Disabling FIPS Mode

Note: Even after disabling FIPS mode, you should always load the signature file before loading the software image file.

Note: If you disable FIPS mode, all local users are removed. Removal of the last local user triggers the removal of AAA configuration specific to local authentication. When no other AAA mechanism (RADIUS or TACACS) is configured, enable aaa console configuration is also removed.
Verify new wording.

Use the no fips enable command to disable FIPS mode on the FastIron device.

device(config)# no fips enable

After you enter the command, a warning displays that FIPS mode will be disabled.

This command performs the following policy-related operations:

  • Enables TFTP access.
  • Re-enables SNMP access to critical security parameter (CSP) MIB objects.
  • Re-enables SNMPv3 encryption protocol DES for future SNMPv3 user configuration.
  • Re-enables access to monitor mode.
  • Zeroizes shared secrets, SSH and HTTPS host keys, and the HTTPS certificate based on the configured FIPS policy.

The no fips enable command also performs the non-policy-related operation of re-enabling the RC4 cipher for the HTTPS server.

Changes to the running configuration are not saved to the startup configuration; therefore, when the device reloads, it returns to FIPS mode.

Use the write memory command to save the running configuration.