Cryptographic Module Validation Program CMVP

Certificate #3516

Details

Module Name
FortiGate-2000E/2500E
Standard
FIPS 140-2
Status
Active
Sunset Date
8/29/2024
Validation Dates
08/30/2019
Overall Level
2
Caveat
When operated in FIPS mode with the tamper evident seals installed as indicated in the Security Policy
Security Level Exceptions
  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The FortiOS is a firmware based operating system that runs exclusively on Fortinet's FortiGate/FortiWiFi product family. The FortiOS provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering and traffic shaping and HA capabilities.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Certs. #4602, #4607 and #4628
CKG vendor affirmed
CVL Certs. #1272, #1287, #1288 and #1329
DRBG Cert. #1543
ECDSA Certs. #1129, #1130 and #1137
HMAC Certs. #3050, #3053 and #3063
KTS AES Cert. #4628 and HMAC Cert. #3063; key establishment methodology provides 128 or 256 bits of encryption strength
RSA Certs. #2512 and #2526
SHS Certs. #3777, #3781 and #3792
Allowed Algorithms
Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 112 and 201 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Hardware Versions
C1AF49 and C1AF51 with Tamper Evident Seal Kits: FIPS-SEAL-RED
Firmware Versions
FortiOS 5.4, b3145, 170602

Vendor

Fortinet, Inc.
1826 Robertson Road
Ottawa, ON K2H 5Z6
Canada

Alan Kaye
akaye@fortinet.com
Phone: 613-225-9381 x87416
Fax: 613-225-2951

Lab

CGI Information Systems & Management Consultants Inc
NVLAP Code: 200928-0