Attachment_5_Library_LMS_USGV6-v1-sdoc-v1.10.xlsx

XLSX spreadsheet 67 KB Posted

Attached to
Library Management System Federal contract opportunity
Solicitation number
ADMIN-18-0087
Issued by
Department of Commerce US Census Bureau

About this file

ATTACHMENT 5

View the file

Other files for this federal contract opportunity

Other files attached to Library Management System, newest first.
File Type Posted
Library_LMS_RFP_Q&A.docx DOCX document
Attachment_4_Library_LMS_NIST_ITSPP_MP_controls.xlsx XLSX spreadsheet
Attachment_3_Library_LMS_Section_J.xlsx XLSX spreadsheet
Attachment_1_Library_LMS_Section_J.docx DOCX document
Attachment_2_Library_LMS_Section_J.docx DOCX document
RFP_ADMIN-18-0087.docx DOCX document
SF1449_RFP__ADMIN-18-0087.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Product Summary

Suppliers Declaration of Conformity for USGv6 ProductsUSGv6-v1 SDOC-v1.10 Page 1
1The Document Requiring Conformity:USGv6 Profile Version 1.0, July 2008. (NIST SP500-267)
2Product Identifier:
3Supplier's Name, Address and SDOC Contact Details

4 Product as Tested/Declared: Product Identifier, version/revision information, details of configuration tested.

5 Product Family (other products using same IPv6 stack(s) to which these results are declared to apply). Check Product Family attestation below.

6 USGv6 Capability summary. (For each distinct IPv6 stack in the product provide a summary of its USGv6 capabilities below and include a detailed test result summary). e.g. example-prod-id/stack-1: USGv6-v1-Host: IPv6-Base+Addr-Arch+IPsec-v3+IKEv2+SLAC+Link=Ethernet.

7Self Contained or Composite SDOC? (Must indicate one).
All of the declared USGv6 capabilities of this product are addressed by orginal test results reported in this SDOC.Some or all of the USGv6 capabilities of this product are provided by the use and/or integration of umodified components that have their own unique USGv6 SDOCs. All of the relevant referenced SDOCs are identified in section 8 and attached. This product's page 2 will indicate which capabilities are provided by specific referenced components (product-id/stack-id).
8Additional Declarations / Attachments: (List supplier & product-id/stack-id for referenced and attached test results in the case of composite products).
Component SupplierProduct ID:Stack ID:Notes:
[1]
[2]
[3]
[4]
9Supplementary Attestations (Answer all).
This product is fully functional in dual stack environments.That is, no claimed capabilities are invalidated ifthis product is operated in a dual stack (6 and 4)network environment.This product is fully functional in IPv6 only environments. That is, no claimed capabilities are invalidated if this product is deployed in a network environment that does not support Ipv4.
This SDOC contains a capabilities test report for each unique IPv6 stack in the product. If not, the stacks/ports not covered are documented, and how their Ipv6 capabilities differ from those reported are explained.All of the products listed in the product family in section 5 are implemented such that their USGv6 capabilities are identical in form and function across the entire product family. The specific conformance and interoperability test results for the USGv6 capabilities of an identified member of this product family are provided in this SDOC. The SDOC attests that these tested USGv6 capabilitiesare identical and unmodified for all the products cited above.
10SignatureDate
Print Name / Title
See instructions for fields 1-12 on Page 4.

Stack-1 DOC

11Suppliers Declaration of Conformity for USGv6 Products: Declared Capabilities and Test Results SummaryUSGv6-v1 SDOC-v1.10 Page 2
Product Id:Stack Id:
Spec / ReferenceContext /Supported CapabilitiesUSGv6 Testing Program Results
SectionUSGv6-v1 Profile RequirementsConfiguration OptionHostRouterNPDTest Suite Conformance/NPDTest Lab / Result ID, Note #, or Component RefTest Suite InteroperabilityTest Lab / Result ID, Note #, or Component Ref
SP500-2676.1IPv6 Basic Requirements
support of IPv6 base (IPv6;ICMPv6;PMTU;ND)IPv6-BaseBasic_v1.*_CBasic_V1.*_I
support of PMTU Discovery Protocol requirementsPMTUBasic_v1.*_CBasic_V1.*_I
support of stateless address auto-configurationSLAACSLAAC-V1.*_CSLAAC-V1.*_I
support of Creation of Global AddressesSLAAC - c(M)SLAAC-V1.*_CSLAAC-V1.*_I
support of SLAAC privacy extensions.PrivAddrSelf TestSelf Test
support of stateful (DHCP) address auto-configurationDHCP-ClientDHCP_Client_v1.*_CDHCP_Client_v1.*_I
support of automated router prefix delegationDHCP-PrefixSelf TestSelf Test
support of neighbor discovery security extensionsSENDSelf TestSelf Test
SP500-2676.6Addressing Requirements
support of addressing architecture reqtsAddr-ArchAddr_Arch_v1.*_CAddr_Arch_v1.*_I
support of cryptographically generated addressesCGASelf TestSelf Test
SP500-2676.7IP Security Requirements
support of the IP security architectureIPsecv3IPsecv3_v1.*_CIPsecv3_v1.*_I
support for automated key managementIKEv2IKEv2_v1.*_CIKEv2_v2.*_I
support for encapsulating security payloads in IPESPESPv3_v1.*_CESP_v1.*_I
SP500-2676.11Application Requirements
support of DNS client/resolver functionsDNS-ClientSelf TestSelf Test
support of Socket application program interfacesSOCKSelf TestSelf Test
support of IPv6 uniform resource identifiersURISelf TestSelf Test
support of a DNS server applicationDNS-ServerSelf TestSelf Test
support of a DHCP server applicationDHCP-ServerSelf TestDHCP_Serv_v1.*_I
SP500-2676.2Routing Protocol Requirements
support of the intra-domain (interior) routing protocolsIGWSelf TestOSPFv3_v1.*_I
support for inter-domain (exterior) routing protocolsEGWSelf TestBGP_v1.*_I
SP500-2676.4Transition Mechanism Requirements
support of interoperation with IPv4-only systemsIPv4Self TestSelf Test
support of tunneling IPv6 over IPv4 MPLS services6PESelf TestSelf Test
SP500-2676.8Network Management RequirementsSelf Test
support of network management servicesSNMPSelf TestSelf Test
SP500-2676.9Multicast Requirements
support of basic multicastMcastSelf Test
full support of multicast communicationsSSMSelf TestSelf Test
SP500-2676.10Mobility Requirements
support of mobile IP capability.MIPSelf TestSelf Test
support of mobile network capabilitiesNEMOSelf TestSelf Test
SP500-2676.3Quality of Service Requirements
support of Differentiated Services capabilitiesDSSelf TestSelf Test
SP500-2676.12Network Protection Device Requirements
support of common NPD reqtsNPDN1|N2|N3|N4_v1.3
support of basic firewall capabilitiesFWN1_FW_v1.3
support of application firewall capabilitiesAPFWSelf Test
support of intrusion detection capabilitiesIDSN3_IDS_v1.3
support of intrusion protection capabilitiesIPSN4_IPS_v1.3
SP500-2676.5Link Specific Technologies
support of robust packet compression servicesROHCSelf TestSelf Test
support of link technology [O:1]Link=Self TestSelf Test
(repeat as needed) support of link technologyLink=
12< Check HERE if this stack's DOC includes additional information about tested capabilities and options on an attached page 3 of notes.
LevelLevel of support for USGv6-v1 Requirements for capability.ColorIndication of USGv6-v1 Recommended Level of Support for device type / stack role.
Blank - SDOC makes no declaration for this capability.Indicates capability that is recommendend as mandatory (unconditional MUST) in the USGv6-v1 Profile.
PPassed required tests of USGv6-V1 requirements for these capabilities.Indicates cabability that is unusal for a given device type / stack role. Do not select without careful analysis.
NSee notes page for details on the level of support of USGv6-v1 reequirements for this capability.Indicates capability that is left optional / ocnditional by the recommedations of the USGv6-v1 Profile.
XUSGv6 capability not supported in product.
Test Suite - Specific USGv6 Test suite used for test. See: http://www.antd.nist.gov/usgv6/test-specifications.htmlNote # - reference to a detailed note about this capability or result on attached page.
Test Lab / Result ID - Abbreviation of accredited laboratory and its local identifier for this test result.Component Ref - Supplier / Product / Stack ID of distinctly tested component that provides this capability.

Stack-1 Notes

Suppliers Declaration of Conformity for USGv6 Products: Notes Page and Detailed Test Results SummaryUSGv6-v1 SDOC-v1.10 Page 3
FieldProduct Id:Stack Id:
13Spec / ReferenceContext /Supported CapabilitiesNotes about USGv6-v1 Capabilities.
Note #SectionUSGv6-v1 Profile RequirementsConfiguration OptionHostRouterNPDTest Suite Conformance/NPDTest Lab / Result ID, NoteTest Suite InteroperabilityTest Lab / Result ID, Note
1
Discussion:
2
Discussion:
3
Discussion:
4
Discussion:
5
Discussion:
6
Discussion:
7
Discussion:
8
Discussion:
9
Discussion:
10
Discussion:
Vendor's General Notes / Discussion about this Product / Stack's capabilities:
Spec / ReferenceUSGv6-v1 RequirementsContext /USGv6-V1 Rec
SectionTitle / DefinitionConfiguration OptionHostRouterNPDNotes about requested USGv6-v1 Capabilities.
IPv6 Basic Requirements
RFC2460IPv6 SpecificationIPv6-BaseMM
2IPv6 Packets: send, receiveIPv6-BaseMM
2IPv6 packet forwardingIPv6-BaseM
4Extension headers: processingIPv6-BaseMM
4.3Hop-by-Hop & unrecognized optionsIPv6-BaseMM
4.5Fragment headers: send, receive, processIPv6-BaseMM
4.6Destination Options extensionsIPv6-BaseMM
RFC5095Deprecation of Type 0 Routing HeadersIPv6-BaseMM
RFC2711IPv6 Router Alert OptionIPv6-BaseM
RFC4443ICMPv6IPv6-BaseMM
RFC4884Extended ICMP for Multi-Part MessagesS+S+
RFC1981Path MTU Discovery for IPv6IPv6-BaseMM
4Discovery Protocol RequirementsIPv6-BaseMS+
RFC2675IPv6 JumbogramsOO
RFC4861Neighbor Discovery for IPv6IPv6-BaseMM
4.1, 4.2Router DiscoveryIPv6-BaseMM
4.6.2Prefix DiscoveryIPv6-BaseMM
7.2Address ResolutionIPv6-BaseMM
7.2.5NA and NS processingIPv6-BaseMM
(RFC4862)7.2.3Duplicate Address DetectionIPv6-BaseMM
7.3Neighbor Unreachability DetectionIPv6-BaseMM
8Redirect functionalitySM
RFC5175IPv6 Router Advertisement Flags OptionSS
RFC4191Default Router PreferenceS+S+
RFC3971Secure Neighbor DiscoverySENDc(M)c(M)
Auto Configuration
RFC4862IPv6 Stateless Address AutoconfigSLAACc(M)
5.3Creation of Link Local AddressesSLAACMM
(RFC4861)5.4Duplicate Address DetectionSLAACMM
5.5Creation of Global AddressesSLAACc(M)
*Ability to Disable Creation of Global AddrsSLAACc(M)
RFC4941Privacy Extensions for IPv6 SLAACSLAAC & PriAddrc(M)
*<2nd context for MIP Mobile Node>SLAAC & MIPc(S+)

RFC3736 Stateless DHCP Service for IPv6 SLAAC c(S+)

RFC3315Dynamic Host Config Protocol (DHCPv6)DHCP-Clientc(M)
*Ability to Administratively DisableDHCP-Clientc(M)
DHCP Client FunctionsDHCP-Clientc(M)
RFC4361Node-specific Client IDs for DHCPv4DHCP-Client & IPv4c(S+)
RFC3633Prefix DelegationDHCP-Prefixc(M,S+)
Addressing Requirements
RFC4291IPv6 Addressing ArchitectureAddr-ArchMM
RFC4007IPv6 Scoped Address ArchitectureAddr-ArchMM
*Ability to manually configure AddressesAddr-ArchMM
RFC4193Unique Local IPv6 Unicast AddressOO
RFC3879Deprecating Site Local AddressesAddr-ArchMM
RFC3484Default Address Selection for IPv6Addr-ArchMM
2.1Configurable Selection PoliciesS+S+
RFC2526Reserved IPv6 Subnet Anycast AddressesAddr-ArchMM
RFC3972Cryptographically Generated AddressesSEND or CGAc(M)c(M)
RFC4581(CGA) Extension Field FormatSEND or CGAc(M)c(M)
RFC4982(CGA) Support for Multiple Hash Algos.SEND or CGAc(M)c(M)
Application Requirements
RFC3596DNS Extensions for IPv6DNS-Clientc(M)c(M)
2.1Support of AAAA recordsDNS-Clientc(M)c(M)
2.5Support of ipv6.arpa PTR recordsDNS-Clientc(M)c(M)
RFC2671Extension Mechanisms for DNS (EDNS0)DNS-Clientc(M)c(M)
RFC3226DNSSEC and IPv6 DNS MSG Size ReqsDNS-Clientc(M)c(M)
RFC3986URI: Generic SyntaxURIc(M)c(M)
RFC3493Basic Socket API for IPv6SOCKc(M)
RFC3542Advanced Socket API for IPv6SOCK & MIPc(M)
RFC4584Extension to Sockets API for Mobile IPv6SOCK & MIPc(M)
RFC3678Socket API Extensions Multicast Source FiltersSOCK & SSMc(M)
RFC5014Socket API for Source Address SelectionSOCKc(S+)
Specific Applications
RFC3596DNS Server FunctionsDNS-Serverc(M)c(M)
RFC3315DHCPv6 Server FunctionsDHCP-Serverc(M)c(M)

Routing Protocol Requirements

Interior Routing Protocol
RFC2740OSPF for IPv6IGWc(M)
RFC4552Authentication/Confidentiality for OSPFv3IGWc(M)
Exterior Routing Protocol
RFC4271Border Gateway Protocol 4 (BGP-4)EGW or 6PEc(M)
RFC1772BGP Application in the InternetEGW or 6PEc(M)
RFC4760BGP Multi-Protocol ExtensionsEGW or 6PEc(M)
RFC2545BGP Multi-Protocol Extensions for IPv6 IDREGW or 6PEc(M)
IP Security Requirements
IPsec-v3
RFC4301Security Architecture for the IPMM
4.1Support of Transport Mode SAsIGW or IPv4Mc(M)
4.5.1Manual SA and Key ManagementMM
4.5.2Automated SA and Key ManagementMM
RFC4303Encapsulating Security Payload (ESP)IPsec-v3MM
RFC4302Authentication Header (AH)IPsec-v3OO
RFC3948UDP Encapsulation of ESP PacketsIPsec-v3OO
RFC4835Cryptographic Algorithms for ESP and AHIPsec-v3MM
*(See additional 4835 requirements below)
RFC4308Cryptographic Suites for IPsecIPsec-v3OO
2.1VPN-AIPsec-v3SS
2.2VPN-BIPsec-v3S+S+
RFC4869Suite B Cryptographic Suites for IPsecIPsec-v3OO
RFC4809Requirements for an IPsec Cert Mgmnt ProfileIPsec-v3S+S+
IKEv2
RFC4306Internet Key Exchange (IKEv2) ProtocolIKEv2MM
4Pre-shared secrets for peer authenticationIKEv2MM
4RSA sig authIKEv2MM
4NAT-T in IKEv2IKEv2OO
3.3.3ESNIKEv2MM
RFC4718IKEv2 Clarifications & Impl. GuidelinesIKEv2SS
RFC4307Cryptographic Algorithms for IKEv2IKEv2MM
(See additional 4307 requirements below)
RFC3526More MODP DH Groups for IKEIKEv2SS
RFC5114Additional DH Groups for Use with IETF StdsIKEv2OO
2.3,3.2Diffie-Hellman MODP group 24IKEv2MM
RFC4945Internet IPsec PKI Profile of IKEv1, IKEv2 & PKIXIKEv2S+S+
Uses of Cryptographic Algorithms
RFC2410NULL EncryptionMM
RFC48353.1.1NULL EncryptionESPMM
RFC2451ESP CBC-mode AlgorithmsMM
2.63DES-CBCESPMM
RFC48353.1.13DES-CBCESPMM
RFC43073.1.13DES-CBCIKEv2MM
RFC3602AES-CBCMM
RFC48353.1.1AES-CBC with 128 bit keysESPMM
RFC43073.1.1AES-CBC with 128 bit keysIKEv2MM
RFC3686AES-CTRSS
RFC48353.1.1AES-CTR with 128-bit keysESPSS
RFC43073.1.3AES-CTR with 128-bit keysIKEv2SS
RFC4309AES-CCMOO
RFC48353.1.2AES-CCM with 128 bit keysESPOO
RFC4106AES-GCMOO
6128-bit ICVESPOO
8.1AES-GCM with 128 bit keysESPOO
RFC4543AES-GMACOO
5.4ENCR-NULL-AUTH-AES-GMAC 128 bit keysESPOO
5.4AUTH-AES-GMAC with 128 bit keysAHOO
RFC2404HMAC-SHA-1-96MM
RFC48353.1.1/3.2HMAC-SHA-1ESP or AHMM
RFC43073.1.1HMAC-SHA-1IKEv2MM
RFC43073.1.4HMAC-SHA-1 as a PRFIKEv2MM
RFC4868HMAC-SHA-256S+S+
2.3HMAC-SHA-256-128ESP or AHS+S+
2.3HMAC-SHA-256-128IKEv2S+S+
2.4HMAC-SHA-256 as a PRFIKEv2S+S+
RFC3566AES-XCBC-MAC-96S+S+
RFC48353.1.1/3.2AES-XCBC-MAC-96ESP or AHS+S+
RFC43073.1.5AES-XCBC-MAC-96IKEv2S+S+
RFC4434AES-XCBC-PRF-128S+S+
RFC43073.1.4AES128-XCBC-PRFIKEv2S+S+
Transition Mechanisms Requirements
RFC4038Application Aspects of IPv6 TransitionIPv4S
RFC4213Transition Mech. for Hosts & RoutersIPv4c(M)c(M)
2Dual Stack IPv4 and IPv6IPv4c(M)c(M)
3Configured TunnelsIPv4c(S)c(M)
RFC4891Using IPsec to Secure IPv6-in-IPv4 TunnelsIPv4c(S)c(M)
RFC2473Generic Packet Tunneling in IPv6IPv4c(M)
RFC2784Generic Routing EncapsulationIPv4c(S+)
IPv6 Provider Edge MPLS Tunneling
RFC4798Connecting IPv6 islands over IPv4 MPLS (6PE)IPv4 & 6PEc(M)
Network Management Requirements
RFC3411SNMP v3 Management FrameworkSNMPc(M)M
RFC3412SNMP Message Process and DispatchSNMPc(M)M
RFC3413SNMP ApplicationsSNMPc(M)M
1.2Command ResponderSNMPc(M)M
1.3Notification GeneratorSNMPc(S)M
RFC3414User-based Security Model for SNMPv3SNMPc(M)M
Management Information Bases
RFC4293MIB for the IPSNMPc(M)M
RFC4292MIB for IP Forwarding TableSNMPM
RFC4022MIB for TCPSNMPc(S+)S+
RFC4113MIB for UDPSNMPc(S+)S+
RFC4087MIB for IP TunnelsSNMP & IPv4c(M)
RFC4807MIB for IPsec Policy Database ConfigurationSNMP & IPsec-v3M
RFC4295MIB for Mobile IPSNMP & MIPc(M)
RFC3289MIB for DiffServSNMP & DSM
Multicast Requirements
RFC3810MLD Version 2 for IPv6McastMM
RFC3306Unicast-Prefix-based IPv6 Mcast AddressesMcastMM
RFC3307Allocation Guidelines for IPv6 Mcast AddrsMcastMM
RFC4607Source-Specific Multicast for IPSSMc(M)c(M)
RFC4604MLDv2 for Source Specific Multicast (SSM)SSMc(M)c(M)
Protocol Independent Multicast (PIM)
RFC4601PIM Sparse Mode (SM)SSMc(S+)
RFC4609PIM-SM Security Issues / EnhancementsSSMc(S)
RFC3956Embedding Rendezvous Point (RP) Mcast AddrSSMc(S+)
Mobility Requirements
RFC3775Mobility Support in IPv6MIPc(M)c(M)
8.1All Nodes as Correspondent NodeMIPM
8.2Route OptimizationMIPc(M)
8.2Allow route optimization to be disabled.MIPc(M)
8.3All IPv6 RoutersMIPM
8.4Home AgentsMIPc(M)
8.5Mobile NodesMIPc(M)
RFC4282The Network Access IdentifierMIPc(S+)c(S+)
RFC4283Mobile Node Identifier option for MIPV6MIPc(S+)c(S+)
RFC4877MIPv6 Op with IKEv2 and Revised IPsec ArchMIPc(M)c(M)
RFC3963Network Mobility (NEMO) Basic SupportNEMOc(M)
Quality of Service Requirements
RFC2474Differentiated Services (DiffServ)DSc(M)M
RFC2475An Architecture for Differentiated ServicesDSS
RFC3260New Terminology / Clarifications for DiffservDSS
RFC2983Differentiated Services and TunnelsDSS
RFC4594Config Guidelines for DS Service ClassesDSS
RFC3086Def. of DiffServe Per Domain Behaviors (PDB)DSS
RFC3140Per Hop Behavior (PHB) Identification CodesDSc(M)M
RFC2597Assured Forwarding PHB GroupDSS+
RFC3246An Expedited Forwarding PHBDSS+
RFC3247Supplemental Info for the New EF PHBDSS+
RFC3168Explicit Congestion Notification (ECN) to IPECNSS+
Link Specific Requirements
RFC2464IPv6 over EthernetLinkc(M)c(M)
RFC2467IPv6 over FDDILinkc(M)c(M)
RFC5072IPv6 over PPPLinkc(M)c(M)
RFC2491IPv6 over Non-Broadcast Multiple Access (NBMA) networksLinkc(M)c(M)
RFC2492IPv6 over ATM NetworksLinkc(M)c(M)
RFC2497IPv6 over ARCnetLinkc(M)c(M)
RFC2590IPv6 over Frame RelayLinkc(M)c(M)
RFC3146IPv6 over IEEE 1394 NetworksLinkc(M)c(M)
RFC3572IPv6 over MAPOS (SONET/SDH)Linkc(M)c(M)
RFC4338IPv6 & IPv4 over Fibre ChannelLinkc(M)c(M)
RFC4944IPv6 over IEEE 802.15.4 NetworksLinkc(M)c(M)
Packet Compression Technologies
RFC2507IP Header CompressionOO
RFC3173IP Payload Compression Protocol (IPComp)OO
RFC4995RObust Header Compression (ROHC) FrameworkROHCc(M)c(M)
RFC4996ROHC Profile for TCPROHCc(M)c(M)
RFC3095ROHC Profiles for RTP, UDP, ESP and UncompROHCc(M)c(M)
RFC4815Corrections and Clarifications to RFC3095ROHCc(M)c(M)
RFC3843ROHC Profile for IP OnlyROHCc(S+)c(S+)
RFC3241ROHC over PPPROHC & Linkc(M)c(M)
RFC4362ROHC: Link Assisted for IP/UDP/RTPROHCc(S+)c(S+)
Network Protection Device Requirements
SP500-2676.12.3.1IPv6 connectivityNPDM
SP500-2676.12.3.2Dual StackNPDM
SP500-2676.12.3.3Administrative FunctionalityNPDM
SP500-2676.12.3.4Authentication and AuthorizationNPDM
SP500-2676.12.3.5Security of Control and CommsNPDM
SP500-2676.12.3.6PersistenceNPDM
SP500-2676.12.3.7Logging and AlertsNPDM
SP500-2676.12.3.8Fragmented Packets HandlingNPDM
SP500-2676.12.3.9Tunneled Traffic HandlingNPDM
SP500-2676.12.4.1.1Port/protocol/address blockingFW or APFWc(M)
SP500-2676.12.4.1.2Asymmetrical BlockingFW or APFWc(M)
SP500-2676.12.4.1.3IPsec Traffic HandlingFW or APFWc(M)
SP500-2676.12.4.1.4Performance Under Load, Fail SafeFW or APFWc(M)
SP500-2676.12.4.2.1No violation of trust barriersAPFWc(M)
SP500-2676.12.4.2.2Session Traffic AuthAPFWc(M)
SP500-2676.12.4.2.3Email, File FilteringAPFWc(M)
SP500-2676.12.5.1.1Known Attack DetectionIDS or IPSc(M)
SP500-2676.12.5.1.2Malformed pkt detectionIDS or IPSc(M)
SP500-2676.12.5.1.3Port scan detectionIDS or IPSc(M)
SP500-2676.12.5.1.4Tunneled traffic detectionIDS or IPSc(M)
SP500-2676.12.5.1.5Logging and AlertsIDS or IPSc(M)
SP500-2676.12.5.1.6Performance Under Load, Fail SafeIDS or IPSc(M)
SP500-2676.12.5.2.1Intrusion PreventionIPSc(M)

http://tools.ietf.org/html/rfc5095http://tools.ietf.org/html/rfc3596http://tools.ietf.org/html/rfc4362http://tools.ietf.org/html/rfc3843http://tools.ietf.org/html/rfc3241http://tools.ietf.org/html/rfc3095http://tools.ietf.org/html/rfc4213http://tools.ietf.org/html/rfc2473http://tools.ietf.org/html/rfc3736http://tools.ietf.org/html/rfc3775http://tools.ietf.org/html/rfc2671http://tools.ietf.org/html/rfc3596http://tools.ietf.org/html/rfc4038http://tools.ietf.org/html/rfc4604http://tools.ietf.org/html/rfc3810http://tools.ietf.org/html/rfc3484http://tools.ietf.org/html/rfc4941http://tools.ietf.org/html/rfc4291http://tools.ietf.org/html/rfc3315http://tools.ietf.org/html/rfc3971http://tools.ietf.org/html/rfc2675http://tools.ietf.org/html/rfc1981http://tools.ietf.org/html/rfc2507http://tools.ietf.org/html/rfc2784http://tools.ietf.org/html/rfc4338http://tools.ietf.org/html/rfc3572http://tools.ietf.org/html/rfc3146http://tools.ietf.org/html/rfc2590http://tools.ietf.org/html/rfc2497http://tools.ietf.org/html/rfc2492http://tools.ietf.org/html/rfc2491http://tools.ietf.org/html/rfc5072http://tools.ietf.org/html/rfc2467http://tools.ietf.org/html/rfc2464http://tools.ietf.org/html/rfc4798http://tools.ietf.org/html/rfc4868http://tools.ietf.org/html/rfc3306http://tools.ietf.org/html/rfc3307http://tools.ietf.org/html/rfc4869http://tools.ietf.org/html/rfc3226http://tools.ietf.org/html/rfc3678http://tools.ietf.org/html/rfc5014http://tools.ietf.org/html/rfc4807http://tools.ietf.org/html/rfc3289http://tools.ietf.org/html/rfc4995http://tools.ietf.org/html/rfc5175http://tools.ietf.org/html/rfc4996http://tools.ietf.org/html/rfc4815http://tools.ietf.org/html/rfc4191http://tools.ietf.org/html/rfc3247http://tools.ietf.org/html/rfc2597http://tools.ietf.org/html/rfc3086http://tools.ietf.org/html/rfc4594http://tools.ietf.org/html/rfc2460http://tools.ietf.org/html/rfc3246http://tools.ietf.org/html/rfc3140http://tools.ietf.org/html/rfc2983http://tools.ietf.org/html/rfc2475http://tools.ietf.org/html/rfc4760http://tools.ietf.org/html/rfc3173http://tools.ietf.org/html/rfc4944http://tools.ietf.org/html/rfc4607http://tools.ietf.org/html/rfc4982http://tools.ietf.org/html/rfc4581http://tools.ietf.org/html/rfc2711http://tools.ietf.org/html/rfc2526http://tools.ietf.org/html/rfc4891http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc4809http://tools.ietf.org/html/rfc4861http://tools.ietf.org/html/rfc4884http://tools.ietf.org/html/rfc4295http://tools.ietf.org/html/rfc3963http://tools.ietf.org/html/rfc4282http://tools.ietf.org/html/rfc3633http://tools.ietf.org/html/rfc4361http://tools.ietf.org/html/rfc4862http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc4543http://tools.ietf.org/html/rfc4443http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc3168http://tools.ietf.org/html/rfc3260http://tools.ietf.org/html/rfc2474http://tools.ietf.org/html/rfc4877http://tools.ietf.org/html/rfc4283http://tools.ietf.org/html/rfc4087http://tools.ietf.org/html/rfc4113http://tools.ietf.org/html/rfc4022http://tools.ietf.org/html/rfc4292http://tools.ietf.org/html/rfc3956http://tools.ietf.org/html/rfc4293http://tools.ietf.org/html/rfc3414http://tools.ietf.org/html/rfc3413http://tools.ietf.org/html/rfc3412http://tools.ietf.org/html/rfc3411http://tools.ietf.org/html/rfc4434http://tools.ietf.org/html/rfc3566http://tools.ietf.org/html/rfc2404http://tools.ietf.org/html/rfc4543http://tools.ietf.org/html/rfc4106http://tools.ietf.org/html/rfc4609http://tools.ietf.org/html/rfc4309http://tools.ietf.org/html/rfc3686http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc3602http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc2451http://tools.ietf.org/html/rfc4835http://tools.ietf.org/html/rfc2410http://tools.ietf.org/html/rfc4945http://tools.ietf.org/html/rfc3526http://tools.ietf.org/html/rfc4601http://tools.ietf.org/html/rfc4307http://tools.ietf.org/html/rfc4306http://tools.ietf.org/html/rfc4308http://tools.ietf.org/html/rfc3948http://tools.ietf.org/html/rfc4302http://tools.ietf.org/html/rfc4303http://tools.ietf.org/html/rfc4301http://tools.ietf.org/html/rfc2545http://tools.ietf.org/html/rfc1772http://tools.ietf.org/html/rfc4271http://tools.ietf.org/html/rfc3315http://tools.ietf.org/html/rfc4552http://tools.ietf.org/html/rfc2740http://tools.ietf.org/html/rfc4584http://tools.ietf.org/html/rfc3542http://tools.ietf.org/html/rfc3493http://tools.ietf.org/html/rfc3986http://tools.ietf.org/html/rfc3972http://tools.ietf.org/html/rfc3879http://tools.ietf.org/html/rfc4193http://tools.ietf.org/html/rfc4007 SDOC-How-to-Complete

Suppliers Declaration of Conformity for USGv6 Description and InstructionsUSGv6-v1 SDOC-v1.10 Page 4
General: This document describes network product from the identified supplier that claims support of USGv6 capabilities. General product and supplier identification is given on Page 1. Overall results of testing USGv6 capabilities for conformance, interoperability and network protection are given on Page 2. Detailed instructions for completing and interpreting each numbered field are given below. Note USGv6 Testing website at: http://www.antd.nist.gov/usgv6/testing.html. Contact: usgv6-project@antd.nist.gov.

Field Description and Instructions Field Description and Instructions

1 The Document Requiring Conformity: Identifies the profile version implemented. Not a user completable field. 11 Summary of Results: The format of this table mirrors the USGv6-v1.0 capabilities checklist (USGv6 Profile, Appendix A). The 12 categories of USGv6 capabilities are listed as subheadings, with subsidiary functions as line items. Configuration options related to conditional implementation of selected capabilities.

2 Product Identifier: Supplier's concise name for the product declared. Product Id/Stack Id: The identification line of this page includes space for Product Id and Stack Id labels. Product Id is the same as given on Page 1. As there may be more than one unique IPv6 stack implemented in the product, the Stack Id field identifies the particular stack described. One Results Summary page per stack is required.

3 Suppliers Name, Address and Contact Details: Company name and point of contact for SDOC questions, street address, phone and email. Host, Router and Network Protection (NPD) columns identify 'preferred' options: cells in green represent the NIST recommendations. Cells in grey denote atypical options, very unlikely to be implemented. The procuring Agency may additionally tailor these fields to indicate requirements for this acquisition.

4 Product as Tested/Declared: Product Identifier and detailed version information. If this SDOC reports oringal test results (page 2), include information about the specific product configuration(s) that was actually tested (e.g., hardware configuration, operating system, etc). Test Suite Conformance and Interoperability columns identify capability sets for which a public test suite exists, and the versions applicable to USGv6-v1.0 test results. Major version v1 and all its minor versions are deemed acceptable. Over time, new versions will be added and older ones retired. There may be periods when more than one major version is acceptable concurrently.

5 Product Family: A list of other products that use the same, unmodified IPv6 stacks such that their USGv6 capabilities are identical in form and function to the specific product configuration above. Test labs are only required to affirm the results for specific products tested. Test labs optionally may affirm recognized product families. The supplier completes the adjacent Test Lab and Result Id column with the test lab acronym and unique result identifier (See Test Lab and Accreditor page on the Website). The buyer may opt to query results with the test laboratory using the specified Result Id(s). The supplier may opt to provide particular explanation of some results (partial results, additional options) in which case reference to note on an attached page 3. (e.g. "See Note# N"). See the USGv6 testing website to identify the test lab, and find contact details.

6 USGv6 Capability Summary: The USGv6 stack implementation summary as identified by the '+' notation described in the USGv6 profile, Appendix A. For each IPv6 stack implementation in the product, a distinct Stack Id and reference to the attached Results Summary page (Page 2). Cells marked Self Test have no associated public test suite. If implemented by the supplier, the required adjacent annotation is "Self Declaration". Note that vendors declaring support for such a capability are declaring support for the associated specific requirements in the USGv6 Profile.

7 Self Contained or Composite SDOC: If this SDOC relies on the test results of other disinct products, list the Supplier & Product ID/Stack IDs referenced and attach those original SDOCs to this one. 12 Additional Options Tested: Vendor checks if it is desired to record tested options not part of the 'Musts' in the profile. Explanations on the page following the results summary.

Headings and Special Notations: as described.

8 Additional Declarations / Attachements: List the supplier / product ID / Stack ID of any test results of composite components referenced by this SDOC.

Options for Test Lab and Result Id: Currently 3 cases: (1) the test lab acronym and alphanumeric Id of the result set as assigned by the test laboratory; (2) 'Self declaration' denoting the supplier attests to adequate QA testing of the capability; (3) See attachment or note 'N', where the supplier explains variations in greater detail.

9 Supplementary Attestations: Suppliers disclosure of IPv6 only capabilities; multiple stacks present; product family applicabilities. These are not included to qualify or disqualify a product from purchase considerations, but to inform network administrators of potential configuration options relevant to USGv6 interoperability. Check all that apply. 13 Stack-1 Notes Instructions: The supplier may choose to use the Notes (page 3) in order to clarify unsupported features or non passing results. Each Note # must reference the same Note # from Page 2.

10 Signature Block: Wet ink signature of the responsible product manager, dated. Printed name and position title on the line below. Complete the Note by including the Spec/Reference and Section (i.e. RFC or USGv6 Profile version), USGv6-v1 Profile Requirements, Config Option (i.e. IPv6-Base), choosing Host/Router/NPD, and Test Selection table version along with Test Lab Result ID. The Discussion includes details about the test result that will be disclosed to the buyer.

Further Description: http://www.antd.nist.gov/usgv6/testing.html, and NIST SP 500-267 USGv6 Testing Program Users Guide available at the website.

File details come from the government source that posted it.