does somebody know how to setup Password Policy for management users in PAN OS 4? I am talking about minimum password length, special characters etc.


This option is available by enabling FIPS mode (FIPS 140-2) on the FW, though the following options will also apply:

Federal Information Processing Standards Support:

• To log into the firewall, the browser must be TLS 1.0 compatible.

• All passwords on the firewall must be at least six characters.

• Accounts are locked after the number of failed attempts that is configured on theDevice > Setup > Management page. If the firewall is not in FIPS mode, it can be configured so that it never locks out; however in FIPS mode, and lockout time is required.

• The firewall automatically determines the appropriate level of self-testing and enforces the appropriate level of strength in encryption algorithms and cipher suites.

• Non-FIPS approved algorithms are not decrypted and are thus ignored during decryption.

• When configuring IPSec, a subset of the normally available cipher suites is available.

• Self-generated and imported certificates must contain public keys that are 2048 bits (or more).

• The serial port is disabled.

• Telnet, TFTP, and HTTP management connections are unavailable.

• Surf control is not supported.

• High availability (HA) encryption is required.

• PAP authentication is disabled..

Below is a Knowledgepoint Article regarding FIPS Mode:

FIPS mode (enabling/details) can be referenced as well via your Admin Guide.



I'm trying to gather more info on the impacts of managing the devices in FIPS mode (beyond the admin guide)...I can't access the link about due to permissions errors.  Is the doc-1536 still applicable?

