300-415 · Question #375
Which two features are not supported when FIPS mode is enabled on a Cisco IOS XE SD-WAN device? (Choose two.)
The correct answer is C. Cisco TrustSec E. PAC Authentication Key. When FIPS mode is enabled on a Cisco IOS XE SD-WAN device, features like Cisco TrustSec and the use of PAC Authentication Keys are not supported due to the strict cryptographic and security requirements of FIPS.
Question
Options
- ASXP reflectors
- BSXP over IPv6
- CCisco TrustSec
- DStatic IP-SLA mapping
- EPAC Authentication Key
How the community answered
(63 responses)- A3% (2)
- B2% (1)
- C89% (56)
- D6% (4)
Why each option
When FIPS mode is enabled on a Cisco IOS XE SD-WAN device, features like Cisco TrustSec and the use of PAC Authentication Keys are not supported due to the strict cryptographic and security requirements of FIPS.
SXP reflectors, which propagate SGTs, are generally supported in FIPS mode unless they rely on a non-FIPS compliant underlying component.
SXP over IPv6 is a protocol transport mechanism and is not specifically disallowed by FIPS mode on SD-WAN devices.
Cisco TrustSec, which uses Security Group Tags (SGTs) for policy enforcement, is not supported in FIPS mode on Cisco IOS XE SD-WAN devices, as TrustSec often relies on security methods not compliant with FIPS standards.
Static IP-SLA mapping is a performance monitoring feature that is typically unaffected by FIPS mode enablement.
The use of PAC Authentication Keys is explicitly not supported when FIPS mode is enabled on Cisco IOS XE SD-WAN devices, as FIPS requires more stringent authentication mechanisms.
Concept tested: FIPS mode compatibility with SD-WAN features
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/m-fips.html
Topics
Community Discussion
No community discussion yet for this question.