64
FIPS compliance
The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for features,
commands, and parameters might differ in FIPS mode and non-FIPS mode. For more information about
FIPS mode, see
Security Configuration Guide
.
Unless otherwise noted, devices in the configuration examples are operating in non-FIPS mode.
HTTP is not supported in FIPS mode.
Configuring HTTP login
NOTE:
This feature is not supported in FIPS mode.
Follow these steps to configure HTTP login:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable the HTTP service
ip http enable
Required
Enabled by default.
Configure the HTTP service port
number
ip http port
port-number
Optional
80 by default.
If you execute the command
multiple times, the last one takes
effect.
Associate the HTTP service with an
ACL
ip http acl
acl-number
Optional
By default, the HTTP service is not
associated with any ACL.
Associating the HTTP service with
an ACL enables the device to allow
only clients permitted by the ACL to
access the device.
Set the web user connection
timeout time
web idle-timeout
minutes
Optional
Set the web log buffer size
web logbuffer size
pieces
Optional
Create a local user and enter local
user view
local-user
user-name
Required
By default, no local user is
configured.
Configure a password for the local
user
password
{
cipher
|
simple
}
password
Required
By default, no password is
configured for the local user.
Specify the command level of the
local user
authorization-attribute level
level
Required
No command level is configured
for the local user.