SV-233339r611394_rule
V-233339
SRG-NET-000151-NAC-000630
FORE-NC-000460
CAT II
10
To enable FIPS mode on the Forescout appliance, start by opening a secure shell to the CLI of the management appliance using Putty or another tool.
Log on using the CLIAdmin credentials established upon initial configuration.
To enable FIPS mode, type "fstool fips". A prompt alerting the user that FIPS 140-2 will be enabled will be displayed. Type "Yes" for FIPS to accept this prompt.
Note: Use of FIPS mode is not mandatory in DoD. However, it is the primary method for mitigation of this requirement and ensuring FIPS compliance.
Log on using the CLIAdmin credentials established upon initial configuration.
Verify FIPS mode by typing the command "fstool version".
If Forescout does not use a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the endpoint device, this is a finding.
V-233339
False
FORE-NC-000460
Log on using the CLIAdmin credentials established upon initial configuration.
Verify FIPS mode by typing the command "fstool version".
If Forescout does not use a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the endpoint device, this is a finding.
M
5250