PAN-OS 10.2 running on PA-220, PA-220R, PA-400 Series, PA-800 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, and PA-7000 Series NGFWs
Caveat: Interim Validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and Physical Kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy
Certificate
| Certificate number | 4760 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Palo Alto Networks, Inc. · website |
| Hardware versions | 910-000102 with Physical Kit 920-000112 [1], 910-000122 with Physical Kit 920-000119 [1], 910-000128 with Physical Kit 920-000084 [1], 910-000147 with Physical Kit 920-000226 [1], 910-000223 with Physical Kit 920-000309 [1], [910-000119 and 910-000120] with Physical Kit 920-000185 [1], [910-000125, 910-000131, 910-000132, and 910-000157] with Physical Kit 920-000186 [1], [910-000162, 910-000163, and 910-000164] with Physical Kit 920-000212 [1], [910-000212, 910-000230, 910-000231, and 910-000232] with Physical Kit 920-000454 [1], [910-000241, 910-000242, 910-000243, and 910-000244] with Physical Kit 920-000333 [1], and [910-000252, 910-000253, and 910-000254] with Physical Kit 920-000320 [2] |
| Firmware versions | 10.2.8-h4 [1] and 10.2.17 [2] |
| Entropy | ENT (P) |
Module description
Palo Alto Networks offers a full line of next-generation security appliances that range from the PA-220, designed for enterprise remote offices, to the PA-7080, which is a modular chassis designed for high-speed datacenters. The platform architecture is based on our single-pass engine, PAN-OS, for networking, security, threat prevention, and management functionality that is consistent across all platforms. The devices differ only in capacities, performance, and physical configuration.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
- Life-cycle assurance: Level 3
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2906 |
| AES-CCM | A2906 |
| AES-CFB128 | A2906 |
| AES-CTR | A2906 |
| AES-GCM | A2906 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2138 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2153 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2165 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2541 |
| Counter DRBG | A2906 |
| ECDSA KeyGen (FIPS186-4) | A2906 |
| ECDSA KeyVer (FIPS186-4) | A2906 |
| ECDSA SigGen (FIPS186-4) | A2906 |
| ECDSA SigVer (FIPS186-4) | A2906 |
| HMAC-SHA-1 | A2906 |
| HMAC-SHA2-224 | A2906 |
| HMAC-SHA2-256 | A2906 |
| HMAC-SHA2-384 | A2906 |
| HMAC-SHA2-512 | A2906 |
| KAS-ECC-SSC Sp800-56Ar3 | A2906 |
| KAS-FFC-SSC Sp800-56Ar3 | A2906 |
| KDF IKEv2 | A2906 |
| KDF SNMP | A2906 |
| KDF SSH | A2906 |
| KDF TLS | A2906 |
| RSA KeyGen (FIPS186-4) | A2906 |
| RSA SigGen (FIPS186-4) | A2906 |
| RSA SigVer (FIPS186-4) | A2906 |
| Safe Primes Key Generation | A2906 |
| Safe Primes Key Verification | A2906 |
| SHA-1 | A2906 |
| SHA2-224 | A2906 |
| SHA2-256 | A2906 |
| SHA2-384 | A2906 |
| SHA2-512 | A2906 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-14 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2025-09-02 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-08-14