
ETEP CLI User Guide
121
7
FIPS 140-2 Level 2 Operation
The ETEPs are FIPS Level 2 compliant. This section describes the FIPS mode of operation on the
ETEPs.
If you plan to operate the ETEP in FIPS mode, we recommend enabling FIPS mode as your first
configuration task. Entering FIPS mode resets many configuration items, such as passwords, policies, and
certificates. To avoid having to reconfigure the ETEP, enable FIPS mode and then perform the rest of the
appliance and policy configuration tasks.
FIPS Mode Requirements
When operating in FIPS mode, the ETEP must be configured to use FIPS-approved encryption and
authentication algorithms. FIPS approved algorithms are listed in
. Note that some of the FIPS-
approved algorithms are available only for use on the management port.
The ETEP prevents entry into FIPS mode when any of the following conditions are true:
●
EncrypTight distributed key policies are installed that use non-FIPS approved algorithms
●
IKE policies are configured on the management port interface that use non-FIPS approved algorithms
●
Manual key policies are installed on the management port interface.
If you plan to use manual key policies, you must deploy them
after
FIPS mode is enabled on the
ETEP.
●
SNMPv3 configuration uses cryptography for SNMP trap hosts, but no IPsec policy has been
configured to protect the SNMP traffic for each specific trap host
●
The debug shell is in use
●
Strict client authentication is enabled on the management port
If you plan to use strict authentication to secure management port communications, you must enable
FIPS mode prior to enabling strict authentication. To learn more about using strict authentication, see
the
EncrypTight User Guide
.
Table 65
FIPS approved encryption and authentication algorithms
Encryption algorithms
Authentication algorithms
3des-cbc
sha1-96-hmac
aes128-cbc
sha2-256-hmac
aes256-cbc
sha2-384-hmac
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...