808bits

FortiGate Next-Generation Firewalls with FortiOS 6.4/7.0

FIPS 140-2 certificate #4497 · Fortinet, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode with the tamper evident seals and entropy token installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role. No assurance of the minimum strength of generated keys

Certificate

Certificate number4497
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Hardware versionsFortiGate-40F (C1AJ53) [1] [2], FortiGateRugged-60F (C1AJ89) [1] [2], FortiGate-60F (C1AJ22) [1] [2], FortiGate-61F (C1AJ23) [1] [2], FortiWiFi-60F (C1AJ24) [1] [2], FortiWiFi-61F (C1AJ25) [1] [2], FortiGate-80F (C1AK17) [1] [2], FortiGate-81F (C1AK18) [1] [2], FortiGate-100F (C1AJ43) [1] [2], FortiGate-101F (C1AJ44) [1] [2], FortiGate-200F (C1AJ87) [1] [2], FortiGate-201F (C1AJ88) [1] [2], FortiGate-600E (C1AH98) [1] [2], FortiGate-601E (C1AH71) [1] [2], FortiGate-1100E (C1AJ67) [1] [2], FortiGate-1101E (C1AJ13) [1] [2], FortiGate-1800F (C1AJ82) [1], FortiGate-1801F (C1AJ83) [1], FortiGate-2600F (C1AK55) [1], FortiGate-2601F (C1AK56) [1], FortiGate-3300E (C1AJ42) [1] [2], FortiGate-3301E (C1AJ38) [1] [2], FortiGate-3400E (C1AH84) [1] [2], FortiGate-3401E (C1AH85) [1] [2], FortiGate-3600E (C1AH86) [1] [2], FortiGate-3601E (C1AH57) [1] [2], FortiGate-4200F (C1AH81) [1], FortiGate-4201F (C1AJ94) [1], FortiGate-4400F (C1AH79) [1], FortiGate-4401F (C1AJ45) [1], FortiGate-6300F (C1AG83) [1], FortiGate-6301F (C1AG85) [1], FortiGate-6500F (C1AG84) [1] and FortiGate-6501F (C1AG86) [1] with Tamper Evident Seal Kit: FIPS-SEAL-RED
Firmware versionsFortiOS 6.4 (FIPS-CC-64-5) [1] and FortiOS 7.0 (FIPS-CC-70-6) [2]

Module description

The FortiGate Next-Generation Firewalls with FortiOS 6.4/7.0 are multiple chip, standalone cryptographic modules consisting of production grade components contained in a physically protected enclosure in accordance with FIPS 140-2 Level 2 requirements.

Security level exceptions

  • Roles, Services, and Authentication: Level 3

Approved algorithms

AlgorithmCAVP certificate
AESA2225, A2229, A2240, A2242, A2269, A2270
CVLA2240, A2242, A2269, A2270
DRBGA2225, A2229
ECDSAA2240, A2242, A2269, A2270
ENT
HMACA2225, A2229, A2240, A2242, A2269, A2270
KAS
KAS-SSCA2269, A2270
KTS
KTS
RSAA2240, A2242, A2269, A2270
SHSA2225, A2229, A2240, A2242, A2269, A2270

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-05-02InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-05-02

Source documents