EasyManuals Logo

H3C MSR Series Command Reference

H3C MSR Series
1187 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1160 background imageLoading...
Page #1160 background image
1137
Default
FIPS mode is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
After you enable FIPS mode and reboot the device, the device operates in FIPS mode. The FIPS
device has strict security requirements, and performs self-tests on cryptography modules to verify
that they are operating correctly.
After you execute the fips mode enable command, the system provides the following methods to
enter FIPS mode:
Automatic reboot
Select the automatic reboot method. The system automatically performs the following tasks:
a. Create a default FIPS configuration file named fips-startup.cfg.
b. Specify the default file as the startup configuration file.
c. Require you to configure the username and password for next login.
You can press Ctrl+C to exit the configuring process so the fips mode enable command will
not be executed.
The system automatically uses the specified startup configuration file to reboot the device after
you configure the administrator's username and password.
Manual reboot
This method requires that you manually complete the configurations for entering FIPS mode,
and then reboot the device.
To use manual reboot to enter FIPS mode:
d. Enable the password control feature globally.
e. Set the number of character types a password must contain to 4, and set the minimum
number of characters for each type to one character.
f. Set the minimum length of user passwords to 15 characters.
g. Add a local user account for device management, including the following items:
A username.
A password that must comply with the password control policies.
A user role of network-admin.
A service type of terminal.
h. Delete the FIPS-incompliant local user service types Telnet, HTTP, and FTP.
i. Save the configuration file and specify it as the startup configuration file.
j. Delete the original startup configuration file in binary format.
k. Reboot the device.
After the fips mode enable command is executed, the system prompts you to choose a reboot
method. If you do not make a choice within 30 seconds, the system uses the manual reboot method
by default.
After the undo fips mode enable command is executed, the system provides the following methods
to exit FIPS mode:
Automatic reboot

Table of Contents

Other manuals for H3C MSR Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the H3C MSR Series and is the answer not in the manual?

H3C MSR Series Specifications

General IconGeneral
CategoryNetwork Router
IPv6 SupportYes
DimensionsVaries by model
WeightVaries by model
Product TypeModular Router
PortsVaries by model
WAN InterfacesVaries by model
FirewallYes
QoSYes
Wireless SupportVaries by model
USB PortsVaries by model
Console PortYes
Power SupplyVaries by model
RedundancyVaries by model
Operating Temperature0°C to 45°C
Storage Temperature-40°C to 70°C
Humidity5% to 95% non-condensing
SeriesMSR
CertificationsCE, FCC, RoHS

Related product manuals