Using FIPS Encryption

Enabling FIPS 140-2 Approved Mode

Users who are subject to government or industry regulations must enable FIPS 140-2 approved mode when using AirWave. When FIPS 140-2 approved mode is on, users can connect to the AirWave server using FIPS 140-2 approved functions (ciphers).

To enable FIPS 140-2 approved mode:

  1. Log in to the AMPCLI session.
  2. In the CLI prompt, enter 7-2 to enable FIPS.
  3. After enabling FIPS, the Enable SSH-RSA Public Key Type for PVOS switches options display, allowing login to the PVOS switch using public key authentication from AirWave.

With FIPS mode enabled, DTLSv1.0 can be enabled or disabled by running the Security> Enable/Disable DTLSv1.0 command.

The AirWave server reboots automatically after FIPS mode is enabled.

FIPS support is available, but is not certified for this release.

Enabling SELinux in Enforcing Mode

To enable SELinux in Enforcing mode, users must first set it to Permissive mode and then, switch to Enforcing mode. To enable SELinux in Permissive mode:

  1. In the CLI, select Security > 3 Configure SELinux > 2 Permissive.

  2. After enabling Permissive mode, select Security > 3 Configure SELinux > 3 Enforcing.