Historical Reason
SP 800-56Arev3 transition - replaced by certificate #4607
Caveat
When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy and with the entropy token installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role. No assurance of the minimum strength of generated keys
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: N/A
- Design Assurance: Level 2
Embodiment
Multi-Chip Stand Alone
Description
The FortiGate-VM is a software module designed to execute on a General Purpose Computer (GPC) hardware platform running the VMware hypervisor. The module provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering, traffic shaping, and HA capabilities.
Tested Configuration(s)
- FortiGate-VM on VMWare ESXi 6.7 running on a MilDef CS9121 (P/N: 211-3102 Ver: 001) with an Intel® Core™ i7-6822EQ processor and the Araneus Alea II entropy token (single-user mode)
- FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-165) with an Intel® Xeon® E-2276ME processor and the Araneus Alea II entropy token
- FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-45) with an Intel® Xeon® E3-1515M processor and the Araneus Alea II entropy token
- FortiGate-VM on VMWare ESXi 6.7 running on a PacStar 451 (P/N: 075-0451-55) with an Intel® Xeon® D-1559 processor and the Araneus Alea II entropy token
Approved Algorithms
AES |
Certs. #C2140, #C2197, #C2199, #C2200 and #C2201 |
CVL |
Certs. #C2197, #C2199, #C2200 and #C2201 |
DRBG |
Certs. #C2195 and #C2198 |
ECDSA |
Certs. #C2197, #C2199, #C2200 and #C2201 |
HMAC |
Certs. #C2197, #C2199, #C2200 and #C2201 |
KTS |
AES Cert. #C2140 and HMAC Certs. #C2199 and #C2201; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
AES Certs. #C2199 and #C2201; key establishment methodology provides 128 or 256 bits of encryption strength |
RSA |
Certs. #A1294, #A1295, #A1296, #C2199 and #C2201 |
SHS |
Certs. #A1294, #A1295, #C2197, #C2199, #C2200 and #C2201 |
Allowed Algorithms
Diffie-Hellman (CVL Certs. #C2197, #C2199, #C2200 and #C2201, key agreement; key establishment methodology provides between 112 and 196 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #C2197, #C2199, #C2200 and #C2201, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength)
Software Versions
FortiGate-VM 6.2, build 5611