ION Device FIPS Mode Enablement
FIPS certification
is in review.
| Starting with Prisma SD-WAN Release 5.6.1, you can toggle between non-FIPS to FIPS
mode for the supported ION devices from the Prisma SD-WAN web interface (controller). When you
enable FIPS mode, all cryptographic security parameters (CSPs),
including the CIC certificate, are cleared and the device is
rebooted. After reboot, the device comes up in FIPS approved mode of
operation with a new CIC provisioned by the controller and FIPS
functionality enabled on the device.
The ION device maintains minimal configurations and reboots when
changing the mode:
- Controller Interface with Static or DHCP
- Used_for Public with Static or DHCP
- PPPoE Interface
- Controller Connection Cipher
- Static/Host entries
- ION-KEY & Secret KEY, and fips
change_mode request
Enable
the FIPS mode on the Prisma SD-WAN web interface as shown in the
image.
Supported devices in Release 5.6.1 are ION 1200, ION 1200-C-NA/ROW, and ION
1200-C5G-WW.
FIPS
is not supported on other models, irrespective of the software version
installed on the device.
|