- play_arrow Junos OS in FIPS Mode of Operation for SRX Series Security Devices
- Understanding Junos OS in FIPS Mode of Operation
- Identifying Secure Delivery
- Understanding FIPS Mode of Operation Terminology and Supported Cryptographic Algorithms
- Understanding Zeroization to Clear System Data for FIPS Mode of Operation
- Understanding FIPS Self-Tests
- Applying Tamper-Evident Seals to the Cryptographic Module
- play_arrow Configuring Roles and Authentication Methods
- Downloading Software Packages from Juniper Networks (FIPS Mode)
- Downloading and Installing Junos Software Packages (FIPS Mode)
- Understanding Roles and Services for Junos OS in FIPS Mode of Operation
- Understanding the Associated Password Rules for an Authorized Administrator
- Understanding FIPS Authentication Methods
- Understanding Services for Junos OS in FIPS Mode of Operation
- play_arrow Configuring SSH and Console Connection
- play_arrow Configuring Junos OS in FIPS Mode of Operation
Unsupported Junos-FIPS Configuration Statements
The following configuration statements are not supported on Junos-FIPS:
Statement | Description |
---|---|
| Junos-FIPS does not allow an unencrypted or weakly encrypted or a connection that relies on a vulnerable key establishment protocol. |
| Junos-FIPS allows the SSHv2 setting only. |
| You must encrypt administrator passwords using strong algorithms, such as Secure Hash Algorithm (sha-256 and sha-512). |
| Junos-FIPS does not support preconfigured proposal sets. You must configure an IKE proposal explicitly. |
| Junos-FIPS does not support Message Digest 5 (MD5). However it does support (sha-256 and sha-384). |
| Junos-FIPS does not support Data Encryption Standard (DES). However it does support Advanced Encryption Standard (AES) or 3DES. |
| Authentication Header (AH) protocol provides authentication but not encryption. Enhanced Security Protocol (ESP) is required. |
| Junos-FIPS does not support Diffie-Hellman (DH) groups 1 and 2. However, DH-group 14 and higher are supported on Junos-FIPS. |