808bits

Firepower Next-Generation IPS Virtual VMware Cryptographic Module

FIPS 140-3 certificate #4734 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5421. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When installed, initialized and configured as specified in section "Secure Operation" of the Security Policy and operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4734
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Software versions7.0.5

Module description

The virtualized offering of the Cisco FirePOWER next-generation IPS (NGIPS) solution providing the Industry-leading threat protection. Real-time contextual awareness. Full-stack visibility. Intelligent security automation. This virtualized highly effective intrusion prevention system provides reliable performance and a low total cost of ownership. Threat protection can be expanded with optional subscription licenses to provide Advanced Malware Protection (AMP), application visibility and control, and URL filtering capabilities.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2952
AES-CBCA3376
AES-GCMA2952
AES-GCMA3376
Counter DRBGA2952
Counter DRBGA3376
ECDSA KeyGen (FIPS186-4)A2952
ECDSA KeyGen (FIPS186-4)A3376
ECDSA KeyVer (FIPS186-4)A2952
ECDSA KeyVer (FIPS186-4)A3376
ECDSA SigGen (FIPS186-4)A2952
ECDSA SigGen (FIPS186-4)A3376
ECDSA SigVer (FIPS186-4)A2952
ECDSA SigVer (FIPS186-4)A3376
HMAC-SHA-1A2952
HMAC-SHA-1A3376
HMAC-SHA2-256A2952
HMAC-SHA2-256A3376
HMAC-SHA2-384A2952
HMAC-SHA2-384A3376
HMAC-SHA2-512A2952
HMAC-SHA2-512A3376
KDF SSHA2952
KDF SSHA3376
RSA KeyGen (FIPS186-4)A2952
RSA KeyGen (FIPS186-4)A3376
RSA SigGen (FIPS186-4)A2952
RSA SigGen (FIPS186-4)A3376
RSA SigVer (FIPS186-4)A2952
RSA SigVer (FIPS186-4)A3376
Safe Primes Key GenerationA2952
Safe Primes Key GenerationA3376
SHA-1A2952
SHA-1A3376
SHA2-256A2952
SHA2-256A3376
SHA2-384A2952
SHA2-384A3376
SHA2-512A2952
SHA2-512A3376
TLS v1.2 KDF RFC7627A2952
TLS v1.2 KDF RFC7627A3376

Tested configurations

  • Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
  • Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA
  • Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
  • Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA

Validation history

DateTypeLab
2024-07-22InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-07-22

Source documents