Modifying the Korean CC Policy

After the device enters the Korean CC mode of operation, you can modify the default security policy.
Note: Making changes to the default security policy on the device is not recommended and weakens the security of the device.

When you make no changes to the policy, the default policy is applied on the device and the device operates in strict Korean CC mode upon reload. The protocols that are disabled as part of the default policy and can be adjusted to set a more flexible policy are:

  • TFTP
  • UDP Syslog server
  • SNMP access to critical security parameter (CSP) MIB objects
  • Non-TLS TACACS+
  • UDP RADIUS

To set a more flexible policy on the RUCKUS ICX device, use the following commands as desired to modify the default policy.

  • Allow TFTP access:
    device(config)# fips policy allow tftp-access

    Syntax: [no] fips policy allow tftp-access

  • Allow access to send the syslogs to the UDP server:
    device(config)# fips policy allow udp-logging
  • Allow SNMP access to the critical security parameter (CSP) MIB objects:
    device(config)# fips policy allow snmp-csp-access

    Syntax: [no] fips policy allow snmp-csp-access

  • Allow access to monitor mode for debugging both from application and boot prompts:
    device(config)# fips policy allow monitor-full-access

    Syntax: [no] fips policy allow monitor-full-access

    Note: During an application reset, monitor access is restored to allow debugging.
  • Allow non-TLS TACACS+:
    device(config)# fips policy allow common-criteria aaa-server-any

    Syntax: [no] fips policy allow common-criteria aaa-server-any

  • Allow non-TLS UDP RADIUS server:
    device(config)# fips policy allow udp-radius-server

    Syntax: [no] fips policy allow udp-radius-server

  • Retain the shared secret keys for all protocols and the host passwords:
    device(config)# fips policy retain shared-secrets

    Syntax: [no] fips policy retain shared-secrets

  • Retain the SSH DSA host keys:
    device(config)# fips policy retain dsa-host-keys

    Syntax: [no] fips policy retain dsa-host-keys

  • Retain the TLS RSA host keys and the TLS server digital certificate:
    device(config)# fips policy retain rsa-host-keys

    Syntax: [no] fips policy retain rsa-host-keys