Reloading the Device
After you have saved the configuration, reload the device using the
reload command:
device# reload
Various tests, including Power-On Self Tests (POSTs) and Known Answer Tests (KATs), are run by the FastIron device during reload, during the transition between non-FIPS mode and FIPS mode.
POSTs check for the consistency of the FIPS-approved algorithms implemented on the device.
KATs are used to exercise various features of FIPS-approved algorithms.
All interfaces on the device are down until the tests are completed successfully.
Possible POST failure messages indicating that the device did not pass the tests successfully include the following messages:
Crypto module initialization and KNown Answer Test (KAT) failed with reason:(Error Code 0x80000000)’CKR_VENDOR_DEFINED’ FIPS: Primary image verification failed FIPS: Secondary image verification failed
If there is a failure while the POSTs are being run, the device reboots. Monitor mode can be accessed to troubleshoot the issue.
After all tests are completed successfully, the device reloads in FIPS mode and FIPS mode is successfully enabled and operational on the FastIron device.
You can verify the status of the device as operationally in FIPS mode by using the
fips show command.
device(config)# fips show
The following example shows
fips show command after the device reloads successfully in the default strict FIPS mode. Administrative
status and operational status are on.
device# fips show Cryptographic Module Version: BRCD-IP-CRYPTO-VER-4.0 FIPS mode: Administrative status ON: Operational status ON Common-Criteria: Administrative status OFF: Operational status OFF System Specific OS monitor access status is: Disabled Management Protocol Specific: Telnet server: Disabled Telnet client: Disabled TFTP client: Disabled HTTPS SSL 3.0: Disabled SNMP Access to security objects: Disabled Critical security Parameter updates across FIPS boundary: Protocol Shared secret and host passwords: Clear Password Display: Disabled HTTPS RSA Host Keys and Signature: Clear SSH DSA Host keys: Clear SSH RSA Host keys: Clear