SonicWall NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700
Caveat: Interim validation. When operated in approved mode
Certificate
| Certificate number | 4995 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2027-03-30 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | SonicWall, Inc. · website |
| Hardware versions | 101-500668-55 (NSa 4700), 101-500667-52 (NSa 5700), 101-500685-55 (NSa 6700), 101-500684-51 (NSsp 10700), 101-500683-51 (NSsp 11700) and 101-500647-54 (NSsp 13700) |
| Firmware versions | SonicOS/X 7.0.1 |
| Entropy | ENT (P) |
Module description
The SonicWall family of firewalls tightly integrates intrusion prevention, malware protection, Application Intelligence, and Control with real-time Visualization. SonicWALL Reassembly-Free Deep Packet Inspection engine scans 100% of traffic and massively scales to meet the needs of the most high-performance networks.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A6598 |
| AES-GCM | A6598 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2138 |
| ECDSA KeyGen (FIPS186-5) | A6598 |
| ECDSA KeyVer (FIPS186-5) | A6598 |
| ECDSA SigGen (FIPS186-5) | A6598 |
| ECDSA SigVer (FIPS186-5) | A6598 |
| Hash DRBG | A6598 |
| HMAC-SHA-1 | A6598 |
| HMAC-SHA2-256 | A6598 |
| HMAC-SHA2-384 | A6598 |
| HMAC-SHA2-512 | A6598 |
| KAS-ECC-SSC Sp800-56Ar3 | A6598 |
| KAS-FFC-SSC Sp800-56Ar3 | A6598 |
| KDF IKEv1 | A6598 |
| KDF IKEv2 | A6598 |
| RSA KeyGen (FIPS186-5) | A6598 |
| RSA SigGen (FIPS186-5) | A6598 |
| RSA SigVer (FIPS186-5) | A6598 |
| Safe Primes Key Generation | A6598 |
| Safe Primes Key Verification | A6598 |
| SHA-1 | A6598 |
| SHA2-256 | A6598 |
| SHA2-384 | A6598 |
| SHA2-512 | A6598 |
| TLS v1.2 KDF RFC7627 | A6598 |
| TLS v1.3 KDF | A6598 |
Allowed algorithms
DSA (Allowed per I.G. C.K resolution #3; Used only as part of SP 800-56Ar3 key agreement scheme)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-03-31 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-03-31