808bits

Juniper Networks MX240, MX480, MX960, MX2010, and MX2020 3D Universal Edge Routers with RE-S-X6-64G/REMX2K-X8-64G Routing Engine and Multiservices MPC

FIPS 140-2 certificate #3379 · Juniper Networks, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 1.2 and 6 of the Security Policy

Certificate

Certificate number3379
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsMX240, MX480, MX960, MX2010 and MX2020 with components identified in Security Policy Table 1
Firmware versionsJunos OS 18.1R1

Module description

Juniper Networks MX Series is a robust portfolio of SDN enabled routing platforms that provide industry leading system capacity, density, security and performance. RE-S-X6-64G/REMX2K-X8-64G routing engines provide enhanced scaling and performance. Key features include support for a wide range of L2/L3 VPN services and advanced broadband network gateway functions, along with integrated routing, switching and security services. Multiservices MPC supports Layer 3 services such as stateful firewall, NAT, IPsec, active flow monitoring and RPM.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES5466, 5467, 5479
CVL1917, 1918, 1919, 1932
DRBG2146, 2147, 2148
ECDSA1462, 1468
HMAC3622, 3623, 3624, 3625, 3634
KTS
KTS
RSA2936, 2943
SHS4385, 4386, 4387, 4388, 4397
Triple-DES2751, 2752, 2758

Allowed algorithms

Diffie-Hellman (CVL Certs. #1919 and #1932, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1917, #1918, #1919 and #1932, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-02-21InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-02-21

Source documents