derive TS DH Shared SecretModulus: 2048, 3072, or 4096 bits - 128- 152 bitsPublic Key - PSPKAS-FFC- KeyGen (TLSv1.2)KAS-FFC (TLSv1.2)
TLS Peer DH Public KeyUsed to derive IKE DH Shared SecretModulus: 2048, 3072, or 4096 bits - 128- 152 bitsPublic Key - PSPKAS-FFC (TLSv1.2)
TLS DH Shared SecretUsed to Derive TLS Session Encryption Key and TLS Session Authenticati on KeyModulus 2048, 3072, or 4096 - 128-152 bitsShared Secret - CSPKAS-FFC (TLSv1.2)KAS-FFC (TLSv1.2)
TLS ECDH Private KeyUsed to Derive TLS ECDH Shared SecretCurves P-256, P- 384, and P-521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (TLSv1.2 )KAS-ECC (TLSv1.2)
TLS ECDH Public KeyUsed to Derive TS ECDH Shared SecretCurves P-256, P- 384, and P-521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (TLSv1.2)KAS-ECC (TLSv1.2)
TLS Peer ECDH Public KeyUsed to derive IKE ECDH Shared SecretCurves: P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC (TLSv1.2)
TLS ECDH Shared SecretUsed to Derive TLS Session Encryption Key andCurves p-256, P- 384, P- 521 -Shared Secret - CSPKAS-ECC (TLSv1.2)KAS-ECC (TLSv1.2)
Page 48
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
TLS Session Authenticati on Key128-256 bits
TLS ECDSA Private KeyUsed to support CO and Admin HTTPS interfacesCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2)
TLS ECDSA Public KeyUsed to support CO and User HTTPS InterfacesCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2)
TLS RSA Private KeyUsed to support CO and Admin HTTPS InterfacesModulus 2048 and 3072 bits - 112- 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigVer (SSHv2, TLSv1.2, and IKEv2)
TLS RSA Public KeyUsed to support CO and User HTTPS interfacesModulus 2048 and 3072 bits - 112- 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigVer (SSHv2, TLSv1.2, and IKEv2)
TLS Master SecretUsed to protect HTTPS Session. Pre-master secretAt least 112 bits - At least 112 bitsMaster Secret - CSPTLS Keying Materials Developme ntTLS Keying Materials Developme nt
TLS Session Encryption KeyUsed to protect HTTPS Session. TLS Master secret128-256 bits - 128-256 bitsSession Key - CSPTLS Keying Materials Developme ntBlock Cipher (TLSv1.2)
TLS Session Authenticati on KeyUsed to protect HTTPS Session. TLS master secretat least 112 bits - at least 112 bitsSession Key - CSPTLS Keying Materials Developme ntMAC (TLSv1.2)
IPSec/IKE DH Private KeyUsed to derive IPSec/IKEMODP- 2048, MODP- 3072,Private Key - CSPKAS- FFC- KeyGen (IKEv2)KAS-FFC (IKEv2)
Page 49
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
DH Shared SecretMODP- 4096 - 112-152 bits
IPSec/IKE DH Public KeyUsed to derive IPSec/IKE DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- KeyGen (IKEv2)KAS-FFC (IKEv2)
IPSec/IKE Peer DH Public KeyUsed to derive IPSec/IKE DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC (IKEv2)
IPSec/IKE DH Shared SecretUsed to derive IPSec/IKE Session Encryption Keys, IPSec/IKE Authenticati on KeysMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsShared Secret - CSPKAS-FFC (IKEv2)KAS-FFC (IKEv2)
IPSec/IKE ECDH Private KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (IKEv2)KAS-ECC (IKEv2)
IPSec/IKE ECDH Public KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (IKEv2)KAS-ECC (IKEv2)
IPSec/IKE Peer ECDH Public KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC (IKEv2)
Page 50
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
IPSec/IKE ECDH Shared SecretUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsShared Secret - CSPKAS-ECC (IKEv2)KAS-ECC (IKEv2)
IPSec/IKE ECDSA Private KeyUsed for IPSec/IKE peer authenticati onCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2)
IPSec/IKE ECDSA Public KeyUsed for IPSec/IKE peer authenticati onCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2)
IPSec/IKE RSA Private KeyUsed for IPSec/IKE peer authenticati onModulus 2048 or 3072 - 112 or 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (SSHv2, TLSv1.2, IKEv2)
IPSec/IKE RSA Public KeyUsed for IPSec/IKE peer authenticati onModulus 2048 or 3072 - 112 or 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigVer (SSHv2, TLSv1.2, and IKEv2)
IPSec/IKE Pre-shared SecretUsed for IPSec/IKE peer authenticati on16-32 bytes character s - 16-32 bytes character sshared secret - CSPIKEv2 Keying Materials Developme nt
SKEYSEEDKeying material used to derive the IPSec/IKE Session Encryption Key and IPSec/IKE Authenticati on Key160 bits - 160 bitsKeying Material - CSPIKEv2 Keying Materials Developme ntIKEv2 Keying Materials Developme nt
IPSec/IKE SessionUsed to secure128-256 bits -Session Key - CSPIKEv2 KeyingBlock Cipher
Page 51
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablishe d ByUsed By
Encryption KeyIPSec/IKEv 2 session confidentialit y128-256 bitsMaterials Developme nt(IPSec/IKEv 2)
IPSec/IKE Authenticati on KeyUsed to secure IPSec/IKEv 2 session integrityat least 160 bits - at least 160 bitsSession Key - CSPIKEv2 Keying Materials Developme ntMAC (IPSec/IKEv 2)
SNMPv3 Shared SecretUsed for SNMPv3 user authenticati on8-32 character s - N/AAuthenticati on Secret - CSPIKEv2 Keying Materials Developme nt
SNMPv3 Encryption KeyUsed to protect SNMPv3 traffic confidentialit y128 bits - 128 bitsEncryption Key - CSPSNMPv3 Keying Materials Developme ntBlock Cipher (SNMPv3)
SNMPv3 Authenticati on KeyUsed to secure SNMPv3 traffic integrityAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPSNMPv3 Keying Materials Developme ntMAC (SNMPv3)
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG Entropy InputDRAM:Plainte xtUntil RebootZeroizatio n CommandDRBG Seed:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG SeedDRAM:Plainte xtUntil RebootZeroizatio n CommandDRBG Entropy Input:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG Internal State V valueDRAM:Plainte xtUntil RebootZeroizatio n CommandDRBG Entropy Input:Used With DRBG Seed:Used With

y y Table 18: SSP Table 1 © 2021-2025 Cisco Systems, Inc.

Page 52
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs DRBG Key:Used With
DRBG KeyDRAM:Plainte xtUntil RebootZeroizatio n CommandDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Internal State V value:Used With
User PasswordPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Encrypt edZeroizatio n Command
Crypto Officer PasswordPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted byFlash:Encrypt edZeroizatio n Command
Page 53
NameInput - Output AES and HMACStorageStorage DurationZeroizatio nRelated SSPs
RADIUS SecretPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Plaintex tZeroizatio n Command
TACACS+ SecretPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Plaintex tZeroizatio n Command
Firmware Load Test KeyFlash:Plaintex tN/A
SSH DH Private KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH DH Public Key:Paired With SSH Peer DH
Page 54
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs Public Key:Used With
SSH DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH DH Private Key:Paired With
SSH Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH DH Private Key:Used With
SSH DH Shared SecretDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH DH Private Key:Derived From SSH DH Public Key:Derived From
SSH ECDH Private KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH ECDH Public Key:Paired With SSH Peer ECDH Public Key:Used With
SSH ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH ECDH Private Key:Paired With
SSH Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH ECDH Private Key:Used With
SSH ECDH Shared SecretDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH ECDH Private Key:Derived From SSH ECDH Public Key:Derived From
SSH RSA Private KeyFlash:Plaintex tZeroizatio n CommandSSH RSA Public Key:Paired With SSH Peer RSA Public Key:Used With
SSH RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandSSH RSA Private Key:Paired With
SSH ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandSSH ECDSA Public Key:Paired With
SSH ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandSSH ECDSA Private Key:Paired With
SSH Session Encryption KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH Session Authentication Key:Used With
Page 55
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SSH Session Authenticati on KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n CommandSSH Session Encryption Key:Used With
TLS DH Private KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS DH Public Key:Paired With TLS Peer DH Public Key:Used With
TLS DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS DH Private Key:Paired With
TLS Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtwhile TLS tunnel is onZeroizatio n CommandTLS DH Private Key:Used With
TLS DH Shared SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS ECDH Private KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS ECDH Public Key:Paired With TLS Peer ECDH Public Key:Used With
TLS ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS ECDH Private Key:Paired With
TLS Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtwhile TLS tunnel is onZeroizatio n CommandTLS ECDH Private Key:Used With
TLS ECDH Shared SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandTLS ECDSA Public Key:Paired With
TLS ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandTLS ECDSA Private Key:Paired With
TLS RSA Private KeyFlash:Plaintex tZeroizatio n CommandTLS RSA Public Key:Paired With
Page 56
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
TLS RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandTLS RSA Private Key:Paired With
TLS Master SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS ECDH Shared Secret:Derived From
TLS Session Encryption KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS Session Authentication Key:Used With
TLS Session Authenticati on KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n CommandTLS Session Encryption Key:Used With
IPSec/IKE DH Private KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE DH Public Key:Paired With IPSec/IKE Peer DH Public Key:Used With
IPSec/IKE DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE DH Private Key:Paired With
IPSec/IKE Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtwhile IPSec/IKE tunnel is onZeroizatio n CommandIPSec/IKE DH Private Key:Used With
IPSec/IKE DH Shared SecretDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandSKEYSEED:Used With
IPSec/IKE ECDH Private KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE ECDH Public Key:Paired With IPSec/IKE Peer ECDH Public Key:Used With
IPSec/IKE ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE ECDH Private Key:Paired With
IPSec/IKE Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE ECDH Private Key:Used With
Page 57
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPSec/IKE ECDH Shared SecretDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandSKEYSEED:Used With
IPSec/IKE ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandIPSec/IKE ECDSA Public Key:Paired With
IPSec/IKE ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandIPSec/IKE ECDSA Private Key:Paired With
IPSec/IKE RSA Private KeyFlash:Plaintex tZeroizatio n CommandIPSec/IKE RSA Public Key:Paired With
IPSec/IKE RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandIPSec/IKE RSA Private Key:Paired With
IPSec/IKE Pre-shared SecretDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandSKEYSEED:Deriv ed to
SKEYSEEDDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From IPSec/IKE Pre- shared Secret:Derived From
IPSec/IKE Session Encryption KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
IPSec/IKE Authenticati on KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
Page 58
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SNMPv3 Shared SecretPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACDRAM:Plainte xtWhile SNMPv3 tunnel is onZeroizatio n CommandSNMPv3 Encryption Key:Derive To SNMPv3 Authentication Key:Derive To
SNMPv3 Encryption KeyDRAM:Plainte xtWhile SNMPv3 tunnel is onZeroizatio n CommandSNMPv3 Shared Secret:Derived From
SNMPv3 Authenticati on KeyDRAM:Plainte xtWhile SNMPv3 tunnel is onZeroizatio n CommandSNMPv3 Shared Secret:Derived From SNMPv3 Encryption Key:Used With
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
RSA SigVer (FIPS186-4) (A4446)RSA SigVer 2048 bits with SHA2-512KATSW/FW IntegrityModule is in normal stateRSA SigVer
Pre-Operational Bypass TestN/AN/ABypassModule is in normal stateN/A
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests © 2021-2025 Cisco Systems, Inc.

Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A4446)256 bitsKATCASTModule is in normal stateEncryptPower Up
AES-CBC (A4446)256 bitsKATCASTModule is in normal stateDecryptPower Up
AES-GCM (A4446)256 bitsKATCASTModule is in normal stateAuthenticated EncryptPower Up
AES-GCM (A4446)256 bitsKATCASTModule is in normal stateAuthenticated DecryptPower Up
Counter DRBG (A4446)AES-128KATCASTModule is in normal stateInstantiate KATPower Up
Counter DRBG (A4446)AES-128KATCASTModule is in normal stateGenerate KATPower Up
Counter DRBG (A4446)AES-128KATCASTModule is in normal stateReseed KATPower Up
ECDSA SigGen (FIPS186-4) (A4446)P-256 curve with SHA2- 256KATCASTModule is in normal stateECDSA SigGen KATPower Up
ECDSA SigVer (FIPS186-4) (A4446)P-256 curve with SHA2- 256KATCASTModule is in normal stateECDSA SigVer KATPower Up
HMAC- SHA-1 (A4446)SHA-1KATCASTModule is in normal stateHMAC-SHA-1Power Up

The module performs the following self-tests, including the pre-operational self-tests and Conditional self-tests. Prior to the module providing any data output via the data output interface, the module performs and passes the pre-operational self-tests. Following the successful pre-operational self-tests, the module executes the Conditional Cryptographic Algorithm Self-tests (CASTs). If anyone of the self-tests fails, the module transitions into an error state and outputs the error message via the module’s status output interface. While the module is in the error state, all data through the data output interface and all cryptographic operations are disabled. The error state can only be cleared by reloading the module. All self-tests must be completed successfully before the module transitions to the operational state.

10.2 Conditional Self-Tests
Page 60
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-256 (A4446)SHA2-256KATCASTModule is in normal stateHMAC-SHA2- 256Power Up
HMAC- SHA2-384 (A4446)SHA2-384KATCASTModule is in normal stateHMAC-SHA2- 384Power Up
HMAC- SHA2-512 (A4446)SHA2-512KATCASTModule is in normal stateHMAC-SHA2- 512Power Up
KAS-ECC- SSC Sp800- 56Ar3 (A4446)P-256 CurveKATCASTModule is in normal statePrimitive Z KATPower Up
KAS-FFC- SSC Sp800- 56Ar3 (A4446)MODP- 2048KATCASTModule is in normal statePrimitive Z KATPower Up
RSA SigGen (FIPS186-4) (A4446)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigGen KATPower Up
RSA SigVer (FIPS186-4) (A4446)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigVer KATPower Up
KDF IKEv2 (A4446)N/AKATCASTModule is in normal stateN/APower Up
KDF SNMP (A4446)N/AKATCASTModule is in normal stateN/APower Up
KDF SSH (A4446)N/AKATCASTModule is in normal stateN/APower Up
TLS v1.2 KDF RFC7627 (A4446)N/AKATCASTModule is in normal stateN/APower Up
SHA-1 (A4446)Message Length: 0- 65536 Increment 8KATCASTModule is in normal stateN/APower Up
AES-CBC (C1026)128 bitsKATCASTModule is in normal stateEncrypt KATPower Up
Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (C1026)128 bitsKATCASTModule is in normal stateDecrypt KATPower Up
AES-GCM (C1026)128 bitsKATCASTModule is in normal stateEncrypt KATPower Up
AES-GCM (C1026)128 bitsKATCASTModule is in normal stateDecrypt KATPower Up
Hash DRBG (C1026)SHA2-512KATCASTModule is in normal stateInstantiate KATPower Up
Hash DRBG (C1026)SHA2-512KATCASTModule is in normal stateGenerate KATPower Up
Hash DRBG (C1026)SHA2-512KATCASTModule is in normal stateReseed KATPower Up
HMAC- SHA-1 (C1026)SHA-1KATCASTModule is in normal stateHMAC-SHA-1Power Up
HMAC- SHA2-256 (C1026)SHA2-256KATCASTModule is in normal stateHMAC-SHA2- 256Power Up
HMAC- SHA2-384 (C1026)SHA2-384KATCASTModule is in normal stateHMAC-SHA2- 384Power Up
HMAC- SHA2-512 (C1026)SHA2-512KATCASTModule is in normal stateHMAC-SHA2- 512Power Up
SHA-1 (C1026)Message Length: 0- 51200 Increment 8KATCASTModule is in normal stateSHA-1Power Up
ECDSA KeyGen (FIPS186-4) (A4446)Curve P- 256 with SHA2-256PCTPCTModule is in normal stateECDSAPerforms all required pair- wise consistency tests on the newly generated key pairs before the first operational use.
RSA KeyGen2048 bit ModulusPCTPCTModule is in normal stateRSAPerforms all required pair- wise
Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
(FIPS186-4) (A4446)consistency tests on the newly generated key pairs before the first operational use.
KAS-ECC- SSC Sp800- 56Ar3 (A4446)Curve P- 256 with SHA2-256PCTPCTModule is in normal stateN/APerforms all required pair- wise consistency tests on the newly generated key pairs before the first operational use.
KAS-FFC- SSC Sp800- 56Ar3 (A4446)MODP- 2048PCTPCTModule is in normal stateN/APerforms all required pair- wise consistency tests on the newly generated key pairs before the first operational use.
HMAC- SHA2-512 (A4446)HMAC- SHA2-512KATSW/FW LoadModule is in normal stateN/AWhen firmware has been uploaded to the module
Conditional BypassN/AN/ABypassModule is in normal stateN/APerforms conditional bypass test before first operational use of bypass service

Table 21: Conditional Self-Tests The module performs on-demand self-tests initiated by the operator, by powering off and powering the module back on. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests. © 2021-2025 Cisco Systems, Inc.

Page 63
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-4) (A4446)KATSW/FW IntegrityRecommend 60 DaysReboot
Pre-Operational Bypass TestN/ABypassRecommend 60 DaysReboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A4446)KATCASTRecommend 60 DaysReboot
AES-CBC (A4446)KATCASTRecommend 60 DaysReboot
AES-GCM (A4446)KATCASTRecommend 60 DaysReboot
AES-GCM (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG (A4446)KATCASTRecommend 60 DaysReboot
ECDSA SigGen (FIPS186-4) (A4446)KATCASTRecommend 60 DaysReboot
ECDSA SigVer (FIPS186-4) (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA-1 (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 256 (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 384 (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 512 (A4446)KATCASTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800-56Ar3 (A4446)KATCASTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800-56Ar3 (A4446)KATCASTRecommend 60 DaysReboot
10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2021-2025 Cisco Systems, Inc.

Page 64
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigGen (FIPS186-4) (A4446)KATCASTRecommend 60 DaysReboot
RSA SigVer (FIPS186-4) (A4446)KATCASTRecommend 60 DaysReboot
KDF IKEv2 (A4446)KATCASTRecommend 60 DaysReboot
KDF SNMP (A4446)KATCASTRecommend 60 DaysReboot
KDF SSH (A4446)KATCASTRecommend 60 DaysReboot
TLS v1.2 KDF RFC7627 (A4446)KATCASTRecommend 60 DaysReboot
SHA-1 (A4446)KATCASTRecommend 60 DaysReboot
AES-CBC (C1026)KATCASTRecommend 60 DaysReboot
AES-CBC (C1026)KATCASTRecommend 60 DaysReboot
AES-GCM (C1026)KATCASTRecommend 60 DaysReboot
AES-GCM (C1026)KATCASTRecommend 60 DaysReboot
Hash DRBG (C1026)KATCASTRecommend 60 DaysReboot
Hash DRBG (C1026)KATCASTRecommend 60 DaysReboot
Hash DRBG (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA-1 (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 256 (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 384 (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 512 (C1026)KATCASTRecommend 60 DaysReboot
SHA-1 (C1026)KATCASTRecommend 60 DaysReboot
ECDSA KeyGen (FIPS186-4) (A4446)PCTPCTRecommend 60 DaysReboot
RSA KeyGen (FIPS186-4) (A4446)PCTPCTRecommend 60 DaysReboot
Page 65
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A4446)PCTPCTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800-56Ar3 (A4446)PCTPCTRecommend 60 DaysReboot
HMAC-SHA2- 512 (A4446)KATSW/FW LoadN/AN/A
Conditional BypassN/ABypassN/AN/A
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error stateSelf-test failureReboot the moduleSystem Halt

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States If any of the above-mentioned self-tests fail, the module reports the error and enters the Error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and perform the selftests, including the pre-operational firmware integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the pre-operational firmware integrity test and the conditional CASTs.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The validated module firmware was installed onto the respective test platforms listed in Table 2 above. The Crypto Officer must configure and enforce the following initialization steps: Step 1: The Crypto Officer must install opacity shields as described in section 7 above. Step 2: The Crypto Officer must apply tamper evidence labels as described in section 7 above. Step 3: The Crypto Officer must securely store any unused tamper evidence labels. Note: Each module has a Type A USB 2.0 port, but it is considered to be disabled once the Crypto Officer has applied the TEL #9. Step 4: Crypto Officer performs the following configurations: © 2021-2025 Cisco Systems, Inc.

Page 66

ciscoasa# configure terminal Note, the Crypto Officer needs to connect the platform to cisco.com to obtain the license for ASA from Cisco. ciscoasa(config)# license smart register idtoken [token data] ciscoasa(config)#license smart ciscoasa(config-smart-lic)# show license all Smart Licensing Status ====================== Smart Licensing is ENABLED -ORciscoasa(config-smart-lic)# show license summary Smart Licensing is ENABLED Registration: Step 5: Enable “Approved Mode” to allow the module to startup the cryptographic module, such as run power-on self-tests and bypass test by using the following command: ciscoasa(config)# fips enable Note: Startup operational mode will not take effect until you save configuration and reboot the device Rebooting the device will force new self-test Step 6: Crypto Officer can verify the version installed and running ciscoasa(config)# show version Step 7: Crypto Officer will need to configure ASA ciscoasa> en ciscoasa# conf t ciscoasa(config)# Step 8: Assign users a Privilege Level of 1. Step 9: Configure IP address for unit and all distant endpoints. Step 10: Define RADIUS and TACACS+ shared secret keys that are at least 8 characters long and secure traffic between the security module and the RADIUS/TACACS+ server via secure (IPSec, TLS) tunnel. Note: Perform this step only if RADIUS/TACAS+ is configured, otherwise skip over and proceed to next step. Step 11: Configure the security module so that any remote connections via Telnet are secured through IPSec. Step 12: Configure the security module so that only approved algorithms are used for IPsec tunnels. Step 13: Configure the security module so that error messages can only be viewed by Crypto Officer. © 2021-2025 Cisco Systems, Inc.

Page 67

Step 14: Disable the TFTP server. Step 15: Disable HTTP for performing system management in approved mode of operation. HTTPS with TLS should always be used for Web-based management. Step 16: Ensure that installed digital certificates are signed using approved algorithms.

11.2 Administrator Guidance

No specific Administrator guidance.

11.3 Non-Administrator Guidance

No specific Non-Administrator guidance.

12 Mitigation of Other Attacks

N/A for this module. © 2021-2025 Cisco Systems, Inc.