Administration mode commands
WatchGuard Command Line Interface Guide
35
Merge
merges the new IP addresses into the
existing list of IP addresses.
Override
replaces all of the existing IP addresses
with the IP addresses on the imported list.
Example
WG(admin)#WG(admin)# import ip blocked
override –ftp 192.168.216.232:/tmp/
blockedip.txt<ENTER>
operation_mode command
WG#admin<ENTER>
WG(admin)#operation_mode
<normal|FIPS|common_criteria>
Effect
This command changes the system mode to
operate in normal, FIPS, or Common Criteria (CC)
mode.
FIPS mode
FIPS 140-2 is a standard that describes government
requirements that cryptographic hardware or
software products must meet. FIPS certification is
required for products that are sold to the
government.
FIPS mode disables or changes the following
functionality:
- Shell access is disabled (for example, sucode).
- Unprotected remote access is disabled, including
telnet and SSH. To login to the box using telnet
requires a physical connection to the console port.
- Non-qualified algorithms are disabled (MD5).
- SSL3.0 is disabled. Support for TLS is still
included.
- A direct crypto interface to the Rapidcore and
other crypto modules is provided for the startup