Configure settings for an evaluated configuration
After installing the SMC, several areas of the configuration must be configured specifically for a Common Criteria evaluated configuration by using the SMC Client.
| Setting | Configuration |
|---|---|
| Time Management |
You can set the time manually on the SMC Appliance or you can use NTP time synchronization. By default, the Security Engine receives the time from the SMC Appliance. You can optionally also configure NTP time synchronization for the Security Engine. To use NTP time synchronization, follow the guidelines in the following topics in the Configuring system communications chapter in the Forcepoint Network Security Platform Product Guide:
Note:
|
| Time Management (continued) |
The NTP implementation for both the SMC Appliance and the Security Engine is an NTP client only. NTP clients support communication with NTPv4 servers. By default, the SMC Appliance and Security Engine NTP clients do not update their times based on multicast or broadcast NTP packets. The NTP server must use only the SHA-1 authentication key. In the properties of the NTP Server element, select SHA1 from the Key Type drop down list. For redundancy, you can configure multiple NTP servers. Create one NTP Server element for each NTP server. When enabling NTP time synchronization on the SMC Appliance, select all of the NTP Server elements. |
| Time Management (continued) |
To set the date and time manually on the SMC Appliance, enter:
where
<Day Mon DD hh:mm:ss [TZ] [YYYY]> is the day of week, month, day of month, time, optional time zone and optional year. |
| Audit Server Configuration |
Follow the guidelines in the following topics and chapters in the Forcepoint Network Security Platform Product Guide:
When setting the options for log or audit data forwarding in the properties of the Management Server or Log Server, select Use Internal Certificate or Use Imported Certificate as the TLS certificate to use. Forcepoint Network Security Platform supports OCSP and CRL revocations for X509v3 certificate validation during negotiation of TLS protected syslog. When handling a certificate bearing OCSP revocation but where Forcepoint Network Security Platform cannot establish a connection with the OCSP responder, Forcepoint Network Security Platform will not accept the certificate (and thus not establish the connection). When handling certificates bearing CRL information but where Forcepoint Network Security Platform cannot establish a connection to the CRL Distribution Point location, Forcepoint Network Security Platform will not accept the certificate as valid. Forcepoint Network Security Platform constructs the certificate path to a trusted certificate, and then verifies the signature, checks the revocation status, validity period, issuer’s name, extended key usage and basic constraints for each certificate starting from the trusted certificate. |
| Audit Server Configuration (continued) |
1) Configure the trusted root CA certificate for the audit server. See the Create Trusted Certificate Authority elements topic in the Managing certificates for system communications chapter in the Forcepoint Network Security Platform Product Guide |
| Audit Server Configuration (continued) |
2) If using an imported certificate, configure the trusted CA certificates for the client certificate. 3) If using an imported certificate, generate the client certificate request.
Note: After creating a certificate request, you must close and re-open the SMC Client in order to export the certificate request.
|
| Audit Server Configuration (continued) | 4) Configure the TLS profile using TLS 1.2.
To use certificate revocation checks, peer certificates must contain the correct CRL Distribution Points extension that refers to a valid CRL Distribution point. The environment must be configured so that the SMC can access the referenced CRL distribution points. If a TLS connection cannot be established because the connection to the CRL server fails, verify the network path to the CRL server and the status of the server, and fix any issues. |
| Audit Server Configuration (continued) | 5) Configure the server identity. Define the following settings for the TLS Server Identity:
For more information, see the Configure TLS server identity topic in the Managing certificates for system communications chapter in the Forcepoint Network Security Platform Product Guide. To complete the configuration select OK in the server properties dialog box. The Log forwarding starts automatically. |
| Audit Server Configuration (continued) |
If the log or audit data forwarding connection to the audit server is not working, do the following:
|
| Logon Banner |
To configure the Logon Banner, complete the following steps:
|
| Administrative Logins |
Follow the guidelines in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide. Use the SMC Client to manage users and passwords in the SMC. The local console user accounts are synchronized with the user accounts used in the SMC. The local console accounts and passwords are managed from the SMC. Only SMC user accounts with unrestricted permissions are available on the SMC Appliance local console.
Note: When the
SMC Appliance Superuser option is selected, the administrator can log in to the
SMC Appliance command line. Administrators with unrestricted permissions (superusers) are permitted to log in
to the SMC Appliance command line only if there are no other administrators with SMC Appliance Superuser permissions active.
|
| Administrative Logins (continued) |
To specify the timeout to terminate an inactive local administrative session,
enter:
where
<TIMEOUT> is the timeout in seconds.To enable temporarily locking administrator accounts after a certain amount of failed logon attempts:
Note: If the administrator account is locked, it is still possible to log on to the SMC Appliance through the local console.
To enable and specify the inactivity timeout for remote administrative sessions:
For information about setting timeouts in the SMC Client and locking administrator accounts, see the Enable and define password policy settings topic in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide |
| Administrative Logins (continued) |
To manually log out of the local console account, enter:
To log out of the SMC Client, select . |
| Password Guidelines |
Follow the guidelines in the Enable and define password policy settings topic in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide. When setting a password, you should select a password that meets these requirements:
By default, Forcepoint Network Security Platform enforces a minimum password length of 10 characters. The minimum password length is configurable from 1 to 80 characters. When operating in a Common Criteria evaluated configuration, we recommend that you set the minimum password length to 15 characters. Configure the Minimum Number of Required Characters setting to enforce these recommendations. Note: Use strong passwords that are at least 15 characters long and contain a combination of numbers, letters, and special characters. Do not base passwords on personal
information such as names, birthdays, ID numbers, phone numbers, street names, registration plate numbers, or names of relatives.
|
| Engine Policy | Use the Firewall Template Policy as the basis for creating a customized Engine Template Policy and security policies that are compliant with Common Criteria. For more information, see the topics in this document about creating a customized Engine Template Policy and creating a Engine Policy. See also the Creating and managing policy elements chapter and the Access rules chapter in the Forcepoint Network Security Platform Product Guide. |
| Web Access |
If you use the Web Access feature to use the SMC Client in a web browser, do the following:
For more details on Web Access configuration, refer to the Using the SMC Client in a web browser section in the Forcepoint Network Security Platform Product Guide. |
- rsa_pkcs1_with_sha256(0x0401)
- rsa_pkcs1with sha384(0x0501)
- rsa_pkcs1_with_sha512(0x0601)
- ecdsa_secp256r1_with_sha256(0x0403)
- ecdsa_secp384r1_with_sha384(0x0503)
- ecdsa_secp521r1_with_sha512(0x0603)
- rsa_pss_rsae_with_sha256(0x0804)
- rsa_pss_rsae_with_sha384(0x0805)
- rsa_pss_rsae_with_sha512(0x0806)
- rsa_pss_pss_with_sha256(0x0809)
- rsa_pss_pss_with_sha384(0x080a)
- rsa_pss_pss_with_sha512(0x080b)