Submit a ticketCall us

Bridging the ITSM Divide
Integrated help desk and remote support software for faster resolution

Join us on Wednesday, November 29, 2017 at 11 a.m. CT, as we discuss the benefits of effectively integrating your help desk software with remote support solutions to help increase the efficiency of IT administration, improve communication, and decrease mean time to resolution (MTTR) for IT issues of all sizes. This directly impacts end-user satisfaction and your business’ bottom line. Register Now.

Home > Success Center > Netflow Traffic Analyzer (NTA) > NTA Installation Guide > Integrated SolarWinds NTA installation > Enable FIPS for security

Enable FIPS for security

Table of contents
No headers

Updated: September 13, 2017

You can run SolarWinds NTA in FIPS-compliant (Federal Information Processing Standard) mode to comply with computer security and interoperability standards used by non-military US government agencies and contractors.

For the full list of tested Orion products for international standards for computer security, see this site. For a certification letter of Orion FIPS compliance, contact us with your request.

  • If FIPS compliance is required, SolarWinds recommends that you enable FIPS as part of a fresh install instead of as part of an upgrade.
  • Before you enable FIPS ensure that the hardware is FIPS-compliant. See the Microsoft Support knowledge base for more information.
  • Not all Orion Platform products are FIPS-compliant. SolarWinds recommends that you install all FIPS-compliant SolarWinds software on FIPS-compliant servers and maintain all non-compliant SolarWinds software on non-compliant servers.
File:Success_Center/Reusable_content_-_InfoDev/NTA/NTA_Installation_Guide/0130-Uninstall_SolarWinds_NTA/checkbox.gif1. Run the SolarWinds FIPS manager

Start the SolarWinds FIPS 140-2 Manager (SolarWinds.FipsManager.exe).

By default, SolarWinds.FipsManager.exe is located in the C:\Program Files (x86)\SolarWinds\Orion folder.

File:Success_Center/Reusable_content_-_InfoDev/NTA/NTA_Installation_Guide/0130-Uninstall_SolarWinds_NTA/checkbox.gif2. Complete FIPS configuration

Read the welcome text, and click Next. The SolarWinds FIPS 140-2 Manager confirms that the current configuration of your SolarWinds products is FIPS-compliant.

  1. If an installed product is not FIPS-compliant, click Close, remove any non-compliant Orion Platform products from the FIPS-compliant server, and run the FIPS 140-2 Manager again.
  2. If FIPS 140-2 is disabled, select Enable FIPS 140-2, and click Next.
  3. If the FIPS Manager provides a list of objects or saved network discovery definitions that are not FIPS-enabled, complete the following steps.

    To refresh the list of non-compliant objects after editing the credentials, restart the FIPS 140-2 Manager.

    • Click the non-compliant monitored node, and edit its Polling Method to be FIPS-compliant.
      1. Select SNMPv3 as the SNMP Version.
      2. Select FIPS-compliant Authentication and Privacy/Encryption methods, and provide the passwords.
      3. Click Submit.
    • Click the non-compliant network discovery, and edit SNMP credentials to be FIPS-compliant.
      1. Confirm that all SNMP credentials are SNMPv3. Delete or edit any credentials that are not FIPS-compliant SNMPv3.
      2. Confirm that all SNMP credentials use FIPS-compliant Authentication and Privacy/Encryption methods, and provide the passwords.
      3. Complete the Network Sonar Wizard using the updated credentials.
File:Success_Center/Reusable_content_-_InfoDev/NTA/NTA_Installation_Guide/0130-Uninstall_SolarWinds_NTA/checkbox.gif3. Restart the server Click Restart now to restart all relevant SolarWinds services.

While the software is FIPS-compliant, you must choose to use FIPS-compliant polling methods, such as SNMPv3, to monitor and discover nodes.

FIPS-Compliant Methods for SNMPv3

Authentication

SHA1
Privacy or encryptionAES128, AES192, AES256

 

Last modified

Tags

Classifications

Public