User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
110
NOTE: Contact
your Fortress rep-
resentative for up-to-
date information on the
Mesh Point’s FIPS vali-
dation status.
FIPS operating mode in the current version of Mesh Point
software may still be in the process of being validated as
compliant with FIPS 140-2 Security Level 2. These Federal
standards enforce security measures beyond those of Normal
operating mode, the most significant of which include:
Only a designated Crypto Officer, as defined by FIPS, may
perform administrative functions on the Mesh Point and its
Secure Clients. (The preconfigured
administrator
-level
admin account corresponds to the FIPS Crypto Officer role;
refer to Section 2.2.3.)
If the Mesh Point encounters a FIPS Error condition, it
shuts down and reboots, running FIPS self-tests as a
normal part of boot-up. If FIPS self-tests pass, the Mesh
Point will return to normal operation. If FIPS self-tests fail,
before any interfaces are accessible, the Mesh Point will
again reboot. If the Mesh Point is unable to pass power-on
self-tests, it will cycle perpetually through this reboot
process. In this case, you must return the Mesh Point to
your vendor for service or replacement.
DH-512 and DH-1024 key establishment (Section 4.1.5)
are no longer FIPS 140-2-compliant and are therefore not
compatible with FIPS operating mode.
NOTE: Only
devices config-
ured on the Mesh Point
to pass clear text on
encrypted interfaces are
permitted to do so, even
when encrypted zone
cleartext is enabled.
Regardless of the current operating mode, the Mesh Point can
be configured to allow unencrypted data on encrypted
interfaces by enabling cleartext traffic in the encrypted zone
(refer to Section 4.1.9). In FIPS terminology, this indicates that
the Mesh Point is in Bypass Mode (BPM), as selectively
permitted clear text can pass, along with any encrypted traffic,
on encrypted interfaces.
The current operating mode can be determined by the
command prompt:
FIPS; for FIPS mode, or > or # for Normal
operating mode.
The
show fips command provides the same information, as
well as a status indicator:
# show fips
State:On
Status:OK
Possible FIPS Status values depend on the current FIPS
State.
When the FIPS State is On:
OK - FIPS tests passed: FIPS tests have either never
failed or have not failed since the last time
set fips
retest
was executed.
Test in progress - FIPS tests are currently running.
When the FIPS State is Off: