808bits

Juniper Networks MX240, MX480, MX960, MX2010, and MX2020 3D Universal Edge Routers with RE1800 Routing Engine and Multiservices MPC

FIPS 140-2 certificate #3386 · Juniper Networks, Inc. · data as of 2026-09-13

Juniper Networks MX240, MX480, MX960, MX2010, and MX2020 3D Universal Edge Routers with RE1800 Routing Engine and Multiservices MPC, from Juniper Networks, Inc., holds FIPS 140-2 certificate #3386 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 1.2 and 6 of the Security Policy

Certificate

Certificate number3386
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsMX240, MX480, MX960, MX2010 and MX2020 with components identified in Security Policy Table 1
Firmware versionsJunos OS 17.4R1-S1

Module description

Quoted from the NIST CMVP entry for this certificate.

Juniper Networks MX Series is a robust portfolio of SDN enabled routing platforms that provide industry leading system capacity, density, security and performance. Key features include support for a wide range of L2/L3 VPN services and advanced broadband network gateway functions, along with integrated routing, switching and security services. Multiservices MPC supports Layer 3 services such as stateful firewall, NAT, IPsec, active flow monitoring and RPM.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES5499, 5500, 5501
CVL1949, 1950
DRBG2168, 2169, 2170
ECDSA1475, 1478
HMAC3648, 3649, 3650, 3651, 3652
KTS
RSA2950, 2951
SHS4407, 4408, 4409, 4410, 4411
Triple-DES2766, 2767, 2768

Allowed algorithms

Diffie-Hellman (CVL Cert. #1950, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1949 and #1950, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-02-28InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-02-28

Source documents