Install the Security Engine in FIPS mode

To comply with Common Criteria evaluation standards, you must enable FIPS-compatible mode and enable 256-bit encryption as the security strength when you configure the Security Engine using the Security Engine Configuration Wizard.

The Security Engine uses TLS 1.2 and the TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 cipher suite for management connections with the SMC.

Note: If the Security Engine is installed as a Virtual Machine in ESXi, the same ESXi entropy configuration caveats apply as in the Enable FIPS mode on the SMC Appliance topic.

These steps are the high-level tasks. For complete installation instructions, see the Forcepoint Network Security Platform Installation Guide. Before upgrading, read the Forcepoint Network Security Platform Release Notes for the version you are upgrading to.

Note: Security Engine appliances come with Security Engine software pre-installed. Before setting the Security Engine to use FIPS mode, upgrade the Security Engine software to the version that you want to use.

Steps

  1. Download the Security Engine software from https://support.forcepoint.com/s/download, then validate the checksums.
    Note: Save the Security Engine upgrade .zip file to the root directory of the USB drive or DVD media.
    For information about obtaining the installation files, see the Forcepoint Network Security Platform Installation Guide.
  2. Upgrade the Security Engine software to the version that you want to use.
    1. In the Security Engine Configuration Wizard, select Upgrade.
    2. In the Select Source Media dialog box, select the appropriate media type, then click OK.
      The software update signature is verified.
    3. Click OK.
      The upgrade starts.
    4. Select Set kernel in FIPS mode after reboot.
    5. Click OK.
    Security Engine appliance restarts and displays the upgraded version.
  3. Configure the Security Engine with the Security Engine Configuration Wizard.
    Follow the normal process to define the Security Engine properties, with these exceptions:
    • Select Restricted FIPS-Compatible Operating Mode.

      This option enables the FIPS 140-3 cryptographic module.

    • Ensure that the 256-bit security strength is selected in the Management Server configuration settings.
      Note: This option is selected by default.
  4. To verify FIPS-Approved mode of operation, verify that the following messages are shown on the console when the Security Engine appliance restarts:
    FIPS: rootfs integrity check OK

    This message confirms that the module's integrity test has been executed successfully. The integrity test verifies an ECDSA P-521 signature with SHA-512 over the root file system. If the integrity test fails, an error message is displayed and the module restarts.

    FIPS power-up tests succeeded

    This message confirms that the FIPS power-up self-tests have been executed successfully. If the power-up tests fail, a power-up test error message is shown and the module restarts.

    If the connection with the Management Server is not established successfully, verify the following:
    • The one-time generated password is correct.
    • The Management Server IP address is correct.
    • The certificate fingerprint is correct.
    • The 256-bit encryption is used for the connection to the Management Server.