Skip to main content
mumbles202
New Member
August 29, 2022
Question

FIPS Confirmation

  • August 29, 2022
  • 2 replies
  • 2618 views

I'm trying to enable FIPS mode on a FGT 200F.  I've entered the following:

 

config system fips-cc
set

next

end

 

and reboot the firewall, but wasn't sure what the correct command was to verify if FIPS was enabled.  Do I instead have to do

 

config system fips-cc

 set entropy-token enable

end

exec reboot

 

2 replies

New Contributor III
August 30, 2022

Dear mumbles202.

Please use the "show" command, i.e

show system fips-cc

mumbles202
New Member
August 30, 2022

Thanks for the reply.  If I run "show system fips-cc" I get this:

 

config system fips-cc
end

 

and if I run "show full-configuration | grep fips" I get the following:

config system fips-cc
set fips-enforce enable

New Contributor III
August 31, 2022

Hello,


You can run the below command and check

get system status

 

The output will be :

FortiGate-VM64-KVM # get system status
Version: FortiGate-VM64-KVM v7.0.6,build0366,220606 (GA.F)
Virus-DB: 1.00000(2018-04-09 18:07)
Extended DB: 1.00000(2018-04-09 18:07)
Extreme DB: 1.00000(2018-04-09 18:07)
AV AI/ML Model: 0.00000(2001-01-01 00:00)
IPS-DB: 6.00741(2015-12-01 02:30)
IPS-ETDB: 6.00741(2015-12-01 02:30)
APP-DB: 6.00741(2015-12-01 02:30)
INDUSTRIAL-DB: 6.00741(2015-12-01 02:30)
IPS Malicious URL Database: 1.00001(2015-01-01 01:01)
Serial-Number: FGVMXXXXXXXXXX
License Status: Warning
VM Resources: 1 CPU/2 allowed, 2007 MB RAM
Log hard disk: Available
Hostname: FortiGate-VM64-KVM
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: 10
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: enable  --------------------------------> 
Current HA mode: standalone
Branch point: 0366
Release Version Information: GA
FortiOS x86-64: Yes
System time: Wed Aug 31 03:49:35 2022
Last reboot reason: warm reboot


You can go through the page 13 and later of this doc for more info:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/08bb20f7-991d-11e9-81a4-00505692583a/FOS56-FIPS-CC-Technote-FINAL.PDF