User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
111
OK - has no meaning with regard to FIPS tests, which
are run regardless of the FIPS
State, but can fail
without affecting the reported FIPS
Status. When FIPS
is
Off, the Mesh Point will continue to pass traffic
regardless of FIPS test results, and the FIPS
Status is
always
OK.
FIPS operating mode, which complies with Federal Information
Processing Standards 140-2, is the default mode of operation.
The Fortress Mesh Point’s
Normal operating mode does not
comply with FIPS.
NOTE: In FIPS
operating mode
the command prompt is
<hostname>FIPS>
(for view-only accounts)
or <hostname>FIPS#
(for
administrator-
level accounts).
Change between operating modes with the set fips
command. To turn FIPS operating mode on:
# set fips on
To place the Mesh Point in Normal operating mode, turn FIPS
operating mode off:
FIPS# set fips off
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.2 FIPS Settings
View complete current FIPS tests settings and statistics with
show fips -v:
FIPS> show fips -v
State:On
Status:OK
TestControl:No periodic tests
RunInterval:86400
ReSeedInterval:86400
RunRngContinuousTests:Yes
Last Run Succeeded:Yes
PrngPostFail:No
SoftCryptHashFailCT:0
SoftCryptCompressFailCT:0
SoftCryptEncryptFailCT:0
SoftCryptRngFailCT:0
SoftCryptMiscFailCT:0
FPCDDuplicateIVFailCT:0
FPCDTrngFailCT:0
FPCDPrngFailCT:0
ECDHKeyGenFailCT:0
OpenSSLFailCT:0
PktEncryptFailCT:0
PktDecryptFailCT:0
BadPktDecryptFailCT:0
SuiteBPktEncryptFailCT:0
SuiteBPktDecryptFailCT:0
SuiteBBadPktDecryptFailCT:0
CCMPPktEncryptFailCT:0
CCMPPktDecryptFailCT:0
CCMPBadPktDecryptFailCT:0
BypassGuestCreateFailCT:0