<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS Mode in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444224#M42196</link>
    <description>&lt;P&gt;Good question. Whatever I am reading so far on "SNMP &amp;amp; FIPS Mode": FIPS mode requires Simple Network Management Protocol version 3 (SNMPv3) with the&lt;STRONG&gt; authentication&lt;/STRONG&gt; and &lt;STRONG&gt;privacy&lt;/STRONG&gt; protocol option (As SNMP version 1 and version 2 use a "community" string mechanism, which is sent as clear text between an SNMP manager and an SNMP agent and hence forbidden by FIPS).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FIPS-Compliant Algorithm for SNMPv3 Communication:&lt;BR /&gt;authentication protocol = sha&lt;BR /&gt;privacy protocol = aes128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steps to configure SNMPv3 users in a cluster for Ontap 9: (FIPS mode)&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/networking/configure_snmpv3_users_in_a_cluster.html#snmpv3-security-parameters" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/networking/configure_snmpv3_users_in_a_cluster.html#snmpv3-security-parameters&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To find out in my environment, I went to system manager, settings, and then under snmp, I noticed we have community string enabled with "NO SNMPv3" user configured under snmpv3 tab, so that's a clear indication that our environment is using v1 &amp;amp; v2 and of course FIPS disabled.&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2023 09:49:46 GMT</pubDate>
    <dc:creator>Ontapforrum</dc:creator>
    <dc:date>2023-05-12T09:49:46Z</dc:date>
    <item>
      <title>FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444176#M42183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am researching FIPS mode on our NetApp clusters and am trying to determine whether or not to enable it. I would love to hear recommendations or insights from anyone who has done this. I plan to test on a simulator but am not sure what to test. What potential functionality could be negatively impacted by making this change? I've read the articles below. Any thoughts appreciated! Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/networking/configure_network_security_using_federal_information_processing_standards_@fips@.html?q=tr-4569#enable-fips" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/networking/configure_network_security_using_federal_information_processing_standards_@fips@.html?q=tr-4569#enable-fips&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netapp.com/media/10674-tr4569.pdf" target="_blank"&gt;https://www.netapp.com/media/10674-tr4569.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:49:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444176#M42183</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2025-06-04T09:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444178#M42184</link>
      <description>&lt;P&gt;Generally speaking, it usually does not hurt to enable FIPS mode. It removes unsecure ciphers/exchanges for SSH and removes older SSL items. I have heard it can affect LDAP (usually in a positive way with the manipulation it provides).&lt;/P&gt;&lt;P&gt;I almost always enable FIPS mode when setting up a new cluster for my customers. I have never had to turn it off.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 21:40:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444178#M42184</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2023-05-10T21:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444193#M42188</link>
      <description>&lt;P&gt;OK thanks&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp;. We still have a few legacy Windows boxes and I wonder about them being affected in particular, in some unknown way. Specifically we still have a handful of Windows Server 2003/2008R2 boxes we're trying to get rid of. But from what you're saying, it sounds like this is only about our ability to SSH into NetApp clusters. I've never configured LDAP settings since we've started using NetApp so I doubt that's a factor. We still have SMB1 enabled on three older CIFS Servers but it doesn't sound like that has an impact?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else have a comment? Has anyone experienced issues with enabling this?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 13:28:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444193#M42188</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2023-05-11T13:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444196#M42189</link>
      <description>&lt;P&gt;I don't have personal experience to share but few pointers that may hopefully help influence your decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does enabling FIPS cause any issues with NFS/CIFS Protocols?&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/Does_enabling_FIPS_cause_any_issues_with_NFS_or_CIFS_Protocols" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/Does_enabling_FIPS_cause_any_issues_with_NFS_or_CIFS_Protocols&lt;/A&gt;&lt;/P&gt;&lt;P&gt;No, NFS and CIFS do not use SSL/TLS encryption. FIPS mode enforces security of SSL/TLS traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related kb/discussions:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/While_FIPS_is_enabled_on_Data_ONTAP_9.0_%2C_users_are_unable_to_SSH_into_the_cluster_or_node" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/While_FIPS_is_enabled_on_Data_ONTAP_9.0_%2C_users_are_unable_to_SSH_into_the_cluster_or_node&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/os/After_enabling_FIPS_the_following_error_is_received%3A_Cannot_enable_the_HTTP_protocol_because_FIPS_is_enabled" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/os/After_enabling_FIPS_the_following_error_is_received%3A_Cannot_enable_the_HTTP_protocol_because_FIPS_is_enabled&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/mgmt/OTV/SRA/SRM_planned_migration_fails_after_configuring_FIPS" target="_blank"&gt;https://kb.netapp.com/mgmt/OTV/SRA/SRM_planned_migration_fails_after_configuring_FIPS&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/os/SSH_public_key_authentication_fails_on_FIPS_enabled_cluster" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/os/SSH_public_key_authentication_fails_on_FIPS_enabled_cluster&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.netapp.com/t5/ONTAP-Discussions/FIPS-mode-any-issues-after-enabling/m-p/134184" target="_blank"&gt;https://community.netapp.com/t5/ONTAP-Discussions/FIPS-mode-any-issues-after-enabling/m-p/134184&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153565" target="_blank"&gt;https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153565&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 14:01:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444196#M42189</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-05-11T14:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444205#M42190</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;this is extremely helpful! Great list of links. I read through them and they gave me a better sense of this change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Couple of additional questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Regarding System Manager, I use HTTPS but the article says you have to have a digital cert. Even though we use a cert manager, the browser still sees them as invalid (for some reason) so we still get the warning each time we log in to a cluster. Would FIPS hiccup on that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Would FIPS impact Active IQ Unified Manager, SnapCenter, the SnapCenter VMware Plug-In, the OnTAP Tools VMware Plug-In, or the old SnapDrive tool? (SnapDrive is unfortunately still in use on some old 2008R2 servers due to compatibility issues). NOTE: OnTAP Tools connections use TLS/443 so I think we're good there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Any issues with PowerShell toolkit commands? I'm using&amp;nbsp;version 9.11.1.2208. I'm guessing the fix mentioned in one of your links isn't needed anymore since it was posted in 2017/2018 - I'm assuming the toolkit has been patched by then to 'just work'. Am I correct?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 15:28:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444205#M42190</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2023-05-11T15:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444212#M42191</link>
      <description>&lt;P&gt;One additional thought. The article below says (under "View FIPS Compliance Status") that "&lt;SPAN&gt;A reboot is required to make sure that all applications in the cluster are running the new security configuration, and for all changes to FIPS on/off mode, protocols, and ciphers."&amp;nbsp; This seems to imply that, despite the earlier note that reboots aren't required after 9.9.1, they actually&amp;nbsp;&lt;STRONG&gt;are&lt;/STRONG&gt; required if you want to "make sure" it is working. Am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/networking/configure_network_security_using_federal_information_processing_standards_@fips@.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/networking/configure_network_security_using_federal_information_processing_standards_@fips@.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 20:01:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444212#M42191</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2023-05-11T20:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444214#M42192</link>
      <description>&lt;P&gt;Just started trying to enable FIPS on the simulator and read through this error. We use SNMP but have no idea which version we are using. I suspect v1 or v2c but have no way of determining it. Any ideas?&lt;BR /&gt;&lt;BR /&gt;Warning: This command will enable FIPS compliance and can potentially cause some non-compliant components to fail.&amp;nbsp;MetroCluster and Vserver DR require FIPS to be enabled on both sites in order to be compatible. An SNMP users or&amp;nbsp;SNMP traphosts that are non-compliant to FIPS will be deleted automatically. An SNMPv1 user, SNMPv2c user or&amp;nbsp;SNMPv3 user (with none or MD5 as authentication protocol or none or DES as encryption protocol or both) is&amp;nbsp;non-compliant to FIPS. An SNMPv1 traphost or SNMPv3 traphost (configured with an SNMPv3 user non-compliant to&amp;nbsp;FIPS) is non-compliant to FIPS. Incoming web service requests over the insecure HTTP protocol will be rejected.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 20:37:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444214#M42192</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2023-05-11T20:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444219#M42193</link>
      <description>&lt;P&gt;A couple things:&lt;/P&gt;&lt;P&gt;1. Anything that uses ssl may be affected. It depends on the TLS version negotiations that take place. Enabling FIPS removes older TLS versions&lt;/P&gt;&lt;P&gt;&amp;nbsp;2. enabling FIPS. I’di recall, 9.8 and lower requires every node to be rebooted (takeover/giveback). 9.9.1 and higher is done on the fly/no reboot needed&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 00:18:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444219#M42193</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2023-05-12T00:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444224#M42196</link>
      <description>&lt;P&gt;Good question. Whatever I am reading so far on "SNMP &amp;amp; FIPS Mode": FIPS mode requires Simple Network Management Protocol version 3 (SNMPv3) with the&lt;STRONG&gt; authentication&lt;/STRONG&gt; and &lt;STRONG&gt;privacy&lt;/STRONG&gt; protocol option (As SNMP version 1 and version 2 use a "community" string mechanism, which is sent as clear text between an SNMP manager and an SNMP agent and hence forbidden by FIPS).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FIPS-Compliant Algorithm for SNMPv3 Communication:&lt;BR /&gt;authentication protocol = sha&lt;BR /&gt;privacy protocol = aes128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steps to configure SNMPv3 users in a cluster for Ontap 9: (FIPS mode)&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/networking/configure_snmpv3_users_in_a_cluster.html#snmpv3-security-parameters" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/networking/configure_snmpv3_users_in_a_cluster.html#snmpv3-security-parameters&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To find out in my environment, I went to system manager, settings, and then under snmp, I noticed we have community string enabled with "NO SNMPv3" user configured under snmpv3 tab, so that's a clear indication that our environment is using v1 &amp;amp; v2 and of course FIPS disabled.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 09:49:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444224#M42196</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-05-12T09:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444246#M42200</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;. Well, we have a community string so I guess I need to do some research on SNMPv3 before moving forward with the FIPS change. Thank you for your thoughts!&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 12:57:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/FIPS-Mode/m-p/444246#M42200</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2023-05-12T12:57:11Z</dc:date>
    </item>
  </channel>
</rss>

