---
title: "FIPS/CC Mode Guidelines, Best Practices, and Recommendations"
canonical: "https://docs.infoblox.com/space/niosfipscc/1565491335/FIPS%2FCC%20Mode%20Guidelines%2C%20Best%20Practices%2C%20and%20Recommendations"
format: markdown
---
This topic lists some best practices and recommendations that you must follow when using a FIPS/CC-enabled Grid:

- On FIPS/CC-enabled Grids, Infoblox recommends that you upload rulesets and modulesets manually instead of configuring the appliance to automatically receive and apply the latest rulesets and modulesets.
- Infoblox recommends that you do not use any non-FIPS/CC certified services for functioning in the  FIPS/CC mode.
- A minimum length of 20 byte characters is required for the Grid’s shared secret in the FIPS/CC mode.
- Communication with the Infoblox Portal is disabled when the FIPS/CC mode is enabled.
- On new installations of NIOS 9.0.7 and later, Infoblox recommends that you join ND/CP/Reporting members without enabling FIPS as a best practice while joining these members to a FIPS-enabled Grid Master.  
If you still want to join these members after enabling FIPS, you must change the Grid’s shared secret key to 20 characters by using the Grid Manager or WAPI, enable FIPS, and then join these members to a FIPS-enabled Grid.
- On a newly installed 9.0.7 FIPS/CC-enabled Grid, cloud connections cannot be enabled. On disabling the FIPS/CC mode in the Grid, the cloud connections will not be restored. You must do it manually by adding the join token.
- Only TLSv1.2 and TLSv1.3 are enabled on FIPS/CC-enabled Grids.
- From NIOS 8.6.5 and 9.0.7 onwards with FIPS enabled, during the first time login, the ‘admin’ user is prompted to change the password.
- From NIOS 8.6.5 and 9.0.7 onwards, on a FIPS/CC-enabled Grid, the lockout feature has been implemented for CLI over the SSH connection.