activityccdp

ccdp  时间:2021-02-27  阅读:()
CorporateHeadquarters:Copyright2001.
CiscoSystems,Inc.
Allrightsreserved.
CiscoSystems,Inc.
,170WestTasmanDrive,SanJose,CA95134-1706USACisco7206VXRRouterSecurityPolicyIntroductionThisnonproprietaryCryptographicModuleSecurityPolicydescribeshowthe7206VXRNPE-400routersmeetthesecurityrequirementsofFederalInformationProcessingStandards(FIPS)140-1,andhowtheyoperateinasecureFIPS140-1mode.
ThepolicywaspreparedaspartoftheLevel2FIPS140-1certificationofthe7206VXRNPE-400router.
NoteThisdocumentmaybecopiedinitsentiretyandwithoutmodification.
Allcopiesmustincludethecopyrightnoticeandstatementsonthelastpage.
TheFIPS140-1publication,"SecurityRequirementsforCryptographicModules"detailstheU.
S.
Governmentrequirementsforcryptographicmodules.
MoreinformationabouttheFIPS140-1standardandvalidationprogramisavailableatthefollowingNationalInstituteofStandardsandTechnology(NIST)website:http://csrc.
nist.
gov/cryptval/Thisdocumentcontainsthefollowingsections:Introduction,page1The7206VXRNPE-400Router,page2SecureOperationoftheCisco7206VXRNPE-400Router,page10ObtainingDocumentation,page12ObtainingTechnicalAssistance,page132Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterReferencesThisdocumentdealswithoperationsandcapabilitiesofthe7206VXRNPE-400routerinthetechnicaltermsofaFIPS140-1cryptographicmodulesecuritypolicy.
FormoreinformationonCisco7206VXRNPE-400routerandtheentire7200series,checkthefollowingsources:TheCiscoSystemswebsitecontainsinformationonthefulllineofCiscoSystemsproducts.
Refertothefollowingwebsite:www.
cisco.
com.
The7200seriesproductdescriptionscanbefoundatthefollowingwebsite:www.
cisco.
com/warp/public/cc/pd/rt/7200/Foranswerstotechnicalorsalesrelatedquestions,pleaserefertothecontactslistedonthefollowingwebsite:www.
cisco.
com.
TerminologyInthisdocument,thecryptographicmoduleisreferredtoasthe7206VXRrouter,therouter,orthesystem.
DocumentOrganizationThesecuritypolicydocumentispartofthecompleteFIPS140-1SubmissionPackage.
Inadditiontothisdocument,thecompletesubmissionpackagecontains:VendorevidencedocumentFinitestatemachineModulesoftwarelistingOthersupportingdocumentationasadditionalreferencesThisdocumentprovidesanoverviewofthe7206VXRNPE-400routerandexplainsthesecureconfigurationandoperationofthecryptographicmodule.
Italsoexplainsthegeneralfeaturesandfunctionalityofthe7206VXRNPE-400routersandaddressestherequiredconfigurationfortheFIPSmodeofoperation.
NoteThissecuritypolicyandothercertificationsubmissiondocumentationwasproducedbyCorsecSecurity,Inc.
undercontracttoCiscoSystems.
Withtheexceptionofthisnonproprietarysecuritypolicy,theFIPS140-1CertificationSubmissiondocumentationisCisco-proprietaryandcanbereleasedonlyunderappropriatenondisclosureagreements.
Foraccesstothesedocuments,pleasecontactCiscoSystems.
The7206VXRNPE-400RouterCisco7200VXRroutersaredesignedtosupportgigabitcapabilitiesandtoimprovedata,voice,andvideointegrationinbothserviceproviderandenterpriseenvironments.
Cisco7200VXRrouterssupportahigh-speednetworkservicesengine(NSE)aswellasthehigh-speednetworkprocessingengine,NPE-400,andallotheravailablenetworkprocessingengines.
3Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterCisco7200VXRroutersaccommodateavarietyofnetworkinterfaceportadaptersandanI/Ocontroller.
ACisco7200VXRrouterequippedwithanNPE-400cansupportuptosixhigh-speedportadaptersandcanalsosupporthigher-speedportadapterinterfacesincludingGigabitEthernetandOC-12ATM.
Cisco7200VXRroutersalsocontainbaysforuptotwoAC-inputorDC-inputpowersupplies.
Cisco7200VXRrouterssupportthefollowingfeatures:Onlineinsertionandremoval(OIR)—Add,replace,orremoveportadapterswithoutinterruptingthesystem.
Dualhot-swappable,load-sharingpowersupplies—Providesystempowerredundancy;ifonepowersupplyorpowersourcefails,theotherpowersupplymaintainssystempowerwithoutinterruption.
Also,whenonepowersupplyispoweredoffandremovedfromtherouter,thesecondpowersupplyimmediatelytakesovertherouterpowerrequirementswithoutinterruptingnormaloperationoftherouter.
Environmentalmonitoringandreportingfunctions—Maintainnormalsystemoperationbyresolvingadverseenvironmentalconditionspriortolossofoperation.
Downloadablesoftware—LoadnewimagesintoFlashmemoryremotely,withouthavingtophysicallyaccesstherouter.
The7206VXRNPE-400CryptographicModuleCisco7206VXRrouterssupportmultiprotocolroutingandbridgingwithawidevarietyofprotocolsandportadaptercombinationsavailableforCisco7200seriesrouters.
Themetalcasingthatfullyenclosesthemoduleestablishesthecryptographicboundaryfortherouter.
Allthefunctionalitydiscussedinthisdocumentisprovidedbycomponentswithinthecasing.
Cisco7206VXRroutershavesixslotsforportadapters,oneslotforaninput/output(I/O)controller,andoneslotforanetworkprocessingengineornetworkservicesengine.
Figure1The7206VXRNPE-400RouterCisco7206VXRNPE-400usesanRM7000microprocessorthatoperatesataninternalclockspeedof350MHz.
TheNPE-400usesSDRAMforstoringallpacketsreceivedorsentfromnetworkinterfaces.
TheSDRAMmemoryarrayinthesystemallowsconcurrentaccessbyportadaptersandtheprocessor.
H5997ETHERNET10BTENABLED0213LINK0123FASTSERIALENTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDENABLEDMIILINKRJ45FASTETHERNET0TOKENRING0123MIIENRJ45ENRJ45LINK1OPWROKRJ-45CPURESETFASTETHERNETINPUT/OUTPUTCONTROLLERENABLEDPCMCIAEJECTSLOT0SLOT1FEMIIAuxiliaryportConsoleportPortadapterleverI/Ocontroller0241356ETHERNET-10BFLENRX01234TXRXTXRXTXRXTXRXTXPortadaptersCisco7200SeriesPCcardslotsOptionalFastEthernetport(MIIreceptacleandRJ-45receptacle)4Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterTheNPE-400hasthreelevelsofcache:aprimaryandasecondarycachethatareinternaltothemicroprocessor,andatertiary4-MBexternalcachethatprovidesadditionalhigh-speedstoragefordataandinstructions.
Cisco7206VXRrouterscomeequippedwithone280WAC-inputpowersupply.
(A280WDC-inputpowersupplyoptionisavailable.
)Apowersupplyfillerplateisinstalledoverthesecondpowersupplybay.
AfullyconfiguredCisco7206VXRrouteroperateswithonlyoneinstalledpowersupply;however,asecond,optionalpowersupplyofthesametypeprovideshot-swappable,load-sharing,redundantpower.
ModuleInterfacesInput/OutputControllerTheinterfacesfortherouterarelocatedonthefrontpanelInput/Output(I/O)Controller,withtheexceptionofthepowerswitchandpowerplug.
ThemodulehastwoFastEthernet(10/100RJ-45)connectorsfordatatransfersinandout.
ThemodulealsohastwootherRJ-45connectorsforaconsoleterminalforlocalsystemaccessandanauxiliaryportforremotesystemaccessordialbackupusingamodem.
Figure2showsthefrontpanelLEDs,whichprovideoverallstatusoftherouteroperation.
Thefrontpaneldisplayswhetherornottherouterisbooted,iftheredundantpowerisattachedandoperational,andoverallactivity/linkstatus.
Figure2I/OControllerTable1providesdetailedinformationconveyedbytheLEDsonthefrontpaneloftheI/OController.
DUALFASTETHERNETINPUT/OUTPUTCONTROLLERCONSOLEAUX100MbpsLINK100MbpsLINKSLOT0EJECTPCMCIASLOT1ENABLEDCPURESETIOPWROK33444CPURESETIOPWROK100MbpsLINKSLOT0SLOT1C7200-I/O-2FE/EENABLEDFE/E0FE/E15Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400Router.
AllofthesephysicalinterfacesareseparatedintothelogicalinterfacesfromFIPSasdescribedinTable2.
Table1FrontPanelLEDsandDescriptionsLEDIndicationDescriptionEnabledGreenIndicatesthatthenetworkprocessingengineornetworkservicesengineandtheI/Ocontrollerareenabledforoperationbythesystem;however,itdoesnotmeanthattheFastEthernetportontheI/Ocontrollerisfunctionalorenabled.
ThisLEDgoesonduringasuccessfulrouterbootandremainsonduringnormaloperationoftherouter.
IOPOWEROKAmberIndicatesthattheI/OcontrollerisonandreceivingDCpowerfromtheroutermidplane.
ThisLEDcomesonduringasuccessfulrouterbootandremainsonduringnormaloperationoftherouter.
OffPoweredofforfailed.
Slot0Slot1GreenTheseLEDsindicatewhichPCCardslotisinusebycomingonwheneitherslotisbeingaccessedbythesystem.
TheseLEDsremainoffduringnormaloperationoftherouter.
LinkGreenIndicatesthattheEthernetRJ-45receptaclehasestablishedavalidlinkwiththenetwork.
OffThisLEDremainsoffduringnormaloperationoftherouterunlessthereisanincomingcarriersignal100MbpsGreenIndicatesthattheportisconfiguredfor100-Mbpsoperation(speed100),orifconfiguredforautonegotiation(speedauto),theporthasdetectedavalidlinkat100Mbps.
OffIftheportisconfiguredfor10-Mbpsoperation,orifitisconfiguredforautonegotiationandtheporthasdetectedavalidlinkat10Mbps,theLEDremainsoff.
Table2FIPS140-1LogicalInterfacesRouterPhysicalInterfaceFIPS140-1LogicalInterface10/100BASE-TXLANPortPortAdapterInterfaceServiceModuleInterfaceConsolePortAuxiliaryPort*PCMCIASlot*DataInputInterface10/100BASE-TXLANPortPortAdapterInterfaceServiceModuleInterfaceConsolePortAuxiliaryPort*PCMCIASlot*DataOutputInterface6Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400Router*DisabledinFIPSmode.
Seethe"SecureOperationoftheCisco7206VXRNPE-400Router"sectioninthisdocumentformoreinformation.
Inadditiontothebuilt-ininterfaces,therouteralsohasadditionalportadaptersthatcanoptionallybeplacedinanavailableslot.
Theseportadaptershavemanyembodiments,includingmultipleEthernet,tokenring,andmodemcardstohandleframerelay,ATM,andISDNconnections.
RolesandServicesTherearetwomainrolesintherouter(asrequiredbyFIPS140-1)thatoperatorscanassume:cryptoofficeroradministratorroleanduserrole.
Theadministratoroftherouterassumesthecryptoofficerroleinordertoconfigureandmaintaintherouterusingcryptoofficerservices,whiletheusersexerciseonlythebasicuserservices.
CryptographicOfficerServicesDuringinitialconfigurationoftherouter,acryptographicofficer(cryptoofficer)password(the"enable"password)isdefinedandallmanagementservicesareavailablefromthisrole.
Thecryptoofficerconnectstotherouterthroughtheconsoleportthroughtheterminalprogram.
Acryptoofficercanassignpermissiontoaccessthecryptoofficerroletoadditionalaccounts,therebycreatingadditionalcryptoofficers.
Atthehighestlevel,cryptoofficerservicesincludethefollowing:Configuretherouter:definenetworkinterfacesandsettings,createcommandaliases,settheprotocolstherouterwillsupport,enableinterfacesandnetworkservices,setsystemdateandtime,andloadauthenticationinformation.
Definerulesandfilters:createpacketfiltersthatareappliedtouserdatastreamsoneachinterface.
EachfilterconsistsofasetofRules,whichdefineasetofpacketstopermitordenybasedoncharacteristicssuchasprotocolID,addresses,ports,TCPconnectionestablishment,orpacketdirection.
PowerSwitchConsolePortAuxiliaryPort*ControlInputInterface10/100BASE-TXLANPortLEDsPwrLEDSysRdyLEDConsolePortAuxiliaryPort*StatusOutputInterfacePowerPlugPowerInterfaceTable2FIPS140-1LogicalInterfaces(continued)RouterPhysicalInterfaceFIPS140-1LogicalInterface7Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterStatusfunctions:viewtherouterconfiguration,routingtables,andactivesessions;viewSNMPMIBIIstatistics,health,temperature,memorystatus,voltage,andpacketstatistics;reviewaccountinglogs,andviewphysicalinterfacestatus.
Managetherouter:logoffusers,shutdownorreloadtherouter,manuallybackuprouterconfigurations,viewcompleteconfigurations,manageruserrights,andrestorerouterconfigurations.
Setencryption/bypass:setuptheconfigurationtablesforIPtunneling.
SetkeysandalgorithmstobeusedforeachIPrangeorallowplaintextpacketstobesetfromspecifiedIPaddresses.
Changeportadapters:insertandremoveadaptersinportadapterslotsasdescribedinthe"InitialSetup"sectioninthisdocument.
UserServicesAuserentersthesystembyaccessingtheconsoleportwithaterminalprogram.
TheIOSpromptstheuserfortheirpassword.
IfitmatchestheplaintextpasswordstoredinIOSmemory,theuserisallowedentrytotheIOSexecutiveprogram.
Atthehighestlevel,userservicesincludethefollowing:StatusFunctions:viewstateofinterfaces,stateoflayer2protocols,versionofIOScurrentlyrunningNetworkFunctions:connecttoothernetworkdevicesthroughoutgoingtelnetorPPP,andinitiatediagnosticnetworkservices(forexample,pingandmtrace)TerminalFunctions:adjusttheterminalsession(thatis,locktheterminalandadjustflowcontrol)DirectoryServices:displaydirectoryoffileskeptinflashmemoryPhysicalSecurityTherouterisentirelyencasedbyathicksteelchassis.
Thefrontoftherouterprovides4portadapterslots,on-boardLANconnectors,PCCardslots,andConsole/Auxiliaryconnectors.
Thepowercableconnection,apowerswitch,andtheaccesstotheNetworkProcessingEngineareattherearoftherouter.
OncetherouterhasbeenconfiguredtomeetFIPS140-1Level2requirements,theroutercannotbeaccessedwithoutsignsoftampering.
Tosealthesystem,applyserializedtamper-evidencelabelsasfollows:Cleanthecoverofanygrease,dirt,oroilbeforeapplyingthetamperevidencelabels.
Alcohol-basedcleaningpadsarerecommendedforthispurpose.
Theambientairmustbeabove10C,otherwisethelabelsmaynotproperlycure.
Thetamperevidencelabelshouldbeplacedsothattheonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthe7206VXRNPE-400Input/OutputController.
ThetamperevidencelabelshouldbeplacedovertheFlashPCCardslotsontheInput/OutputController.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot1.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot2.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot3.
8Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterThetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot4.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot5.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheportadapterslot6.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthenetworkprocessingengine.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoversthepowersupplyplate.
Thetamperevidencelabelshouldbeplacedsothatonehalfofthelabelcoverstheenclosureandtheotherhalfcoverstheredundantpowersupplyplate.
Thelabelscompletelycurewithinfiveminutes.
Figure3showsthetamperevidencelabelplacements.
9Cisco7206VXRRouterSecurityPolicyThe7206VXRNPE-400RouterFigure3TamperEvidenceLabelPlacementThetamperevidencesealsareproducedfromaspecialthingaugevinylwithself-adhesivebacking.
Anyattempttoremoveportadaptersorservicemoduleswilldamagethetamperevidencesealsorthepaintedsurfaceandmetalofthemodulecover.
Sincethetamperevidencelabelshavenonrepeatedserialnumbers,thelabelscanbeinspectedfordamageandcomparedagainsttheappliedserialnumberstoverifythatthemodulehasnotbeentamperedwith.
Tamperevidencelabelscanalsobeinspectedforsignsoftampering,whichincludethefollowing:curledcorners,bubbling,crinkling,rips,tears,andslices.
Theword"Opened"canappearifthelabelwaspeeledback.
NoteTheCisco7206routersupportsthefollowingFIPS-approvedalgorithms:DES,3DES,andSHA-1.
Thesealgorithmsreceivedcertificationnumbers74,17,and26respectively.
61228ETHERNET10BTENABLED0213LINK0123FASTSERIALENTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDTDTCRDRCLBCDENABLEDMIILINKRJ45FASTETHERNET0TOKENRING0123MIIENRJ45ENRJ45LINK1OPWROKRJ-45CPURESETFASTETHERNETINPUT/OUTPUTCONTROLLERENABLEDPCMCIAEJECTSLOT0SLOT1FEMIIAuxiliaryportConsoleportPortadapterleverI/Ocontroller0241356ETHERNET-10BFLENRX01234TXRXTXRXTXRXTXRXTXPortadaptersBlankportadapterPCCardslotsOptionalFastEthernetport(MIIreceptacleandRJ-45receptacle)Cisco7200SeriesVXR61229NETWORKPROCESSINGENGINE-150InternalfansNetworkprocessingengineornetworkservicesengineAC-inputpowersupplyAC-inputreceptaclePowersupplyfillerplateChassisgroundingreceptaclesPowerswitch10Cisco7206VXRRouterSecurityPolicySecureOperationoftheCisco7206VXRNPE-400RouterCryptographicKeyManagementTheroutersecurelyadministersbothcryptographickeysandothercriticalsecurityparameterssuchaspasswords.
Thetamperevidencesealsprovidephysicalprotectionforallkeys.
Keysarealsopasswordprotectedandcanbezeroizedbythecryptoofficer.
KeysareexchangedmanuallyandenteredelectronicallyviamanualkeyexchangeorInternetKeyExchange(IKE).
Self-TestsInordertopreventanysecuredatafrombeingreleased,itisimportanttotestthecryptographiccomponentsofasecuritymoduletoinsureallcomponentsarefunctioningcorrectly.
Therouterincludesanarrayofself-teststhatarerunduringstartupandperiodicallyduringoperations.
Theself-testrunatpower-upincludesacryptographicknownanswertests(KAT)ontheFIPS-approvedcryptographicalgorithms(DES,3DES),onthemessagedigest(SHA-1),andontheDiffie-Hellmanalgorithm.
AlsoperformedatstartupareasoftwareintegritytestusinganEDC,andasetofStatisticalRandomNumberGenerator(RNG)tests.
Thefollowingtestsarealsorunperiodicallyorconditionally:abypassmodetestperformedconditionallypriortoexecutingIPSec,asoftwareloadtestforupgrades,andthecontinuousrandomnumbergeneratortest.
Ifanyoftheseself-testsfail,theroutertransitionsintoanerrorstate.
Withintheerrorstate,allsecuredatatransmissionishaltedandtherouteroutputsstatusinformationindicatingthefailure.
SecureOperationoftheCisco7206VXRNPE-400RouterCisco7206VXRNPE-400routermeetsalltheLevel2requirementsforFIPS140-1.
FollowthesettinginstructionsprovidedbelowtoplacethemoduleinFIPSmode.
OperatingthisrouterwithoutmaintainingthefollowingsettingswillremovethemodulefromtheFIPSapprovedmodeofoperation.
InitialSetupThecryptoofficermustapplytamperevidencelabelsasdescribedinthe"PhysicalSecurity"sectionofthisdocument.
Thecryptoofficermustsecurelystoretamperevidencelabelsbeforeuse,andanytamperevidencelabelsnotusedshouldalsobestoredsecurely.
Onlyacryptoofficercanaddandremoveportadapters.
Whenremovingthetamperevidencelabel,thecryptoofficershouldremovetheentirelabelfromtherouterandcleanthecoverofanygrease,dirt,oroilwithanalcohol-basedcleaningpad.
Thecryptoofficermustreapplytamperevidencelabelsontherouterasdescribedinthe"PhysicalSecurity"sectioninthisdocument.
SystemInitializationandConfigurationThecryptoofficermustperformtheinitialconfiguration.
TheIOSversionshippedwiththerouter,version12.
1(9)E,istheonlyallowableimage.
Nootherimagecanbeloaded.
Thevalueofthebootfieldmustbe0x0101(thefactorydefault).
ThissettingdisablesthebreakfromtheconsoletotheROMmonitorandautomaticallybootstheIOSimage.
Fromtheconfigureterminalcommandline,thecryptoofficerentersthefollowingsyntax:config-register0x010111Cisco7206VXRRouterSecurityPolicySecureOperationoftheCisco7206VXRNPE-400RouterThecryptoofficermustcreatethe"enable"passwordforthecryptoofficerrole.
Thepasswordmustbeatleast8charactersandisenteredwhenthecryptoofficerfirstengagestheenablecommand.
Thecryptoofficerentersthefollowingsyntaxatthe"#"prompt:enablesecret[PASSWORD]Thecryptoofficermustalwaysassignpasswords(ofatleast8characters)tousers.
IdentificationandauthenticationoftheconsoleportisrequiredforUsers.
Fromtheconfigureterminalcommandline,thecryptoofficerentersthefollowingsyntax:linecon0password[PASSWORD]loginlocalThecryptoofficershallonlyassignuserstoaprivilegelevel1(thedefault).
Thecryptoofficershallnotassignacommandtoanyprivilegelevelotherthanitsdefault.
ThePCMCIAFlashmemorycardslotisnotconfiguredinFIPSmode.
Itsuseisrestrictedviatamperevidencelabels.
Seethe"PhysicalSecurity"sectionformoredetails.
NonFIPS-ApprovedAlgorithmsThefollowingalgorithmsarenotFIPSapprovedandshouldbedisabled:–RSAforencryption–MD-5forsigning–AH-SHA-HMAC–ESP-SHA-HMAC–HMACSHA-1ProtocolsThefollowingnetworkservicesaffectthesecuritydataitemsandmustnotbeconfigured:NTP,TACACS+,RADIUS,Kerberos.
SNMPv3overasecureIPSectunnelcanbeemployedforauthenticated,secureSNMPGetsandSets.
SinceSNMPv2Cusescommunitystringsforauthentication,onlygetsareallowedunderSNMPv2C.
RemoteAccessAuxiliaryterminalservicesmustbedisabled,exceptfortheconsole.
Thefollowingconfigurationdisablesloginservicesontheauxiliaryconsoleline.
lineaux0noexec12Cisco7206VXRRouterSecurityPolicyObtainingDocumentationTelnetaccesstothemoduleisonlyallowedviaasecureIPSectunnelbetweentheremotesystemandthemodule.
ThecryptoofficermustconfigurethemodulesothatanyremoteconnectionsviatelnetaresecuredthroughIPSec.
ObtainingDocumentationThefollowingsectionsprovidesourcesforobtainingdocumentationfromCiscoSystems.
WorldWideWebYoucanaccessthemostcurrentCiscodocumentationontheWorldWideWebatthefollowingsites:http://www.
cisco.
comhttp://www-china.
cisco.
comhttp://www-europe.
cisco.
comDocumentationCD-ROMCiscodocumentationandadditionalliteratureareavailableinaCD-ROMpackage,whichshipswithyourproduct.
TheDocumentationCD-ROMisupdatedmonthlyandcanbemorecurrentthanprinteddocumentation.
TheCD-ROMpackageisavailableasasingleunitorasanannualsubscription.
OrderingDocumentationCiscodocumentationisavailableinthefollowingways:RegisteredCiscoDirectCustomerscanorderCiscoProductdocumentationfromtheNetworkingProductsMarketPlace:http://www.
cisco.
com/cgi-bin/order/order_root.
plRegisteredCisco.
comuserscanordertheDocumentationCD-ROMthroughtheonlineSubscriptionStore:http://www.
cisco.
com/go/subscriptionNonregisteredCisco.
comuserscanorderdocumentationthroughalocalaccountrepresentativebycallingCiscocorporateheadquarters(California,USA)at408526-7208or,inNorthAmerica,bycalling800553-NETS(6387).
DocumentationFeedbackIfyouarereadingCiscoproductdocumentationontheWorldWideWeb,youcansubmittechnicalcommentselectronically.
ClickFeedbackinthetoolbarandselectDocumentation.
Afteryoucompletetheform,clickSubmittosendittoCisco.
Youcane-mailyourcommentstobug-doc@cisco.
com.
13Cisco7206VXRRouterSecurityPolicyObtainingTechnicalAssistanceTosubmityourcommentsbymail,usetheresponsecardbehindthefrontcoverofyourdocument,orwritetothefollowingaddress:AttnDocumentResourceConnectionCiscoSystems,Inc.
170WestTasmanDriveSanJose,CA95134-9883Weappreciateyourcomments.
ObtainingTechnicalAssistanceCiscoprovidesCisco.
comasastartingpointforalltechnicalassistance.
Customersandpartnerscanobtaindocumentation,troubleshootingtips,andsampleconfigurationsfromonlinetools.
ForCisco.
comregisteredusers,additionaltroubleshootingtoolsareavailablefromtheTACwebsite.
Cisco.
comCisco.
comisthefoundationofasuiteofinteractive,networkedservicesthatprovidesimmediate,openaccesstoCiscoinformationandresourcesatanytime,fromanywhereintheworld.
ThishighlyintegratedInternetapplicationisapowerful,easy-to-usetoolfordoingbusinesswithCisco.
Cisco.
comprovidesabroadrangeoffeaturesandservicestohelpcustomersandpartnersstreamlinebusinessprocessesandimproveproductivity.
ThroughCisco.
com,youcanfindinformationaboutCiscoandournetworkingsolutions,services,andprograms.
Inaddition,youcanresolvetechnicalissueswithonlinetechnicalsupport,downloadandtestsoftwarepackages,andorderCiscolearningmaterialsandmerchandise.
Valuableonlineskillassessment,training,andcertificationprogramsarealsoavailable.
Customersandpartnerscanself-registeronCisco.
comtoobtainadditionalpersonalizedinformationandservices.
Registereduserscanorderproducts,checkonthestatusofanorder,accesstechnicalsupport,andviewbenefitsspecifictotheirrelationshipswithCisco.
ToaccessCisco.
com,gotothefollowingwebsite:http://www.
cisco.
comTechnicalAssistanceCenterTheCiscoTACwebsiteisavailabletoallcustomerswhoneedtechnicalassistancewithaCiscoproductortechnologythatisunderwarrantyorcoveredbyamaintenancecontract.
ContactingTACbyUsingtheCiscoTACWebsiteIfyouhaveaprioritylevel3(P3)orprioritylevel4(P4)problem,contactTACbygoingtotheTACwebsite:http://www.
cisco.
com/tac14Cisco7206VXRRouterSecurityPolicyObtainingTechnicalAssistanceP3andP4levelproblemsaredefinedasfollows:P3—Yournetworkperformanceisdegraded.
Networkfunctionalityisnoticeablyimpaired,butmostbusinessoperationscontinue.
P4—YouneedinformationorassistanceonCiscoproductcapabilities,productinstallation,orbasicproductconfiguration.
Ineachoftheabovecases,usetheCiscoTACwebsitetoquicklyfindanswerstoyourquestions.
ToregisterforCisco.
com,gotothefollowingwebsite:http://www.
cisco.
com/register/IfyoucannotresolveyourtechnicalissuebyusingtheTAConlineresources,Cisco.
comregistereduserscanopenacaseonlinebyusingtheTACCaseOpentoolatthefollowingwebsite:http://www.
cisco.
com/tac/caseopenContactingTACbyTelephoneIfyouhaveaprioritylevel1(P1)orprioritylevel2(P2)problem,contactTACbytelephoneandimmediatelyopenacase.
Toobtainadirectoryoftoll-freenumbersforyourcountry,gotothefollowingwebsite:http://www.
cisco.
com/warp/public/687/Directory/DirTAC.
shtmlP1andP2levelproblemsaredefinedasfollows:P1—Yourproductionnetworkisdown,causingacriticalimpacttobusinessoperationsifserviceisnotrestoredquickly.
Noworkaroundisavailable.
P2—Yourproductionnetworkisseverelydegraded,affectingsignificantaspectsofyourbusinessoperations.
Noworkaroundisavailable.
AccessPath,AtmDirector,BrowsewithMe,CCIP,CCSI,CD-PAC,CiscoLink,theCiscoPoweredNetworklogo,CiscoSystemsNetworkingAcademy,theCiscoSystemsNetworkingAcademylogo,FastStep,FollowMeBrowsing,FormShare,FrameShare,GigaStack,IGX,InternetQuotient,IP/VC,iQBreakthrough,iQExpertise,iQFastTrack,theiQLogo,iQNetReadinessScorecard,MGX,theNetworkerslogo,Packet,RateMUX,ScriptBuilder,ScriptShare,SlideCast,SMARTnet,TransPath,Unity,VoiceLAN,WavelengthRouter,andWebVieweraretrademarksofCiscoSystems,Inc.
;ChangingtheWayWeWork,Live,Play,andLearn,DiscoverAllThat'sPossible,andEmpoweringtheInternetGeneration,areservicemarksofCiscoSystems,Inc.
;andAironet,ASIST,BPX,Catalyst,CCDA,CCDP,CCIE,CCNA,CCNP,Cisco,theCiscoCertifiedInternetworkExpertlogo,CiscoIOS,theCiscoIOSlogo,CiscoPress,CiscoSystems,CiscoSystemsCapital,theCiscoSystemslogo,Enterprise/Solver,EtherChannel,EtherSwitch,FastHub,FastSwitch,IOS,IP/TV,LightStream,MICA,NetworkRegistrar,PIX,Post-Routing,Pre-Routing,Registrar,StrataViewPlus,Stratm,SwitchProbe,TeleRouter,andVCOareregisteredtrademarksofCiscoSystems,Inc.
and/oritsaffiliatesintheU.
S.
andcertainothercountries.
Byprintingormakingacopyofthisdocument,theuseragreestousethisinformationforproductevaluationpurposesonly.
SaleofthisinformationinwholeorinpartisnotauthorizedbyCiscoSystems.
AllothertrademarksmentionedinthisdocumentorWebsitearethepropertyoftheirrespectiveowners.
TheuseofthewordpartnerdoesnotimplyapartnershiprelationshipbetweenCiscoandanyothercompany.
(0110R)Cisco7206VXRRouterSecurityPolicyCopyright2001,CiscoSystems,Inc.
Allrightsreserved.

华纳云不限流量¥324/年,香港双向CN2(GIA)云服务器/1核1G/50G存储/2Mbps

华纳云(HNCloud Limited)是一家专业的全球数据中心基础服务提供商,总部在香港,隶属于香港联合通讯国际有限公司,拥有香港政府颁发的商业登记证明,保证用户的安全性和合规性。 华纳云是APNIC 和 ARIN 会员单位。主要提供香港和美国机房的VPS云服务器和独立服务器。商家支持支付宝、网银、Paypal付款。华纳云主要面向国内用户群,所以线路质量还是不错的,客户使用体验总体反响还是比较好...

亚州云-美国Care云服务器,618大带宽美国Care年付云活动服务器,采用KVM架构,支持3天免费无理由退款!

官方网站:点击访问亚州云活动官网活动方案:地区:美国CERA(联通)CPU:1核(可加)内存:1G(可加)硬盘:40G系统盘+20G数据盘架构:KVM流量:无限制带宽:100Mbps(可加)IPv4:1个价格:¥128/年(年付为4折)购买:直达订购链接测试IP:45.145.7.3Tips:不满意三天无理由退回充值账户!地区:枣庄电信高防防御:100GCPU:8核(可加)内存:4G(可加)硬盘:...

易探云:香港物理机服务器仅550元/月起;E3-1230/16G DDR3/SATA 1TB/香港BGP/20Mbps

易探云怎么样?易探云(yitanyun.com)是一家知名云计算品牌,2017年成立,从业4年之久,目前主要从事出售香港VPS、香港独立服务器、香港站群服务器等,在售VPS线路有三网CN2、CN2 GIA,该公司旗下产品均采用KVM虚拟化架构。目前,易探云推出免备案香港物理机服务器性价比很高,E3-1230 8 核*1/16G DDR3/SATA 1TB/香港BGP线路/20Mbps/不限流量,仅...

ccdp为你推荐
安装程序配置服务器失败安装用友T3出现安装程序配置服务器失败是怎么回事支付宝查询余额怎么查询支付宝里的余额渗透测试web渗透测试有前途吗安卓应用平台现在android平台的手机都有哪些?中小企业信息化中小企业如何进行企业信息化规划iphone越狱后怎么恢复苹果手机越狱后怎么恢复畅想中国20年后中国会变成什么样?--畅想一下未来的中国!!迅雷云点播账号求个迅雷VIP 是VIP就可以 只用来看云点播 改密码是孙子。 谢了 ! 362135668@qq.com淘宝网页显示不正常淘宝网显示不正常宕机人们说的宕机是什么意思
名片模板psd 好看的留言 华为云主机 建站代码 小米数据库 双线主机 in域名 360云服务 空间租赁 中国电信网络测速 深圳域名 阿里云邮箱登陆 免费php空间 免费个人网页 卡巴斯基官网下载 windowsserver2012r2 forwarder 留言板 招聘瓦工 sockscap怎么用 更多