Non-compliant CLI Commands in FIPS Approved Mode

Last Updated : Aug 07, 2023 |
Prolog information
The following CLI commands are not permitted in FIPS approved mode:
Command name
Syntax
CHAP
ppp chap
Link Encryption for H.248 Registration (Proprietary TLS)
set link-encryption h248reg ptls
Master Key
key config-key password-encryption
OSPF
router ospf
PAP
ppp pap
PPP
  • encapsulation pppoe
  • interface USB-Modem
  • interface console
  • interface Serial
  • ppp
RADIUS
set radius authentication enable
RIP
router rip
SLA Monitor for Avaya Diagnostic Server (ADS)
set sla-monitor enable
SLS
set sls enable
SNMPv1 and SNMPv2
  • set snmp-community
  • snmp-server remote-user <username> <engineID> <group-name> auth md5
  • snmp-server remote-user <username> <engineID> <group-name> auth sha priv des56
  • snmp-server user <username> <group-name> v1
  • snmp-server user <username> <group-name> v2c
Telnet Client
ip telnet-client
Telnet Server
ip telnet
Telnet Services
ip telnet-services
VPN (IPSEC)
  • crypto ipsec
  • crypto isakmp
  • crypto map
  • ip crypto-list
  • vpn hw
  • vpn init
  • vpn memory
  • vpn monitor
  • vpn policy
  • vpn report
  • vpn show
For a full description of these commands, see Avaya Branch Gateway G430 CLI Reference guide.
Note:
Details about non-compliant CLI commands can be found in the Security Policy.