Highlights
Highlights
In CMMC Compliance with FortiGate Firewalls – Part 1, we discussed CMMC compliance, FIPS, and how to obtain certified FIPS firmware from Fortinet. In this article we will discuss how to enable FIPS mode on the firewall and do the initial configuration.
It is important to note that FIPS-CC mode can be enabled on all FortiOS versions (which enables FIPS-compliant behavior), but only a subset of firmware is certified for FIPS-CC. Even when using certified builds, FIPS-CC mode is disabled by default after installing the firmware. Additionally, FIPS-CC mode can only be activated/configured using a serial console connection.
Enter the following commands:
show full-configuration
config system fips-cc
set status enable
set entropy-token enable
end
end
Please enter admin administrator password:
New password must conform to the password policy enforced on this device:
minimum-length=8; must contain upper-case-letter lower-case-letter number non-alphanumeric
Warning: most configuration will be lost, do you want to continue? (y/n)
config system interface
edit internal
set status up
set ip <ip_address> <netmask>
set allowaccess ping https
end
After the LAN or internal interface is active and https is allowed, management and configuration can be done from the Web UI. On a side note, with FIPS mode enabled, firewall rules, security profiles, and other settings are disable by default and need to be configured from scratch.
If you have any other questions about CMMC compliance, FIPS mode, or FortiGate firewalls please contact Sikich. You can also check out the following references from the FortiGate community:
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.
About the Author
Joe Gehrke
Joe has over 13 years of experience working in the IT industry. He started my career in a small computer repair shop and continued to evolve his skills to take on new responsibilities as a Help Desk Administrator, Systems Administrator, and at his current role as a Senior Network Consultant in Sikich’s Network Operation’s Center. He has certifications from VMware, Microsoft, and SonicWall.
Sign up for Insights
Join 14,000+ Business executives and decision makers.
Latest Insights
Information Technology
How to Deploy a FIPS-CC Certified FortiGate Virtual Firewall...
October 9, 2025
CMMC
How to Deploy a FIPS-CC-Certified FortiGate Appliance
July 25, 2025
CMMC
How Microsoft Copilot Boosts CMMC Compliance
July 16, 2025
CMMC
Preparing Your Team for CMMC: Key Roles and Responsibilities...
April 15, 2025
CMMC
Risks of Non-Compliance and Lack of Risk Management for CMMC...
March 11, 2025
Technology
Navigating CMMC Compliance and Risk Management: Essential St...
February 25, 2025
Security
Breaking the ‘Too Small to Fail’ Mindset: Modern...
October 29, 2024
Technology
How ISO 9001 and the Sikich STARS Program Can Support CMMC C...
February 27, 2023
Technology
How Sikich’s STARS Program Assists DoD Contractors with CM...
December 6, 2022
Technology
Understanding the Cybersecurity Maturity Model Certification...
March 10, 2020