808bits

Juniper Networks SRX1500, SRX4100 and SRX4200 Services Gateways

FIPS 140-2 certificate #3136 · Juniper Networks, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with tamper evident seals installed as indicated in the Security Policy

Certificate

Certificate number3136
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsSRX1500 SYS-JB-AC, SRX1500 SYS-JB-DC, SRX4100 SYS-JB-AC, SRX4100 SYS-JB-DC, SRX4200 SYS-JB-AC, SRX4200 SYS-JB-DC; with Tamper Seals JNPR-FIPS-TAMPER-LBLS
Firmware versionsJUNOS 15.1X49-D100

Module description

The SRX1500, SRX4100, SRX4200 Service Gateways offer outstanding protection, performance, scalability, availability, and integrated security services. Designed for high-performance security services architecture, and seamless integration of networking and security in a single platform, the SRX1500, SRX4100, and SRX4200 are best suited for campuses, regional headquarters and enterprise data centers with a focus on application visibility and control, intrusion prevention, advanced threat protection, authentication, confidentiality of information, and integrated cloud-based security.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4631, 4632, 4710, 4711, 4721, 4722
CKGvendor affirmed
CVL1291, 1292, 1293, 1355
DRBG1559, 1560, 1602, 1603
ECDSA1140, 1141, 1163, 1164
HMAC3066, 3067, 3128, 3129, 3138, 3139
KTS
KTS
RSA2528, 2529, 2566, 2567
SHS3795, 3796, 3797, 3798, 3856, 3857, 3866, 3867
Triple-DES2463, 2464, 2496, 2497, 2503, 2504

Allowed algorithms

Diffie-Hellman (CVL Certs. #1291, #1292, #1293 and #1355, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1291, #1292, #1293 and #1355, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-02-23InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-02-23

Source documents