808bits

IBM Security XGS 3100, XGS 4100, XGS 5100, and XGS 7100

FIPS 140-2 certificate #2567 · IBM Security · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 3. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2567
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorIBM Security · website
Hardware versionsXGS 3100, XGS 4100, XGS 5100 and XGS 7100; FIPS-LABELS: FIPS 140 tamper evidence labels P/N 00VM255
Firmware versions5.3.1 and 5.3.3

Module description

The Network Intrusion Prevention System (IPS) automatically blocks malicious attacks while preserving network bandwidth and availability. The appliances are purpose-built, Layer 2 network security appliances that you can deploy either at the gateway or the network to block intrusion attempts, denial of service (DoS) attacks, malicious code, backdoors, spyware, peer-to-peer applications, and a growing list of threats without requiring extensive network reconfiguration. The XGS 3100, XGS 4100, XGS 5100, and XGS 7100 can be securely managed via SiteProtector, which is a central management console

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3280, 3282, 3283, 3284, 3307, 3308, 3309, 3310
CVL463, 465, 466, 467
DRBG738, 740, 741, 742, 756, 757, 758, 759
DSA937, 939, 940, 941
ECDSA633, 635, 636, 637, 640, 641, 642, 643
HMAC2077, 2079, 2080, 2081, 2099, 2100, 2101, 2102
RSA1677, 1679, 1680, 1681, 1691, 1692, 1693, 1694
SHS2718, 2720, 2721, 2722, 2740, 2741, 2742, 2743
Triple-DES1867, 1869, 1870, 1871, 1883, 1884, 1885, 1886

Other algorithms

RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-02-19InitialCOACT INC CAFE LAB
2016-12-20UpdateCOACT INC CAFE LAB

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-02-19, 2016-12-20

Source documents