![HP Fabric OS v7.0.1 Administrator'S Manual Download Page 568](http://html.mh-extra.com/html/hp/fabric-os-v7-0-1/fabric-os-v7-0-1_administrators-manual_165056568.webp)
530
Fabric OS Administrator’s Guide
53-1002446-01
Preparing the switch for FIPS
C
11. Enter the portCfgEncrypt
--
disable command to disable in-flight encryption. You must first
disable the port.
Example
myswitch:root>
portdisable 0
myswitch:root>
portcfgencrypt --disable 0
myswitch:root>
portenable 0
12. Enter the ipSecConfig
--
disable command to disable Ethernet IPsec.
13. Disable IPsec for FCIP connections. The procedure depends on the type of extension blade
used.
For FX8-24 extension blades, enter the portCfg fciptunnel [
slot
/]
port
modify -ipsec 0
command.
For FR4-18i router blades, follow these steps:
a. Enter the portCfg fciptunnel [
slot
/]
port
delete
tunnel_id
command to delete the FCIP
tunnel.
b. Enter the policy
--
delete ipsec command to delete the associated IPsec policy.
c. Enter the policy
--
delete ike command to delete the associated IKE policy.
14. Enter the portCfg
--
mgmtif delete command to disable in band management.
15. Enter the fipsCfg
--
enable selftests command to enable KAT and conditional tests on the
switch.
16. Enter the fipsCfg
--
verify fips command to verify the switch is FIPS-ready.
17. Enter the fipsCfg
--
enable fips command.
18. Reboot the switch. If a Backbone, reboot both CPs.
Zeroizing for FIPS
1. Log in to the switch using an account with admin or securityadmin permissions, or a user
account with OM permissions for the FIPSCfg RBAC class of commands.
2. Enter the fipsCfg
--
zeroize command.
3. Reboot the switch.
Displaying FIPS configuration
1. Log in to the switch using an account with admin or securityadmin permissions, or a user
account with the O permission for the FCIPCfg RBAC class of commands.
2. Enter the fipsCfg
--
showall command.
Summary of Contents for Fabric OS v7.0.1
Page 1: ...53 1002446 01 15 December 2011 Fabric OS Administrator s Guide Supporting Fabric OS v7 0 1 ...
Page 22: ...xxii Fabric OS Administrator s Guide 53 1002446 01 ...
Page 26: ...xxvi Fabric OS Administrator s Guide 53 1002446 01 ...
Page 30: ...xxx Fabric OS Administrator s Guide 53 1002446 01 ...
Page 38: ...xl Fabric OS Administrator s Guide 53 1002446 01 ...
Page 40: ...2 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 214: ...176 Fabric OS Administrator s Guide 53 1002446 01 Management interface security 7 ...
Page 228: ...190 Fabric OS Administrator s Guide 53 1002446 01 Brocade configuration form 8 ...
Page 248: ...210 Fabric OS Administrator s Guide 53 1002446 01 Validating a firmware download 9 ...
Page 334: ...296 Fabric OS Administrator s Guide 53 1002446 01 Setting up TI over FCR sample procedure 12 ...
Page 360: ...322 Fabric OS Administrator s Guide 53 1002446 01 Encryption and compression example 14 ...
Page 404: ...366 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 430: ...392 Fabric OS Administrator s Guide 53 1002446 01 Ports on Demand 18 ...
Page 502: ...464 Fabric OS Administrator s Guide 53 1002446 01 Buffer credit recovery 23 ...
Page 572: ...534 Fabric OS Administrator s Guide 53 1002446 01 Hexadecimal overview D ...
Page 584: ...546 Fabric OS Administrator s Guide 53 1002446 01 ...