Protocol Changes in FIPS Mode

The following table lists the protocols that undergo changes while the device is in FIPS mode with the default policy applied.

Protocol Changes

Protocols / Algorithms

Supported in FIPS Mode

Supported in Non-FIPS Mode

For more information on individual protocol changes, refer to the following sections:

BGP

Yes

Yes

BGP

HTTP

No

Yes

HTTP

HTTPS client

Yes, with limitations (HTTPS client only)

Yes

HTTPS

IPsec

Yes, with limitations

Yes

IKEv2/IPsec

MD5 password encryption

Yes, with limitations (MD5 password encryption is supported for AAA and RADIUS).

Yes

RADIUS

NTP

Yes, with limitations (supports SHA1 only)

Yes (supports SHA1 and MD5 hash only)

NTP

OSPFv2

Yes

Yes

OSPFv2

PKI

Yes

Yes

PKI

Proprietary 2-way encryption algorithms

No

Yes

Proprietary 2-way encryption algorithms

RADIUS

Yes

Yes

RADIUS

SCP

Yes

Yes

SCP

SNMP

Yes, with limitations

Yes

SNMP

SSHv2

Yes, with limitations

Yes

SSHv2

Telnet

No

Yes

Telnet

TFTP

No

Yes

TFTP