808bits

Juniper Networks SRX1500, SRX4100 and SRX4200 Services Gateways

FIPS 140-2 certificate #3319 · Juniper Networks, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with tamper evident seals installed as indicated in the Security Policy

Certificate

Certificate number3319
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsSRX1500 SYS-JB-AC, SRX1500 SYS-JB-DC, SRX4100 SYS-JB-AC, SRX4100 SYS-JB-DC, SRX4200 SYS-JB-AC and SRX4200 SYS-JB-DC; with Tamper Seals JNPR-FIPS-TAMPER-LBLS
Firmware versionsJunos OS 17.4R1-S1

Module description

The SRX1500, SRX4100, SRX4200 Service Gateways offer outstanding protection, performance, scalability, availability, and integrated security services. Designed for high-performance security services architecture, and seamless integration of networking and security in a single platform, the SRX1500, SRX4100, and SRX4200 are best suited for campuses, regional headquarters and enterprise data centers with a focus on application visibility and control, intrusion prevention, advanced threat protection, authentication, confidentiality of information, and integrated cloud-based security.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES5303, 5304, 5307, 5308, 5339, 5340
CVL1769, 1770, 1773, 1774
DRBG2039, 2041, 2042, 2043, 2046, 2047
ECDSA1388, 1389, 1392, 1393
HMAC3501, 3503, 3504, 3505, 3507, 3508, 3511, 3512, 3536, 3537
KTS
KTS
RSA2838, 2839, 2842, 2843
SHS4255, 4257, 4258, 4259, 4261, 4262, 4265, 4266, 4290, 4291
Triple-DES2679, 2680, 2683, 2684, 2698, 2699

Allowed algorithms

Diffie-Hellman (CVL Certs. #1769, #1770, #1773 and #1774, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1769, #1770, #1773 and #1774, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-11-05InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-11-05

Source documents