Phase 2: FIPS Compliance

For organizations requiring adherence to federal security standards, Cisco ISE must be configured in FIPS (Federal Information Processing Standards) Mode. This mode enforces higher cryptographic standards but requires careful configuration of how ISE communicates with network devices.

Enabling FIPS Mode

Enabling FIPS mode is a significant change that affects how ISE handles encryption and authentication.

  1. Warning: Enabling FIPS mode is generally a one-way operation. Ensure you have a full backup of your configuration before proceeding.
  2. Configuration Path: Navigate to Administration > System > Settings > FIPS Mode.
  3. Enablement: Select the option to enable FIPS mode.
  4. System Restart: The ISE nodes will require a restart to initialize the FIPS-compliant cryptographic modules.

Configuring RADIUS Allowed Protocols

When FIPS mode is enabled, ISE restricts the use of "weak" or non-compliant cryptographic algorithms. This often means that standard RADIUS configurations must be updated to use more secure protocols.

Impact on Protocols

Many legacy authentication methods that rely on weak hashing or encryption are disabled or restricted. You must ensure your network devices (switches, wireless controllers) are configured to use FIPS-compliant protocols.

Updating Allowed Protocols in ISE

To ensure your policy sets can still function, you must explicitly allow the compliant protocols:

  1. Navigate to Administration > System > Settings > Allowed Protocols.
  2. Review Protocols: Examine the list of supported protocols.
  3. Select Compliant Protocols: Ensure that only FIPS-compliant protocols are selected. Typically, this includes:
    • EAP-TLS: Using strong, modern cipher suites.
    • PEAP (with appropriate MS-CHAPv2 or EAP-MSCHAPv2 settings): Note that the strength of the underlying TLS tunnel is what matters for FIPS.
    • PAP/ASCII: Use with extreme caution and only where absolutely required and protected by a secure tunnel.
  4. Verification: Once configured, use the Test or Verify features (if available in your version) to ensure that the chosen protocols are accepted by the FIPS engine.

Crucial Step: After updating these settings in ISE, you must also update the configuration on your Network Access Devices (NADs) to ensure they are attempting to use the same compliant protocols.