activityccdp

ccdp  时间:2021-02-27  阅读:()
CorporateHeadquarters:Copyright2001.
CiscoSystems,Inc.
Allrightsreserved.
CiscoSystems,Inc.
,170WestTasmanDrive,SanJose,CA95134-1706USACisco7206VXRRouterSecurityPolicyIntroductionThisnonproprietaryCryptographicModuleSecurityPolicydescribeshowthe7206VXRNPE-400routersmeetthesecurityrequirementsofFederalInformationProcessingStandards(FIPS)140-1,andhowtheyoperateinasecureFIPS140-1mode.
ThepolicywaspreparedaspartoftheLevel2FIPS140-1certificationofthe7206VXRNPE-400router.
NoteThisdocumentmaybecopiedinitsentiretyandwithoutmodification.
Allcopiesmustincludethecopyrightnoticeandstatementsonthelastpage.
TheFIPS140-1publication,"SecurityRequirementsforCryptographicModules"detailstheU.
S.
Governmentrequirementsforcryptographicmodules.
MoreinformationabouttheFIPS140-1standardandvalidationprogramisavailableatthefollowingNationalInstituteofStandardsandTechnology(NIST)website:http://csrc.
nist.
gov/cryptval/Thisdocumentcontainsthefollowingsections:Introduction,page1The7206VXRNPE-400Router,page2SecureOperationoftheCisco7206VXRNPE-400Router,page10ObtainingDocumentation,page12ObtainingTechnicalAssistance,page132Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterReferencesThisdocumentdealswithoperationsandcapabilitiesofthe7206VXRNPE-400routerinthetechnicaltermsofaFIPS140-1cryptographicmodulesecuritypolicy.
FormoreinformationonCisco7206VXRNPE-400routerandtheentire7200series,checkthefollowingsources:TheCiscoSystemswebsitecontainsinformationonthefulllineofCiscoSystemsproducts.
Refertothefollowingwebsite:www.
cisco.
com.
The7200seriesproductdescriptionscanbefoundatthefollowingwebsite:www.
cisco.
com/warp/public/cc/pd/rt/7200/Foranswerstotechnicalorsalesrelatedquestions,pleaserefertothecontactslistedonthefollowingwebsite:www.
cisco.
com.
TerminologyInthisdocument,thecryptographicmoduleisreferredtoasthe7206VXRrouter,therouter,orthesystem.
DocumentOrganizationThesecuritypolicydocumentispartofthecompleteFIPS140-1SubmissionPackage.
Inadditiontothisdocument,thecompletesubmissionpackagecontains:VendorevidencedocumentFinitestatemachineModulesoftwarelistingOthersupportingdocumentationasadditionalreferencesThisdocumentprovidesanoverviewofthe7206VXRNPE-400routerandexplainsthesecureconfigurationandoperationofthecryptographicmodule.
Italsoexplainsthegeneralfeaturesandfunctionalityofthe7206VXRNPE-400routersandaddressestherequiredconfigurationfortheFIPSmodeofoperation.
NoteThissecuritypolicyandothercertificationsubmissiondocumentationwasproducedbyCorsecSecurity,Inc.
undercontracttoCiscoSystems.
Withtheexceptionofthisnonproprietarysecuritypolicy,theFIPS140-1CertificationSubmissiondocumentationisCisco-proprietaryandcanbereleasedonlyunderappropriatenondisclosureagreements.
Foraccesstothesedocuments,pleasecontactCiscoSystems.
The7206VXRNPE-400RouterCisco7200VXRroutersaredesignedtosupportgigabitcapabilitiesandtoimprovedata,voice,andvideointegrationinbothserviceproviderandenterpriseenvironments.
Cisco7200VXRrouterssupportahigh-speednetworkservicesengine(NSE)aswellasthehigh-speednetworkprocessingengine,NPE-400,andallotheravailablenetworkprocessingengines.
3Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterCisco7200VXRroutersaccommodateavarietyofnetworkinterfaceportadaptersandanI/Ocontroller.
ACisco7200VXRrouterequippedwithanNPE-400cansupportuptosixhigh-speedportadaptersandcanalsosupporthigher-speedportadapterinterfacesincludingGigabitEthernetandOC-12ATM.
Cisco7200VXRroutersalsocontainbaysforuptotwoAC-inputorDC-inputpowersupplies.
Cisco7200VXRrouterssupportthefollowingfeatures:Onlineinsertionandremoval(OIR)—Add,replace,orremoveportadapterswithoutinterruptingthesystem.
Dualhot-swappable,load-sharingpowersupplies—Providesystempowerredundancy;ifonepowersupplyorpowersourcefails,theotherpowersupplymaintainssystempowerwithoutinterruption.
Also,whenonepowersupplyispoweredoffandremovedfromtherouter,thesecondpowersupplyimmediatelytakesovertherouterpowerrequirementswithoutinterruptingnormaloperationoftherouter.
Environmentalmonitoringandreportingfunctions—Maintainnormalsystemoperationbyresolvingadverseenvironmentalconditionspriortolossofoperation.
Downloadablesoftware—LoadnewimagesintoFlashmemoryremotely,withouthavingtophysicallyaccesstherouter.
The7206VXRNPE-400CryptographicModuleCisco7206VXRrouterssupportmultiprotocolroutingandbridgingwithawidevarietyofprotocolsandportadaptercombinationsavailableforCisco7200seriesrouters.
Themetalcasingthatfullyenclosesthemoduleestablishesthecryptographicboundaryfortherouter.
Allthefunctionalitydiscussedinthisdocumentisprovidedbycomponentswithinthecasing.
Cisco7206VXRroutershavesixslotsforportadapters,oneslotforaninput/output(I/O)controller,andoneslotforanetworkprocessingengineornetworkservicesengine.
Figure1The7206VXRNPE-400RouterCisco7206VXRNPE-400usesanRM7000microprocessorthatoperatesataninternalclockspeedof350MHz.
TheNPE-400usesSDRAMforstoringallpacketsreceivedorsentfromnetworkinterfaces.
TheSDRAMmemoryarrayinthesystemallowsconcurrentaccessbyportadaptersandtheprocessor.
H5997ETHERNET10BTENABLED0213LINK0123FASTSERIALENTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDENABLEDMIILINKRJ45FASTETHERNET0TOKENRING0123MIIENRJ45ENRJ45LINK1OPWROKRJ-45CPURESETFASTETHERNETINPUT/OUTPUTCONTROLLERENABLEDPCMCIAEJECTSLOT0SLOT1FEMIIAuxiliaryportConsoleportPortadapterleverI/Ocontroller0241356ETHERNET-10BFLENRX01234TXRXTXRXTXRXTXRXTXPortadaptersCisco7200SeriesPCcardslotsOptionalFastEthernetport(MIIreceptacleandRJ-45receptacle)4Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterTheNPE-400hasthreelevelsofcache:aprimaryandasecondarycachethatareinternaltothemicroprocessor,andatertiary4-MBexternalcachethatprovidesadditionalhigh-speedstoragefordataandinstructions.
Cisco7206VXRrouterscomeequippedwithone280WAC-inputpowersupply.
(A280WDC-inputpowersupplyoptionisavailable.
)Apowersupplyfillerplateisinstalledoverthesecondpowersupplybay.
AfullyconfiguredCisco7206VXRrouteroperateswithonlyoneinstalledpowersupply;however,asecond,optionalpowersupplyofthesametypeprovideshot-swappable,load-sharing,redundantpower.
ModuleInterfacesInput/OutputControllerTheinterfacesfortherouterarelocatedonthefrontpanelInput/Output(I/O)Controller,withtheexceptionofthepowerswitchandpowerplug.
ThemodulehastwoFastEthernet(10/100RJ-45)connectorsfordatatransfersinandout.
ThemodulealsohastwootherRJ-45connectorsforaconsoleterminalforlocalsystemaccessandanauxiliaryportforremotesystemaccessordialbackupusingamodem.
Figure2showsthefrontpanelLEDs,whichprovideoverallstatusoftherouteroperation.
Thefrontpaneldisplayswhetherornottherouterisbooted,iftheredundantpowerisattachedandoperational,andoverallactivity/linkstatus.
Figure2I/OControllerTable1providesdetailedinformationconveyedbytheLEDsonthefrontpaneloftheI/OController.
DUALFASTETHERNETINPUT/OUTPUTCONTROLLERCONSOLEAUX100MbpsLINK100MbpsLINKSLOT0EJECTPCMCIASLOT1ENABLEDCPURESETIOPWROK33444CPURESETIOPWROK100MbpsLINKSLOT0SLOT1C7200-I/O-2FE/EENABLEDFE/E0FE/E15Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400Router.
AllofthesephysicalinterfacesareseparatedintothelogicalinterfacesfromFIPSasdescribedinTable2.
Table1FrontPanelLEDsandDescriptionsLEDIndicationDescriptionEnabledGreenIndicatesthatthenetworkprocessingengineornetworkservicesengineandtheI/Ocontrollerareenabledforoperationbythesystem;however,itdoesnotmeanthattheFastEthernetportontheI/Ocontrollerisfunctionalorenabled.
ThisLEDgoesonduringasuccessfulrouterbootandremainsonduringnormaloperationoftherouter.
IOPOWEROKAmberIndicatesthattheI/OcontrollerisonandreceivingDCpowerfromtheroutermidplane.
ThisLEDcomesonduringasuccessfulrouterbootandremainsonduringnormaloperationoftherouter.
OffPoweredofforfailed.
Slot0Slot1GreenTheseLEDsindicatewhichPCCardslotisinusebycomingonwheneitherslotisbeingaccessedbythesystem.
TheseLEDsremainoffduringnormaloperationoftherouter.
LinkGreenIndicatesthattheEthernetRJ-45receptaclehasestablishedavalidlinkwiththenetwork.
OffThisLEDremainsoffduringnormaloperationoftherouterunlessthereisanincomingcarriersignal100MbpsGreenIndicatesthattheportisconfiguredfor100-Mbpsoperation(speed100),orifconfiguredforautonegotiation(speedauto),theporthasdetectedavalidlinkat100Mbps.
OffIftheportisconfiguredfor10-Mbpsoperation,orifitisconfiguredforautonegotiationandtheporthasdetectedavalidlinkat10Mbps,theLEDremainsoff.
Table2FIPS140-1LogicalInterfacesRouterPhysicalInterfaceFIPS140-1LogicalInterface10/100BASE-TXLANPortPortAdapterInterfaceServiceModuleInterfaceConsolePortAuxiliaryPort*PCMCIASlot*DataInputInterface10/100BASE-TXLANPortPortAdapterInterfaceServiceModuleInterfaceConsolePortAuxiliaryPort*PCMCIASlot*DataOutputInterface6Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400Router*DisabledinFIPSmode.
Seethe"SecureOperationoftheCisco7206VXRNPE-400Router"sectioninthisdocumentformoreinformation.
Inadditiontothebuilt-ininterfaces,therouteralsohasadditionalportadaptersthatcanoptionallybeplacedinanavailableslot.
Theseportadaptershavemanyembodiments,includingmultipleEthernet,tokenring,andmodemcardstohandleframerelay,ATM,andISDNconnections.
RolesandServicesTherearetwomainrolesintherouter(asrequiredbyFIPS140-1)thatoperatorscanassume:cryptoofficeroradministratorroleanduserrole.
Theadministratoroftherouterassumesthecryptoofficerroleinordertoconfigureandmaintaintherouterusingcryptoofficerservices,whiletheusersexerciseonlythebasicuserservices.
CryptographicOfficerServicesDuringinitialconfigurationoftherouter,acryptographicofficer(cryptoofficer)password(the"enable"password)isdefinedandallmanagementservicesareavailablefromthisrole.
Thecryptoofficerconnectstotherouterthroughtheconsoleportthroughtheterminalprogram.
Acryptoofficercanassignpermissiontoaccessthecryptoofficerroletoadditionalaccounts,therebycreatingadditionalcryptoofficers.
Atthehighestlevel,cryptoofficerservicesincludethefollowing:Configuretherouter:definenetworkinterfacesandsettings,createcommandaliases,settheprotocolstherouterwillsupport,enableinterfacesandnetworkservices,setsystemdateandtime,andloadauthenticationinformation.
Definerulesandfilters:createpacketfiltersthatareappliedtouserdatastreamsoneachinterface.
EachfilterconsistsofasetofRules,whichdefineasetofpacketstopermitordenybasedoncharacteristicssuchasprotocolID,addresses,ports,TCPconnectionestablishment,orpacketdirection.
PowerSwitchConsolePortAuxiliaryPort*ControlInputInterface10/100BASE-TXLANPortLEDsPwrLEDSysRdyLEDConsolePortAuxiliaryPort*StatusOutputInterfacePowerPlugPowerInterfaceTable2FIPS140-1LogicalInterfaces(continued)RouterPhysicalInterfaceFIPS140-1LogicalInterface7Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterStatusfunctions:viewtherouterconfiguration,routingtables,andactivesessions;viewSNMPMIBIIstatistics,health,temperature,memorystatus,voltage,andpacketstatistics;reviewaccountinglogs,andviewphysicalinterfacestatus.
Managetherouter:logoffusers,shutdownorreloadtherouter,manuallybackuprouterconfigurations,viewcompleteconfigurations,manageruserrights,andrestorerouterconfigurations.
Setencryption/bypass:setuptheconfigurationtablesforIPtunneling.
SetkeysandalgorithmstobeusedforeachIPrangeorallowplaintextpacketstobesetfromspecifiedIPaddresses.
Changeportadapters:insertandremoveadaptersinportadapterslotsasdescribedinthe"InitialSetup"sectioninthisdocument.
UserServicesAuserentersthesystembyaccessingtheconsoleportwithaterminalprogram.
TheIOSpromptstheuserfortheirpassword.
IfitmatchestheplaintextpasswordstoredinIOSmemory,theuserisallowedentrytotheIOSexecutiveprogram.
Atthehighestlevel,userservicesincludethefollowing:StatusFunctions:viewstateofinterfaces,stateoflayer2protocols,versionofIOScurrentlyrunningNetworkFunctions:connecttoothernetworkdevicesthroughoutgoingtelnetorPPP,andinitiatediagnosticnetworkservices(forexample,pingandmtrace)TerminalFunctions:adjusttheterminalsession(thatis,locktheterminalandadjustflowcontrol)DirectoryServices:displaydirectoryoffileskeptinflashmemoryPhysicalSecurityTherouterisentirelyencasedbyathicksteelchassis.
Thefrontoftherouterprovides4portadapterslots,on-boardLANconnectors,PCCardslots,andConsole/Auxiliaryconnectors.
Thepowercableconnection,apowerswitch,andtheaccesstotheNetworkProcessingEngineareattherearoftherouter.
OncetherouterhasbeenconfiguredtomeetFIPS140-1Level2requirements,theroutercannotbeaccessedwithoutsignsoftampering.
Tosealthesystem,applyserializedtamper-evidencelabelsasfollows:Cleanthecoverofanygrease,dirt,oroilbeforeapplyingthetamperevidencelabels.
Alcohol-basedcleaningpadsarerecommendedforthispurpose.
Theambientairmustbeabove10C,otherwisethelabelsmaynotproperlycure.
Thetamperevidencelabelshouldbeplacedsothattheonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthe7206VXRNPE-400Input/OutputController.
ThetamperevidencelabelshouldbeplacedovertheFlashPCCardslotsontheInput/OutputController.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot1.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot2.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot3.
8Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterThetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot4.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot5.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot6.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthenetworkprocessingengine.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthepowersupplyplate.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheredundantpowersupplyplate.
Thelabelscompletelycurewithinfiveminutes.
Figure3showsthetamperevidencelabelplacements.
9Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterFigure3TamperEvidenceLabelPlacementThetamperevidencesealsareproducedfromaspecialthingaugevinylwithself-adhesivebacking.
Anyattempttoremoveportadaptersorservicemoduleswilldamagethetamperevidencesealsorthepaintedsurfaceandmetalofthemodulecover.
Sincethetamperevidencelabelshavenonrepeatedserialnumbers,thelabelscanbeinspectedfordamageandcomparedagainsttheappliedserialnumberstoverifythatthemodulehasnotbeentamperedwith.
Tamperevidencelabelscanalsobeinspectedforsignsoftampering,whichincludethefollowing:curledcorners,bubbling,crinkling,rips,tears,andslices.
Theword"Opened"canappearifthelabelwaspeeledback.
NoteTheCisco7206routersupportsthefollowingFIPS-approvedalgorithms:DES,3DES,andSHA-1.
Thesealgorithmsreceivedcertificationnumbers74,17,and26respectively.
61228ETHERNET10BTENABLED0213LINK0123FASTSERIALENTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDENABLEDMIILINKRJ45FASTETHERNET0TOKENRING0123MIIENRJ45ENRJ45LINK1OPWROKRJ-45CPURESETFASTETHERNETINPUT/OUTPUTCONTROLLERENABLEDPCMCIAEJECTSLOT0SLOT1FEMIIAuxiliaryportConsoleportPortadapterleverI/Ocontroller0241356ETHERNET-10BFLENRX01234TXRXTXRXTXRXTXRXTXPortadaptersBlankportadapterPCCardslotsOptionalFastEthernetport(MIIreceptacleandRJ-45receptacle)Cisco7200SeriesVXR61229NETWORKPROCESSINGENGINE-150InternalfansNetworkprocessingengineornetworkservicesengineAC-inputpowersupplyAC-inputreceptaclePowersupplyfillerplateChassisgroundingreceptaclesPowerswitch10Cisco7206VXRRouterSecurityPolicySecureOperationoftheCisco7206VXRNPE-400RouterCryptographicKeyManagementTheroutersecurelyadministersbothcryptographickeysandothercriticalsecurityparameterssuchaspasswords.
Thetamperevidencesealsprovidephysicalprotectionforallkeys.
Keysarealsopasswordprotectedandcanbezeroizedbythecryptoofficer.
KeysareexchangedmanuallyandenteredelectronicallyviamanualkeyexchangeorInternetKeyExchange(IKE).
Self-TestsInordertopreventanysecuredatafrombeingreleased,itisimportanttotestthecryptographiccomponentsofasecuritymoduletoinsureallcomponentsarefunctioningcorrectly.
Therouterincludesanarrayofself-teststhatarerunduringstartupandperiodicallyduringoperations.
Theself-testrunatpower-upincludesacryptographicknownanswertests(KAT)ontheFIPS-approvedcryptographicalgorithms(DES,3DES),onthemessagedigest(SHA-1),andontheDiffie-Hellmanalgorithm.
AlsoperformedatstartupareasoftwareintegritytestusinganEDC,andasetofStatisticalRandomNumberGenerator(RNG)tests.
Thefollowingtestsarealsorunperiodicallyorconditionally:abypassmodetestperformedconditionallypriortoexecutingIPSec,asoftwareloadtestforupgrades,andthecontinuousrandomnumbergeneratortest.
Ifanyoftheseself-testsfail,theroutertransitionsintoanerrorstate.
Withintheerrorstate,allsecuredatatransmissionishaltedandtherouteroutputsstatusinformationindicatingthefailure.
SecureOperationoftheCisco7206VXRNPE-400RouterCisco7206VXRNPE-400routermeetsalltheLevel2requirementsforFIPS140-1.
FollowthesettinginstructionsprovidedbelowtoplacethemoduleinFIPSmode.
OperatingthisrouterwithoutmaintainingthefollowingsettingswillremovethemodulefromtheFIPSapprovedmodeofoperation.
InitialSetupThecryptoofficermustapplytamperevidencelabelsasdescribedinthe"PhysicalSecurity"sectionofthisdocument.
Thecryptoofficermustsecurelystoretamperevidencelabelsbeforeuse,andanytamperevidencelabelsnotusedshouldalsobestoredsecurely.
Onlyacryptoofficercanaddandremoveportadapters.
Whenremovingthetamperevidencelabel,thecryptoofficershouldremovetheentirelabelfromtherouterandcleanthecoverofanygrease,dirt,oroilwithanalcohol-basedcleaningpad.
Thecryptoofficermustreapplytamperevidencelabelsontherouterasdescribedinthe"PhysicalSecurity"sectioninthisdocument.
SystemInitializationandConfigurationThecryptoofficermustperformtheinitialconfiguration.
TheIOSversionshippedwiththerouter,version12.
1(9)E,istheonlyallowableimage.
Nootherimagecanbeloaded.
Thevalueofthebootfieldmustbe0x0101(thefactorydefault).
ThissettingdisablesthebreakfromtheconsoletotheROMmonitorandautomaticallybootstheIOSimage.
Fromtheconfigureterminalcommandline,thecryptoofficerentersthefollowingsyntax:config-register0x010111Cisco7206VXRRouterSecurityPolicySecureOperationoftheCisco7206VXRNPE-400RouterThecryptoofficermustcreatethe"enable"passwordforthecryptoofficerrole.
Thepasswordmustbeatleast8charactersandisenteredwhenthecryptoofficerfirstengagestheenablecommand.
Thecryptoofficerentersthefollowingsyntaxatthe"#"prompt:enablesecret[PASSWORD]Thecryptoofficermustalwaysassignpasswords(ofatleast8characters)tousers.
IdentificationandauthenticationoftheconsoleportisrequiredforUsers.
Fromtheconfigureterminalcommandline,thecryptoofficerentersthefollowingsyntax:linecon0password[PASSWORD]loginlocalThecryptoofficershallonlyassignuserstoaprivilegelevel1(thedefault).
Thecryptoofficershallnotassignacommandtoanyprivilegelevelotherthanitsdefault.
ThePCMCIAFlashmemorycardslotisnotconfiguredinFIPSmode.
Itsuseisrestrictedviatamperevidencelabels.
Seethe"PhysicalSecurity"sectionformoredetails.
NonFIPS-ApprovedAlgorithmsThefollowingalgorithmsarenotFIPSapprovedandshouldbedisabled:–RSAforencryption–MD-5forsigning–AH-SHA-HMAC–ESP-SHA-HMAC–HMACSHA-1ProtocolsThefollowingnetworkservicesaffectthesecuritydataitemsandmustnotbeconfigured:NTP,TACACS+,RADIUS,Kerberos.
SNMPv3overasecureIPSectunnelcanbeemployedforauthenticated,secureSNMPGetsandSets.
SinceSNMPv2Cusescommunitystringsforauthentication,onlygetsareallowedunderSNMPv2C.
RemoteAccessAuxiliaryterminalservicesmustbedisabled,exceptfortheconsole.
Thefollowingconfigurationdisablesloginservicesontheauxiliaryconsoleline.
lineaux0noexec12Cisco7206VXRRouterSecurityPolicyObtainingDocumentationTelnetaccesstothemoduleisonlyallowedviaasecureIPSectunnelbetweentheremotesystemandthemodule.
ThecryptoofficermustconfigurethemodulesothatanyremoteconnectionsviatelnetaresecuredthroughIPSec.
ObtainingDocumentationThefollowingsectionsprovidesourcesforobtainingdocumentationfromCiscoSystems.
WorldWideWebYoucanaccessthemostcurrentCiscodocumentationontheWorldWideWebatthefollowingsites:http://www.
cisco.
comhttp://www-china.
cisco.
comhttp://www-europe.
cisco.
comDocumentationCD-ROMCiscodocumentationandadditionalliteratureareavailableinaCD-ROMpackage,whichshipswithyourproduct.
TheDocumentationCD-ROMisupdatedmonthlyandcanbemorecurrentthanprinteddocumentation.
TheCD-ROMpackageisavailableasasingleunitorasanannualsubscription.
OrderingDocumentationCiscodocumentationisavailableinthefollowingways:RegisteredCiscoDirectCustomerscanorderCiscoProductdocumentationfromtheNetworkingProductsMarketPlace:http://www.
cisco.
com/cgi-bin/order/order_root.
plRegisteredCisco.
comuserscanordertheDocumentationCD-ROMthroughtheonlineSubscriptionStore:http://www.
cisco.
com/go/subscriptionNonregisteredCisco.
comuserscanorderdocumentationthroughalocalaccountrepresentativebycallingCiscocorporateheadquarters(California,USA)at408526-7208or,inNorthAmerica,bycalling800553-NETS(6387).
DocumentationFeedbackIfyouarereadingCiscoproductdocumentationontheWorldWideWeb,youcansubmittechnicalcommentselectronically.
ClickFeedbackinthetoolbarandselectDocumentation.
Afteryoucompletetheform,clickSubmittosendittoCisco.
Youcane-mailyourcommentstobug-doc@cisco.
com.
13Cisco7206VXRRouterSecurityPolicyObtainingTechnicalAssistanceTosubmityourcommentsbymail,usetheresponsecardbehindthefrontcoverofyourdocument,orwritetothefollowingaddress:AttnDocumentResourceConnectionCiscoSystems,Inc.
170WestTasmanDriveSanJose,CA95134-9883Weappreciateyourcomments.
ObtainingTechnicalAssistanceCiscoprovidesCisco.
comasastartingpointforalltechnicalassistance.
Customersandpartnerscanobtaindocumentation,troubleshootingtips,andsampleconfigurationsfromonlinetools.
ForCisco.
comregisteredusers,additionaltroubleshootingtoolsareavailablefromtheTACwebsite.
Cisco.
comCisco.
comisthefoundationofasuiteofinteractive,networkedservicesthatprovidesimmediate,openaccesstoCiscoinformationandresourcesatanytime,fromanywhereintheworld.
ThishighlyintegratedInternetapplicationisapowerful,easy-to-usetoolfordoingbusinesswithCisco.
Cisco.
comprovidesabroadrangeoffeaturesandservicestohelpcustomersandpartnersstreamlinebusinessprocessesandimproveproductivity.
ThroughCisco.
com,youcanfindinformationaboutCiscoandournetworkingsolutions,services,andprograms.
Inaddition,youcanresolvetechnicalissueswithonlinetechnicalsupport,downloadandtestsoftwarepackages,andorderCiscolearningmaterialsandmerchandise.
Valuableonlineskillassessment,training,andcertificationprogramsarealsoavailable.
Customersandpartnerscanself-registeronCisco.
comtoobtainadditionalpersonalizedinformationandservices.
Registereduserscanorderproducts,checkonthestatusofanorder,accesstechnicalsupport,andviewbenefitsspecifictotheirrelationshipswithCisco.
ToaccessCisco.
com,gotothefollowingwebsite:http://www.
cisco.
comTechnicalAssistanceCenterTheCiscoTACwebsiteisavailabletoallcustomerswhoneedtechnicalassistancewithaCiscoproductortechnologythatisunderwarrantyorcoveredbyamaintenancecontract.
ContactingTACbyUsingtheCiscoTACWebsiteIfyouhaveaprioritylevel3(P3)orprioritylevel4(P4)problem,contactTACbygoingtotheTACwebsite:http://www.
cisco.
com/tac14Cisco7206VXRRouterSecurityPolicyObtainingTechnicalAssistanceP3andP4levelproblemsaredefinedasfollows:P3—Yournetworkperformanceisdegraded.
Networkfunctionalityisnoticeablyimpaired,butmostbusinessoperationscontinue.
P4—YouneedinformationorassistanceonCiscoproductcapabilities,productinstallation,orbasicproductconfiguration.
Ineachoftheabovecases,usetheCiscoTACwebsitetoquicklyfindanswerstoyourquestions.
ToregisterforCisco.
com,gotothefollowingwebsite:http://www.
cisco.
com/register/IfyoucannotresolveyourtechnicalissuebyusingtheTAConlineresources,Cisco.
comregistereduserscanopenacaseonlinebyusingtheTACCaseOpentoolatthefollowingwebsite:http://www.
cisco.
com/tac/caseopenContactingTACbyTelephoneIfyouhaveaprioritylevel1(P1)orprioritylevel2(P2)problem,contactTACbytelephoneandimmediatelyopenacase.
Toobtainadirectoryoftoll-freenumbersforyourcountry,gotothefollowingwebsite:http://www.
cisco.
com/warp/public/687/Directory/DirTAC.
shtmlP1andP2levelproblemsaredefinedasfollows:P1—Yourproductionnetworkisdown,causingacriticalimpacttobusinessoperationsifserviceisnotrestoredquickly.
Noworkaroundisavailable.
P2—Yourproductionnetworkisseverelydegraded,affectingsignificantaspectsofyourbusinessoperations.
Noworkaroundisavailable.
AccessPath,AtmDirector,BrowsewithMe,CCIP,CCSI,CD-PAC,CiscoLink,theCiscoPoweredNetworklogo,CiscoSystemsNetworkingAcademy,theCiscoSystemsNetworkingAcademylogo,FastStep,FollowMeBrowsing,FormShare,FrameShare,GigaStack,IGX,InternetQuotient,IP/VC,iQBreakthrough,iQExpertise,iQFastTrack,theiQLogo,iQNetReadinessScorecard,MGX,theNetworkerslogo,Packet,RateMUX,ScriptBuilder,ScriptShare,SlideCast,SMARTnet,TransPath,Unity,VoiceLAN,WavelengthRouter,andWebVieweraretrademarksofCiscoSystems,Inc.
;ChangingtheWayWeWork,Live,Play,andLearn,DiscoverAllThat'sPossible,andEmpoweringtheInternetGeneration,areservicemarksofCiscoSystems,Inc.
;andAironet,ASIST,BPX,Catalyst,CCDA,CCDP,CCIE,CCNA,CCNP,Cisco,theCiscoCertifiedInternetworkExpertlogo,CiscoIOS,theCiscoIOSlogo,CiscoPress,CiscoSystems,CiscoSystemsCapital,theCiscoSystemslogo,Enterprise/Solver,EtherChannel,EtherSwitch,FastHub,FastSwitch,IOS,IP/TV,LightStream,MICA,NetworkRegistrar,PIX,Post-Routing,Pre-Routing,Registrar,StrataViewPlus,Stratm,SwitchProbe,TeleRouter,andVCOareregisteredtrademarksofCiscoSystems,Inc.
and/oritsaffiliatesintheU.
S.
andcertainothercountries.
Byprintingormakingacopyofthisdocument,theuseragreestousethisinformationforproductevaluationpurposesonly.
SaleofthisinformationinwholeorinpartisnotauthorizedbyCiscoSystems.
AllothertrademarksmentionedinthisdocumentorWebsitearethepropertyoftheirrespectiveowners.
TheuseofthewordpartnerdoesnotimplyapartnershiprelationshipbetweenCiscoandanyothercompany.
(0110R)Cisco7206VXRRouterSecurityPolicyCopyright2001,CiscoSystems,Inc.
Allrightsreserved.

Sharktech$129/月,1Gbps不限流量,E5-2678v3(24核48线程)

Sharktech最近洛杉矶和丹佛低价配置大部分都无货了,只有荷兰机房还有少量库存,商家又提供了两款洛杉矶特价独立服务器,价格不错,CPU/内存/硬盘都是高配,1-10Gbps带宽不限流量最低129美元/月起。鲨鱼机房(Sharktech)我们也叫它SK机房,是一家成立于2003年的老牌国外主机商,提供的产品包括独立服务器租用、VPS主机等,自营机房在美国洛杉矶、丹佛、芝加哥和荷兰阿姆斯特丹等,主...

raksmart:年中大促,美国物理机$30/月甩卖;爆款VPS仅月付$1.99;洛杉矶/日本/中国香港多IP站群$177/月

RAKsmart怎么样?RAKsmart发布了2021年中促销,促销时间,7月1日~7月31日!,具体促销优惠整理如下:1)美国西海岸的圣何塞、洛杉矶独立物理服务器低至$30/月(续费不涨价)!2)中国香港大带宽物理机,新品热卖!!!,$269.23 美元/月,3)站群服务器、香港站群、日本站群、美国站群,低至177美元/月,4)美国圣何塞,洛杉矶10G口服务器,不限流量,惊爆价:$999.00,...

Digital-VM80美元新加坡和日本独立服务器

Digital-VM商家的暑期活动促销,这个商家提供有多个数据中心独立服务器、VPS主机产品。最低配置月付80美元,支持带宽、流量和IP的自定义配置。Digital-VM,是2019年新成立的商家,主要从事日本东京、新加坡、美国洛杉矶、荷兰阿姆斯特丹、西班牙马德里、挪威奥斯陆、丹麦哥本哈根数据中心的KVM架构VPS产品销售,分为大硬盘型(1Gbps带宽端口、分配较大的硬盘)和大带宽型(10Gbps...

ccdp为你推荐
可以发外链的论坛发外链的论坛哪个比较好,哪个论坛能发外链,能发广告急求。。。。微信如何建群微信可以建立两个人的群吗?有一个是自己淘宝店推广淘宝店铺推广有哪些渠道?godaddyGO DADDY服务器空间域名怎么样畅想中国未来的中国是什么样子的创维云电视功能很喜欢创维云电视,它到底有哪些独特功能?人人逛街包公免费逛街打一成语iphone6上市时间苹果6什么时候出?多少钱虚拟专用网虚拟专用网适用于什么行业如何快速收录如何让百度快速收录
查域名 域名服务器上存放着internet主机的 三级域名网站 线路工具 商务主机 cn3 如何用qq邮箱发邮件 t云 空间登入 我的世界服务器ip 阿里云免费邮箱 云销售系统 google搜索打不开 godaddy中文 发证机构 ping值 tko linuxvi命令 海尔t68驱动 华为云服务器宕机 更多