12.07.2015 Views

L3 Box E* VPN Gateway for Confidential Communication - ZSIS

L3 Box E* VPN Gateway for Confidential Communication - ZSIS

L3 Box E* VPN Gateway for Confidential Communication - ZSIS

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

( <strong>Box</strong> S)<strong>L3</strong> <strong>Box</strong> <strong>E*</strong><strong>VPN</strong> <strong>Gateway</strong> <strong>for</strong> Confi dential<strong>Communication</strong>Benefits:» Approved up toCONFIDENTIAL» High per<strong>for</strong>mance» High availability» Increased temperatureranges» Switchable optical fibrenetwork interfaces» SINA Management inonline operationAs a <strong>VPN</strong> gateway, the SINA <strong>L3</strong> <strong>Box</strong> is a key component of the central IT infrastructure inhigh-security networks. The data exchanged between the SINA components is securelytransmitted via encrypted <strong>VPN</strong> tunnels. SINA <strong>L3</strong> <strong>Box</strong>es connect public authority orcorporate networks via public lines such as the Internet. Additionally, SINA <strong>L3</strong> <strong>Box</strong>escan be confi gured as cryptographic network access points <strong>for</strong> SINA clients to (terminal)servers.The SINA <strong>L3</strong> <strong>Box</strong> E and its predecessor, SINA <strong>Box</strong> S Zone 1, are the onlyIP-based encryption systems approved <strong>for</strong> transmitting classified in<strong>for</strong>mation<strong>for</strong> CONFIDENTIAL, NATO CONFIDENTIAL and CONFIDENTIEL UEclassification levels. Just like its predecessor, the SINA <strong>L3</strong> <strong>Box</strong> E also servesnational and international high security networks <strong>for</strong> public authorities.In direct comparison with the SINA <strong>Box</strong> S Zone 1 (19” 3U), the SINA <strong>L3</strong><strong>Box</strong> E is substantially more powerful and lighter with a more compact 19”,2U design. Due to the increased temperature ranges the SINA <strong>L3</strong> <strong>Box</strong> Eis more flexible to use. The fibre optic network interfaces can be switchedbetween 100 MBit/s and 1 GBit/s – this allows a flexible reaction in caseof network infrastructure changes. A new device variant now supportscopper network interfaces as well. More service-friendly features includerechargeable batteries that can be replaced without the need <strong>for</strong> subsequentre-tempestation.IT security conceptThe SINA <strong>L3</strong> <strong>Box</strong> E is based on an integrated IT security concept.In particular, this concept includes:▀ A hardened and intensively evaluated Linux system plat<strong>for</strong>m▀ Smart card technology▀ IPsec-based virtual private networks▀ Hardware, firmware and software scaled and configured according toapproval requirementsSecure system boot and operationDepending on the actual conditions of the IT infrastructure and projectspecificcommunications requirements, it is possible to use the SINA <strong>L3</strong><strong>Box</strong>es E with thousands of simultaneous security associations. Uponsystem start-up, the SINA <strong>L3</strong> <strong>Box</strong> software is securely loaded from flashmemory using Coreboot (SINA BIOS). All initial configuration data and


<strong>L3</strong> <strong>Box</strong> Esecurity associations <strong>for</strong> the SINA <strong>L3</strong> <strong>Box</strong> are stored in a protected areaof the SINA smart card. When a SINA <strong>L3</strong> <strong>Box</strong> is started, the security associationsto the SINA Management and the communications-related SINA<strong>L3</strong> <strong>Box</strong>es are set up as IPsec <strong>VPN</strong> tunnels. If necessary, additional securityassociations or configuration data can be downloaded from the SINAManagement. This greatly simplifies configuration, installation and hardwarereplacement with the SINA <strong>L3</strong> <strong>Box</strong>.Systems monitoringThe SINA <strong>L3</strong> <strong>Box</strong>es log all system-monitoring relevant data duringoperation. The syslog data can be imported into network managementsystems <strong>for</strong> further processing and/or displayed as required.High availabilityUsing redundant configurations it is possible to increase availability andsafeguard against failure of SINA <strong>L3</strong> <strong>Box</strong>es. An automatic switchovermode triggers a second SINA <strong>L3</strong> <strong>Box</strong> to take over the functions of thefailed, once active SINA <strong>L3</strong> <strong>Box</strong>.Satellite communicationThe use of SINA <strong>L3</strong> <strong>Box</strong>es requires IP-enabled transport networks, includingsatellite communication lines. Satellite optimisers support theeffective use of the available bandwidth of the satellite lines.ManagementThe SINA Management is used <strong>for</strong> central configuration of all SINA <strong>L3</strong><strong>Box</strong>es in the network. An integrated public key infrastructure (PKI) withthe corresponding user management supports the main administrativeprocesses, particularly the personalisation, generation and/or updating ofkeys and cryptographic parameters as well as the administration of associatedPINs and PUKs on the smart cards.Approval-related construction classesApproval levelFirmwareSoftware versions 2.2Manipulation protectionSINA <strong>L3</strong> <strong>Box</strong> E 400M Z1CONFIDENTIAL, NATO CONFIDENTIAL; CONFIDENTIEL UESINA BIOS (Coreboot)IntegratedTempest Zone 1 (SDIP 27 Level B)Authentication tokenNetwork interfacesItem numberGeneral technical dataSizeWeightPower consumptionCrypto hardwareEncryption per<strong>for</strong>manceSymmetric cryptographyAsymmetric cryptographyLAN connectionsNetwork interfacesSINA smart cardoptical fi bre, Cu**SB50.25; SB50.26Additional details and per<strong>for</strong>mance dataConnector typeAdapter cablesMiscellaneousService bay19” 2 U12 kg80 W400 MBit/sChiasmus, AESEC-GDSA, EC-DHTemperatureOperation +5 °C to +45 °CTransport -25 °C to +60 °C4 x 100/1000 MBit optical NICs (switchable) (SB50.25)4 x 10/100/1000 MBit Cu (SB50.26**)LCFor LC to SC plugs or <strong>for</strong> LC to ST plugs respectivelyFor rechargeable battery replacement(subsequent re-tempestation not required)* For further in<strong>for</strong>mation about the new naming concept refer to: www.secunet.com/en/sina.** The use of this device variant which is equipped with copper network interfaces and is approved <strong>for</strong> up to CONFIDENTIEL UE requires additional network infrastructuralprotection measures (as per IASG-04-01 and IASG-04-02). The use of nationally approved SINA <strong>L3</strong> <strong>Box</strong>es E (Germany) requires FO network interfaces.About SINAsecunet developed SINA – the Secure Inter-Network Architecture – <strong>for</strong>the German Federal Office <strong>for</strong> In<strong>for</strong>mation Security (BSI). The productfamily of crypto systems enables the secure processing, storage andtransmission of classified in<strong>for</strong>mation as well as other sensitive data –according to approval requirements.The product portfolio covers different gateways, line encryptors, clientsand management systems which have been in use in the public sector,armed <strong>for</strong>ces and companies handling classified in<strong>for</strong>mation <strong>for</strong> manyyears. Selected SINA components are approved <strong>for</strong> processing andtransmitting classified in<strong>for</strong>mation up to and including the classificationlevels NATO SECRET and SECRET UE.More in<strong>for</strong>mation:www.secunet.com/en/sinaSINA_<strong>L3</strong><strong>Box</strong>E_V1_09/12_GBsecunet Security Networks AGKronprinzenstraße 3045128 Essen, GermanyPhone: +49 - 201- 54 54 - 0Fax: +49 - 201- 54 54 -1000E-mail: info@secunet.comwww.secunet.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!