User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
112
BypassBroadcastFailCT:0
BypassUnknownDAFailCT:0
BypassHostToGuestFailCT:0
BypassHostToClientFailCT:0
BypassRcvClrFromClientFailCT:0
BypassCCMPSecureFailCT:0
BypassCCMPNonSecureFailCT:0
PktEncryptTimeoutCT:0
PktDecryptTimeoutCT:0
BadPktDecryptTimeoutCT:0
SuiteBPktEncryptTimeoutCT:0
SuiteBPktDecryptTimeoutCT:0
SuiteBBadPktDecryptTimeoutCT:0
CCMPPktEncryptTimeoutCT:0
CCMPPktDecryptTimeoutCT:0
CCMPBadPktDecryptTimeoutCT:0
BypassGuestCreateTimeoutCT:0
BypassBroadcastTimeoutCT:0
BypassUnknownDATimeoutCT:0
BypassHostToGuestTimeoutCT:0
BypassHostToClientTimeoutCT:0
BypassRcvClrFromClientTimeoutCT:0
BypassCCMPSecureTimeoutCT:0
BypassCCMPNonSecureTimeoutCT:0
KeyGenCryptoFailCT:0
LastFailedRunTS:0
FailedRunCT:0
LastCompleteRunTS:Sun May 17 08:23:38 2015
CompleteRunCT:183
NOTE: In FIPS
operating mode,
the Mesh Point stops
passing traffic in the
encrypted zone upon
any FIPS test failure and
until all FIPS tests are
again passed.
You can display just the first two lines of the show fips -v
output by omitting the -v switch.
The Mesh Point runs a number of self-tests described in FIPS
140-2, (Federal Information Processing Standards’ Security
Requirements for Cryptographic Modules).
FIPS tests run—and self-test failures are logged—regardless
of whether it is in FIPS or Normal operating mode. When the
Mesh Point is in FIPS operating mode, it will additionally shut
down and reboot upon the failure of any FIPS self-test, as
required by FIPS 140-2 (refer to Section 4.1.1).
FIPS tests can be automatically triggered or manually
executed, and automatic FIPS testing is always enabled,
regardless of operating mode or FIPS settings. Automatic test
triggers include any security-related change to the Mesh
Point’s configuration (deleting a user, for example, or changing
the re-key interval).
Use the
set fips command to change FIPS test settings and
to manually initiate FIPS self-tests.
Run FIPS self tests manually with
set fips:
FIPS# set fips retest