Module Name
FireEye NX Series: NX1500V, NX2500V, NX2550V, NX4500V, NX6500V
Validation Dates
02/20/2018
Caveat
When operated in FIPS mode.
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The FireEye Network Threat Prevention Platform identifies and blocks zero-day Web exploits, droppers (binaries), and multi-protocol callbacks to help organizations scale their advanced threat defenses across a range of deployments, from the multi-gigabit headquarters down to remote, branch, and mobile offices. FireEye Network with Intrusion Prevention System (IPS) technology further optimizes spend, substantially reduces false positives, and enables compliance while driving security across known and unknown threats.
Tested Configuration(s)
- FEYEOS 8.0 on VMware ESXi 6.5 running on Dell R630 (single-user mode)
FIPS Algorithms
AES |
Cert. #4775 |
CKG |
vendor affirmed |
CVL |
Certs. #1419 and #1420 |
DRBG |
Cert. #1653 |
DSA |
Cert. #1286 |
ECDSA |
Cert. #1200 |
HMAC |
Cert. #3185 |
KTS |
AES Cert. #4775 and HMAC Cert. #3185; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
Triple-DES Cert. #2537 and HMAC Cert. #3185; key establishment methodology provides 112 bits of encryption strength |
RSA |
Certs. #2613 and #2616 |
SHS |
Certs. #3916 and #3919 |
Triple-DES |
Cert. #2537 |
Allowed Algorithms
Diffie-Hellman (CVL Cert. #1419 with CVL Cert. #1420, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1419 with CVL Cert. #1420, key agreement; key establishment methodology provides 128 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)