Issue 5 June 2008
707
Non-Approved Algorithms in FIPS mode
●
Diffie-Hellman for IKE key exchanges - groups 2, 5, and 14
●
MD5 for Radius Client role and peer OSPF router authentication
●
HMAC-MD5-96 for SNMPv3 authentication
The cryptographic module relies on the implemented deterministic random number generator
(DRNG) that is compliant with X9.31 with 128-bit Key, 64-bit Seed for generation of all
cryptographic keys. The non-deterministic random seed generator is used for the periodic
re-seeding of the PRNG.
Setting the cryptographic module run mode
The user can determine if the cryptographic module is running in FIPS vs. non-FIPS mode via:
●
Execution of the
show running-config
command.
●
Verification that the configuration meets the requirements specified in
Administration
Procedures
on page 721.
●
Verification that the HW version and the firmware version of the module firmware code in
banks A and B are FIPS-approved versions.
Non-FIPS mode of operation
In non-FIPS mode, the cryptographic module provides non-FIPS-approved algorithms and uses
FIPS-approved algorithms in non-compliant ways, as shown in
Table 168
:
Table 168: Non-FIPS-approved operations and algorithms
MD5
HMAC
-SHA1
PTLS
TDES
DES
AES
AEA
DH
RSA
decryption
DSS
IKE
X
Group 1
IPSEC
X
SNMPv3
X
X
SSH2
X
X
X
Group
786-
2048 bit
VoIP Bearer (Media)
Encryption
X
X
1 of 2
Summary of Contents for Media Gateway G250
Page 1: ...Administration for the Avaya G250 and Avaya G350 Media Gateways 03 300436 Issue 5 June 2008 ...
Page 24: ...Contents 24 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 32: ...Introduction 32 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 38: ...Configuration overview 38 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 244: ...Configuring logging 244 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 258: ...Configuring VoIP QoS 258 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 370: ...Configuring SNMP 370 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 548: ...Configuring the router 548 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 664: ...Configuring policy 664 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Page 686: ...Setting synchronization 686 Administration for the Avaya G250 and Avaya G350 Media Gateways ...