<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Queries about enhanced secure mode in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118649#M2950</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;safely enable Enhanced Secure Mode on VOSS switches without losing config:&lt;/P&gt;&lt;P&gt;Back up the config first.&lt;/P&gt;&lt;P&gt;Prepare a secure-mode-compatible config (adjust passwords, users).&lt;/P&gt;&lt;P&gt;Use console access to enable secure mode — not SSH/Telnet.&lt;/P&gt;&lt;P&gt;Immediately create a new admin user via console.&lt;/P&gt;&lt;P&gt;Reload the modified config after secure mode is enabled.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 06:51:06 GMT</pubDate>
    <dc:creator>nipo535darly</dc:creator>
    <dc:date>2025-04-29T06:51:06Z</dc:date>
    <item>
      <title>Queries about enhanced secure mode</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118632#M2947</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have VOSS fabric switches and we want to enable password complexity rule on all switches. I have faced some issues after enabling enhanced secure mode in 1 switch.&lt;/P&gt;&lt;P&gt;1. All user account deleted, I have logged in with default credential (admin/password) and luckily it asked me to create new user.&lt;/P&gt;&lt;P&gt;2. Now I want to create another user with privilege access but it says that you can not create it with telnet/ssh session. I can create users in operator or auditor mode but not with privilege&lt;/P&gt;&lt;P&gt;3. I read in user guide that when you migrate from enhanced secure mode disabled to enabled mode, configuration file can not guaranteed to be transferred. I have many more switches in which enhanced secure mode needs to be enabled. What will be best way to enable it without loosing config?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 10:13:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118632#M2947</guid>
      <dc:creator>gaurav-pandya</dc:creator>
      <dc:date>2025-04-25T10:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Queries about enhanced secure mode</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118649#M2950</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;safely enable Enhanced Secure Mode on VOSS switches without losing config:&lt;/P&gt;&lt;P&gt;Back up the config first.&lt;/P&gt;&lt;P&gt;Prepare a secure-mode-compatible config (adjust passwords, users).&lt;/P&gt;&lt;P&gt;Use console access to enable secure mode — not SSH/Telnet.&lt;/P&gt;&lt;P&gt;Immediately create a new admin user via console.&lt;/P&gt;&lt;P&gt;Reload the modified config after secure mode is enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 06:51:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118649#M2950</guid>
      <dc:creator>nipo535darly</dc:creator>
      <dc:date>2025-04-29T06:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Queries about enhanced secure mode</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118652#M2951</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I will follow suggested procedure for remaining switches. I am facing issue for couple of switches for which I have already enabled enhanced secure mode. Switches are not accessible through credentials which I have created first time after enabling enhanced secure mode.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 12:22:22 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118652#M2951</guid>
      <dc:creator>gaurav-pandya</dc:creator>
      <dc:date>2025-04-29T12:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Queries about enhanced secure mode</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118663#M2952</link>
      <description>&lt;P&gt;Hi Gaurav,&lt;/P&gt;&lt;P&gt;&lt;EM&gt;1. All user account deleted, I have logged in with default credential (admin/password) and luckily it asked me to create new user.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Response: This is expected behavior - for Enhanced Secured mode we have different users to meet security requirements of various certifications like FIPS, Common Criteria etc.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2. Now I want to create another user with privilege access but it says that you can not create it with telnet/ssh session. I can create users in operator or auditor mode but not with privilege&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Response: Again, due to the same security requirements,&amp;nbsp;Privilege user can only access the switch via the serial console.&lt;/P&gt;&lt;P&gt;3.&lt;EM&gt; I read in user guide that when you migrate from enhanced secure mode disabled to enabled mode, configuration file can not guaranteed to be transferred. I have many more switches in which enhanced secure mode needs to be enabled. What will be best way to enable it without loosing config?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Response: It is true, the security related config and user accounts are not preserved - again this is due to security requirements to zeroize them in case of change Enhanced Secured Mode. Layer 2/Layer 3 and the other config not security related is preserved.&amp;nbsp;The recommendation is to log in via console after you change to Enhanced Secured Mode, admin/admin is the default admin password and you will be asked to change at the first login as you've seen already.&lt;/P&gt;&lt;P&gt;I also noticed a follow-on question - if you are trying to login as a privileged user, you can only do this through the serial console.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 15:15:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/queries-about-enhanced-secure-mode/m-p/118663#M2952</guid>
      <dc:creator>Dinesh_Rego</dc:creator>
      <dc:date>2025-05-01T15:15:13Z</dc:date>
    </item>
  </channel>
</rss>

