Reference v4.1.0 Instruction Manual

Network OS Command Reference 563
53-1003115-01
prom-access disable
2
prom-access disable
Disables access to the Boot PROM for FIPS compliance.
Synopsis prom-access disable
Operands None
Defaults The Boot PROM is accessible.
Command Modes Privileged EXEC mode
Description Use this command to disable access to the boot PROM for compliance with FIPS.
In non-FIPS compliant mode, you can access the Boot PROM by holding down the ESC key during
the 4-second period when the switch is booting up. In FIPS compliant state, PROM access is
disabled to prevent users from net-installing firmware.
Usage Guidelines Under normal operating conditions, this command is hidden to prevent accidental use.
Enter unhide fips with the passwordfibranne” to make the command available.
ATTENTION
Use this command only when preparing a switch for FIPS compliance.
CAUTION
Once Boot PROM access is disabled, you cannot re-enable it.
Examples To disable access to the Boot PROM:
switch# unhide fips
Password: *****
switch# prom-access disable
You are disabling PROM access. Do you want to continue? [yes/no] (no): yes
switch# PROM access Disabled
See Also cipherset, fips root disable, fips selftests, fips zeroize, show prom-access, unhide fips