Enabling CCEAL4 or FIPS Mode in High Availability
Created On 02/07/19 23:33 PM - Last Updated 02/07/19 23:34 PM
This document describes how to enable and disable CCEAL4 mode on a Palo Alto Networks firewall with high availability.
Before attempting this procedure, read the following article to understand the changes and impact of enabling the FIPS/CCEAL4 mode:
Changes that Occur if FIPS Mode is Enabled.
If you attempt to change an HA pair into FIPS mode, one by one, this will result in both devices in the HA pair to be in a suspended state. Due to the mismatch in the operational mode, both devices entered a suspended state. This is an expected behavior.
To properly configure an HA pair in FIPS mode:
1. Configure both devices for FIPS mode individually.
Note: If both devices are currently in an HA pair, the HA needs to be broken first and then brought into an HA pair.