User's Guide Part 1

Table Of Contents
Chapter 1: Product description FIPS 140-2 mode
Enforced configuration in FIPS approved mode
When the PTP 700 ODU operates in the FIPS approved mode, the following configuration
settings are automatically enforced:
Identity-based user accounts is Enabled.
Telnet management interface is Disabled.
SNMP control of HTTP and Telnet is Disabled.
SNMP control of passwords is Disabled.
TFTP client is Disabled.
Secure mode alarm
The Secure mode alarm indicates that the unit is operating in the FIPS approved mode, but that
it has not been configured correctly for FIPS 140-2 operation. The secure mode alarm appears
in the System Summary page as shown in Figure 6.
Figure 6
Secure mode alarm in the System Summary page
The Secure mode alarm is also displayed in the first page of the Security Wizard as shown in
Figure 7.
Figure 7
Secure mode alarm in the Security Wizard
Security configuration for FIPS approved mode
The security configuration for the FIPS approved mode consists of the following:
The HTTPS/TLS management interface must be correctly configured, including:
o Key of keys (128-bit or 256-bit to match the AES license)
o Entropy (512-bit)
o Private key (2048-bit key size)
o Public key certificate (2048-bit key size)
Page 1-54