808bits

Juniper Networks MX104 3D Universal Edge Router with the Multiservices MIC

FIPS 140-2 certificate #3423 · Juniper Networks, Inc. · data as of 2026-09-08

Juniper Networks MX104 3D Universal Edge Router with the Multiservices MIC, from Juniper Networks, Inc., holds FIPS 140-2 certificate #3423 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 1.2.1 and 6 of the Security Policy

Certificate

Certificate number3423
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsMX104 with RE-MX104 and MS-MIC-16G
Firmware versionsJunos OS 18.2R1

Module description

Quoted from the NIST CMVP entry for this certificate.

MX104 3D Universal Edge router is a modular, highly redundant, mobile back haul optimized full featured MX series platform built for space and power constrained service provider and enterprise facilities. Multiservices MIC supports Layer 3 services such as stateful firewall, NAT, IPsec, active flow monitoring and RPM.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES5605, 5606, 5607
CVL2028, 2029, 2030, 2031
DRBG2247, 2248, 2249
ECDSA1516, 1517
HMAC3736, 3737, 3738, 3739, 3740
KTS
RSA3014, 3015
SHS4500, 4501, 4502, 4503, 4504
Triple-DES2819, 2820, 2821

Allowed algorithms

Diffie-Hellman (CVL Certs. #2030 and #2031, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #2028, #2029, #2030 and #2031, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-03-31InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-03-31

Source documents