IntroductionThis guide describes the requirements and guidelines for configuring the Forcepoint Network Security Platform to comply with Common Criteria evaluation standards.
Evaluated capabilitiesThe Forcepoint Network Security Platform is comprised of several components that have specific capabilities that have been evaluated.
How Security Engine process trafficSecurity Engines permit or deny traffic according to Engine filtering rules that are contained in an Engine Policy. Rules match based on administrator defined properties of the traffic and the interface.
Establishing a security configuration A Common Criteria configuration that also meets IPsec VPN gateway requirements for Commercial Solutions for Classified (CSfC) solutions program requires a specific configuration of the SMC Appliance, SMC software, and Security Engines.
Secure the update processWhen applying appliance upgrades and patches, review and follow the guidance in the Forcepoint Network Security Platform Product Guide to ensure that the update is secure.
VPN Recovery Instructions In case VPN connection does not work, recovery should start from investigating why VPN tunnel is not established. Examining logging in detail gives indication of the underlying problem. Basic steps to follow are described below
Network processes Many network processes can run on the appliances while in an evaluated configuration.