SV3800, SV3800B, and SV3800B-20 Security Policy
2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
14
Table 2
–2 SV3800/SV3800B/SV3800B-20 Appliance Configurations
Appliance Model
Appliance Type
Hardware Version
SV3800
Hardware Appliance
090-03064
SV3800
Try-and-Buy
Appliance
080-03563
SV3800
Cold Standby
Appliance
080-03679
SV3800B
Hardware Appliance
090-03550
SV3800B
Try-and-Buy
Appliance
080-03782
SV3800B
Cold Standby
Appliance
080-03787
SV3800B-20
Hardware Appliance
090-03551
SV3800B-20
Try-and-Buy
Appliance
080-03783
SV3800B-20
Cold Standby
Appliance
080-03788
The Crypto Officer and User services of the module are identical for both
appliance types. A Try-And-Buy appliance varies from the Hardware Appliance
only in that the firmware that is provided with the appliance is valid for 60 days,
after which the full license must be purchased or the hardware appliance must be
returned to Symantec. A Cold Standby appliance varies only in there is no valid
license. For the Cold Standby Appliance to become active, a license must be
acquired to convert the Cold Standby to an active Hardware Appliance. For each
appliance model, the hardware is the same for all appliance types. The Crypto
Officer and User services of the module are identical for all appliance types.
The SV3800/SV3800B/SV3800B-20 is a high performance transparent SSL/TLS
proxy that can be deployed in both Gigabit Ethernet and 10G Ethernet networks.
The SV3800/SV3800B/SV3800B-20 is a 2U high rack mountable device.
The SV3800/SV3800B/SV3800B-20 has seven front facing modular I/O bays that
allow for flexibility in the number of network interfaces and in the type of media
supported. Network I/O Modules (Netmods) are installed in the seven bays to
configure the desired combination of interfaces.
All of the Netmod interfaces and the switching module that plug into the front of
the SV3800/SV3800B/SV3800B-20 connect to the network segments on which
traffic is being monitored/ inspected. These ports are only used to access the
network data that is being processed by the SV3800/SV3800B/SV3800B-20; they
are not associated with any cryptographic processes, keys, critical security
parameters (CSP) or any FIPS relevant data.
These ports do not allow access to the management services of the SV3800 and
cannot be used to input or output cryptographic keys, CSPs or any FIPS relevant
data. The Netmods and associated switch are therefore deemed to be outside the
logical cryptographic boundary.