808bits

FortiGate-VM

FIPS 140-2 certificate #4073 · Fortinet, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4607. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy and with the entropy token installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role. No assurance of the minimum strength of generated keys

Certificate

Certificate number4073
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Software versionsFortiGate-VM 6.2, build 5611

Module description

The FortiGate-VM is a software module designed to execute on a General Purpose Computer (GPC) hardware platform running the VMware hypervisor. The module provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering, traffic shaping, and HA capabilities.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESC2140, C2197, C2199, C2200, C2201
CVLC2197, C2199, C2200, C2201
DRBGC2195, C2198
ECDSAC2197, C2199, C2200, C2201
HMACC2197, C2199, C2200, C2201
KTS
KTS
RSAA1294, A1295, A1296, C2199, C2201
SHSA1294, A1295, C2197, C2199, C2200, C2201

Allowed algorithms

Diffie-Hellman (CVL Certs. #C2197, #C2199, #C2200 and #C2201, key agreement; key establishment methodology provides between 112 and 196 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #C2197, #C2199, #C2200 and #C2201, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength)

Tested configurations

  • FortiGate-VM on VMWare ESXi 6.7 running on a MilDef CS9121 (P/N: 211-3102 Ver: 001) with an Intel® Core™ i7-6822EQ processor and the Araneus Alea II entropy token (single-user mode)
  • FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-165) with an Intel® Xeon® E-2276ME processor and the Araneus Alea II entropy token
  • FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-45) with an Intel® Xeon® E3-1515M processor and the Araneus Alea II entropy token
  • FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-55) with an Intel® Xeon® D-1559 processor and the Araneus Alea II entropy token

Validation history

DateTypeLab
2021-11-17InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-11-17

Source documents