To configure the Palo Alto Networks security platform to operate in FIPS mode:
Power off the device by unplugging it from the electrical outlet.
Connect a console cable from the console port to a computer serial port, and use a terminal program to connect to the Palo Alto Networks device.
The serial parameters are 9600 baud, 8 data bits, no parity, and 1 stop bit.
A USB to serial adapter will be necessary if the computer does not have a serial port.
During the boot sequence, this message will appear:
"Autoboot to default partition in 5 seconds".
Enter "maint" to boot to "maint" partition.
Enter "maint" to enter maintenance mode.
Press "Enter", and the "Maintenance Recovery tool" menu will appear.
Select "Set FIPS Mode" (or fips-cc for later versions) from the menu; once the device has finished rebooting, it will be in FIPS mode.
Note: This will remove all installed licenses and disable the serial port. |