808bits

Juniper Networks SRX1500, SRX4100, SRX4200 and SRX4600 Services Gateways

FIPS 140-2 certificate #3705 · Juniper Networks, Inc · data as of 2026-09-08

Juniper Networks SRX1500, SRX4100, SRX4200 and SRX4600 Services Gateways, from Juniper Networks, Inc, holds FIPS 140-2 certificate #3705 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition - replaced by certificate #4664. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 1.2 and 6 of the Security Policy

Certificate

Certificate number3705
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc · website
Hardware versions[SRX1500 SYS-JB-AC, SRX1500 SYS-JB-DC, SRX4100 SYS-JB-AC, SRX4100 SYS-JB-DC, SRX4200 SYS-JB-AC, SRX4200 SYS-JB-DC, SRX4600 (AC), SRX4600 (DC)] with JNPR-FIPS-TAMPER-LBLS
Firmware versionsJUNOS OS 19.2R1

Module description

Quoted from the NIST CMVP entry for this certificate.

The SRX1500, SRX4100, SRX4200 and SRX4600 Service Gateways offer outstanding protection, performance, scalability, availability, and integrated security services. Designed for high-performance security services architecture, and seamless integration of networking and security in a single platform, the SRX1500, SRX4100, SRX4200 and SRX 4600 are best suited for campuses, regional headquarters and enterprise data centers with a focus on application visibility and control, intrusion prevention, advanced threat protection, authentication, confidentiality of information, and integrated cloud-based security.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESC1045, C1046, C1049
CVLC1045, C1049, C1050
DRBGC1044, C1045, C1049
ECDSAC1045, C1049
HMACC1043, C1044, C1045, C1046, C1049
KAS-SSCvendor affirmed
KTS
RSAC1045, C1049
SHSC1043, C1044, C1045, C1046, C1049
Triple-DESC1045, C1046, C1049

Allowed algorithms

EC Diffie-Hellman (CVL Cert. #C1049, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2020-09-01InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-09-01

Source documents