How FIPS Works

You place a device in FIPS mode by entering the fips enable CLI command on the management station while the station is connected to the device console port with a serial cable. After you enter the fips enable command, the device is administratively in FIPS mode and by default runs in strict FIPS-compliant mode upon reload.

The default FIPS policy is for the system to run in a strict mode that fully supports FIPS 140-2 specifications. However, the device allows you the flexibility to configure a modified FIPS policy according to your network requirements. .

Note: A FIPS policy that varies from the default policy weakens the intent of the FIPS 140-2 specifications; when implemented, the device is not operating in full compliance with these specifications. Refer to Modifying the FIPS policy

The default FIPS policy enforces the following actions for strict FIPS compliance:

  • Disables TFTP access
  • Disables monitor access to memory access commands
  • Returns 0 or null for SNMP MIBs for passwords or keys (referred to as critical security parameter objects)
  • Zeroizes shared secrets and passwords

The device performs the following functions automatically during reboot after the fips enable command is entered:

  • Disables Telnet
  • Enables SCP access
  • Disables the HTTP server
  • Disables SNMP access to critical security parameter (CSP) MIB objects

After defining the FIPS policy, save the configuration, and reboot the device. While the device is booting, several tests are run to ensure the device is FIPS-compliant.

After these tests are completed successfully, the device reloads and is operationally in FIPS mode.

All the optional FIPS policy commands are provided to perform various non-approved FIPS operations when FIPS is enabled.

Note: If any of these policy commands are configured, the module is not operating in the approved FIPS mode.
Note: Web server is not supported in FIPS/CC mode.