Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[NSM] Cannot manage transparent firewall in FIPS mode

0

0

Article ID: KB27971 KB Last Updated: 16 Sep 2013Version: 1.0
Summary:

This article describes why a firewall device running in transparent mode (L2) with Federal Information Processing Standards (FIPS) mode enabled cannot be managed via NSM.

Symptoms:

A firewall is running in transparent mode (L2) with FIPS mode enabled.  The device cannot be managed via NSM.

Cause:

This is a limitation of FIPS mode on the device.

Solution:

The NSM traffic is generated from the self zone, which is a functional zone.  As such, we cannot create a policy to send the traffic through an Advanced Encryption Standard (AES) tunnel, which is an FIPS requirement. Configuring a route based VPN places the device into L2/L3 mixed mode, which is not supported.

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search