Find Technical Content
  • Home
  • Ruckus Support Portal
  • Ruckus Networks
  • Table of Contents
  • Dark Mode

Powered by Titania Delivery

⚠ This cached page may be outdated. Click refresh to get the latest content.
Cached Version You are Offline

You are viewing a cached version of this page.

You are currently offline. This page was loaded from cache.

RUCKUS FastIron FIPS and Common Criteria Configuration Guide, 08.0.95 53-1005704-01

  • 1 Copyright Statement
  • Preface Ruckus
    • 3 Preface
      • 3.1 Document Conventions
      • 3.2 Command Syntax Conventions
      • 3.3 Document Feedback
      • 3.4 RUCKUS Product Documentation Resources
      • 3.5 Online Training Resources
      • 3.6 Contacting RUCKUS Customer Services and Support
  • 4 About This Document
    • 4.1 Supported hardware and software
  • 5 Federal Information Processing Standards
    • 5.1 FIPS Overview
    • 5.2 How FIPS Works
  • Upgrading Software on FIPS-enabled devices
    • 6 Upgrading and Downgrading Software on FIPS-enabled Devices
      • 6.1 Software Downgrades from FIPS
      • 6.2 Upgrading FIPS-enabled Devices
        • 6.2.1 Preparing for a FIPS Software Upgrade
        • 6.2.2 Image Verification in FIPS or CC Mode
        • 6.2.3 Performing a FIPS or CC Software Upgrade to FastIron 08.0.95
        • 6.2.4 SSH Connection after Upgrading a FIPS or CC Operational Device to FastIron 08.0.01 or Later
      • 6.3 Downgrading from FIPS to Non-FIPS Mode
  • 7 FIPS Configuration
    • 7.1 User Roles in FIPS Mode
    • 7.2 Commands Disabled in FIPS Mode
    • 7.3 Hidden Files in FIPS Mode
    • 7.4 Cryptographic Algorithms in FIPS Mode
    • 7.5 SSH
    • 7.6 SSH Clients
    • 7.7 Usernames and SSH Public Key Authentication
      • 7.7.1 Implementation
      • 7.7.2 Restrictions
    • 7.8 Protocol Changes in FIPS Mode
      • 7.8.1 BGP
      • 7.8.2 HTTP
      • 7.8.3 HTTPS
        • 7.8.3.1 TLS implementation in FastIron devices
      • 7.8.4 IKEv2/IPsec
      • 7.8.5 OSPFv2
      • 7.8.6 OSPFv3
      • 7.8.7 PKI
      • 7.8.8 Proprietary 2-way Encryption Algorithms
      • 7.8.9 RADIUS Protocol in FIPS Mode
      • 7.8.10 SCP
      • 7.8.11 SNMP
      • 7.8.12 SSHv2
      • 7.8.13 Telnet
      • 7.8.14 TFTP
      • 7.8.15 NTP
    • 7.9 System Reset and Boot up in FIPS Mode
    • 7.10 Debugging in FIPS Mode
    • 7.11 Placing the Device in FIPS Mode
      • 7.11.1 General Steps to Place the Device in FIPS Mode
      • 7.11.2 Enabling FIPS Mode
      • 7.11.3 Zeroizing Shared Secrets and Host Keys
      • 7.11.4 Configuring User Authentication
      • 7.11.5 Saving the Configuration
      • 7.11.6 Reloading the Device
      • 7.11.7 Performing a FIPS Self-test
      • 7.11.8 Modifying the FIPS Policy
    • 7.12 Disabling FIPS Mode
    • 7.13 Running FIPS Self-tests
  • 8 Common Criteria Certification
    • 8.1 Common Criteria Overview
      • 8.1.1 Features Unavailable in Common Criteria Mode
      • 8.1.2 Features Available in Common Criteria Mode
      • 8.1.3 Supported Algorithms for SSH Client
      • 8.1.4 Supported Cipher Suites
      • 8.1.5 RADIUS Protocol in CC Mode
      • 8.1.6 SCP for Common Criteria
    • 8.2 Enabling Common Criteria Mode
      • 8.2.1 Entering Common Criteria Administrative Mode
        • 8.2.1.1 General Considerations when the Device is in the Common Criteria Administrative Mode
      • 8.2.2 SSH Rekey Exchange
      • 8.2.3 CLI Banner Configuration
      • 8.2.4 Entering Common Criteria Operational Mode
      • 8.2.5 Displaying Common Criteria Information
    • 8.3 Encrypted Syslog Servers in Common Criteria Mode
    • 8.4 AAA Servers in Common Criteria Mode
      • 8.4.1 Modifying the Common Criteria Policies to Use Non-encrypted AAA Servers
    • 8.5 Downgrading from Common Criteria Mode to Non-FIPS Mode
    • 8.6 Commercial Solutions for Classified program
    • 8.7 Configuring NTP
    • 8.8 Configuring PKI
      • 8.8.1 PKI Manual Import
      • 8.8.2 Revocation Check for Peer Certificates
    • 8.9 Network Device Collaborative Protection Profile with VPN Gateway
      • 8.9.1 Support for Logging IKE and PKI Transaction Details
      • 8.9.2 Management Commands
    • 8.10 IPsec Configuration
      • 8.10.1 Configuring an IKEv2 Proposal and Policy
      • 8.10.2 Configuring an IKEv2 Authentication Proposal for Use in an IPsec Profile
        • 8.10.2.1 Configuration Example: Creating an IPsec Profile for Tunnels that Use X.509 Certificates
      • 8.10.3 Configuring IPv4 and IPv6 IPsec Tunnels
      • 8.10.4 IPsec SPD Rules
      • 8.10.5 ACL Rules
        • 8.10.5.1 Logging ACL Rules
  • 9 Configuring Logging and RADIUS Server Hosts
    • 9.1 Logging Servers
    • 9.2 Configuring an SSL Profile for Use with Logging and RADIUS Server Hosts for NDcPP
    • 9.3 Logging and RADIUS Server Host Configuration for NDcPP
      • 9.3.1 Configuring a Logging Host for NDcPP
      • 9.3.2 Configuring a RADIUS Server Host for NDcPP
    • 9.4 Setting Up Logging Hosts for VPN Gateway Configurations
  • Syslog messages
    • 10 Syslog Messages
      • 10.1 Syslog Messages in FIPS and CC Modes
  • OpenSSL license
    • 11 OpenSSL License
      • 11.1 OpenSSL License Overview

Copyright Statement

Copyright, Trademark and Proprietary Rights Information

© 2021 CommScope, Inc. All rights reserved.

No part of this content may be reproduced in any form or by any means or used to make any derivative work (such as translation, transformation, or adaptation) without written permission from CommScope, Inc. and/or its affiliates ("CommScope"). CommScope reserves the right to revise or change this content from time to time without obligation on the part of CommScope to provide notification of such revision or change.

Export Restrictions

These products and associated technical data (in print or electronic form) may be subject to export control laws of the United States of America. It is your responsibility to determine the applicable regulations and to comply with them. The following notice is applicable for all products or technology subject to export control:

   These items are controlled by the U.S. Government and authorized for export only to the country of ultimate destination for use by the ultimate consignee or end-user(s) herein identified. They may not be resold, transferred, or otherwise disposed of, to any other country or to any person other than the authorized ultimate consignee or end-user(s), either in their original form or after being incorporated into other items, without first obtaining approval from the U.S. government or as otherwise authorized by U.S. law and regulations.  

Disclaimer

THIS CONTENT AND ASSOCIATED PRODUCTS OR SERVICES ("MATERIALS"), ARE PROVIDED "AS IS" AND WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMISSIBLE PURSUANT TO APPLICABLE LAW, COMMSCOPE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, FREEDOM FROM COMPUTER VIRUS, AND WARRANTIES ARISING FROM COURSE OF DEALING OR COURSE OF PERFORMANCE. CommScope does not represent or warrant that the functions described or contained in the Materials will be uninterrupted or error-free, that defects will be corrected, or are free of viruses or other harmful components. CommScope does not make any warranties or representations regarding the use of the Materials in terms of their completeness, correctness, accuracy, adequacy, usefulness, timeliness, reliability or otherwise. As a condition of your use of the Materials, you warrant to CommScope that you will not make use thereof for any purpose that is unlawful or prohibited by their associated terms of use.

Limitation of Liability

IN NO EVENT SHALL COMMSCOPE, COMMSCOPE AFFILIATES, OR THEIR OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SUPPLIERS, LICENSORS AND THIRD PARTY PARTNERS, BE LIABLE FOR ANY DIRECT, INDIRECT, SPECIAL, PUNITIVE, INCIDENTAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES WHATSOEVER, EVEN IF COMMSCOPE HAS BEEN PREVIOUSLY ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, WHETHER IN AN ACTION UNDER CONTRACT, TORT, OR ANY OTHER THEORY ARISING FROM YOUR ACCESS TO, OR USE OF, THE MATERIALS. Because some jurisdictions do not allow limitations on how long an implied warranty lasts, or the exclusion or limitation of liability for consequential or incidental damages, some of the above limitations may not apply to you.

Trademarks

ARRIS, the ARRIS logo, COMMSCOPE, RUCKUS, RUCKUS WIRELESS, the Ruckus logo, the Big Dog design, BEAMFLEX, CHANNELFLY, FASTIRON, ICX, SMARTCELL and UNLEASHED are trademarks of CommScope, Inc. and/or its affiliates. Wi-Fi Alliance, Wi-Fi, the Wi-Fi logo, Wi-Fi Certified, the Wi-Fi CERTIFIED logo, Wi-Fi Protected Access, the Wi-Fi Protected Setup logo, Wi-Fi Protected Setup, Wi-Fi Multimedia and WPA2 and WMM are trademarks or registered trademarks of Wi-Fi Alliance. All other trademarks are the property of their respective owners.

Did you find what you were looking for?

Thanks!

Ruckus Wireless

© 2026 Ruckus Wireless LLC All rights reserved.

  • Accessibility
  • Privacy & Cookies
  • Do Not Sell My Information
  • Trademarks
  • Terms
  • Feedback