Validated Product - Check Point VPN-1/FireWall-1 NGX

Certificate Date: 25 August 2006

Validation Report Number: CCEVS-VR-06-0033

Product Type: Firewall, IDS/IPS, VPN

Conformance Claim: EAL4 Augmented with ALC_FLR.3

PP Identifier: Intrusion Detection System System Protection Profile, Version 1.5 (Archived)

CC Testing Lab: SAIC Common Criteria Testing Laboratory


PRODUCT DESCRIPTION

The TOE is one or more network boundary devices managed remotely by a management server, using management GUI interfaces. The product provides controlled connectivity between two or more network environments. It mediates information flows between clients and servers located on internal and external networks governed by the firewalls.

The claimed security functionality described in the Security Target is a subset of the product's full functionality. The evaluated configuration is a subset of the possible configurations of the product, established according to the evaluated configuration guidance.

The security functionality within the scope of the evaluation included information flow control using stateful inspection and application proxies, IKE/IPSec Virtual Private Networking (VPN) in both gateway to gateway and Remote Access configurations, Intrusion Detection and Prevention (IDS/IPS). Additionally, the TOE provides auditing and centralized management functionality.

SECURITY EVALUATION SUMMARY

The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the TOEmeets the security requirements contained in the Security Target. The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the TOE is EAL 4 augmented with ALC_FLR.3. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target. Several validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in July 2006. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Check Point VPN-1/FireWall-1 NGX (R60) HFA 03 prepared by CCEVS.

ENVIRONMENTAL STRENGTHS

Check Point VPN-1/Firewall-1 NGX (R60) HFA 03 is commercial boundary protection device that provide information flow control, security management, Protection of the TSF, cryptographic functionality, audit security functions, and explicit intrusion detection functionality. Check Point VPN-1/FireWall-1 NGX (R60) HFA 03 provides a level of protection that is appropriate for IT environments that require that information flows be controlled and restricted among network nodes where the Check Point components can be appropriately protected from physical attacks.

Check Point Softare Technologies Ltd.

Wendi Ittah
703-859-6748
wittah@us.checkpoint.com

http://www.checkpoint.com