FortiGate-51E [1], FortiGate-61E [2], FortiWifi-61E [3], FortiWifi-90D [4] and FortiGateRugged-60D [5]
FortiGate-51E [1], FortiGate-61E [2], FortiWifi-61E [3], FortiWifi-90D [4] and FortiGateRugged-60D [5], from Fortinet, Inc., holds FIPS 140-2 certificate #3572 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 3572 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Fortinet, Inc. · website |
| Hardware versions | C1AD19 [1], C1AE14 [2], C1AE18 [3], C1AA12 [4], and C1AB57 [5], with Tamper Evident Seal Kits: FIPS-SEAL-RED |
| Firmware versions | FortiOS 5.4, b9791, 170802 [1,4,5] and FortiOS 5.4, b3141, 170602 [2,3] |
Module description
Quoted from the NIST CMVP entry for this certificate.
The FortiOS is a firmware based operating system that runs exclusively on Fortinet's FortiGate/FortiWiFi product family. The FortiOS provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering and traffic shaping and HA capabilities.
Security level exceptions
- Cryptographic Module Ports and Interfaces: Level 3
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
Approved algorithms (8)
| Algorithm | CAVP certificates |
|---|---|
| AES | 4602, 4603, 4607, 4628 |
| CVL | 1272, 1287, 1288, 1329 |
| DRBG | 1543 |
| ECDSA | 1129, 1130, 1137 |
| HMAC | 3050, 3051, 3053, 3063 |
| KTS | |
| RSA | 2509, 2512, 2526 |
| SHS | 3777, 3778, 3781, 3792 |
Allowed algorithms
Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 112 and 200 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-11-25 | Initial | CGI Information Systems & Management Consultants Inc |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-11-25