808bits

Cisco Firepower Threat Defense on Cisco Firepower 2100 Series Appliances

FIPS 140-2 certificate #3258 · Cisco Systems, Inc. · data as of 2026-09-03

Cisco Firepower Threat Defense on Cisco Firepower 2100 Series Appliances, from Cisco Systems, Inc., holds FIPS 140-2 certificate #3258 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals and opacity shield installed as indicated in the Security Policy

Certificate

Certificate number3258
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsFP2110, FP2120, FP2130 and FP2140 with FIPS Kit (AIR-AP-FIPSKIT=) and opacity shield 69-100250-01
Firmware versions6.2

Module description

Quoted from the NIST CMVP entry for this certificate.

Cisco Firepower 2100 Series is a family of four threat-focused NGFW security platforms. These are all next generation security services platforms capable of running multiple (firewall (NGFW), traffic management) security services simultaneously.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES4234, 4905
CKGvendor affirmed
CVL983, 1521
DRBG1317, 1735
ECDSA1254
HMAC2772, 3272
RSA2286, 2678
SHS3471, 4012
Triple-DES2293, 2559

Allowed algorithms

Diffie-Hellman (CVL Certs. #983 and #1521, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #983 and #1521, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-08-09InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-08-09

Source documents