52
CN4093 Application Guide for N/OS 8.4
Boot Strict Mode
The
implementations
specified
in
this
section
are
compliant
with
National
Institute
of
Standards
and
Technology
(NIST)
Special
Publication
(SP)
800
‐
131A.
The
CN4093
10
Gb
Converged
Scalable
Switch
can
operate
in
two
boot
modes:
Compatibility
mode
(default):
This
is
the
default
switch
boot
mode.
This
mode
may
use
algorithms
and
key
lengths
that
may
not
be
allowed/acceptable
by
NIST
SP
800
‐
131A
specification.
This
mode
is
useful
in
maintaining
compatibility
with
previous
releases
and
in
environments
that
have
lesser
data
security
requirements.
Strict
mode:
Encryption
algorithms,
protocols,
and
key
lengths
in
strict
mode
are
compliant
with
NIST
SP
800
‐
131A
specification.
When
in
boot
strict
mode,
the
switch
uses
Secure
Sockets
Layer
(SSL)/Transport
Layer
Security
(TLS)
1.2
protocols
to
ensure
confidentiality
of
the
data
to
and
from
the
switch.
By
default,
HTTP,
Telnet,
and
SNMPv1
and
SNMPv2
are
disabled
on
the
CN4093.
Before
enabling
strict
mode,
ensure
the
following:
The
software
version
on
all
connected
switches
is
Enterprise
NOS
8.4.
NIST
Strict
compliance
is
enabled
on
the
Chassis
Management
Module.
The
supported
protocol
versions
and
cryptographic
cipher
suites
between
clients
and
servers
are
compatible.
For
example:
if
using
SSH
to
connect
to
the
switch,
ensure
that
the
SSH
client
supports
SSHv2
and
a
strong
cipher
suite
that
is
compliant
with
the
NIST
standard.
Compliant
Web
server
certificate
is
installed
on
the
switch,
if
using
BBI.
A
new
self
‐
signed
certificate
is
generated
for
the
switch
(
CN 4093(config)#
access https generate-certificate
).
The
new
certificate
is
generated
using
2048
‐
bit
RSA
key
and
SHA
‐
256
digest.
Protocols
that
are
not
NIST
SP
800
‐
131A
compliant
must
be
disabled
or
not
used.
Only
SSHv2
or
higher
is
used.
The
current
configuration,
if
any,
must
be
saved
in
a
location
external
to
the
switch.
When
the
switch
reboots,
both
the
startup
and
running
configuration
are
lost.
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...