808bits

WatchGuard Firebox M200[1], M300[2], M400[3], M500[4], M440[5], M4600[6], M5600[7]

FIPS 140-2 certificate #2863 · WatchGuard Technologies, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper-evident seals installed as indicated in the Security Policy

Certificate

Certificate number2863
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorWatchGuard Technologies, Inc. · website
Hardware versionsML3AE8 [1,2]; SL1AE24 [5]; KL5AE8 [3,4]; CL4AE24 [6] with WG8583, WG8584 and WG8597; CL5AE32 [7] with WG8583, WG8584, WG8585, WG8022, and WG8598; FIPS Kit P/N: WG8566
Firmware versionsFireware OS v11.11.2

Module description

WatchGuard® Firebox appliances are built for enterprise-grade performance with blazing throughput and numerous connectivity options. Advanced networking features include clustering, high availability (active/active), VLAN support, multi-WAN load balancing and enhanced VoIP security, plus inbound and outbound HTTPS inspection, to give the strong security enterprises need. And the FIREBOX appliances are completely configurable - turn on or off components and services to fit different network security deployment requirements.

Approved algorithms

AlgorithmCAVP certificate
AES3670, 3671, 3672, 3676, 3677, 3960
CVL793
DRBG1160
HMAC2417, 2418, 2419, 2423, 2424, 2580
RSA2023
SHS3085, 3086, 3087, 3091, 3092, 3266
Triple-DES2049, 2050, 2051, 2055, 2056, 2171

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); AES (non-compliant); DES; MD5; PBKDF (non-compliant); TKIP

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-03-16InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-03-16

Source documents