Find Technical Content
  • Home
  • Ruckus Support Portal
  • Ruckus Networks
  • Table of Contents
  • Dark Mode

Powered by Titania Delivery

⚠ This cached page may be outdated. Click refresh to get the latest content.
Cached Version You are Offline

You are viewing a cached version of this page.

You are currently offline. This page was loaded from cache.

RUCKUS FastIron FIPS and Common Criteria Configuration Guide, 10.0.10 53-1005820-04

  • 1 CommScope Legal Statements
  • Preface Ruckus
    • 3 Contact Information, Resources, and Conventions
      • 3.1 Contacting RUCKUS Customer Services and Support
      • 3.2 Document Feedback
      • 3.3 RUCKUS Product Documentation Resources
      • 3.4 Online Training Resources
      • 3.5 Document Conventions
      • 3.6 Command Syntax Conventions
  • 4 About This Document
    • 4.1 Supported hardware and software
  • 5 Federal Information Processing Standards
    • 5.1 FIPS Overview
    • 5.2 How FIPS Works
  • Upgrading Software on FIPS-enabled devices
    • 6 Upgrading and Downgrading Software on FIPS-enabled Devices
      • 6.1 Software Downgrades from FIPS
      • 6.2 Upgrading FIPS-enabled Devices
        • 6.2.1 Preparing for a FIPS Software Upgrade
        • 6.2.2 Image Verification in FIPS or CC Mode
        • 6.2.3 Performing a FIPS or CC Software Upgrade to FastIron 10.0.10d
        • 6.2.4 SSH Connection after Upgrading a FIPS or CC Operational Device to FastIron 08.0.10 or Later
      • 6.3 Downgrading from FIPS to Non-FIPS Mode
  • 7 FIPS Configuration
    • 7.1 User Roles in FIPS Mode
    • 7.2 Commands Disabled in FIPS Mode
    • 7.3 Hidden Files in FIPS Mode
    • 7.4 Cryptographic Algorithms in FIPS Mode
    • 7.5 SSH
    • 7.6 SSH Clients
    • 7.7 Usernames and SSH Public Key Authentication
      • 7.7.1 Implementation
      • 7.7.2 Restrictions
    • 7.8 Protocol Changes in FIPS Mode
      • 7.8.1 BGP
      • 7.8.2 HTTP / HTTPS
      • 7.8.3 TLS
        • 7.8.3.1 TLS Implementation in FastIron Devices
      • 7.8.4 PKI
      • 7.8.5 Proprietary 2-way Encryption Algorithms
      • 7.8.6 RADIUS Protocol in FIPS Mode
      • 7.8.7 SCP
      • 7.8.9 SSHv2
      • 7.8.10 Telnet
      • 7.8.11 TFTP
    • 7.9 System Reset and Boot up in FIPS Mode
    • 7.10 Debugging in FIPS Mode
    • 7.11 Placing the Device in FIPS Mode
      • 7.11.1 General Steps to Place the Device in FIPS Mode
      • 7.11.2 Enabling FIPS Mode
      • 7.11.3 Zeroizing Shared Secrets and Host Keys
      • 7.11.4 Configuring User Authentication
      • 7.11.5 Saving the Configuration
      • 7.11.6 Reloading the Device
      • 7.11.7 Performing a FIPS Self-test
      • 7.11.8 Modifying the FIPS Policy
    • 7.12 Disabling FIPS Mode
    • 7.13 Running FIPS Self-tests
  • 8 Common Criteria Certification
    • 8.1 Common Criteria Overview
      • 8.1.1 Features Unavailable in FIPS and Common Criteria Mode
      • 8.1.2 Features Available in Common Criteria Mode
      • 8.1.3 Supported Algorithms for SSH Client
      • 8.1.4 Supported Cipher Suites
      • 8.1.5 RADIUS Protocol in CC Mode
      • 8.1.6 SCP for Common Criteria
    • 8.2 Enabling Common Criteria Mode
      • 8.2.1 Entering Common Criteria Administrative Mode
      • 8.2.2 SSH Rekey Exchange
      • 8.2.3 CLI Banner Configuration
      • 8.2.4 Entering Common Criteria Operational Mode
      • 8.2.5 Displaying Common Criteria Information
    • 8.3 Encrypted Syslog Servers in Common Criteria Mode
    • 8.4 AAA Servers in Common Criteria Mode
      • 8.4.1 Modifying the Common Criteria Policies to Use Non-encrypted AAA Servers
    • 8.5 Downgrading from Common Criteria Mode to Non-FIPS Mode
    • 8.6 Commercial Solutions for Classified program
    • 8.7 Configuring NTP
      • 8.7.1 Enabling NTP
      • 8.7.2 Disabling NTP
      • 8.7.3 Enabling NTP Authentication
      • 8.7.4 Defining an Authentication Key
      • 8.7.5 Configuring the NTP Client
      • 8.7.6 Displaying NTP Status
      • 8.7.7 Displaying NTP Association Information
      • 8.7.8 Displaying NTP Association Details
      • 8.7.9 NTP Client Mode Configuration Example
      • 8.7.10 NTP Strict Authentication Configuration Example
    • 8.8 Configuring PKI
      • 8.8.1 PKI Manual Import
      • 8.8.2 Revocation Check for Peer Certificates
    • 8.9 Network Device Collaborative Protection Profile
      • 8.9.1 Support for Logging PKI Transaction Details
      • 8.9.2 Management Commands
    • 8.10 MACsec Configuration
      • 8.10.1 MACsec Overview
      • 8.10.2 Configuring MACsec
      • 8.10.3 Enabling MACsec and Configuring Group Parameters
        • 8.10.3.1 Configuring MACsec Key-Server Priority
        • 8.10.3.2 Configuring MACsec Integrity and Encryption
        • 8.10.3.3 Configuring MACsec Frame Validation
        • 8.10.3.4 Configuring Replay Protection
        • 8.10.3.5 Configuring Data-Delay Protection
      • 8.10.4 MKA Keychain Overview and Considerations
        • 8.10.4.1 Creating and Configuring an MKA Keychain
      • 8.10.5 Enabling and Configuring Group Interfaces for MACsec
        • 8.10.5.1 Configuring the Pre-shared Key
      • 8.10.6 Sample MACsec Configuration
      • 8.10.7 Displaying MACsec Information
        • 8.10.7.1 Displaying MACsec Configuration Details
        • 8.10.7.2 Displaying Information on Current MACsec Sessions
        • 8.10.7.3 Displaying MKA Protocol Statistics for an Interface
        • 8.10.7.4 Displaying MACsec Secure Channel Activity for an Interface
  • 9 Configuring Logging and RADIUS Server Hosts
    • 9.1 Logging Servers
    • 9.2 Configuring an SSL Profile for a TLS Connection
    • 9.3 Logging and RADIUS Server Host Configuration for NDcPP
      • 9.3.1 Configuring a Logging Host for NDcPP
      • 9.3.2 Configuring a RADIUS Server Host for NDcPP
  • Syslog messages
    • 10 Syslog Messages
      • 10.1 Syslog Messages in FIPS and CC Modes
  • OpenSSL license
    • 11 OpenSSL License
      • 11.1 OpenSSL License Overview

Upgrading and Downgrading Software on FIPS-enabled Devices

In this section:

  1. Software Downgrades from FIPS
  2. Upgrading FIPS-enabled Devices
    FIPS 140-3 compliance is a combination of implemented hardware procedures and the activation of a software-based security policy.
  3. Downgrading from FIPS to Non-FIPS Mode
    Once the ICX device is enabled for FIPS, it remains enabled internally, so that the signature file must be copied first whenever the image is copied.

Did you find what you were looking for?

Thanks!

Ruckus Wireless

© 2026 Ruckus Wireless LLC All rights reserved.

  • Accessibility
  • Privacy & Cookies
  • Do Not Sell My Information
  • Trademarks
  • Terms
  • Feedback