
Appliance management
The table below pro
vides guidance for configuring features used in managing y
our appliance.
Table 3-3 Appliance management
Feature Guidance
Time and date To maintain compliance with the TOE configuration NTP Servers should not
be configured. The administrator should set the time and date manually,
and ensure it is check
ed regularly to adjust any time drift. The connection
between the TOE and NTP servers does not support encryption.
Application
management remote
access
The use of SSH and out‑of‑band management for remote access is not
supported in the TOE. Therefore, these features should not be enabled.
Load balancing An additional role, Scanning Appliance Administrator, becomes available
if load balancing is enabled. However, this role is not relevant to operation
in accordance with the evaluated configuration.
User management
The table below pro
vides guidance to assist y
ou in configuring and managing users
Table 3-4 Users
Feature Guidance
Directory services menu
(authentication groups)
Directory services is not supported in the evaluated configuration because
the security of the external directory servers cannot be assured.
Therefore, this feature should not be enabled.
W
eb user authentication
menu (authentication
groups)
Web user authentication (through RADIUS, Kerberos, NTLM, LDAP, or
Microsoft Active Directory) is not supported in the TOE because the
security of the external authentication servers cannot be assured.
Therefore, these features should not be enabled.
Policy groups menu Specifying LDAP groups for policies based on group membership is not
supported in the TOE because the security of the external LDAP servers
cannot be assured. Therefore, LDAP groups should not be configured in
policy groups.
Role‑based user accounts The password requirements for user accounts and roles to adhere to the
TOE are as follows:
• Minimum length of six characters
• Include either numeric or special characters
Virtual hosting No further guidance is necessary in addition to that provided in the
McAfee Email Gateway 7.0 Appliances Administrators Guide.
Logs, alerts, and SNMP
This section provides additional information to help you configure and manage logs and alerts.
All relevant logs are contained within the Message logs and the System logs.
The Message logs include the following information for each event recorded:
• Date/time • Source IP address
• Sender • Properties
Maintaining a TOE configuration
Logs, alerts, and SNMP
3
McAfee
®
Email Gateway 7.0.1 Common Criteria Ev
aluated Configuration Guide
Appliances
19
Commentaires sur ces manuels