Protocol Changes in FIPS Mode

The following table lists the protocols that undergo changes while the device is in FIPS mode with the default policy applied.

Protocol Changes

Protocols / Algorithms

Supported in FIPS Mode

Supported in Non-FIPS Mode

For more information on individual protocol changes, refer to the following sections:

BGP

Yes

Yes

BGP

HTTP / HTTPS

No

Yes

HTTP / HTTPS

NTP

No

Yes (supports SHA1 and MD5 hash only)

Configuring NTP

PKI

Yes

Yes

PKI

Proprietary 2-way encryption algorithms

No

Yes

Proprietary 2-way encryption algorithms

RADIUS

Yes

Yes

RADIUS

SCP

Yes

Yes

SCP

SSHv2

Yes, with limitations

Yes

SSHv2

Telnet

No

Yes

Telnet

TFTP

No

Yes

TFTP

TLS Yes Yes TLS