Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cybervex
New Contributor

Disabling FIPS mode

Hey all

 

I am looking to disable FIPS mode on a FortiGate 100E, 200E, 500E.

 

Is it as simple as format, load new firmware, restore config?

 

Is there anything in the config that needs to be edited out?

 

 

 

 

3 REPLIES 3
hbac
Staff
Staff

Hi @cybervex,

 

Do you have FIPS certified firmware image installed or just have FIPS-CC enabled? FIPS-CC can be disabled in the CLI, please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-FIPS-CC-mode/ta-p/196629

 

config system fips-cc
set status disable 

end

 

Regards, 

cybervex
New Contributor

It is as simple as I hoped.

I had a fips version installed.  I backed it up. Formatted.  Installed a non-fips version. Restored my configuration. I then cleaned up the leftover bits in policies and profiles.

GeorgeZhong
Staff
Staff

We can execute the CLI command 'execute factoryreset' to reset the device to the factory default configuration to disable the FIPS-CC. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors