FortiGate-3950B/3951B
Caveat: When operated in FIPS mode and tamper evident seals installed as indicated in the Security Policy
Certificate
| Certificate number | 1866 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | Fortinet, Inc. · website |
| Hardware versions | FortiGate-3950B (C4DE23) and FortiGate-3951B [(C4EL37) and FSM-064 (PE4F79)] with Blank Face Plate (P06698-02) and Tamper Evident Seal: FIPS-SEAL-RED |
| Firmware versions | FortiOS 4.0, build8892, 111128 |
Module description
FortiGate Multi-Threat Security Solutions are dedicated, hardware-based devices that deliver complete content protection against blended threats at the network perimeter or within the internal network.
Security level exceptions
- Cryptographic Module Ports and Interfaces: Level 3
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 1856, 1857, 1858 |
| HMAC | 1103, 1104, 1105 |
| RNG | 974 |
| RSA | 939 |
| SHS | 1633, 1634, 1635 |
| Triple-DES | 1203, 1204, 1205 |
Other algorithms
MD5; HMAC-MD5; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 201 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); SHA-256 (non-compliant); HMAC-SHA-256 (non-compliant); DES
Validation history
| Date | Type | Lab |
|---|---|---|
| 2012-12-19 | Initial | EWA - Canada |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2012-12-19