15
3 SecureOperationoftheContivitySwitchTheContivitySwitchisaversatilemachine;itcanberuninaNormalOperatingModeor
aFIPSOperatingMode(FIPSmode).InFIPSmode,theswitchmeetsalltheLevel2
requirementsforFIPS140-1.ToplacethemoduleinFIPSmode,clickthe“FIPS
Enabled”buttonontheServicesAvailablemanagementscreenandrestartthemodule.A
numberofconfigurationsettingsarerecommendedwhenoperatingtheContivitySwitch
inaFIPS140-1compliantmanner.Otherchangesarerequiredinordertomaintain
compliancewithFIPS140-1requirements.Theseincludethefollowing:
Recommended
• Changethedefaultadministratorpasswordontheswitch.
• Disableallmanagementprotocolsoverprivatenon-tunneledinterfaces
Required
• Selectthe“FIPSEnabled”buttonontheServiceAvailableManagementscreens
andrestartthemodule.
• Applythetamperevidentlabelsasdescribedinsection2.3
• Disablecryptographicservicesthatemploynon-FIPSapprovedalgorithms.
• ForIPSec:WhenoperatingthedeviceinaFIPS140-1compliantmanner,
onlytheTripleDESESP,DESESP,andHMAC-SHAAHmaybe
enabled.MD5isnotanapprovedFIPSalgorithm.
• ForPPTPandL2TP:WhenoperatedinaFIPS140-1compliantmanner,
MS-CHAPandCHAParenotenabledwithRC4encryption.
• ForL2P:CHAPmustbedisabledtooperateinaFIPScompliantmanner.
• TheinternalLDAPdatabasemustbeusedinplaceofanexternalLDAP
server.
• SecureSocketsLayer(SSL)cannotbeusedtoestablishsecureconnections
• ForRoutingInformationProtocol(RIP)–InFIPSmode,MD5mustbe
disabled.
ThereareseveralservicesthatareaffectedbytransitioningthemoduleintoFIPS
compliantmode.WhenthemoduleisrestartedinFIPSmode,severaladministrative
servicesaccessingtheshell,includingthedebuggingscripts,aredisabled.Whenthe
moduleisinFIPSmode,theadministratorisgivenadditionalauthoritytoresetthe
defaultadministrator’spasswordandusername.Theintegratedfirewallprogram,by
Checkpoint,andtherestorecapabilitiesaredisabledduringFIPSmode.TheFTPdemon
isalsoturnedoff,preventinganyoutsideintruderfromFTPingintotheserver.Inorder
totransitionthemodeoutofFIPSmode,theFIPSdisablebutton,ontheServices
Availablemanagementscreen,mustbeclickedandthemodulemustberestarted.
WhentransitioningthemodulefromNon-FIPSmodetoFIPSmode,theCryptoOfficer
shouldensurethatthemoduleisrunningonlytheNortelsupplied,FIPS140-1validated
firmware.Ifthereisaconcernthatthefirmwarehasbeenmodifiedduringoperationin
Non-FIPSmode(Thismightbedonebyanunauthenticatedmaliciousremoteuserwho