
Command Reference
144
ETEP CLI User Guide
fips-mode-enable
Description
The
fips-mode-enable
command enables and disables FIPS mode on the ETEP.
User Type
Administrator
Hierarchy Level
Configuration mode
Syntax
fips-mode-enable {true | false}
Usage Guidelines
When operating in FIPS mode, the ETEP must be configured to use FIPS-approved encryption and
authentication algorithms.
The ETEP prevents entry into FIPS mode when any of the following conditions are true:
●
EncrypTight distributed key policies are installed that use non-FIPS approved algorithms
●
IKE policies are configured on the management port interface that use non-FIPS approved algorithms
●
Manual key policies are installed on the management port interface
●
SNMPv3 configuration uses cryptography for SNMP trap hosts, but no IPsec policy has been
configured to protect the SNMP traffic for each specific trap host
●
The debug shell is in use
●
Strict client authentication is enabled on the management port
Placing the ETEP in a FIPS-compliant configuration can take several minutes. When putting the ETEP in
FIPS mode, the ETEP performs the following actions and self-tests:
●
Runs self-tests during the boot process and when entering FIPS mode that include cryptographic
algorithm tests, firmware integrity tests, and critical function tests
●
Performs a software integrity test
●
Clears pre-existing polices and keys
●
Generates a new self-signed certificate on the management interface
●
Removes all externally signed certificates
●
Resets passwords to the factory defaults
●
Closes remote SSH client sessions
When FIPS is disabled, the existing policies continue to run until they are replaced or deleted. The
current SSH session is terminated.
See
“FIPS 140-2 Level 2 Operation” on page 121
for more information about FIPS mode.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...