Juniper Networks SRX300, SRX320, SRX340, SRX345, SRX345-DUAL-AC, SRX550M, SRX5400, SRX5600 and SRX5800 Services Gateways
Juniper Networks SRX300, SRX320, SRX340, SRX345, SRX345-DUAL-AC, SRX550M, SRX5400, SRX5600 and SRX5800 Services Gateways, from Juniper Networks, Inc, holds FIPS 140-2 certificate #4663 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Sections 1.2 and 5 of the Security Policy
Certificate
| Certificate number | 4663 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Juniper Networks, Inc · website |
| Hardware versions | [SRX300, SRX320, SRX340, SRX345, SRX345-DUAL-AC, SRX550M, SRX5400, SRX5600 and SRX5800] with JNPR-FIPS-TAMPER-LBLS |
| Firmware versions | JUNOS OS 19.2R1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Juniper Networks SRX Series Services Gateways are a series of secure routers that provide essential capabilities to connect, secure, and manage work force locations sized from handfuls to hundreds of users. By consolidating fast, highly available switching, routing, security, and applications capabilities in a single device, enterprises can economically deliver new services, safe connectivity, and a satisfying end user experience.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (10)
| Algorithm | CAVP certificates |
|---|---|
| AES | C1084, C1085, C1107, C1109, C1129 |
| CVL | C1084, C1085, C1111, C1113 |
| DRBG | C1079, C1084, C1085, C1106, C1107 |
| ECDSA | C1085, C1107, C1151 |
| HMAC | C1052, C1079, C1084, C1085, C1106, C1107, C1109, C1129 |
| KAS-SSC | vendor affirmed |
| KTS | |
| RSA | C1107, C1110, C1151 |
| SHS | C1052, C1079, C1084, C1085, C1106, C1107, C1109, C1129 |
| Triple-DES | C1084, C1085, C1107, C1109, C1129 |
Allowed algorithms
NDRNG
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-11-28 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2023-11-28