User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
109
Chapter 4
Network Security, Authentication and Auditing
4.1 Fortress Security Settings
NOTE:
Fortress
MSP is not sup-
ported on an ES210 Mesh
Point in
Station Mode
(refer to Section 3.4.10).
The CLI provides controls for various aspects of the Mesh
Point’s overall network security provisions: Fortress MSP
(Mobile Security Protocol) functions including key
establishment, data encryption and network Access ID; FIPS
operation; global session timeouts; and several additional
management and network access settings.
A basic set of security settings can be viewed through the
Mesh Point CLI with
show crypto:
# show crypto
CryptoEngine:AES256
ReKeyInterval:14400 seconds (4h)
Key Beacon Interval:30 seconds
DHsize:1024,2048
Compression:On
Legacy:Off
The Security settings you can view through show crypto are
configured through the
set crypto
command, using various
switches, as described in the relevant subsections below.
The Access ID and passwords cannot be displayed for security
reasons.
Several security settings have their own
show and set
commands, as described in their respective subsections.
4.1.1 Operating Mode
The Fortress Mesh Point can be operated in either of two
modes: Normal or FIPS (the default).
The rigidly enforced administrative requirements of FIPS
operating mode are required by deployments and applications
that must comply with the Federal Information Processing
Standards (FIPS) for cryptographic modules. However, the
high levels of security that can be implemented in Normal
operating mode generally meet or exceed the needs of virtually
all networked environments that are not required to comply
with FIPS.