System Initialization And Configuration; Ipsec Requirements And Cryptographic Algorithms - Cisco 2621XM Operations

Modular access routers with aim-vpn/ep fips 140-2 non-proprietary security policy
Hide thumbs Also See for 2621XM:
Table of Contents

Advertisement

Secure Operation of the Cisco 2621XM/2651XM Router

System Initialization and Configuration

IPSec Requirements and Cryptographic Algorithms

Cisco 2621XM and Cisco 2651XM Modular Access Routers with AIM-VPN/EP FIPS 140-2 Non-Proprietary Security Policy
18
The Crypto Officer must disable IOS Password Recovery by executing the following commands:
configure terminal
no service password-recovery
end
show version
Once Password Recovery is disabled, administrative access to the module without the
Note
password will not be possible.
The Crypto Officer must perform the initial configuration. Cisco IOS version 12.3(3d) is the only
allowable image; no other image may be loaded.
The value of the boot field must be 0x0102. This setting disables break from the console to the ROM
monitor and automatically boots the Cisco IOS image. From the "configure terminal" command
line, the Crypto Officer enters the following syntax:
config-register 0x0102
The Crypto Officer must create the "enable" password for the Crypto Officer role. The password
must be at least 8 characters and is entered when the Crypto Officer first engages the "enable"
command. The Crypto Officer enters the following syntax at the "#" prompt:
enable secret <PASSWORD>
The Crypto Officer must always assign passwords (of at least 8 characters) to users. Identification
and authentication on the console port is required for Users. From the "configure terminal"
command line, the Crypto Officer enters the following syntax:
line con 0
password <PASSWORD>
login local
The Crypto Officer shall only assign users to a privilege level 1 (the default).
The Crypto Officer shall not assign a command to any privilege level other than its default.
The Crypto Officer may configure the module to use RADIUS or TACACS+ for authentication.
Configuring the module to use RADIUS or TACACS+ for authentication is optional. If the module
is configured to use RADIUS or TACACS+, the Crypto-Officer must define RADIUS or TACACS+
shared secret keys that are at least 8 characters long.
If the Crypto Officer loads any IOS image onto the router, this will put the router into a non-FIPS
mode of operation.
There are two types of key management method that are allowed in FIPS mode: Internet Key
Exchange (IKE) and IPSec manually entered keys.
Although the Cisco IOS implementation of IKE allows a number of algorithms, only the following
algorithms are allowed in a FIPS 140-2 configuration:
ah-sha-hmac
esp-des
OL-6262-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents