808bits

Cisco Firepower 4100 and Cisco Firepower 9300 Series

FIPS 140-2 certificate #3795 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. When installed with the tamper evident seals and opacity shields, initialized and configured as specified in Section 3 of the Security Policy. This module contains the embedded module Cisco ASA Cryptographic Module validated to FIPS 140-2 under Cert. #3789 operating in FIPS mode

Certificate

Certificate number3795
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsFPR4110-NGFW-K9[1], FPR4115-NGFW-K9[1], FPR4120-NGFW-K9[1], FPR4125-NGFW-K9[1], FPR4140-NGFW-K9[1], FPR4145-NGFW-K9[1], FPR4150-NGFW-K9[1], FPR9K-Sup (SM-24)[2], FPR9K-Sup (SM-36)[2], FPR9K-Sup (SM-40)[2], FPR9K-Sup (SM-44)[2], FPR9K-Sup (SM-48)[2] and FPR9K-Sup (SM-56)[2] with FIPS Kit (Cisco_TEL.FIPS_Kit), and opacity shield 69-100250-01[1] or 800-102843-01[2]
Firmware versions2.6

Module description

This Cisco Firepower eXtensible Operating System (FX-OS) is part of the Cisco Application Centric Infrastructure (ACI) Security Solution and provides an agile, open, built for scalability, consistent control, and simplified management. The FX-OS provides provides high performance, flexible input/output configurations, and scalability. A graphical user interface provides streamlined, visual representation of current chassis status and simplified configuration of chassis features. A command-based interface for configuring features, monitoring chassis status, and accessing advanced troublesho

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2034, 2035, 4905, C784, C1026
CVL1521, C784
DRBG197, 1735, C784, C1026
ECDSA1254, C784
HMAC1233, 3272, C784, C1026
RSA2678, C784
SHS1780, 4012, C784, C1026
Triple-DES1311, 2559, C784, C1026

Allowed algorithms

Diffie-Hellman (CVL Certs. #1521 and #C784, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C784, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-01-21InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-01-21

Source documents