Unable to upload firmware in FIPS mode in Gen7 Firewalls

Description

If you are operating in FIPS mode on a Gen7 UTM firewall with firmware version higher than 7.0.1-5111, you may encounter an error message when attempting to upload newer firmware. The message will state: "Upload firmware is disabled in FIPS mode. Please turn off FIPS mode to upload."

Image

NOTE: Please note that this error does not occur if your Gen7 Firewall is running firmware older than version 7.0.1-5111. Additionally, this error applies only to Gen7 firewalls and not to Gen6 UTM firewalls.

Cause

This is to comply with the requirements of FIPS 140-3.

Resolution

  1. Navigate to Device | Firmware and Settings | Settings | FIPS/NDPP and disable FIPS mode. Accept the changes.
  2. The firewall will prompt for a restart; please proceed with the restart.
  3. After the firewall restarts, upload the newer firmware you were attempting to install earlier. Boot into the current configurations. For reference, you can visit: [How Can I Upgrade SonicOS Firmware?](https://www.sonicwall.com/support/knowledge-base/how-can-i-upgrade-sonicos-firmware/170504337655458/)
  4. Once the firewall is back up with the new firmware, re-enable FIPS mode.
  5. The firewall will again request a restart, so please restart it.
  6. After the restart, ensure that FIPS mode remains enabled. 

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?