|
沙发

楼主 |
发表于 2006-4-6 10:56:05
|
只看该作者
<h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327451"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">1<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327451;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">范围</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范规定了小型防火墙产品的安全技术要求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范适用于小型防火墙产品安全功能的研制、开发、测试、评估和产品的采购。<span lang="EN-US"><p></p></span></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327452"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">2<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327452;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">引用标准</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman"><span style="mso-spacerun: yes;"> </span>GB/T 18019-1999 </font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">信息技术包过滤防火墙安全技术要求</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327453"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">3<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327453;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">小型防火墙定义</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman"> </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙是专门为中小企业、中小型办公室环境或家庭用户提供安全保护的防火墙产品。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman"> </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的目的是要在内外网络之间建立一个安全控制点,通过允许、拒绝或重定向经过防火墙的数据流,实现对进出内部网络的服务和访问的审计和控制。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman"> </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的特点是体积小、硬件配置低、流量性能低,其主要访问控制能力与普通防火墙基本相同,但其部分安全功能要求比普通防火墙低,只能适用于中小企业、中小型办公室环境或家庭用户,建议内网用户一般不超过</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman">10</font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">个。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327454"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">4<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327454;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">安全功能要求</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327455"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.1<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327455;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">用户数据保护功能类(<span lang="EN-US">FDP</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327456"></a><a name="_Toc29354113"></a><a name="_Toc29353922"></a><a name="_Toc27892983"><span style="mso-bookmark: _Toc29353922;"><span style="mso-bookmark: _Toc29354113;"><span style="mso-bookmark: _Toc61327456;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.1<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892983;"><span style="mso-bookmark: _Toc29353922;"><span style="mso-bookmark: _Toc29354113;"><span style="mso-bookmark: _Toc61327456;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">完整的客体访问控制(<span lang="EN-US">FDP_ACC.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应在以下方面执行未鉴别的端到端策略<span lang="EN-US">:<p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)主体:未经防火墙鉴别的主机;<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)客体:内部或外部网上的主机。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">以及安全功能策略所包括主体和客体上的所有操作。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保安全功能策略包括了控制范围中的任何主体和客体之间的所有操作。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327457"></a><a name="_Toc29354114"></a><a name="_Toc29353923"></a><a name="_Toc27892984"><span style="mso-bookmark: _Toc29353923;"><span style="mso-bookmark: _Toc29354114;"><span style="mso-bookmark: _Toc61327457;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.2<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892984;"><span style="mso-bookmark: _Toc29353923;"><span style="mso-bookmark: _Toc29354114;"><span style="mso-bookmark: _Toc61327457;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">访问授权与拒绝(<span lang="EN-US">FDP_ACF.4</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应执行未鉴别的端到端策略。根据主体和客体的安全属性值提供明确的访问保障能力。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应执行未鉴别的端到端策略。根据主体和客体的安全属性值提供明确的拒绝访问能力。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327458"></a><a name="_Toc29354115"></a><a name="_Toc29353924"></a><a name="_Toc27892985"><span style="mso-bookmark: _Toc29353924;"><span style="mso-bookmark: _Toc29354115;"><span style="mso-bookmark: _Toc61327458;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.3<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892985;"><span style="mso-bookmark: _Toc29353924;"><span style="mso-bookmark: _Toc29354115;"><span style="mso-bookmark: _Toc61327458;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">多种安全属性访问控制(<span lang="EN-US">FDP_ACF.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应根据源地址,目的地址,传输层协议和请求的服务(如源端口号或目的端口号)对客体执行未鉴别的端到端策略。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行以下规则以确定受控主体与受控客体之间的操作是否被允许:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有内部网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有广播网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">c</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有保留网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">d</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有环回网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327459"></a><a name="_Toc29354117"></a><a name="_Toc29353926"></a><a name="_Toc27892987"><span style="mso-bookmark: _Toc29353926;"><span style="mso-bookmark: _Toc29354117;"><span style="mso-bookmark: _Toc61327459;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.4<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892987;"><span style="mso-bookmark: _Toc29353926;"><span style="mso-bookmark: _Toc29354117;"><span style="mso-bookmark: _Toc61327459;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">管理员属性修改(<span lang="EN-US">FDP_SAM.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行访问控制的功能策略(<span lang="EN-US">SFP</span>):未鉴别的端到端策略,向授权管理员提供修改下述参数的能力:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)标识与角色(例如:管理员)的关联。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)<span lang="EN-US">FDP_ACF.2</span>中标识的访问控制属性。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">c</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)与安全有关的管理数据。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327460"></a><a name="_Toc29354118"></a><a name="_Toc29353927"></a><a name="_Toc27892988"><span style="mso-bookmark: _Toc29353927;"><span style="mso-bookmark: _Toc29354118;"><span style="mso-bookmark: _Toc61327460;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.5<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892988;"><span style="mso-bookmark: _Toc29353927;"><span style="mso-bookmark: _Toc29354118;"><span style="mso-bookmark: _Toc61327460;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">管理员属性查询(<span lang="EN-US">FDP_SAQ.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行访问控制的功能策略:未鉴别的端到端策略,向授权管理员提供以下查询:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)<span lang="EN-US">FDP_ACF.2</span>中标识的访问控制属性。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)主机名。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327461"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.2<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327461;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">识别与鉴别功能类(<span lang="EN-US">FIA</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327462"></a><a name="_Toc29354120"></a><a name="_Toc29353929"></a><a name="_Toc27892990"><span style="mso-bookmark: _Toc29353929;"><span style="mso-bookmark: _Toc29354120;"><span style="mso-bookmark: _Toc61327462;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.1<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892990;"><span style="mso-bookmark: _Toc29353929;"><span style="mso-bookmark: _Toc29354120;"><span style="mso-bookmark: _Toc61327462;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员和可信主机鉴别数据初始化(<span lang="EN-US">FIA_ADA.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应根据<span lang="EN-US">FIA_UAU.1</span>和<span lang="EN-US">FIA_UAU.2</span>中规定的鉴别数据提供授权管理员和可信主机鉴别数据的初始化功能。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应确保只允许授权管理员使用这些功能。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327463"></a><a name="_Toc29354121"></a><a name="_Toc29353930"></a><a name="_Toc27892991"><span style="mso-bookmark: _Toc29353930;"><span style="mso-bookmark: _Toc29354121;"><span style="mso-bookmark: _Toc61327463;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.2<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892991;"><span style="mso-bookmark: _Toc29353930;"><span style="mso-bookmark: _Toc29354121;"><span style="mso-bookmark: _Toc61327463;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员和可信主机鉴别数据的基本保护(<span lang="EN-US">FIA_ADP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应保护存储于设备中的鉴别数据不受未授权查阅、修改和破坏。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327464"></a><a name="_Toc29354123"></a><a name="_Toc29353932"></a><a name="_Toc27892993"><span style="mso-bookmark: _Toc29353932;"><span style="mso-bookmark: _Toc29354123;"><span style="mso-bookmark: _Toc61327464;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.3<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892993;"><span style="mso-bookmark: _Toc29353932;"><span style="mso-bookmark: _Toc29354123;"><span style="mso-bookmark: _Toc61327464;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员可信主机和主机属性的初始化(<span lang="EN-US">FIA_ATA.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应提供用默认值对授权管理员,可信主机和主机属性初始化的能力。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327465"></a><a name="_Toc29354124"></a><a name="_Toc29353933"></a><a name="_Toc27892994"><span style="mso-bookmark: _Toc29353933;"><span style="mso-bookmark: _Toc29354124;"><span style="mso-bookmark: _Toc61327465;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.4<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892994;"><span style="mso-bookmark: _Toc29353933;"><span style="mso-bookmark: _Toc29354124;"><span style="mso-bookmark: _Toc61327465;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员、可信主机和主机唯一属性定义(<span lang="EN-US">FIA_ATD.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应为每一个规定的授权管理员、可信主机和主机提供一套唯一的,为了执行安全策略所必须的安全属性。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327466"></a><a name="_Toc29354125"></a><a name="_Toc29353934"></a><a name="_Toc27892995"><span style="mso-bookmark: _Toc29353934;"><span style="mso-bookmark: _Toc29354125;"><span style="mso-bookmark: _Toc61327466;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.5<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892995;"><span style="mso-bookmark: _Toc29353934;"><span style="mso-bookmark: _Toc29354125;"><span style="mso-bookmark: _Toc61327466;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员的基本鉴别(<span lang="EN-US">FIA_UAU.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应鉴别任何通过防火墙的控制口履行授权管理员功能的管理员身份。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327467"></a><a name="_Toc29354126"></a><a name="_Toc29353935"></a><a name="_Toc27892996"><span style="mso-bookmark: _Toc29353935;"><span style="mso-bookmark: _Toc29354126;"><span style="mso-bookmark: _Toc61327467;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.6<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892996;"><span style="mso-bookmark: _Toc29353935;"><span style="mso-bookmark: _Toc29354126;"><span style="mso-bookmark: _Toc61327467;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">单一使用的鉴别机制(<span lang="EN-US">FIA_UAU.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应鉴别任何声称要履行授权管理员和可信主机功能的管理员和主机的身份。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应预防与远程管理和远程可信主机操作有关的鉴别数据的重用。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327468"></a><a name="_Toc29354127"></a><a name="_Toc29353936"></a><a name="_Toc27892997"><span style="mso-bookmark: _Toc29353936;"><span style="mso-bookmark: _Toc29354127;"><span style="mso-bookmark: _Toc61327468;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.7<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892997;"><span style="mso-bookmark: _Toc29353936;"><span style="mso-bookmark: _Toc29354127;"><span style="mso-bookmark: _Toc61327468;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员、可信主机和主机唯一身份识别(<span lang="EN-US">FIA_UID.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保在所有授权管理员、可信主机和主机请求执行的任何操作之前,对每个授权管理员、可信主机和主机进行唯一身份识别。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327469"></a><a name="_Toc29354128"></a><a name="_Toc29353937"></a><a name="_Toc27892998"><span style="mso-bookmark: _Toc29353937;"><span style="mso-bookmark: _Toc29354128;"><span style="mso-bookmark: _Toc61327469;"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.3<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892998;"><span style="mso-bookmark: _Toc29353937;"><span style="mso-bookmark: _Toc29354128;"><span style="mso-bookmark: _Toc61327469;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">保密功能类(<span lang="EN-US">FEN</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327470"></a><a name="_Toc29354129"></a><a name="_Toc29353938"></a><a name="_Toc27892999"><span style="mso-bookmark: _Toc29353938;"><span style="mso-bookmark: _Toc29354129;"><span style="mso-bookmark: _Toc61327470;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.3.1<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892999;"><span style="mso-bookmark: _Toc29353938;"><span style="mso-bookmark: _Toc29354129;"><span style="mso-bookmark: _Toc61327470;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">符合规定的加密操作(<span lang="EN-US">FCS_COP.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应保证其从外部网络到防火墙的远程管理会话的加密符合国家密码管理的有关规定。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327471"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.4<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327471;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">可信安全功能保护类(<span lang="EN-US">FPT</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327472"></a><a name="_Toc29354131"></a><a name="_Toc29353940"></a><a name="_Toc27893001"><span style="mso-bookmark: _Toc29353940;"><span style="mso-bookmark: _Toc29354131;"><span style="mso-bookmark: _Toc61327472;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.4.1<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893001;"><span style="mso-bookmark: _Toc29353940;"><span style="mso-bookmark: _Toc29354131;"><span style="mso-bookmark: _Toc61327472;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">防火墙安全策略的不可旁路性(<span lang="EN-US">FPT_RVM.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保任何与安全有关的操作被允许执行之前,都必须通过安全策略的检查。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327473"></a><a name="_Toc29354132"></a><a name="_Toc29353941"></a><a name="_Toc27893002"><span style="mso-bookmark: _Toc29353941;"><span style="mso-bookmark: _Toc29354132;"><span style="mso-bookmark: _Toc61327473;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.4.2<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893002;"><span style="mso-bookmark: _Toc29353941;"><span style="mso-bookmark: _Toc29354132;"><span style="mso-bookmark: _Toc61327473;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">安全功能区域分割(<span lang="EN-US">FPT_SEP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应为其自身的执行过程设定一个安全区域,以保护其免遭不可信主体的干扰和篡改。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327474"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.5<span style="mso-spacerun: yes;"> </span></span></a><span style="mso-bookmark: _Toc61327474;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">安全审计功能类(<span lang="EN-US">FAU</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327475"></a><a name="_Toc29354136"></a><a name="_Toc29353945"></a><a name="_Toc27893006"><span style="mso-bookmark: _Toc29353945;"><span style="mso-bookmark: _Toc29354136;"><span style="mso-bookmark: _Toc61327475;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.1<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893006;"><span style="mso-bookmark: _Toc29353945;"><span style="mso-bookmark: _Toc29354136;"><span style="mso-bookmark: _Toc61327475;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">审计数据生成(<span lang="EN-US">FAU_GEN.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应能够对可审计事件生成一个审计记录:<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327476"></a><a name="_Toc29354138"></a><a name="_Toc29353947"></a><a name="_Toc27893008"><span style="mso-bookmark: _Toc29353947;"><span style="mso-bookmark: _Toc29354138;"><span style="mso-bookmark: _Toc61327476;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.2<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893008;"><span style="mso-bookmark: _Toc29353947;"><span style="mso-bookmark: _Toc29354138;"><span style="mso-bookmark: _Toc61327476;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">可理解的格式(<span lang="EN-US">FAU_POP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应使审计记录中的所有审计数据可为人所理解。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327477"></a><a name="_Toc29354139"></a><a name="_Toc29353948"></a><a name="_Toc27893009"><span style="mso-bookmark: _Toc29353948;"><span style="mso-bookmark: _Toc29354139;"><span style="mso-bookmark: _Toc61327477;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.3<span style="mso-spacerun: yes;"> </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893009;"><span style="mso-bookmark: _Toc29353948;"><span style="mso-bookmark: _Toc29354139;"><span style="mso-bookmark: _Toc61327477;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">限制审计跟踪访问(<span lang="EN-US">FAU_PRO.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应只允许授权管理员访问审计记录。<span lang="EN-US"><p></p></span></span></p> |
|