Juniper Networks SRX5600 and SRX5800 Services Gateways
Juniper Networks SRX5600 and SRX5800 Services Gateways, from Juniper Networks, Inc., holds FIPS 140-2 certificate #1602 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 1602 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | Juniper Networks, Inc. · website |
| Hardware versions | (SRX5600BASE-AC, SRX5600BASE-DC, SRX5800BASE-AC and SRX5800BASE-DC) with JNPR-FIPS-TAMPER-LBLS |
| Firmware versions | 10.4R4 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Juniper Networks SRX5000 line of services gateways is the next generation solution for securing the ever increasing network infrastructure and applications requirements for both enterprise and service provider environments. Designed from the ground up to provide flexible processing scalability, I/O scalability, and services integration, the SRX5000 line can meet the network and security requirements of data center hyper-consolidation, rapid managed services deployments, and aggregation of security solutions.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms (7)
| Algorithm | CAVP certificates |
|---|---|
| AES | 1573, 1578 |
| DSA | 484 |
| HMAC | 920, 924 |
| RNG | 847 |
| RSA | 766 |
| SHS | 1393, 1397 |
| Triple-DES | 1030, 1034 |
Other algorithms
RSA (key wrapping; key establishment methodology provides 80 bits of encryption strength; non-compliant); Diffie-Hellman (key agreement; key establishment methodology provides 96 bits of encryption strength; non-compliant)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2011-09-20 | Initial | ICSA |
| 2011-11-08 | Update | ICSA |
| 2013-12-11 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2011-09-20, 2011-11-08, 2013-12-11