808bits

Panorama 11.0 M-200, M-300, M-600 and M-700

FIPS 140-3 certificate #4927 · Palo Alto Networks, Inc. · data as of 2026-08-28
Active. Sunset date 2026-12-18, 111 days away.
Caveat: Interim Validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy

Certificate

Certificate number4927
StandardFIPS 140-3
Statusactive
Sunset date2026-12-18
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks, Inc. · website
Hardware versions910-000175 with 920-000209, 910-000176 with 920-000208, 910-000270 with 920-000318, 910-000271 with 920-000319
Firmware versions11.0.4

Module description

Panorama M-Series management appliances provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall.

Security level exceptions

  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3453
AES-CFB128A3453
AES-CTRA3453
AES-GCMA3453
Conditioning Component AES-CBC-MAC SP800-90BA2165
Conditioning Component AES-CBC-MAC SP800-90BA2518
Counter DRBGA3453
ECDSA KeyGen (FIPS186-4)A3453
ECDSA KeyVer (FIPS186-4)A3453
ECDSA SigGen (FIPS186-4)A3453
ECDSA SigVer (FIPS186-4)A3453
HMAC-SHA-1A3453
HMAC-SHA2-224A3453
HMAC-SHA2-256A3453
HMAC-SHA2-384A3453
HMAC-SHA2-512A3453
KAS-ECC-SSC Sp800-56Ar3A3453
KAS-FFC-SSC Sp800-56Ar3A3453
KDF SNMPA3453
KDF SSHA3453
RSA KeyGen (FIPS186-4)A3453
RSA SigGen (FIPS186-4)A3453
RSA SigVer (FIPS186-4)A3453
Safe Primes Key GenerationA3453
Safe Primes Key VerificationA3453
SHA-1A3453
SHA2-224A3453
SHA2-256A3453
SHA2-384A3453
SHA2-512A3453
TLS v1.2 KDF RFC7627A3453

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-12-19InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-12-19

Source documents