How to Enable and Configure Junos OS in FIPS Mode of Operation
You, as Security Administrator, can enable and configure Junos OS in FIPS mode of operation on your device. Before you begin enabling and configuring FIPS mode of operation on the device:
Verify the secure delivery of your device. See Identifying Secure Product Delivery.
Apply tamper-evident seals. See Applying Tamper-Evident Seals to the Cryptographic Module.
To enable the Junos OS in FIPS mode of operation, perform the following steps:
For SRX1500, SRX4100, SRX4200, SRX4600 devices:
Zeroize the device before enabling FIPS mode of operation
user@host>request system zeroize hypervisorFor SRX1600, SRX2300, SRX4300 devices:
Zeroize the device before enabling FIPS mode of operation
user@host>request vmhost zeroize-
Enable the FIPS mode on the device.
user@host# set system fips level 2 -
Set the root password.
user@host# set system root-authentication plain-text-password.Enter a password.
-
Remove the CSPs on commit check.
user@host# commit -
After you reboot the device, perform integrity and self-test when the module is operating in FIPS mode.
- Configure IKEv2 when AES-GCM is used for encryption of IKE and/or IPSec.
user@host# set security ike proposal <ike_proposal_name> encryption-algorithm ? Possible completions: aes-128-cbc AES-CBC 128-bit encryption algorithm aes-128-gcm AES-GCM 128-bit encryption algorithm aes-192-cbc AES-CBC 192-bit encryption algorithm aes-256-cbc AES-CBC 256-bit encryption algorithm aes-256-gcm AES-GCM 256-bit encryption algorithm user@host# set security ike proposal <ike_proposal_name> encryption-algorithm aes-256-gcm user@host# set security ipsec proposal <ipsec_proposal_name> encryption-algorithm aes-128-gcm user@host# set security ike gateway <gateway_name> version ? Possible completions: v1-only The connection must be initiated using IKE version 1 v2-only The connection must be initiated using IKE version 2 user@host# set security ike gateway <gateway_name> version v2-only user@host# commit commit complete
user@host-srx4200:fips> show version Hostname: host-srx4200 Model: srx4200 Family: junos-es Junos: 24.4R1.9 JUNOS OS Kernel 64-bit [20241104.1ed86e6_builder_bsd15_244] JUNOS OS libs [20241104.1ed86e6_builder_bsd15_244] JUNOS OS vmguest [20241104.1ed86e6_builder_bsd15_244] JUNOS OS libs compat32 [20241104.1ed86e6_builder_bsd15_244] JUNOS modules [20241219.060016_builder_junos_244_r1] JUNOS srxtvp modules [20241219.060016_builder_junos_244_r1] JUNOS OS 32-bit compatibility [20241104.1ed86e6_builder_bsd15_244] JUNOS OS runtime [20241104.1ed86e6_builder_bsd15_244] JUNOS jail runtime [20241104.1ed86e6_builder_bsd15_244] JUNOS py extensions [20241219.060016_builder_junos_244_r1] JUNOS py base [20241219.060016_builder_junos_244_r1] JUNOS OS package [20241014.220147_builder_main] JUNOS OS crypto [20241104.1ed86e6_builder_bsd15_244] JUNOS OS boot-ve files [20241104.1ed86e6_builder_bsd15_244] JUNOS srxtvp libs [20241219.060016_builder_junos_244_r1] JUNOS srx libs [20241219.060016_builder_junos_244_r1] JUNOS OS time zone information [20241104.1ed86e6_builder_bsd15_244] JUNOS network stack and utilities [20241219.060016_builder_junos_244_r1] JUNOS libs [20241219.060016_builder_junos_244_r1] JUNOS vmguest [20241219.060016_builder_junos_244_r1] JUNOS srx daemons [20241219.060016_builder_junos_244_r1] JUNOS libs compat32 [20241219.060016_builder_junos_244_r1] JUNOS daemons [20241219.060016_builder_junos_244_r1] JUNOS srx libs compat32 [20241219.060016_builder_junos_244_r1] JUNOS OS network modules [20241104.1ed86e6_builder_bsd15_244] JUNOS mtx network modules [20241219.060016_builder_junos_244_r1] JUNOS srx runtime [20241219.060016_builder_junos_244_r1] JUNOS runtime [20241219.060016_builder_junos_244_r1] JUNOS dsa [20241219.060016_builder_junos_244_r1] JUNOS SSH Tunnel Daemon [20241219.060016_builder_junos_244_r1] JUNOS na telemetry [24.4R1.9] JUNOS Web Management Platform Package [20241219.060016_builder_junos_244_r1] JUNOS lite sysmond [20241219.060016_builder_junos_244_r1] JUNOS support scripts [20241219.060016_builder_junos_244_r1] JUNOS publish subscribe base [20241219.060016_builder_junos_244_r1] Junos scheduler tracing [20241219.060016_builder_junos_244_r1] JUNOS common platform support [20241219.060016_builder_junos_244_r1] JUNOS python routing scripts for consistency check in RIB/FIB/PFE [20241219.060016_builder_junos_244_r1] JUNOS Routing mpls-oam-basic [20241219.060016_builder_junos_244_r1] JUNOS Routing lsys [20241219.060016_builder_junos_244_r1] JUNOS Routing controller-external [20241219.060016_builder_junos_244_r1] JUNOS Routing 32-bit Compatible Version [20241219.060016_builder_junos_244_r1] JUNOS Routing aggregated [20241219.060016_builder_junos_244_r1] JUNOS probe utility [20241219.060016_builder_junos_244_r1] JUNOS pppoe [20241219.060016_builder_junos_244_r1] JUNOS Openconfig [24.4R1.9] JUNOS L2 RSI Scripts [20241219.060016_builder_junos_244_r1] JUNOS Key Manager [20241219.060016_builder_junos_244_r1] JUNOS srx Data Plane Crypto Support [20241219.060016_builder_junos_244_r1] JUNOS Phone-home [20241219.060016_builder_junos_244_r1] JUNOS Juniper Malware Removal Tool (JMRT) [1.0.0+20241219.060016_builder_junos_244_r1] JUNOS J-Insight [20241219.060016_builder_junos_244_r1] JUNOS Online Documentation [20241219.060016_builder_junos_244_r1] JUNOS FIPS mode utilities [20241219.060016_builder_junos_244_r1] JUNOS Common BIOS [20241219.060016_builder_junos_244_r1] JUNOS Extension Toolkit [20241219.060016_builder_junos_244_r1] JUNOS srx platform support [20241219.060016_builder_junos_244_r1] JUNOS Juniper Malware Removal Tool (JMRT) Test [1.0.0+20241219.060016_builder_junos_244_r1] JUNOS SRX CASB Daemon [20241219.060016_builder_junos_244_r1] JUNOS SRX TVP AppQos Daemon [20241219.060016_builder_junos_244_r1] JUNOS srxtvp runtime [20241219.060016_builder_junos_244_r1]
The fips keyword next to the hostname in the output
indicates that the module is operating in FIPS mode for Junos Software Release 24.4R1
for SRX1500, SRX1600, SRX2300, SRX4100, SRX4200, SRX4300, SRX4600, and vSRX devices.