808bits

McAfee Firewall Enterprise S1104, S2008, S3008, S4016, S5032 and S6032

FIPS 140-2 certificate #2040 · McAfee, Inc. · data as of 2026-09-03

McAfee Firewall Enterprise S1104, S2008, S3008, S4016, S5032 and S6032, from McAfee, Inc., holds FIPS 140-2 certificate #2040 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as indicated in the Security Policy in Section 3. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2040
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorMcAfee, Inc. · website
Hardware versions(FWE-S1104, FWE-S2008, FWE-S3008, FWE-S4016, FWE-S5032 and FWE-S6032) with FRU-686-0089-00
Firmware versions8.3.1

Module description

Quoted from the NIST CMVP entry for this certificate.

McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today's networks and applications.

Approved algorithms (7)

AlgorithmCAVP certificates
AES1833, 2303, 2305
DSA722, 724
HMAC1086, 1418, 1420
RNG964, 1146, 1148
RSA1187, 1189
SHS1612, 1988, 1990
Triple-DES1185, 1451, 1453

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2013-11-15InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-11-15

Source documents