<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable FIPS mode in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/249569#M41729</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'd like to confirm that from R82 SSH and WebUI were made FIPS compliant, and enabled for use in FIPS mode.&lt;/P&gt;
&lt;P&gt;I can also confirm that our accredited lab submitted a report to NIST-CMVP to add R81.20 and R82 to our current certificate after completing their evaluation. We are waiting for a certificate update or response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 May 2025 06:08:30 GMT</pubDate>
    <dc:creator>Malcolm_Levy</dc:creator>
    <dc:date>2025-05-22T06:08:30Z</dc:date>
    <item>
      <title>Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157849#M26645</link>
      <description>&lt;P&gt;I have searched all over and have found no information on how to enable FIPS mode. Needing to do some testing but can't find documentation on how to enable it.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 14:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157849#M26645</guid>
      <dc:creator>fly1ng_circus</dc:creator>
      <dc:date>2022-09-22T14:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157857#M26646</link>
      <description>&lt;P&gt;Here you can find it, a switch called called ext_fips:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98252&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk98252: List of Role-Based Access features in Gaia OS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 15:59:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157857#M26646</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-22T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157900#M26649</link>
      <description>&lt;P&gt;Here an older discussion with more information:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/FIPS-mode-operation-and-some-manual-configurations/m-p/97289?search-action-id=50024436337&amp;amp;search-result-uid=97289" target="_blank"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FIPS mode operation and some manual configurations &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 09:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157900#M26649</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-23T09:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157907#M26651</link>
      <description>&lt;P&gt;Not very clear what to look for in that article once you are in /bin and check fips file...if you search for ext_fips, does not find anything.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 13:12:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157907#M26651</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T13:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157908#M26652</link>
      <description>&lt;P&gt;no none of it is very clear. I did find the switch to turn it on, but this was very obscure when trying to hunt it all down.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 13:30:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157908#M26652</guid>
      <dc:creator>fly1ng_circus</dc:creator>
      <dc:date>2022-09-23T13:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157909#M26653</link>
      <description>&lt;P&gt;Agree 100%.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 13:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157909#M26653</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T13:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157956#M26658</link>
      <description>&lt;P&gt;Did you read&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/FIPS-mode-operation-and-some-manual-configurations/m-p/97289?search-action-id=50024436337&amp;amp;search-result-uid=97289" target="_blank" rel="noopener"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FIPS mode operation and some manual configurations &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Sep 2022 06:10:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/157956#M26658</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-24T06:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158041#M26670</link>
      <description>&lt;P&gt;I have been looking through that Doc yes. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 13:34:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158041#M26670</guid>
      <dc:creator>fly1ng_circus</dc:creator>
      <dc:date>2022-09-26T13:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158063#M26677</link>
      <description>&lt;P&gt;the problem I think that is still happening is that when FIPS mode is enabled on the gateway the management station immediately loses connectivity to the gateway. This is what appears to be very poorly documented as to how to complete the full configuration and keep communication established to the gateways from the management server once fips mode is turned on.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 17:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158063#M26677</guid>
      <dc:creator>fly1ng_circus</dc:creator>
      <dc:date>2022-09-26T17:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158064#M26678</link>
      <description>&lt;P&gt;I guess I can't say it loses all connectivity. SIC claims that it is still communicating. but policy can no longer be installed.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 17:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158064#M26678</guid>
      <dc:creator>fly1ng_circus</dc:creator>
      <dc:date>2022-09-26T17:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158113#M26681</link>
      <description>&lt;P&gt;please take this with TAC&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 07:15:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/158113#M26681</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T07:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193628#M32401</link>
      <description>&lt;P&gt;I can confirm that when I run 'fips on' in an R81.20/R81.10 environment, I do NOT lose SIC connectivity on the gateways.&lt;/P&gt;&lt;P&gt;I do lose the WebUI (443 or 4434), SSH, &lt;STRIKE&gt;SSL VPN&lt;/STRIKE&gt; (SSL VPN works), and remote access IPSEC VPN (see screenshot).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IKE-Negotiation-Fails.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22579i55C5620FF4E114FD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IKE-Negotiation-Fails.JPG" alt="IKE-Negotiation-Fails.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However I can still install policy on the gateways in FIPS mode.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 06:16:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193628#M32401</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-09-27T06:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193630#M32402</link>
      <description>&lt;P&gt;Whats the command you ran to enable it? I want to try it in the lab tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 23:13:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193630#M32402</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-26T23:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193633#M32403</link>
      <description>&lt;P&gt;I ran just the basic 'fips on'. BTW make sure to snapshot the image, because 'fips off' is no longer supported (despite what the documentation might say). You will not be able to back out of FIPS once you enable it on the gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oooops." style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22580iA49B6B30B28DA2C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="FIPS.JPG" alt="Oooops." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Oooops.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@firewall-test:0]# fips&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Usage:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;fips on | off | integrity on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@firewall-test:0]# fips on&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cpridstop: cprid watchdog stopped&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cpridstop: cprid stopped&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Stopping sshd: [ OK ]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Generating default filter&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;defaultfilter:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Compiled OK.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;defaultfilter:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Compiled OK.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Backing up default.bin as default.bin.bak&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Backing up default.bin6 as default.bin6.bak&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@firewall-test:0]# fips off&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The command 'fips off' is no longer supported. FIPS mode cannot be disabled&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 23:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193633#M32403</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-09-26T23:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193636#M32404</link>
      <description>&lt;P&gt;Wow, thats crazy. Ok, I got lots of R81.20 lab fws, so will try on one tomorrow and update.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 23:47:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193636#M32404</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-26T23:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193638#M32405</link>
      <description>&lt;P&gt;Yup, got EXACT same result...wow, thats truly disappointing. I hope it gets changed at some point.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-TEST-ONLY-FW:0]# fips on&lt;BR /&gt;cpridstop: cprid watchdog stopped&lt;BR /&gt;cpridstop: cprid stopped&lt;BR /&gt;Stopping sshd: [ OK ]&lt;BR /&gt;Generating default filter&lt;BR /&gt;defaultfilter:&lt;BR /&gt;Compiled OK.&lt;BR /&gt;defaultfilter:&lt;BR /&gt;Compiled OK.&lt;BR /&gt;Backing up default.bin as default.bin.bak&lt;BR /&gt;Backing up default.bin6 as default.bin6.bak&lt;BR /&gt;initial_module:&lt;BR /&gt;Compiled OK.&lt;BR /&gt;initial_module:&lt;BR /&gt;Compiled OK.&lt;BR /&gt;[Expert@CP-TEST-ONLY-FW:0]# fips off&lt;BR /&gt;.bash_history .bash_profile .clish_history 1&lt;BR /&gt;.bash_logout .bashrc .toprc last_dump.log&lt;BR /&gt;[Expert@CP-TEST-ONLY-FW:0]# fips off&lt;BR /&gt;The command 'fips off' is no longer supported. FIPS mode cannot be disabled&lt;BR /&gt;[Expert@CP-TEST-ONLY-FW:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 00:47:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193638#M32405</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-27T00:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193639#M32406</link>
      <description>&lt;P&gt;Btw, if you want couple minutes, web UI does come back.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 00:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193639#M32406</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-27T00:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193645#M32408</link>
      <description>&lt;P&gt;I corrected my post above. After running 'fips on'&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SSL VPN portal page &lt;U&gt;does&lt;/U&gt; come up and allows login&lt;/LI&gt;&lt;LI&gt;SSH: disabled (expected)&lt;/LI&gt;&lt;LI&gt;GAIA WebGUI on 4434: disabled (expected)&lt;/LI&gt;&lt;LI&gt;Check Point Mobile client sees "Ike negotiation with gateway failed" (not expected)&lt;/LI&gt;&lt;LI&gt;Site-to-site VPN not tested yet&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lab Environment:&lt;/P&gt;&lt;P&gt;R81.20 SMS w Jumbo 10&lt;/P&gt;&lt;P&gt;R81.10 gateway w Jumbo 110&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 06:24:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193645#M32408</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-09-27T06:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193660#M32412</link>
      <description>&lt;P&gt;Here are my results on R81.20 jumbo 26:&lt;/P&gt;
&lt;P&gt;web UI on port 443 failed initially after enabling FIPS, but then worked 2 mins later&lt;/P&gt;
&lt;P&gt;ssh failed&lt;/P&gt;
&lt;P&gt;S2S failed&lt;/P&gt;
&lt;P&gt;AFTER reboot web UI also failed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 10:20:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193660#M32412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-27T10:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FIPS mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193711#M32418</link>
      <description>&lt;P&gt;Instructions for enabling FIPS mode are included in the Security Policy that is published by NIST under the certification listing together with the certification certificate&amp;nbsp;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 23:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Enable-FIPS-mode/m-p/193711#M32418</guid>
      <dc:creator>Malcolm_Levy</dc:creator>
      <dc:date>2023-09-27T23:02:55Z</dc:date>
    </item>
  </channel>
</rss>

