Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mumbles202
New Contributor II

FIPS Confirmation

I'm trying to enable FIPS mode on a FGT 200F.  I've entered the following:

 

config system fips-cc
set

next

end

 

and reboot the firewall, but wasn't sure what the correct command was to verify if FIPS was enabled.  Do I instead have to do

 

config system fips-cc

 set entropy-token enable

end

exec reboot

 

3 REPLIES 3
akumarr
Staff
Staff

Dear mumbles202.

Please use the "show" command, i.e

show system fips-cc

Best regards,
ARUNKUMAR.R.
mumbles202
New Contributor II

Thanks for the reply.  If I run "show system fips-cc" I get this:

 

config system fips-cc
end

 

and if I run "show full-configuration | grep fips" I get the following:

config system fips-cc
set fips-enforce enable

vsahu
Staff
Staff

Hello,


You can run the below command and check

get system status

 

The output will be :

FortiGate-VM64-KVM # get system status
Version: FortiGate-VM64-KVM v7.0.6,build0366,220606 (GA.F)
Virus-DB: 1.00000(2018-04-09 18:07)
Extended DB: 1.00000(2018-04-09 18:07)
Extreme DB: 1.00000(2018-04-09 18:07)
AV AI/ML Model: 0.00000(2001-01-01 00:00)
IPS-DB: 6.00741(2015-12-01 02:30)
IPS-ETDB: 6.00741(2015-12-01 02:30)
APP-DB: 6.00741(2015-12-01 02:30)
INDUSTRIAL-DB: 6.00741(2015-12-01 02:30)
IPS Malicious URL Database: 1.00001(2015-01-01 01:01)
Serial-Number: FGVMXXXXXXXXXX
License Status: Warning
VM Resources: 1 CPU/2 allowed, 2007 MB RAM
Log hard disk: Available
Hostname: FortiGate-VM64-KVM
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: 10
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: enable  --------------------------------> 
Current HA mode: standalone
Branch point: 0366
Release Version Information: GA
FortiOS x86-64: Yes
System time: Wed Aug 31 03:49:35 2022
Last reboot reason: warm reboot


You can go through the page 13 and later of this doc for more info:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/08bb20f7-991d-11e9-81a4-005056...


Regards,
Vishal
Labels
Top Kudoed Authors