808bits

Forcepoint Next Generation Firewall

FIPS 140-3 certificate #4867 · Forcepoint · data as of 2026-09-15

Forcepoint Next Generation Firewall, from Forcepoint, holds FIPS 140-3 certificate #4867 at overall level 2. The validation is active, with a sunset date of 2029-11-05. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-11-05, 1146 days away.
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals ACFIPS3 Forcepoint NGFW FIPS Kit installed as indicated in the Security Policy

Certificate

Certificate number4867
StandardFIPS 140-3
Statusactive
Sunset date2029-11-05
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorForcepoint · website
Hardware versions[2201, 2205, 2210, 3401 and 3410] with Forcepoint NGFW FIPS Kit ACFIPS3
Firmware versions6.10.3.26158

Module description

Quoted from the NIST CMVP entry for this certificate.

The NGFW appliances are high-performance network security appliances that add a broad range of built-in security features, including VPN, IPS, anti-evasion, TLS inspection, SD-WAN, and mission-critical application proxies, to a traditional firewall and provides end-to-end protection across the entire enterprise network.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (33)

AlgorithmCAVP certificates
AES-CBCA2155, A2166
AES-CFB128A2209
AES-ECBA2155, A2209
AES-GCMA2155, A2166
AES-KWPA2155
Counter DRBGA2155
ECDSA KeyGen (FIPS186-4)A2155
ECDSA KeyVer (FIPS186-4)A2155
ECDSA SigGen (FIPS186-4)A2155
ECDSA SigVer (FIPS186-4)A2155
HMAC-SHA-1A2155, A2166
HMAC-SHA2-224A2155, A2166
HMAC-SHA2-256A2155, A2166
HMAC-SHA2-384A2155, A2166
HMAC-SHA2-512A2155, A2166
KAS-ECC-SSC Sp800-56Ar3A2155
KAS-FFC-SSC Sp800-56Ar3A2155
KDF IKEv1A2155
KDF IKEv2A2155
KDF SP800-108A2209
PBKDFA2209
RSA KeyGen (FIPS186-4)A2155
RSA SigGen (FIPS186-4)A2155
RSA SigVer (FIPS186-4)A2155
Safe Primes Key GenerationA2155
Safe Primes Key VerificationA2155
SHA-1A2155, A2166
SHA2-224A2155, A2166
SHA2-256A2155, A2166
SHA2-384A2155, A2166
SHA2-512A2155, A2166
SHA3-256A2167
TLS v1.2 KDF RFC7627A2155

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-11-06InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-11-06

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2025-126907.8HIGH

Source documents