SRX

 View Only
last person joined: 7 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  ascii-text not available

    Posted 11-03-2023 08:25

    Hi All. I am trying to configure a IPSec tunnel on a SRX running version 22.2R1.9 in FIPS mode.

    Pretty straightforward config but the option for "ascii-text" is not available.

    [edit security ike policy XXXX]
    FwA:fips# set pre-shared-key ?
    No valid completions

    Any thoughts?

    Paul



    ------------------------------
    Paul Andreozzi
    ------------------------------


  • 2.  RE: ascii-text not available

    Posted 11-03-2023 08:26

    The FIPS standard requires that some less secure methods and commands are disabled in the software so they cannot be used.



    ------------------------------
    Steve Puluka BSEET - Juniper Ambassador
    IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP - Retired)
    http://puluka.com/home
    ------------------------------



  • 3.  RE: ascii-text not available

    Posted 11-03-2023 09:15

    Thanks Steve, just to confirm your statement I ran through the same exercise with a SRX without FIPS mode enabled and the option for preshared-key is available. 


    When enabling FIPS mode the commit check requires that the plain text password is removed.


    I am now required to use certificates in FIPS mode and will look into this.



    ------------------------------
    Paul Andreozzi
    ------------------------------