How to disable FIPS-CC Mode to restore console access

How to disable FIPS-CC Mode to restore console access

6170
Created On 05/31/23 16:38 PM - Last Modified 07/13/24 02:23 AM


Objective


This article explains How to disable FIPS-CC Mode  to restore console access



Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • FIPS-CC mode


Procedure


You can follow the steps below to disable FIPS-CC mode. This will restore console access.

  1.  Access the module’s CLI via SSH, and enter maintenance mode with the command below
    • >debug system maintenance-mode
    • The module will reboot
    • Note: Establish a serial connection to the console port
  2.  After reboot, select “Continue”
  3. Select the “Set FIPS-CC” option, and press enter
  4. Select “Disable FIPS-CC Mode”, and press enter
  5. The module will disable FIPS-CC mode, and perform a factory reset
Alternatively, directly perform a factory reset on the firewall.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI0gCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail