How FIPS Works
fips enable CLI command on the management station while the station is connected to the device
console port with a serial cable. After you enter the
fips enable command, the device is administratively in FIPS mode and by default runs in strict
FIPS-compliant mode upon reload.
The default FIPS policy is for the system to run in a strict mode that fully supports FIPS 140-3 specifications. However, the device allows you the flexibility to configure a modified FIPS policy according to your network requirements.
The default FIPS policy enforces the following actions for strict FIPS compliance:
- Disables TFTP access
- Disables monitor access to memory access commands
- Returns 0 or null for SNMP MIBs for passwords or keys (referred to as critical security parameter objects)
- Zeroizes shared secrets and passwords
The device performs the following functions automatically during reboot after the
fips enable command is entered:
- Disables Telnet
- Enables SCP access
- Disables the HTTP and HTTPS servers
- Disables SNMP access to critical security parameter (CSP) MIB objects
After defining the FIPS policy, save the configuration, and reboot the device. While the device is booting, several tests are run to ensure the device is FIPS-compliant.
After these tests are completed successfully, the device reloads and is operationally in FIPS mode.
All the optional FIPS policy commands are provided to perform various non-approved FIPS operations when FIPS is enabled.