question

stylus avatar image
0 Likes"
stylus asked

How to enable FIPS-CC mode on a FortiGate?

How do I enable FIPS-CC mode on my Fortigate? The instructions mention that I should run the following commands:

 # config system fips-cc
 (fips-cc) # set status enable
 (fips-cc) # end

But "status" isn't there and I get an error when I try to set it.

FortiOS
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
pingmemaybe avatar image
2 Likes"
pingmemaybe answered

In order to see the "status" option, you must use a serial console connected to the FGT. The FGT will drop most configuration settings and restart, so it's recommended to backup before you continue.

You might also need to disable the entropy token in the fips-cc config if your device fails to boot:

set entropy-token disable
· 2
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

stylus avatar image stylus ♦♦ commented ·

Thank you!

0 Likes 0 ·

This statement "You might also need to disable the entropy token in the fips-cc config if your device fails to boot:" Should read "You will need to disable the entropy token in the fips-cc config if your device doesn't have an entropy token or your device will fail to boot:" The fix action is re-image.

0 Likes 0 ·

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space