Forcepoint Next Generation Firewall
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals ACFIPS3 Forcepoint NGFW FIPS Kit installed as indicated in the Security Policy
Certificate
| Certificate number | 4867 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-11-05 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Forcepoint · website |
| Hardware versions | [2201, 2205, 2210, 3401 and 3410] with Forcepoint NGFW FIPS Kit ACFIPS3 |
| Firmware versions | 6.10.3.26158 |
Module description
The NGFW appliances are high-performance network security appliances that add a broad range of built-in security features, including VPN, IPS, anti-evasion, TLS inspection, SD-WAN, and mission-critical application proxies, to a traditional firewall and provides end-to-end protection across the entire enterprise network.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2155 |
| AES-CBC | A2166 |
| AES-CFB128 | A2209 |
| AES-ECB | A2155 |
| AES-ECB | A2209 |
| AES-GCM | A2155 |
| AES-GCM | A2166 |
| AES-KWP | A2155 |
| Counter DRBG | A2155 |
| ECDSA KeyGen (FIPS186-4) | A2155 |
| ECDSA KeyVer (FIPS186-4) | A2155 |
| ECDSA SigGen (FIPS186-4) | A2155 |
| ECDSA SigVer (FIPS186-4) | A2155 |
| HMAC-SHA-1 | A2155 |
| HMAC-SHA-1 | A2166 |
| HMAC-SHA2-224 | A2155 |
| HMAC-SHA2-224 | A2166 |
| HMAC-SHA2-256 | A2155 |
| HMAC-SHA2-256 | A2166 |
| HMAC-SHA2-384 | A2155 |
| HMAC-SHA2-384 | A2166 |
| HMAC-SHA2-512 | A2155 |
| HMAC-SHA2-512 | A2166 |
| KAS-ECC-SSC Sp800-56Ar3 | A2155 |
| KAS-FFC-SSC Sp800-56Ar3 | A2155 |
| KDF IKEv1 | A2155 |
| KDF IKEv2 | A2155 |
| KDF SP800-108 | A2209 |
| PBKDF | A2209 |
| RSA KeyGen (FIPS186-4) | A2155 |
| RSA SigGen (FIPS186-4) | A2155 |
| RSA SigVer (FIPS186-4) | A2155 |
| Safe Primes Key Generation | A2155 |
| Safe Primes Key Verification | A2155 |
| SHA-1 | A2155 |
| SHA-1 | A2166 |
| SHA2-224 | A2155 |
| SHA2-224 | A2166 |
| SHA2-256 | A2155 |
| SHA2-256 | A2166 |
| SHA2-384 | A2155 |
| SHA2-384 | A2166 |
| SHA2-512 | A2155 |
| SHA2-512 | A2166 |
| SHA3-256 | A2167 |
| TLS v1.2 KDF RFC7627 | A2155 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-11-06 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-11-06
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2025-12690 | 7.8 | HIGH |