Panorama 10.2 M-200, M-300, M-600 and M-700
Caveat: Interim Validation. When operated in approved mode and when installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy
Certificate
| Certificate number | 4777 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Palo Alto Networks, Inc. · website |
| Hardware versions | 910-000175 with FIPS Kit 920-000209, 910-000176 with FIPS Kit 920-000208, 910-000270 with FIPS Kit 920-000318, 910-000271 with FIPS Kit 920-000319 |
| Firmware versions | 10.2.3-h1 |
| Entropy | ENT (NP) |
Module description
Panorama M-Series management appliances provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
- Life-cycle assurance: Level 3
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2906 |
| AES-CFB128 | A2906 |
| AES-CTR | A2906 |
| AES-GCM | A2906 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2165 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2518 |
| Counter DRBG | A2906 |
| ECDSA KeyGen (FIPS186-4) | A2906 |
| ECDSA KeyVer (FIPS186-4) | A2906 |
| ECDSA SigGen (FIPS186-4) | A2906 |
| ECDSA SigVer (FIPS186-4) | A2906 |
| HMAC-SHA-1 | A2906 |
| HMAC-SHA2-224 | A2906 |
| HMAC-SHA2-256 | A2906 |
| HMAC-SHA2-384 | A2906 |
| HMAC-SHA2-512 | A2906 |
| KAS-ECC-SSC Sp800-56Ar3 | A2906 |
| KAS-FFC-SSC Sp800-56Ar3 | A2906 |
| KDF SNMP | A2906 |
| KDF SSH | A2906 |
| KDF TLS | A2906 |
| RSA KeyGen (FIPS186-4) | A2906 |
| RSA SigGen (FIPS186-4) | A2906 |
| RSA SigVer (FIPS186-4) | A2906 |
| Safe Primes Key Generation | A2906 |
| Safe Primes Key Verification | A2906 |
| SHA-1 | A2906 |
| SHA2-224 | A2906 |
| SHA2-256 | A2906 |
| SHA2-384 | A2906 |
| SHA2-512 | A2906 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-23 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-08-23