Skip to main content
New Member
August 31, 2026
Question

Enabling FIPS-CC error code 61

  • August 31, 2026
  • 2 replies
  • 26 views

We are attempting to run the following on my 70G but it is returning the following error. I was wondering if there is something we are doing incorrectly to try and enable the fips-cc mode. Any help would be greatly appreciated. 

 

FortiGate-70G # config system fips-cc 

FortiGate-70G (fips-cc) # show

config system fips-cc

end

FortiGate-70G (fips-cc) # set status enable

command parse error before 'status'

Command fail. Return code -61

FortiGate-70G (fips-cc) # 

2 replies

osoleimani
Staff
Staff
August 31, 2026

Hi,

The command syntax you are using is documented by Fortinet for enabling FIPS-CC:

config system fips-cc
set status enable

Since the FortiGate is returning “command parse error before 'status'”, I would first verify that the FortiOS version/build running on the 70G supports this configuration option. FIPS-CC functionality and CLI options can be version- and platform-dependent.

I would recommend checking the FortiOS Administration Guide / CLI Reference for the exact FortiOS version running on your FortiGate 70G before proceeding.

If the status option is not available in the CLI for that specific build, I would recommend opening a Fortinet Support case to confirm the supported FIPS-CC image/configuration for the 70G rather than trying alternative commands.

Hope this points you in the right direction.

osoleimani
Staff
Staff
August 31, 2026

Hi,

I wanted to add one more detail to my previous reply, as I believe it explains the behavior you are seeing.

According to Fortinet's documentation, FIPS-CC mode can only be activated/configured through the FortiGate serial console. It cannot be enabled through the Web GUI CLI or SSH. Fortinet specifically notes that the status option is not available when the CLI is accessed through the Web GUI.

This would explain the error you are seeing:

command parse error before 'status'
Command fail. Return code -61

If you connect to the FortiGate 70G through the serial console, the status option should be available on supported systems:

config system fips-cc
set status enable
show
end

Please note that enabling FIPS-CC is a significant change. Fortinet indicates that the process can require setting a new administrator password, warns that most of the existing configuration will be lost, and reboots the FortiGate to perform the FIPS-CC self-tests. I would therefore make sure you have a suitable configuration backup and a maintenance/recovery plan before proceeding.

For the complete procedure and additional considerations, please refer to the Fortinet Community Technical Tip: How to enable FIPS-CC mode.

I hope this additional detail helps explain the -61 error and points you in the right direction.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!