beautypg.com

Brocade Mobility RFS7000-GR Controller CLI Reference Guide (Supporting software release 4.1.0.0-040GR and later) User Manual

Page 16

background image

2

Brocade Mobility RFS7000-GR Controller CLI Reference Guide

53-1001945-01

Common Criteria Operational Requirements

1

9. Common Criteria Filter shall be enabled. Refer to

“common-criteria”

on page 181 for details on

the common-criteria command.

To run the product in the Common Criteria evaluated configuration, the following assumptions shall
be satisfied:

Configuration of MAC ACL For Common Criteria Operation

If access points are connected over L2 network then user shall use MAC ACLs as explained below.

RFS7000#

RFS7000#configure terminal

Enter configuration commands, one per line. End with CNTL/Z.

RFS7000(config)#

Assigning IP Address to Management VLAN

RFS7000(config)#interface vlan 1

RFS7000(config-if)#ip address 172.17.1.100/24 RFS7000(config-if)#exit

Assigning access VLAN2 on GE1

RFS7000(config)#interface ge 1

RFS7000(config-if)#switchport mode access

RFS7000(config-if)#switchport access vlan 2

RFS7000(config-if)#exit

Assigning access VLAN3 on GE2

RFS7000(config)#interface ge 2

RFS7000(config-if)#switchport access mode access

RFS7000(config-if)#switchport access vlan 3

RFS7000(config-if)#exit

Assigning access VLAN4 on GE3

RFS7000(config)#interface ge 3

RFS7000(config-if)#switchport mode access

RFS7000(config-if)#switchport access vlan 4

RFS7000(config-if)#exit

Name

Assumption

A.NO_EVIL

Administrators shall be non-hostile,
appropriately trained and follow all
administrator guidance.

A.NO_GENERAL_PURPOSE

There shall be no general-purpose computing or
storage repository capabilities (e.g., compilers,
editors, or user applications) available on the
TOE.

A.PHYSICAL

Physical security, commensurate with the value
of the product and the data it contains shall be
provided by the environment.

A.TOE_NO_BYPASS

Wireless clients shall be configured so that
information cannot flow between a wireless
client and any other wireless client or host
networked to the product without passing
through the product.