To enable FIPS-140-2

Purpose

Perform this procedure to enable FIPS-140-2 level 1 support.

The NFM-P returns an SNMP deployment error from the NE for operations that are not supported because of FIPS restrictions.

Consider the following when you enable FIPS-140-2:

  • The following algorithms are not accessible for keychains:
    • MD5

    • HMAC-MD5

    • DES

  • The following algorithms are not available:
    • MD5

    • DES

Note: FIPS-140-2 level 1 is only supported on the 7705 SAR, Release 8.0 R6 or later. If you enable FIPS-140-2 from the node CLI and perform an NE reboot or software upgrade from Release 8.0 R4 to Release 8.0 R5 in the NFM-P GUI, the 7705 SAR NE will not boot.

Steps
 

On the equipment or routing tree, right-click on an NE. The Network Element (Edit) form opens.


Click on the Polling tab. In the General sub-tab, enable the Enable FIPS-140-2 parameter.


Save your changes and close the form.


Reboot the NE.

End of steps