FIPS Support in Fireware
Applies To: Locally-managed Fireboxes
The Federal Information Processing Standards Publication 140-3, Security Requirements for Cryptographic Modules (FIPS 140-3), describes the United States Federal Government requirements for cryptographic modules.
Your Firebox is designed and validated to meet the requirements for FIPS 140-3 Level 2 security, when configured in a FIPS-compliant manner with Fireware v12.11. For more information about FIPS validation status, go to Product Certifications on the WatchGuard Trust Center website.
Supported Hardware Models and Fireware Versions
FIPS 140-3 is supported in Fireware v12.11 with these hardware models:
- Firebox T Series: NV5, T20, T20-W, T40, T40-W, T80, T25, T25-W, T45, T45-PoE, T45-W-PoE, T45-CW, T85-PoE
- Firebox M Series: M290, M390, M590, M690, M4800, M5800
Any minor version release of v12.11 is also FIPS 140-3 compliant (v12.11.x).
FIPS 140-2 is supported only in Fireware v12.3.1 for these hardware models:
- Firebox T Series: T15, T15-W, T35, T35-W, T55, T55-W, T70
- Firebox M Series: M200, M270, M300, M370, M400, M440, M470, M500, M570, M670, M4600, M5600
The FIPS 140-2 certification is archived and not recommended for new deployments. Customers that require FIPS certification must use hardware and Fireware compliant with FIPS 140-3. Fireware v12.3.1 is the latest FIPS 140-2 certified version of Fireware. In Fireware v12.4 and higher, Fireware uses a version of OpenSSL that does not support FIPS 140-2.
Firebox Management with FIPS
When you enable FIPS mode on a Firebox, you can only manage the Firebox locally with the Fireware Web UI or CLI. You cannot use WatchGuard System Manager or Firebox System Manager.
The ability to use WatchGuard Cloud to manage the Firebox or add the device to WatchGuard Cloud for visibility, monitoring, and logging is not supported in FIPS mode.
You must use the Fireware Command Line Interface (CLI) to enable FIPS mode on a Firebox. When the Firebox operates in FIPS mode, each time the device is powered on, it runs a set of self-tests required by the FIPS specification. If any of the tests fail, the Firebox writes an error message to the console log file and shuts down.
- For more information about limitations when the Firebox is in FIPS mode, go to About FIPS Mode Limitations.
- For more information about the FIPS CLI commands for FIPS 140-3 support in Fireware v12.11, go to the Command Line Interface Reference.
- For more information about the FIPS CLI commands for FIPS 140-2 support in Fireware v12.3.1, go to the Command Line Interface Reference for Fireware v12.6 and lower.
Enable FIPS Mode
The Firebox does not operate in FIPS mode by default. You must enable FIPS mode from the Firebox CLI.
Caution: If you enable FIPS mode on an unsupported Firebox hardware device model, or FireboxV or Firebox Cloud, you cannot disable FIPS mode from the CLI. To disable FIPS mode on an unsupported device, you must reset the Firebox to factory-default settings. For more information, go to Cannot Disable FIPS Mode on an Unsupported Device Model in the Knowledge Base.
To enable FIPS mode operation:
- Log in to the Fireware CLI.
- Type the command fips enable
The Firebox immediately reboots and automatically begins to run the FIPS self-tests.
If you start the Firebox in recovery mode, the device does not operate in FIPS mode.
Show FIPS Mode
To determine if the Firebox has FIPS mode enabled, type the CLI command show fips.
If you run Fireware v12.11.x, the FIPS version returned is Fireware v12.11. Any minor version release of Fireware v12.11 is FIPS compliant.
Disable FIPS Mode Operation
Issue the CLI command no fips enable to disable FIPS mode operation.
Perform FIPS Zeroization
For FIPS 140-3 support in Fireware v12.11, you can use the CLI command fips zeroize to disable FIPS mode operation and restore the Firebox to factory-default settings. The device automatically reboots after the zeroization process.
About FIPS Mode Limitations
When you use a Firebox in FIPS mode, your use of the device is subject to these limitations. We recommend that you consider your requirements carefully before you decide to operate your Firebox in FIPS mode. In some environments you could be required to use a FIPS-compliant device, but you might not have to configure the device in a FIPS-compliant manner.
To use the Firebox in a FIPS-compliant manner:
Management
- You cannot use WSM or Firebox System Manager.
- You cannot use WatchGuard Cloud to manage the device or add the device to WatchGuard Cloud for visibility, monitoring, and logging.
- You cannot log in to the Firebox from the console port. Console input is disabled.
Unsupported Features and Protocols
- Do not use FireCluster.
- Do not use PPPoE.
- Do not use Mobile VPN with PPTP.
- Do not use RADIUS authentication.
- Do not use the wireless or cellular interfaces on Fireboxes with built-in wireless capabilities.
- Do not use a USB device for backup.
- Do not use the Autotask, ConnectWise, or Tigerpaw PSA integrations.
- PFX file import for certificates is not supported. You must import keys and related certificates individually.
Cryptographic and Authentication Requirements
- You must configure web browsers to use only Transport Layer Security (TLS) v1.2 and v1.3 and FIPS-approved cipher suites.
- You must use a minimum of 2048 bits for all RSA keys.
- You must configure Telnet and SSH clients to use SSH-2 and RSA authentication. If the SSH client uses Diffie-Hellman key exchange, configure the client to use DH 2048-bit or greater.
- You must not use non-approved algorithms (MD5, DES, 3DES, and DSA). If you use these algorithms, a warning message appears in the logs.
- You cannot use DSA for certificate key generation or signature generation in FIPS mode because DSA is not a FIPS-approved algorithm.
Proxy Policies
- In TLS profiles used by proxy policies (HTTPS, SMTP, POP3), do not set Perfect Forward Secrecy (PFS) to None. FIPS 140-3 restricts TLS 1.2 cipher suites to ECDHE-based ciphers, which require PFS. If you set PFS to None, proxy-inspected TLS 1.2 connections fail because no FIPS-approved cipher suites are available. Set PFS to Allowed or Required.
Access Portal
- SSH key-based authentication from Access Portal to OpenSSH-based servers is limited to FIPS-approved algorithms and key sizes, and older key types or ciphers (for example, RSA and DSA keys that rely on deprecated SSH-1 or non-FIPS ciphers such as 3DES) cause private key authentication to fail.
- OpenSSH 7.9P1 or higher is required by the SSH server to support Access Portal connections with a private key.
- You cannot use the Access Portal with an RDP server configured with the NLA security type.
VPN
- Mobile VPN with SSL uses TLS v1.2 and v1.3. Only choose FIPS-approved authentication and encryption algorithms (SHA-1, SHA-256, SHA-512, AES-128, AES-192, AES-256).
- When you configure IPSec VPN tunnels, only choose FIPS-approved authentication and encryption algorithms (SHA-1, SHA-256, SHA-384, SHA-512, AES-128, AES-192, AES-256).
- When you configure IPSec VPN tunnels, choose Diffie-Hellman Group 14 (2048-bit), Group 15 (3072-bit), Group 19 (256-bit elliptic curve), or Group 20 (384-bit elliptic curve) for IKE Phase 1 negotiation.
- When you configure IPSec VPN tunnels, use pre-shared keys or RSA certificates for authentication.
BOVPN Over TLS and Mobile VPN with SSL Peer Requirements
When a Firebox with FIPS 140-3 enabled on Fireware v12.11.9 (or higher v12.11.x version) acts as a branch office virtual private network (BOVPN) over TLS or Mobile VPN with SSL server, the peer must support Extended Master Secret (EMS, RFC 7627).
- The minimum supported peer version is Fireware v12.5.x.
- Legacy peers that run Fireware v12.1.x through v12.3.x are not supported for BOVPN over TLS or Mobile VPN with SSL connections to a FIPS-enabled Firebox.
For end-to-end FIPS 140-3 compliance, enable FIPS mode on both endpoints. The TLS handshake requires only that the peer supports EMS, available in Fireware v12.5.x and later regardless of FIPS mode.