808bits

SonicWALL NSA Series 2600, 3600, 4600, 5600

FIPS 140-2 certificate #2751 · SonicWall, Inc. · data as of 2026-09-03

SonicWALL NSA Series 2600, 3600, 4600, 5600, from SonicWall, Inc., holds FIPS 140-2 certificate #2751 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The protocols SSH and SNMP shall not be used when operated in FIPS mode.

Certificate

Certificate number2751
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorSonicWall, Inc. · website
Hardware versionsP/Ns 101-500362-63 Rev. A (NSA 2600), 101-500338-64 Rev. A (NSA 3600), 101-500365-64 Rev. A (NSA 4600), 101-500360-65 Rev. A (NSA 5600)
Firmware versionsSonicOS v6.2.5

Module description

Quoted from the NIST CMVP entry for this certificate.

Enterprise-class security and performance made afordable for small- to medium-sized business. The NSA Series offers industry leading next-generation firewall protection, performance, and scalability. A suite of tools, including intrusion prevention, gateway anti-virus, and anti-spyware plus application intelligence and control, offer granular control through application blocking, bandwidth management and more.

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (7)

AlgorithmCAVP certificates
AES3901
CVL756
DRBG1117
DSA1061
HMAC2531
RSA1986
SHS3214

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); MD5; NDRNG; ARCFOUR; ARCFOUR128; DES; SNMP KDF (non-compliant); SSH KDF (non-compliant); Triple-DES (non-compliant)

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-09-19InitialUL Verification Services, Inc.
2017-06-12UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-09-19, 2017-06-12

Source documents