<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - FIPS Disabled but SSH using FIPS!?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4074765#M559899</link>
    <description>&lt;P&gt;Hi Melaine&lt;/P&gt;&lt;P&gt;Apologies for the late follow up, TAC found a bug in 2.6 patch 4 and have been able to replicate, it is apparently fixed in 2.6 patch 5 though I've yet to obtain downtime to test, due to current restrictions.&amp;nbsp; As soon as I'm able to, I'll post an update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2020 10:08:08 GMT</pubDate>
    <dc:creator>R M C</dc:creator>
    <dc:date>2020-04-27T10:08:08Z</dc:date>
    <item>
      <title>ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003185#M454814</link>
      <description>&lt;P&gt;Merry Christmas Everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a quick query...&lt;/P&gt;&lt;P&gt;I have a pair of ISE nodes running 2.4 Patch 10 that seems to insist on trying to use FIPS for SSH/SFTP which I believe is causing the connecttion to fail as the remote server is not FIPS capable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FIPS Mode is disabled via the GUI, though I can't see where to change this on the CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated, below is the error when testing SSH.&amp;nbsp; This is currently preventing me upgrading to 2.6.&amp;nbsp; I have another pair of ISE boxes, running the same version/patch which do not experience this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ise01/admin# ssh &amp;lt;serverIP&amp;gt; diserepo&lt;BR /&gt;Operating in CiscoSSL FIPS mode&lt;BR /&gt;FIPS mode initialized&lt;BR /&gt;ssh_dispatch_run_fatal: Connection to &amp;lt;serverIP&amp;gt; port 22: error in libcrypto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 15:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003185#M454814</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2019-12-24T15:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003199#M454815</link>
      <description>&lt;P&gt;Have you tried to stop and restart the ISE services?&amp;nbsp; Or maybe a reboot of the node?&amp;nbsp; If a reboot doesn't resolve the issue, then I would recommend opening a TAC case.&amp;nbsp; There is no option on the CLI to disable FIPS.&amp;nbsp; It sounds like FIPS is disabled but for some reason, SSH didn't get the message.&amp;nbsp; That's why I think a reboot may help.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 16:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003199#M454815</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-12-24T16:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003254#M454817</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773"&gt;@Colby LeMaire&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Have you tried to stop and restart the ISE services?&amp;nbsp; Or maybe a reboot of the node?&amp;nbsp; If a reboot doesn't resolve the issue, then I would recommend opening a TAC case.&amp;nbsp; There is no option on the CLI to disable FIPS.&amp;nbsp; It sounds like FIPS is disabled but for some reason, SSH didn't get the message.&amp;nbsp; That's why I think a reboot may help.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;agree if that fails might be a bug, check with TAC&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 20:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003254#M454817</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-24T20:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003287#M454820</link>
      <description>&lt;P&gt;Thanks Colby and Jason&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had try restarting the services and then when that didn't fix it a hard boot but alas neither worked.&amp;nbsp; It looks like a call to TAC.&amp;nbsp; I'll update with the findings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again and have a great Christmas.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 02:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4003287#M454820</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2019-12-25T02:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4074743#M559897</link>
      <description>Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/96928"&gt;@R M C&lt;/a&gt;, any findings here? think in advance</description>
      <pubDate>Mon, 27 Apr 2020 09:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4074743#M559897</guid>
      <dc:creator>EdoukouMelaine81749</dc:creator>
      <dc:date>2020-04-27T09:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4074765#M559899</link>
      <description>&lt;P&gt;Hi Melaine&lt;/P&gt;&lt;P&gt;Apologies for the late follow up, TAC found a bug in 2.6 patch 4 and have been able to replicate, it is apparently fixed in 2.6 patch 5 though I've yet to obtain downtime to test, due to current restrictions.&amp;nbsp; As soon as I'm able to, I'll post an update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 10:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4074765#M559899</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2020-04-27T10:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4092455#M560698</link>
      <description>&lt;P&gt;This fails for me in 2.6 patch 6.&amp;nbsp; I'm opening a case now.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 21:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4092455#M560698</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2020-05-26T21:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4115475#M561587</link>
      <description>&lt;P&gt;It is still failing for me in 2.6 patch 6 too.&amp;nbsp; TAC are still investigating.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 17:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4115475#M561587</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2020-07-08T17:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4138781#M562421</link>
      <description>&lt;P&gt;Same problem for me as well in 2.6 patch 7. Have you found solution ?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 13:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4138781#M562421</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2020-08-20T13:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4139233#M562435</link>
      <description>&lt;P&gt;There are a couple of bugs that could be involved here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCum13116" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCum13116&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt88460" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt88460&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest running the following commands from the CLI, capturing the output from the console, and opening a TAC case to investigate further.&lt;/P&gt;
&lt;PRE&gt;debug transfer 7
debug copy 7
show repository &amp;lt;reponame&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 21 Aug 2020 07:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4139233#M562435</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-08-21T07:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4140350#M562482</link>
      <description>Hi Pradeep&lt;BR /&gt;&lt;BR /&gt;My case is still open, apparently it is a 'feature' that was enabled. They are currently in discussions as to whether this will be disabled in a future release, though that's still with the dev team. Unusually, it doesn't seem to affect SFTP....&lt;BR /&gt;&lt;BR /&gt;I'll post an update as soon as I hear further.&lt;BR /&gt;Thanks</description>
      <pubDate>Mon, 24 Aug 2020 11:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4140350#M562482</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2020-08-24T11:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4305123#M566023</link>
      <description>&lt;P&gt;I ended up closing the TAC case, I was no longer able to replicate the issue, I'm not sure if the server team had change encryption ciphers, they certainly hadn't enabled FIPS compliance.&amp;nbsp; But it is now working....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is an explanation as to how the repository lookup worked though SSH didn't, I hope it helps someone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sh repo command works because it activates SFTP protocol in its underlying script, unlike the SSH command itself (e.g. SSH to Microsoft server will use Microsoft server ciphers, sh repo &amp;lt;name&amp;gt; will SFTP to SFTP server and use the ciphers that are available in that application’s software/version level – again both use-cases being the same L3 address).&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 18:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4305123#M566023</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2021-03-10T18:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4493799#M570719</link>
      <description>&lt;P&gt;RMC,&amp;nbsp; Do you remember the TAC case number?&amp;nbsp; I'm running v2.7 p4 and I have this problem when trying to set up FIPS mode for a STIG.When I try to enable FIPS I get the same error.&amp;nbsp; No matter what boxes I deselect it will never go enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error Message: 'The following "Allowed Protocols" are configured to use non-FIPS compliant protocols. FIPS can not be enabled until these "Allowed Protocols" are deleted or they are edited to use only FIPS compliant protocols.'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 21:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4493799#M570719</guid>
      <dc:creator>davsnet2000</dc:creator>
      <dc:date>2021-10-27T21:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4531537#M572206</link>
      <description>&lt;P&gt;I had the same issue.&amp;nbsp; I disabled MD5 hash and was able to enable FIPS.&amp;nbsp; But, I now can't SSH into ISE since I turning FIPS on.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4531537#M572206</guid>
      <dc:creator>tucker1231</dc:creator>
      <dc:date>2022-01-14T12:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - FIPS Disabled but SSH using FIPS!??</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4637378#M575674</link>
      <description>&lt;P&gt;Hi Davsnet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies for the delay, my issue was the opposite, I had FIPS disabled however the connection was defaulting to FIPS enabled.&amp;nbsp; The issue appear to resolve itself unfortunately and I could no longer replicate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 11:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fips-disabled-but-ssh-using-fips/m-p/4637378#M575674</guid>
      <dc:creator>R M C</dc:creator>
      <dc:date>2022-06-23T11:58:54Z</dc:date>
    </item>
  </channel>
</rss>

