808bits

SonicWALL TZ 300/TZ 300W, TZ 400/TZ 400W, TZ 500/TZ 500W, TZ 600, SOHOW, SM 9200, SM 9400, SM 9600 and NSₐ 2650, NSₐ 3600, NSₐ 3650, NSₐ 4600, NSₐ 4650, NSₐ 5600, NSₐ 5650, NSₐ 6600

FIPS 140-2 certificate #3289 · SonicWall, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3289
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorSonicWall, Inc. · website
Hardware versions101-500410-54 Rev. E (SOHOW), 101-500403-55 Rev. F (TZ 300), 101-500404-54 Rev. E (TZ 300W), 101-500405-55 Rev. F (TZ 400), 101-500406-54 Rev. E (TZ 400W), 101-500411-56 Rev. G (TZ 500), 101-500412-55 Rev. F (TZ 500W), 101-500413-56 Rev. G (TZ 600), 101-500452-50 Rev. A (NSₐ 2650), 101-500459-54 Rev. E (NSₐ 3600), 101-500514-50, (NSₐ 3650), 101-500458-54 Rev. E (NSₐ 4600), 101-500451-50 (NSₐ 4650), 101-500457-54 Rev. E (NSₐ 5600), 101-500517-50 (NSₐ 5650), 101-500456-54 Rev. E (NSₐ 6600), 101-500455-54 Rev. E (SM 9200), 101-500454-54 Rev. E (SM 9400), 101-500453-54 Rev. E (SM 9600)
Firmware versionsSonicOS v6.5.1

Module description

The SonicWall family of firewalls tightly integrates intrusion prevention, malware protection, Application Intelligence and Control with real-time Visualization. Dell SonicWALL Reassembly-Free Deep Packet Inspection engine scans 100% of traffic and massively scales to meet needs of the most high-performance networks.

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES5346
CKGvendor affirmed
CVL1808, 1809, 1810
DRBG2066
DSA1381
ECDSA1406
HMAC3543
KTS
PBKDFvendor affirmed
RSA2861
SHS4297
Triple-DES2704

Allowed algorithms

Diffie-Hellman (CVL Certs. #1808 and #1809, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1808, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-09-20InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-09-20

Source documents