Juniper Networks EX4600, QFX5100 and QFX5200 Ethernet Switches
Juniper Networks EX4600, QFX5100 and QFX5200 Ethernet Switches, from Juniper Networks, Inc., holds FIPS 140-2 certificate #3499 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 3499 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Juniper Networks, Inc. · website |
| Hardware versions | EX4600-40F, QFX5100-24Q, QFX5100-48S, QFX5100-48SH, QFX5100-48T, QFX5100-48TH, QFX5100-96S, QFX5200-32C, QFX5200-48Y |
| Firmware versions | JUNOS 18.1R1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
QFX and EX Series switches provide the universal building blocks for multiple data center fabric architectures, including Junos Fusion, Virtual Chassis Fabric (VCF), Ethernet VPN (EVPN)-Virtual Extensible LAN (VXLAN), and IP Fabric. With throughput of up to 6 Tbps per slot, QFX Series switches provide sustained wire-speed switching with low latency and jitter for virtualized data center environments. Redundant fabrics, power, and cooling, combined with separate control and data planes, ensure maximum system availability
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (10)
| Algorithm | CAVP certificates |
|---|---|
| AES | 5388, 5389, 5518, 5520 |
| CKG | vendor affirmed |
| CVL | 1852, 1965 |
| DRBG | 2086, 2087, 2182, 2184 |
| ECDSA | 1424, 1484 |
| HMAC | 3569, 3571, 3575, 3670, 3674, 3677 |
| KTS | |
| RSA | 2882, 2961 |
| SHS | 4322, 4323, 4324, 4429, 4432 |
| Triple-DES | 2715, 2716, 2780, 2782 |
Allowed algorithms
Diffie-Hellman (CVL Certs. #1852 and #1965, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1852 and #1965, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-07-30 | Initial | BAE SYSTEMS APPLIED INTELLIGENCE |
| 2019-09-19 | Update | BAE SYSTEMS APPLIED INTELLIGENCE |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-07-30, 2019-09-19