808bits

FortiGate-3401E/3601E/3960E/3980E

FIPS 140-2 certificate #4610 · Fortinet, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy with the tamper evident seals installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role.

Certificate

Certificate number4610
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Hardware versionsFortiGate-3401E (C1AH85), FortiGate-3960E (C1AF81), FortiGate-3601E (C1AH57) and FortiGate-3980E (C1AF63) with Tamper Evident Seal Kit: FIPS-SEAL-RED
Firmware versionsFortiOS 6.2 build 5203

Module description

The FortiGate-3401E, 3601E, 3960E and 3980E are multiple chip, standalone cryptographic modules consisting of production grade components contained in a physically protected enclosure in accordance with FIPS 140-2 Level 2 requirements.

Security level exceptions

  • Roles, Services, and Authentication: Level 3

Approved algorithms

AlgorithmCAVP certificate
AESC1549, C1575, C1576, C1578
CVLC1575, C1576, C1578
DRBGC1573
ECDSAC1575, C1576, C1578
HMACC1575, C1576, C1578
KAS
KAS-SSCA1187
KTS
KTS
RSAA1187, A1252, C1576, C1578
SHSA1187, C1575, C1576, C1578

Allowed algorithms

NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-09-27InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2023-09-27

Source documents