FIPS mode requirement and configuration for PTP 820

Summary

This document explains about the requirement and configuration required in PTP 820 for FIPS 140-2-Compliance

Cause

The objective of FIPS 140-2 is to provide a standard for secured communication devices, with an emphasis on encryption and cryptographic methods. The FIPS standards are broadcasted by the National Institute of Standards and Technology (NIST) and provide an extensive set of requirements for both hardware and software. It is the responsibility of the customer to ensure that the above FIPS requirements are met

Solution

In order to confirm that the radios are FIPS 140-2 Compliance, we must ensure that:

  1. To use the FIPS hardware
  2. The FIPS validated software version to be used.

PTP 820 FIPS Requirements and Configuration

Release 8.3, PTP 820G PTP 820C and PTP 820S can be configured to be FIPS 140-2-compliant in specific hardware and software configurations.

Hardware Requirements

For PTP 820 C/S/G nodes to be FIPS-compliant, the unit must be FIPS-compliant hardware.

Software Requirements

FIPS compliance requires the user to operate the PTP 820C/S/G in FIPS mode. FIPS mode must be enabled by the user. It can be enabled via the Web EMS, the CLI, or SNMPv3. Enabling FIPS mode requires a system reset.

Requirements for FIPS Compliance:

For PTP 820C or PTP 820S node to be FIPS-compliant, the unit must be FIPS-compliance hardware.

For PTP 820G node to be FIPS-compliant, the chassis must be FIPS-compliant.

For PTP 820C, PTP 820S, or PTP 820G AES-256 Payload Encryption must be configured

Note: Special labels must be affixed to a FIPS-compliant PTP 820G unit. These labels are tamper-evident and must be applied in such a way that it is not possible to open the chassis. These labels must be replaced whenever components are added to or removed from the unit. Replacement labels can be ordered from Cambium Networks. Tamper-evident labels should be inspected for integrity at least once every six months. For further details, refer to the PTP 820G Installation Guide.

Enabling FIPS Mode from GUI

To set the unit to operate in FIPS mode:

1.Select Platform > Security > General > Configuration. The Security General Configuration page opens:

2.Click on enable under FIPS admin configuration and then apply the configuration:

Note: Changing the FIPS configuration causes a unit reset.

3.Apply the same configuration on second radio as well.

Enabling  FIPS Mode from CLI

To set the unit to operate in FIPS mode, enter the following command in root view:

root> platform security fips-mode set admin enable


Note: Changing the FIPS configuration causes a unit reset.


To disable FIPS mode, enter the following command in root view:

root> platform security fips-mode set admin disable

To display the unit’s current FIPS setting, enter the following command in root view:

root> platform security fips-mode show

Status values are:

  • enable – FIPS mode is enabled.
  • disable – FIPS mode is disabled.

Enabling  FIPS Mode from SNMP

The below MIB OID to be used for enabling the FIPS admin configuration and to check the status:

MIB OID

 MIB Name

 MIB Type

 MIB Access

 Description

1.3.6.1.4.1.2281.10.11.10.1

genEquipSecurityFipsAdmin

INTEGER (2..3)

read-write

FIPS admin configuration parameter

 1.3.6.1.4.1.2281.10.11.10.2.0                         

 genEquipSecurityFipsStatus          

INTEGER {down(0) Up (1)}

read-only

 FIPS operational status

After enabling FIPS:

  • The MD5 option for SNMPv3 is blocked.
  • After any system reset, the length of time before users can log back into the system is longer than usual due to FIPS-related self-testing.

FIPS certified latest software versions:

https://support.cambiumnetworks.com/files/ptp820/#r2

For PTP 820 C & S - PTP820CS - G2U-8.3.0.0.0.517 Firmware 12-December-2018

For PTP 820 G - PTP820G - G2U-8.3.0.0.0.517 Firmware 12-December-2018

FIPS certified PTP 820 G/C/S part numbers:

FIPS certified PTP 820 C part numbers

SN

Part number

Description

1

C150082B051

PTP 820C FIPS-140 Ready Radio,15GHz,TR640,ChH,Hi,15245-15355MHz

2

C150082B052

PTP 820C FIPS-140 Ready Radio,15GHz,TR640,ChH,Lo,14605-14715MHz

3

C150082B050

PTP 820C FIPS-140 Ready Radio,NTIA 15GHz,TR640,All, Lo,14500-14710MHz

4

C150082B049

PTP 820C FIPS-140 Ready Radio,NTIA 15GHz,TR640,All,Hi,15140-15350MHz

5

C230082B035

PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChH,Hi,23000-23600MHz

6

C230082B036

PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChH,Lo,21780-22400MHz

7

C230082B033

PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChL,Hi,22400-23020MHz

8

C230082B034

PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChL,Lo,21200-21800MHz

9

C070082B093

PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch1W5,Hi,7434.5-7585.5MHz

10

C070082B094

PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch1W5,Lo,7134.5-7285.5MHz

11

C070082B095

PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch6W10,Hi,7584.5-7765.5MHz

12

C070082B096

PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch6W10,Lo,7284.5-7465.5MHz

13

C080082B087

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch1W5,Hi,8095-8245MHz

14

C080082B088

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch1W5,Lo,7735-7885MHz

15

C080082B089

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch5W9,Hi,8215-8365MHz

16

C080082B090

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch5W9,Lo,7855-8005MHz

17

C080082B091

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch9W13,Hi,8335-8485MHz

18

C080082B092

PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch9W13,Lo,7975-8125MHz

FIPS certified  PTP 820 G part numbers

SN

Part number

Description

1

C000082M021

PTP 820G NTIA FIPS-140 Ready, Dual Modem, Eth + 16 E1/T1

2

N000082H004

PTP 820GX RMC-B card, FIPS-140 Ready

3

N000082H002

PTP 820GX TCC-B2 Card, FIPS-140 Ready

4

N000082H003

PTP 820GX TCC-B2-XG-MC card, FIPS-140 Ready

5

N000082H001

PTP 820GX TCC-B-MC Card, FIPS-140 Ready

FIPS certified  PTP 820 S part numbers

SN

Part number

Description

1

C150082B047

PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChH,Hi,15245-15355MHz

2

C150082B048

PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChH,Lo,14605-14715MHz

3

C150082B045

PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChL,Hi,15140-15250MHz

4

C150082B046

PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChL,Lo,14500-14610MHz

5

C070082B089

PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch1W5,Hi,7434.5-7585.5MHz

6

C070082B090

PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch1W5,Lo,7134.5-7285.5MHz

7

C070082B091

PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch6W10,Hi,7584.5-7765.5MHz

8

C070082B092

PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch6W10,Lo,7284.5-7465.5MHz

9

C080082B081

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch1W5,Hi,8095-8245MHz

10

C080082B082

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch1W5,Lo,7735-7885MHz

11

C080082B083

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch5W9,Hi,8215-8365MHz

12

C080082B084

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch5W9,Lo,7855-8005MHz

13

C080082B085

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch9W13,Hi,8335-8485MHz

14

C080082B086

PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch9W13,Lo,7975-8125MHz