Install the Security Engine in FIPS mode
To comply with Common Criteria evaluation standards, you must enable FIPS-compatible mode and enable 256-bit encryption as the security strength when you configure the Security Engine using the Security Engine Configuration Wizard.
The Security Engine uses TLS 1.2 and the TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 cipher suite for management connections with the SMC.
Note: If the Security Engine is installed as a Virtual Machine in ESXi, the same ESXi entropy configuration caveats apply as in the Enable FIPS mode on the SMC Appliance
topic.
These steps are the high-level tasks. For complete installation instructions, see the Forcepoint Network Security Platform Installation Guide. Before upgrading, read the Forcepoint Network Security Platform Release Notes for the version you are upgrading to.
Note: Security Engine appliances come with Security Engine software pre-installed. Before setting the Security Engine to use FIPS mode, upgrade the Security Engine software to the version that you want to use.