Configure settings for an evaluated configuration

After installing the SMC, several areas of the configuration must be configured specifically for a Common Criteria evaluated configuration by using the SMC Client.

Setting Configuration
Time Management

You can set the time manually on the SMC Appliance or you can use NTP time synchronization. By default, the Security Engine receives the time from the SMC Appliance. You can optionally also configure NTP time synchronization for the Security Engine.

To use NTP time synchronization, follow the guidelines in the following topics in the Configuring system communications chapter in the Forcepoint Network Security Platform Product Guide:

  • Create NTP Server elements
  • Enable NTP time synchronization on the SMC Appliance
  • Enable NTP time synchronization for Forcepoint Network Security Platform Engines
Note:
  • Ensure that NTP is disabled for the servers if it is not used.
  • Ensure that only secure NTP servers are selected if you are using NTP.
  • Pre-configured NTP servers cannot be used as they do not use authentication keys.
Time Management (continued)

The NTP implementation for both the SMC Appliance and the Security Engine is an NTP client only. NTP clients support communication with NTPv4 servers. By default, the SMC Appliance and Security Engine NTP clients do not update their times based on multicast or broadcast NTP packets.

The NTP server must use only the SHA-1 authentication key. In the properties of the NTP Server element, select SHA1 from the Key Type drop down list.

For redundancy, you can configure multiple NTP servers. Create one NTP Server element for each NTP server. When enabling NTP time synchronization on the SMC Appliance, select all of the NTP Server elements.

Time Management (continued)
To set the date and time manually on the SMC Appliance, enter:
sudo date -s '<Day Mon DD hh:mm:ss [TZ] [YYYY]>'
where <Day Mon DD hh:mm:ss [TZ] [YYYY]> is the day of week, month, day of month, time, optional time zone and optional year.
Audit Server Configuration

Follow the guidelines in the following topics and chapters in the Forcepoint Network Security Platform Product Guide:

  • Configuring the Log Server chapter
  • Using certificates to secure communications to external components topic in the Managing certificates for system communications chapter
  • Forward audit data from Management Servers to external hosts topic in the Reconfiguring the SMC and engines chapter

When setting the options for log or audit data forwarding in the properties of the Management Server or Log Server, select Use Internal Certificate or Use Imported Certificate as the TLS certificate to use.

Forcepoint Network Security Platform supports OCSP and CRL revocations for X509v3 certificate validation during negotiation of TLS protected syslog. When handling a certificate bearing OCSP revocation but where Forcepoint Network Security Platform cannot establish a connection with the OCSP responder, Forcepoint Network Security Platform will not accept the certificate (and thus not establish the connection). When handling certificates bearing CRL information but where Forcepoint Network Security Platform cannot establish a connection to the CRL Distribution Point location, Forcepoint Network Security Platform will not accept the certificate as valid. Forcepoint Network Security Platform constructs the certificate path to a trusted certificate, and then verifies the signature, checks the revocation status, validity period, issuer’s name, extended key usage and basic constraints for each certificate starting from the trusted certificate.

Audit Server Configuration (continued)

1) Configure the trusted root CA certificate for the audit server.

See the Create Trusted Certificate Authority elements topic in the Managing certificates for system communications chapter in the Forcepoint Network Security Platform Product Guide

Audit Server Configuration (continued)

2) If using an imported certificate, configure the trusted CA certificates for the client certificate.

3) If using an imported certificate, generate the client certificate request.

  • See the Create a certificate request topic in the Managing certificates for system communications chapter in the Forcepoint Network Security Platform Product Guide.
  • Select either RSA or ECDSA based algorithm. For RSA available key sizes are 2048, 3072 or 4096 bits. For ECDSA available key sizes are 256 bits for P-256, 384 bits for P-384 and 521 bits for P-521.
  • The target of evaluation generates certificate requests that include a public key, Common Name, Organization, Organizational Unit, Country and device-specific information in the form of Subject Alternative Name.
Note: After creating a certificate request, you must close and re-open the SMC Client in order to export the certificate request.
Audit Server Configuration (continued) 4) Configure the TLS profile using TLS 1.2.
  • The cipher suites that can be used:
    Important:
    • Ensure that the TLS cipher suites that is selected match the RSA and ECDSA parameters that are configured.
    • When using an ECDHE cipher suite, P-256, P-384, and P-521 are automatically used in the TLS key establishment.
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
    • TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
    • TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  • Select the trusted CAs.
  • Select Check Revocation.
  • You must not select these settings in the evaluated configuration:
    • Delay CRL Fetching For
    • Ignore OCSP Failures For
    • Ignore Revocation Check Failures if There Are Connectivity Problems

To use certificate revocation checks, peer certificates must contain the correct CRL Distribution Points extension that refers to a valid CRL Distribution point. The environment must be configured so that the SMC can access the referenced CRL distribution points. If a TLS connection cannot be established because the connection to the CRL server fails, verify the network path to the CRL server and the status of the server, and fix any issues.

Audit Server Configuration (continued) 5) Configure the server identity. Define the following settings for the TLS Server Identity:
  • TLS Server Identity — DNS Name or IP Address.
  • Identity Value — the DNS name or IP address of the audit server.

For more information, see the Configure TLS server identity topic in the Managing certificates for system communications chapter in the Forcepoint Network Security Platform Product Guide.

To complete the configuration select OK in the server properties dialog box. The Log forwarding starts automatically.

Audit Server Configuration (continued)

If the log or audit data forwarding connection to the audit server is not working, do the following:

  • In the properties of the Management Server, verify the settings on the Audit Forwarding tab.
  • In the properties of the Log Server, verify the settings on the Log Forwarding tab.
  • Restart the Management Server on the local console. Use the command:

    sudo daemon-ctl restart sgMgtServer

  • Restart the Log Server on the local console. Use the command:

    sudo daemon-ctl restart sgLogServer

Logon Banner
To configure the Logon Banner, complete the following steps:
  1. In the SMC Client, select Settings > Global System Properties.
  2. Click the Banners tab.
  3. Select the Show Logon Banner checkbox and add a text to be shown on login screens in the text field below the Show Logon Banner checkbox.
  4. Click the OK button.
Administrative Logins

Follow the guidelines in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide.

Use the SMC Client to manage users and passwords in the SMC. The local console user accounts are synchronized with the user accounts used in the SMC. The local console accounts and passwords are managed from the SMC.

Only SMC user accounts with unrestricted permissions are available on the SMC Appliance local console.
Note: When the SMC Appliance Superuser option is selected, the administrator can log in to the SMC Appliance command line. Administrators with unrestricted permissions (superusers) are permitted to log in to the SMC Appliance command line only if there are no other administrators with SMC Appliance Superuser permissions active.
Administrative Logins (continued)
To specify the timeout to terminate an inactive local administrative session, enter:
TMOUT=<TIMEOUT>;echo "export TMOUT=$TMOUT" >> ~/.bashrc;logger -s -p
local3.info "changed console timeout to $TMOUT"
where <TIMEOUT> is the timeout in seconds.

To enable temporarily locking administrator accounts after a certain amount of failed logon attempts:

  1. In the SMC Client, select Settings > Global System Properties.
  2. On the Password Policy tab, select Enforce Password Settings for All the Administrators and Web Portal Users.
  3. In the Logon options section, select Temporarily Lock Account After Failed Logon Attempts.
  4. Enter the maximum number of failed logon attempts, and set how long to lock the account for.
  5. Click OK.
Note: If the administrator account is locked, it is still possible to log on to the SMC Appliance through the local console.

To enable and specify the inactivity timeout for remote administrative sessions:

  1. In the SMC Client, select Settings > Global System Properties.
  2. On the Password Policy tab, select Enforce Password Settings for All the Administrators and Web Portal Users.
  3. In the Logon options section, select Lock the SMC Client Window After the User Session is Idle for and select Close the SMC Client.
  4. Select the time unit and enter the inactivity timeout in the selected time units.
  5. Click OK.

For information about setting timeouts in the SMC Client and locking administrator accounts, see the Enable and define password policy settings topic in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide

Administrative Logins (continued)

To manually log out of the local console account, enter:

logout

To log out of the SMC Client, select Admin User Menu > Exit.

Password Guidelines

Follow the guidelines in the Enable and define password policy settings topic in the Administrator accounts chapter in the Forcepoint Network Security Platform Product Guide.

When setting a password, you should select a password that meets these requirements:

  • Minimum ten characters long
  • At least one uppercase character
  • At least one number
  • At least one special character: "!", "@", "#", "$", "%", "^", "&", "*", "(", ")"
  • Cannot be the same as the user name

By default, Forcepoint Network Security Platform enforces a minimum password length of 10 characters. The minimum password length is configurable from 1 to 80 characters. When operating in a Common Criteria evaluated configuration, we recommend that you set the minimum password length to 15 characters. Configure the Minimum Number of Required Characters setting to enforce these recommendations.

Note: Use strong passwords that are at least 15 characters long and contain a combination of numbers, letters, and special characters. Do not base passwords on personal information such as names, birthdays, ID numbers, phone numbers, street names, registration plate numbers, or names of relatives.
Engine Policy Use the Firewall Template Policy as the basis for creating a customized Engine Template Policy and security policies that are compliant with Common Criteria. For more information, see the topics in this document about creating a customized Engine Template Policy and creating a Engine Policy. See also the Creating and managing policy elements chapter and the Access rules chapter in the Forcepoint Network Security Platform Product Guide.
Web Access
If you use the Web Access feature to use the SMC Client in a web browser, do the following:
  • In the Management Server Properties dialog-box, click the Web Access tab.
  • Select the Enable checkbox.
  • Select the Use Internal Certificate checkbox to use the same certificate that is issued for the Management Server.
  • Select only the following algorithms for the TLS Cryptography Suite Set element:
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
  • Click OK.

For more details on Web Access configuration, refer to the Using the SMC Client in a web browser section in the Forcepoint Network Security Platform Product Guide.

Additionally, when SMC acts as the TLS client for log or audit data forwarding, the list of supported algorithms in the TLS signature_algorithms extension is fixed to:
  • rsa_pkcs1_with_sha256(0x0401)
  • rsa_pkcs1with sha384(0x0501)
  • rsa_pkcs1_with_sha512(0x0601)
  • ecdsa_secp256r1_with_sha256(0x0403)
  • ecdsa_secp384r1_with_sha384(0x0503)
  • ecdsa_secp521r1_with_sha512(0x0603)
  • rsa_pss_rsae_with_sha256(0x0804)
  • rsa_pss_rsae_with_sha384(0x0805)
  • rsa_pss_rsae_with_sha512(0x0806)
  • rsa_pss_pss_with_sha256(0x0809)
  • rsa_pss_pss_with_sha384(0x080a)
  • rsa_pss_pss_with_sha512(0x080b)