IP-20G, IP-20C, IP-20S, IP-20C-HP, IP-20N, IP-20A, IP-50C, IP-50E
Caveat: When operated in approved mode, installed, initialized and configured as specified in Section 11.3 of the Security Policy. The tamper evident seals installed as indicated in the Security Policy.
Certificate
| Certificate number | 5072 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2030-04-15 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Ceragon Networks Ltd. · website |
| Hardware versions | [IP-20N with TEL P/N: BS-0341-2 and with components: IP-20 TCC-B2-XG-MC: N000082H003; IP-20 TCC-U: N000082H005; IP-20 RMC-B: N000082H004], [IP-20A with TEL P/N: BS-0341-2 and with components IP-20 TCC-B2-XG-MC: N000082H003, IP-20 TCC-U: N000082H005, IP-20 RMC-B: N000082H004], [IP-20G], [IP-20C], [IP-20S], [IP-20C-HP], [IP-50C], and [IP-50E (Rev. 6)] |
| Firmware versions | Release 12.0.1 |
| Entropy | ENT (P) |
Module description
Ceragon Networks IP-20 and IP-50 are a Point-to-Point wireless broadband solution for mission-critical communications in government, industrial and public safety spaces. Integrated with leading networking functionality with the industry most advanced microwave technologies, the platform creates a superior transport solution.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2755 |
| AES-CBC | A2758 |
| AES-CFB128 | A2758 |
| AES-CTR | A680 |
| AES-CTR | A2758 |
| AES-ECB | A2758 |
| AES-GCM | A2758 |
| AES-KW | A2758 |
| AES-OFB | AES 4014 |
| Counter DRBG | A2758 |
| DSA KeyGen (FIPS186-4) | A2758 |
| ECDSA KeyGen (FIPS186-4) | A2758 |
| ECDSA KeyVer (FIPS186-4) | A2758 |
| ECDSA SigGen (FIPS186-4) | A2758 |
| ECDSA SigVer (FIPS186-4) | A2758 |
| HMAC-SHA-1 | A2758 |
| HMAC-SHA2-256 | A2755 |
| HMAC-SHA2-256 | A2758 |
| HMAC-SHA2-384 | A2758 |
| HMAC-SHA2-512 | A2758 |
| KAS-ECC-SSC Sp800-56Ar3 | A2758 |
| KAS-FFC-SSC Sp800-56Ar3 | A2758 |
| KDF IKEv1 | A2756 |
| KDF SNMP | A2757 |
| KDF SSH | A2758 |
| RSA KeyGen (FIPS186-4) | A2758 |
| RSA SigGen (FIPS186-4) | A2758 |
| RSA SigVer (FIPS186-4) | A2758 |
| SHA-1 | A2758 |
| SHA2-256 | A2755 |
| SHA2-256 | A2758 |
| SHA2-384 | A2758 |
| SHA2-512 | A2758 |
| TLS v1.2 KDF RFC7627 | A2758 |
| TLS v1.3 KDF | A2758 |
Allowed algorithms
AES-CBC-MAC (AES-CBC-MAC is allowed for use within OTAR until November 1, 2023.; [IG D.C] AES MAC for Project 25 APCO OTAR )
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-09-26 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-09-26